1. Introduction
Zagvo is a workspace where founders and product teams turn an idea into a specification and a build plan. You describe what you want to build, the workspace asks questions, and it produces documentation, tasks and prompts you can take to an AI builder. Doing that well requires holding a meaningful amount of information about your product, so we take the handling of that information seriously.
This policy applies to the Zagvo marketing website, the Zagvo web application, and the support and billing interactions connected to them (together, the Service). It does not apply to third-party products you choose to use alongside Zagvo, such as an AI builder you paste a prompt into, or a code host you deploy to. Those services have their own policies.
If any part of this policy is unclear, ask us before you rely on it. We would rather answer a question than have you assume.
2. Definitions
These terms carry the same meaning in every Zagvo legal document, the Terms of Service, Refund Policy, Cookie Policy and Acceptable Use Policy included.
- Service
- The Zagvo website, web application, APIs and supporting systems operated by us.
- Account
- The credentials and profile through which you access the Service, whether created with an email address and password or through Google sign-in.
- Workspace
- The authenticated area of the Service in which you create and manage Projects.
- Project
- A single product or initiative inside your Workspace, together with everything attached to it: discovery answers, build plan, tasks, conversations, documents, memory and uploaded files.
- Customer Content
- Anything you provide to or create in the Service: prompts, messages, discovery answers, project descriptions, tasks, notes, uploaded files, and the documents generated from them.
- Output
- Material the Service generates in response to your input, for example a product brief, PRD, technical specification, task list, builder prompt or mentor reply.
- Personal Data
- Information relating to an identified or identifiable individual, as defined under applicable data protection law.
- Processing
- Any operation performed on Personal Data, collection, storage, use, transmission, deletion and so on.
- Sub-processor
- A third party we engage to process Personal Data on our behalf in order to deliver the Service, such as our hosting, database, payment or AI providers.
- AI Provider
- A third-party provider of large language models that generates Output in response to requests we send on your behalf.
3. Data controller and scope
3.1 Who is responsible for your data
The controller for Personal Data processed through the Service is [Legal entity name, to be confirmed], registered at [Registered company address, to be confirmed]. Where this policy says "we", "us" or "Zagvo", it means that entity.
Our privacy contact is Zagvo's legal and privacy team (legal@zagvo.com), reachable at legal@zagvo.com. Where we are required to appoint a representative in the European Union or the United Kingdom, that representative is [EU / UK representative, to be confirmed].
3.2 Controller and processor roles
We act as a controller for account, billing, support and analytics data: we decide why and how that data is processed.
For Customer Content, we act primarily as a processor on your instructions: we store it, transmit it to AI Providers to generate the Output you ask for, and return it to you. If you place another person's Personal Data inside a Project, you are the controller of that data and are responsible for having a lawful basis to include it.
3.3 What this policy does not cover
This policy does not cover third-party AI builders, repositories, hosting platforms or analytics tools that you connect to or paste Zagvo Output into, nor websites we link to. Review their policies separately.
4. Information we collect
We collect three broad categories: information you give us, content you create in the Service, and information generated automatically when you use it. We do not collect special-category data (such as health or biometric data) and ask that you do not place it into a Project.
4.1 Account information
Your email address, and the password hash if you register with an email and password. We never store passwords in plain text. If you register through Google sign-in, we receive your email address, name and profile image from Google. We never receive your Google password.
4.2 Profile information
An optional display name, avatar image and workspace preferences such as notification and interface settings. All of these are optional and editable in settings.
4.3 Authentication data
Session tokens, refresh tokens, sign-in timestamps, IP address and user agent at sign-in, password reset tokens, and records of failed sign-in attempts. This data exists to keep your Account secure and to let us investigate suspicious access.
4.4 Project information
Project names and descriptions, discovery answers, build plans, phases and tasks, task status and progress, launch readiness state, and any notes you record. This is the substance of your Workspace.
4.5 AI conversations
Messages you exchange with the mentor and with guided discovery, the prompts we construct from your Project, and the replies returned. We retain these so conversations stay coherent, so your Project has continuity, and so you can return to earlier reasoning.
4.6 Project documentation and knowledge
Documents you generate (product briefs, PRDs, technical specifications, database schemas, API specifications, UX flows, QA checklists, security reviews and launch checklists) together with their version history, approvals, change events and the structured project knowledge derived from them.
