ZapSightLegal
Privacy Policy
A concise explanation of the information ZapSight handles and why.
Effective July 22, 2026
What this policy covers
This Privacy Policy explains how ZapSight handles information when you use ZapSight websites, applications, AI agents, analytics, workflows, dashboards, and collaboration integrations. Questions and privacy requests can be sent to team@zapsight.com.
Information we receive
- Account and organization information, such as your name, email address, authentication details, organization membership, roles, permissions, and user preferences.
- Content you submit or create, including prompts, chat messages, AI responses, uploaded files, dashboards, agents, workflows, feed posts, comments, reactions, saved prompts, and generated reports or artifacts.
- Connected-service information, including connector names, configuration details, authorization references, database metadata, query results, and permissions. Secrets are intended to be stored through managed secret references rather than in connector records.
- Collaboration information when Slack or Microsoft Teams is connected, including workspace or tenant identifiers, external user identifiers, messages sent to the bot, conversation references, pairing events, and delivery events.
- Email configuration and delivery information when email workflows are enabled, including sender settings, recipients, report content, and attachments.
- Contact and demo information, such as your name, work email, company, message, and the browser user-agent submitted through public contact or lead forms.
- Technical information processed by our hosting, authentication, and security providers, such as request metadata, logs, device or browser information, and approximate network information.
How we use information
- To authenticate users, administer organizations, enforce permissions, and keep customer data separated by organization.
- To provide chat, analytics, AI reasoning, dashboards, workflows, file handling, memory, notifications, email delivery, and collaboration features requested by you or your organization.
- To connect to customer-authorized systems, run requested queries or analysis, generate outputs, troubleshoot failures, prevent abuse, and maintain security.
- To measure usage and AI consumption for service operations and organization administration. We do not use customer content for advertising.
Service providers and sharing
We share information with service providers only as needed to operate the requested service, protect it, or comply with law. Which providers receive data depends on the features and integrations enabled by an organization.
- WorkOS for authentication, organization membership, and identity administration.
- Convex and Cloudflare for application hosting, databases, file storage, functions, delivery, and operational logs.
- OpenAI and, where enabled, OpenRouter for AI processing of prompts, context, uploaded or connected data, and generated outputs.
- Supermemory for optional persistent memories, uploaded knowledge files, and schema or query lessons when memory features are enabled.
- Daytona and SQL MCP for optional sandbox execution, file or code work, database introspection, queries, and analysis requested by the user.
- Gmail, SMTP providers, Slack, Microsoft Teams, and other connected services when an organization chooses to enable those integrations.
- Supabase for public contact and demo lead submissions where those forms are used.
- Government authorities, professional advisers, or other parties when disclosure is required by law or necessary to protect rights, safety, and service integrity.
Customer-controlled data
Organizations are responsible for ensuring that they have the right to connect systems and provide data to ZapSight. If you connect a database, SaaS system, Slack workspace, Microsoft Teams tenant, email account, or other service, the permissions and data made available to ZapSight are controlled by that organization and its administrators.
Retention and deletion
We retain information while an account or organization uses the service and for as long as reasonably needed to provide the service, maintain security, resolve disputes, meet legal obligations, and preserve legitimate business records. Retention varies by data type and feature. Backups, audit records, provider logs, and legal records may remain for a limited period after deletion. Contact team@zapsight.com to request account or data deletion; we will coordinate the request with the organization administrator and applicable providers.
Security
ZapSight uses organization-scoped authorization, managed authentication, encrypted transport, access controls, secret references, and operational monitoring. No online service can guarantee absolute security, so organizations should use least-privilege credentials and avoid sending data they are not authorized to disclose.
Cookies and local storage
ZapSight uses authentication cookies and related session technologies to keep signed-in users secure. The website may also use browser local storage for interface preferences and limited form-state convenience. We do not use these technologies for interest-based advertising.
International processing
ZapSight and its providers may process information in countries other than the country where you or your organization is located. By using the service, you acknowledge that cross-border processing may be required for the features you enable. Organizations remain responsible for obtaining any required notices, permissions, and agreements for their data.
Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, or export personal information, or to object to certain processing. Requests should be sent to team@zapsight.com. We may need to verify your identity and coordinate with your organization because organization administrators control many service records.
Children and policy changes
ZapSight is intended for organizations and professional users and is not directed to children. We may update this policy when the service or legal requirements change. The updated version will be posted on this page with a revised effective date.