Privacy Policy
Last updated: August 20, 2026
AppZoo ("we", "us") makes business software run by AI assistants. This policy explains what we collect, why, who we share it with, and what you can make us do about it. It covers appzoo.ai and every app inside it.
What we collect
Most of what we hold is content you put into the product on purpose. We group it as follows.
Account and workspace
Your name, email address, profile photo, sign-in provider, the workspaces you belong to, and your role in each. Created when you sign up; needed to give you an account at all.
Work content
Tasks, notes, knowledge-base documents, uploaded files, calendar and schedule entries, and anything else you or your team create in an app.
Conversations
Full message history with the AI assistants, including anything you paste into a chat, plus the memory the assistants keep about your business so they don't ask twice.
Customer records
If you use Customer Center or Sales: the contacts, companies, deals and offerings you enter — which usually means personal data about your customers. You are the controller of that data; we process it for you.
Financial data
If you connect a bank through Cashflow: account balances and transaction history retrieved via Plaid. We never receive your bank login — Plaid holds that. Read our subprocessor list for what Plaid is and does.
Connected accounts
If you connect Gmail, Google Calendar, Google Drive, Outlook, GitHub or Mixpanel through Switchboard: an access token for that account, encrypted at rest with AES-256-GCM, plus whatever the connector reads on your instruction. Disconnecting deletes the token.
Billing
Subscription status, credit balance and usage ledger. Card details go straight to Stripe and never touch our servers — we store only Stripe's customer identifier.
Technical and usage
Server logs (IP address, user agent, request path, timestamps), AI-usage volume per workspace for fair-use limits, and — only if you consent — product analytics and session replay. See Cookies below.
Why we're allowed to
Where the GDPR applies, our lawful bases are: contract for everything needed to run the account and the apps; legitimate interests for security, abuse prevention, fair-use enforcement and keeping the service working; and consent for analytics, session replay and marketing email. You can withdraw consent at any time without affecting the service.
How AI processing works
The assistants are built on large language models we do not operate. When you send a message or ask an assistant to do something, the relevant content — your prompt, and the workspace context needed to answer it — is sent to Anthropic, Google or OpenAI for processing, and the response comes back to you.
We use these providers under their commercial API terms, which commit them not to train their models on the content we send. We are not able to promise more than the providers promise us. If your business can't send its data to a third-party model at all, App Zoo is not the right product for you today, and we would rather tell you that now.
Who else touches your data
We do not sell personal data, and we do not share it for advertising — there is no ad network, no audience building, and no data broker in this product. We do use service providers to run it. The complete list, with what each one does and where it processes, is on the subprocessor page.
We may also disclose data where we are legally required to, or to establish or defend a legal claim. If we're ever compelled to hand over your workspace data, we will tell you unless we are legally forbidden from doing so.
Cookies and tracking
Nothing optional runs before you say yes. The first time you visit you're asked, and until you answer, no analytics or session-replay script is loaded at all. You can change your answer any time from the Cookies link in the footer. We honor Global Privacy Control and Do Not Track: if your browser sends either, we record a refusal and never ask.
Strictly necessary — always on
AuthToken keeps you signed in (12 days, httpOnly). az-active-tenant remembers which workspace you're in. Short-lived *_oauth_state cookies protect connector sign-in against cross-site request forgery. az-consent stores this choice. None of them track you off our site.
Product analytics — off until you allow it
Google Analytics 4 and Mixpanel, counting page views and feature usage against a pseudonymous ID. Never message content, never business records. Advertising and personalisation signals are hard-denied regardless of what you choose.
Session replay — off until you allow it
Microsoft Clarity records clicks, scrolling and typing on App Zoo pages and replays them as video so we can find confusing screens. This is the most intrusive thing we run, which is why it is a separate choice from analytics and why it is off by default. To be plain about what turns it on: choosing Accept all on the cookie banner allows it, as does its own switch under Choose.
How long we keep it
Workspace content is kept for as long as the workspace exists. Owners and admins can set a shorter retention window for AI memory and conversation history in Control Room → Memory & Data; content older than that window is deleted automatically each night.
When you delete your account, the deletion runs immediately and is not reversible — see below for exactly what goes. Server logs roll off after 30 days. Billing records are kept for seven years because tax law requires it. Backups are retained for 30 days, so deleted content can persist in an encrypted backup for up to that long before ageing out.
Your rights
Wherever you live, you can do the two important ones yourself, right now, without asking us:
Get a copy of your data
Control Room → Memory & Data → Your data generates a machine-readable JSON export of your account, workspace content, conversations and billing history.
Delete your account
Same page. Deletes your account, your personal data, and any workspace where you are the only owner. Workspaces you merely belong to keep working for everyone else.
You also have the right to correct inaccurate data, to object to or restrict processing, to withdraw consent, and — under the GDPR — to complain to your local supervisory authority. Under California law you have the right to know, to delete, to correct, and to opt out of sale or sharing; we do not sell or share personal information, and we honor Global Privacy Control as an opt-out signal regardless.
For anything the self-service tools don't cover, email dan@appzoo.ai or use the contact form. We respond within 30 days. We will not charge you for a request or make you justify it.
If you're a customer of one of our customers
When a business uses App Zoo to manage its own customers, that business is the data controller and we are its processor. Send your request to them; if you send it to us we will pass it on and tell you we have.
Where your data lives
App Zoo runs on Google Cloud in the United States. If you are in the UK, EEA or Switzerland, using the product means your data is transferred to the US; we rely on the European Commission's Standard Contractual Clauses with our providers for those transfers. Some AI and email providers process in other regions — the subprocessor list says which.
Security
Data is encrypted in transit (TLS) and at rest. Connector and bank tokens get a second layer of application-level AES-256-GCM encryption. Access between workspaces is isolated at the query layer and checked by an automated job that looks for isolation anomalies. Administrative changes are written to an append-only audit log you can read in Control Room. No system is perfectly secure; if we ever suffer a breach affecting your data we will notify you and the relevant regulator within the deadlines the law sets.
Children
App Zoo is a business product and is not directed at anyone under 16. We don't knowingly collect their data; if we learn we have, we delete it.
Changes
If we change this policy materially we'll say so in the product before the change takes effect, and — where the change affects cookies or tracking — ask for your choice again rather than carrying the old one forward.
Contact
Privacy questions and data requests: dan@appzoo.ai. Anything else: the contact form.