4.7 Uploaded files
Files and screenshots you upload to a Project, their filenames, size, type and upload time, and any text extracted from them for analysis. Do not upload material you are not permitted to share, and do not upload secrets such as production credentials or private keys.
4.8 Usage analytics
Which pages and features are used, when key actions occur (for example creating a Project, generating a document or completing a task), feature adoption, error events, and aggregate credit consumption. We use this to understand what works and to size capacity, not to build advertising profiles.
4.9 Technical, browser and device information
IP address, approximate location derived from it at city or country level, browser type and version, operating system, device type, screen size, language, referring URL, and request timestamps. Our bot-protection and rate-limiting systems also process request metadata to distinguish legitimate traffic from automated abuse.
4.10 Cookies and similar technologies
Cookies and browser storage used for authentication, security and preferences, and, where permitted, analytics. Categories, purposes and durations are set out in full in our Cookie Policy.
4.11 Payment and billing metadata
Plan, subscription status, billing period, renewal and cancellation dates, invoice history, amounts, currency, tax status, credit allocations and credit consumption records.
We do not see your card
Card numbers, expiry dates and security codes are collected and processed directly by our payment processor. Zagvo receives only a payment token, the last four digits, card brand and the outcome of the transaction. Card details never reach our servers.
4.12 Support communications
Messages you send through the contact form or by email, and our replies, including any diagnostic detail you choose to share.
5. How we use information
We use the information described above for the following purposes, and no others.
- Providing the Service. Authenticating you, storing your Projects, generating documents and plans, running the mentor, and keeping your Workspace consistent between sessions.
- Personalising your Workspace. Using your Project history, documentation and memory so guidance is specific to what you are building rather than generic.
- Billing and credits. Managing subscriptions, allocating and metering AI credits, issuing invoices, and preventing billing abuse.
- Security and abuse prevention. Detecting fraud, credential stuffing, automated abuse and violations of our Acceptable Use Policy; enforcing rate limits.
- Reliability and improvement. Diagnosing errors, monitoring performance, and improving features based on aggregate usage patterns.
- Communication. Sending transactional messages such as verification, password resets, billing notices, security alerts and material service changes.
- Support. Investigating and resolving the issues you report.
- Legal compliance. Meeting tax, accounting and regulatory obligations and responding to lawful requests.
5.1 Marketing communications
We send product and marketing email only where you have opted in or where permitted by law for existing customers. Every marketing email includes an unsubscribe link. Transactional messages that are necessary to operate your Account cannot be unsubscribed from while your Account is active.
5.2 No automated decisions with legal effect
We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you. Automated systems do apply rate limits and flag suspected abuse, but enforcement decisions that suspend or terminate an Account involve human review, as described in the Acceptable Use Policy.
6. AI processing and model providers
6.1 How AI processing works
When you ask the Service to generate a document, plan, task breakdown or mentor reply, we assemble a prompt from your instruction and the relevant parts of your Project (such as discovery answers, approved documentation and project memory) and send it to an AI Provider over an encrypted connection. The Provider returns Output, which we store in your Project and display to you.
6.2 Who the providers are
We reach model providers through an AI gateway rather than contracting with each model vendor individually. Requests are transmitted under contractual terms that restrict use of the transmitted content to generating your response. A current list of AI Providers is available on request from legal@zagvo.com.
6.3 What we log about AI usage
For every AI action we record metadata: which Project it belonged to, the feature that triggered it, the model used, token counts, credits consumed, latency and whether the request succeeded. This supports billing accuracy, quality investigation and abuse detection.
6.4 Limits you should understand
AI Output can be inaccurate, incomplete or confidently wrong. Do not put information into a prompt that you would not be comfortable transmitting to a third-party processor, and review Output before relying on it. Section 15 of the Terms of Service sets out the limitations of AI Output in more detail.
7. AI training statement
Your content is not used to train models
We do not use your Customer Content or Output to train, fine-tune or otherwise improve any foundation model, whether ours or a third party's. We do not sell Customer Content, and we do not license it to model vendors for training.
Content is transmitted to AI Providers for one purpose only: producing the response you requested. Our arrangements with providers reached through our AI gateway are made on terms that exclude training on transmitted content.
We do analyse aggregate, de-identified usage signals (for example how often a document type is regenerated, or the distribution of plan sizes) to improve prompts, validation rules and product behaviour. These signals contain no Customer Content and cannot be used to reconstruct your Project.
