Privacy policy
This is a demonstration product, and this page is illustrative rather than a real privacy policy. Before operating zrdio commercially, replace it with a policy reviewed for the privacy laws that apply to you and your users.
What we store
- Account data: your name, email address and a salted, memory-hard hash of your password. Never the password itself.
- Workspace content: projects, generated site versions, scan reports and content you create.
- Session data: a hashed session token, your browser's user-agent string and IP address, used for the signed-in devices list.
- Usage data: counts of AI generations and scans, used for plan limits and shown to you on the billing page.
What we send to third parties
- AI generation: when an API key is configured, your briefs and site content are sent to the AI provider to produce the output you requested. In simulation mode nothing leaves the server.
- Payments: when Stripe is configured, billing details are handled by Stripe. Card numbers never touch our servers.
- Scanning: scans fetch the URL you specify from our server. We send that site a normal HTTP request identifying our crawler.
What we do not do
We do not sell your data, run third-party advertising trackers, or read your generated content for any purpose other than serving it back to you.
Retention and deletion
Deleting a project permanently removes its versions, scans, findings and content. Deleting your account removes your user record, sessions and notifications. Invoices are retained as required by accounting law.
Cookies
One cookie: the session token that keeps you signed in. It is HttpOnly, SameSite=Lax and, in production, Secure. There are no tracking cookies, which is why there is no cookie banner.