If we ever intend to change this position, we will give advance notice, explain the scope, and make participation opt-in. It will never be applied retroactively to content created under this version of the policy.
8. Data storage and retention
8.1 Where data is stored
Application data is stored in a managed cloud database and object storage; the Service is delivered from a global edge network. Our primary hosting region is the United States (USA), with India as a secondary region. Edge delivery means static assets and request routing may be handled from a location near you, while your Project data remains in the primary region.
8.2 Retention periods
We keep data only as long as it serves the purpose it was collected for, or as long as the law requires.
| Category | Retention | Reason |
|---|---|---|
| Account and profile | For the life of the Account, then up to 30 days | Operate the Account; short window to recover accidental deletion |
| Projects, documents, conversations, memory | Until you delete them, or 30 days after Account deletion | Deliver the Workspace; allow recovery from mistaken deletion |
| Uploaded files | Until deleted by you or with the Project | Provide document analysis and context |
| AI request metadata | Up to 24 months | Billing accuracy, abuse detection, quality investigation |
| Security and access logs | Typically 12 months | Incident investigation and account security |
| Billing records and invoices | As required by tax and accounting law, typically 6–10 years | Statutory retention |
| Support correspondence | Up to 24 months after resolution | Continuity of support and dispute handling |
| Analytics events | Up to 14 months, then aggregated | Product measurement |
8.3 Backups
Encrypted backups are retained on a rolling schedule for disaster recovery. Deleted data may persist in backups for a limited period after deletion from the live system, and is overwritten as backups rotate. Backups are never used to resurrect data you deleted.
9. Security measures
No system is perfectly secure, and we will not claim otherwise. What follows is an honest description of the controls we operate.
9.1 Encryption
Data is encrypted in transit using TLS, and encrypted at rest by our database and storage providers. Passwords are stored only as salted hashes. Secrets and API keys are held in a managed secret store and are never committed to source code or exposed to the browser.
9.2 Access controls
The Service enforces row-level authorisation in the database: queries are evaluated against the identity of the signed-in user, so one Account cannot read another Account's Projects even if a request is manipulated. Administrative capability is separated from ordinary product use, and administrators do not gain automatic access to customer Project content or the ability to edit it.
9.3 Employee access
Access to production systems is limited to personnel who need it, granted on a least-privilege basis, protected by multi-factor authentication, and revoked promptly when it is no longer required. Personnel are bound by confidentiality obligations. We access Customer Content only to resolve a support request you have raised, to investigate a suspected violation or security incident, or where legally compelled.
9.4 Logging and audit trails
We log authentication events, administrative actions, billing changes, document lifecycle events such as generation, approval and version changes, and AI request metadata. Logs are retained for investigation and are protected against casual access.
9.5 Incident response
We maintain an internal process for triaging and responding to security incidents. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected users without undue delay and, where required, within 72 hours of becoming aware of it.
9.6 Your responsibilities
Use a strong, unique password, keep your credentials private, do not share Accounts, and tell us immediately if you suspect unauthorised access. Do not store production credentials, private keys or customer databases inside a Project.
10. Legal bases for processing
If you are in the European Economic Area, the United Kingdom or Switzerland, we rely on the following legal bases under the GDPR and equivalent law.
| Processing | Legal basis |
|---|---|
| Creating and operating your Account; delivering the Workspace | Performance of a contract |
| Processing payments, credits and invoices | Performance of a contract; legal obligation |
| Security, fraud prevention, rate limiting, abuse investigation | Legitimate interests |
| Service improvement and aggregate analytics | Legitimate interests; consent where required |
| Non-essential cookies and analytics | Consent |
| Marketing email | Consent, or legitimate interests for existing customers |
| Tax, accounting and regulatory retention | Legal obligation |
Where we rely on legitimate interests, we have assessed that our interest in operating a secure, reliable service does not override your rights. You may object to that processing as described in Section 12.
11. International transfers
Our providers operate globally, so your information may be processed in countries other than your own, including the United States. Where data leaves the EEA, the UK or Switzerland, we rely on an appropriate transfer mechanism: an adequacy decision where one exists, or the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), supported by technical measures such as encryption in transit and at rest.
You can request information about the transfer mechanism applicable to a particular provider by contacting legal@zagvo.com.
12. Third-party services and sub-processors
We do not sell Personal Data and we do not share it for cross-context behavioural advertising. We share it only with the providers below, each engaged under a data processing agreement that limits them to processing on our documented instructions.
| Provider category | Purpose | Data involved |
|---|---|---|
| Google (sign-in) | Optional authentication via Google sign-in | Email address, name, profile image |
| Payment processor (Stripe) | Card processing, subscriptions, invoices, tax calculation | Card data collected directly by the processor; billing metadata |
| Database, authentication and storage provider | Storing Accounts, Projects, documents and uploaded files | Account data and Customer Content |
| Edge hosting and CDN provider | Serving the application, routing, DDoS and bot protection | IP address, request metadata |
| AI gateway and model providers | Generating documents, plans and mentor replies | Prompt content drawn from your Project |
| Transactional email provider | Verification, password reset, billing and security email | Email address, message content |
| Error monitoring provider | Diagnosing crashes and runtime errors | Error traces, technical metadata, Account identifier |
| Product analytics provider | Aggregate usage measurement | Pseudonymous usage events and device metadata |
12.1 Other disclosures
We may disclose information where required by law, to respond to a valid legal process, to protect our rights or the safety of users, or in connection with a merger, acquisition or sale of assets. In a corporate transaction we will give notice before your data becomes subject to a different privacy policy, and the acquirer will be bound by commitments no less protective than these.
12.2 Changes to sub-processors
We may add or replace sub-processors as the Service evolves. Where required by contract or law, we will provide notice and an opportunity to object before a new sub-processor begins processing your data.
13. Your rights and choices
Your rights depend on where you live, but we extend the core controls (access, export, correction and deletion) to every user regardless of location.
13.1 Rights under the GDPR and UK GDPR
- Access: obtain confirmation of whether we process your data and a copy of it.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: have your data deleted where we no longer have grounds to keep it.
- Restriction: limit how we process your data while a dispute is resolved.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent: where processing relies on consent, withdraw it without affecting prior processing.
- Complain: lodge a complaint with your local supervisory authority. We ask that you contact us first so we can try to resolve it.
13.2 Rights under the CCPA/CPRA and US state laws
If you are a California resident, you have the right to know what Personal Data we collect and the purposes for it, to request deletion, to request correction, to opt out of sale or sharing, to limit use of sensitive personal information, and not to be discriminated against for exercising these rights.
We do not sell Personal Data and we do not share it for cross-context behavioural advertising, so there is no opt-out to exercise. We do not use or disclose sensitive personal information beyond the purposes permitted without a right to limit. Residents of other US states with comparable laws have equivalent rights and may exercise them the same way.
13.3 Export requests
You can export individual documents from your Workspace in Markdown, PDF or DOCX at any time. For a complete export of your Account and Project data, contact us and we will provide a machine-readable archive.
13.4 Correction requests
Account and profile details can be corrected directly in settings. For information you cannot edit yourself, contact us and we will correct it or explain why we cannot.
13.5 Deletion requests
You can delete individual Projects, documents and files at any time. To delete your entire Account, contact us. Deletion removes your Personal Data and Customer Content from the live Service, subject to backup rotation described in Section 8.3.
What we must keep
We retain invoices, tax records and a minimal record of the Account's existence and enforcement history where required by law or necessary to defend legal claims. We also retain records necessary to prevent a terminated Account from being immediately recreated to continue abuse.
13.6 How to exercise your rights
Email legal@zagvo.com from the address associated with your Account, or use the contact page. We respond within 30 days and may extend by a further 60 days for complex requests, telling you if we do. We may need to verify your identity before acting. Authorised agents may submit requests with written proof of authority. Exercising these rights is free unless a request is manifestly unfounded or excessive.
14. Children's privacy
The Service is intended for business use by adults. It is not directed at children, and we do not knowingly collect Personal Data from anyone under 16, or under the higher minimum age required in your jurisdiction.
If you believe a child has provided us with Personal Data, contact legal@zagvo.com and we will delete the Account and its data promptly. Eligibility requirements are set out in the Terms of Service.
15. Changes to this policy
We may revise this document from time to time to reflect changes in the Service, our providers, or applicable law. When we make material changes we will update the “Last updated” date, publish the revised document on this page, and (where the change materially reduces your rights or materially expands your obligations) notify account holders by email or in-product notice before the change takes effect. Changes are effective on the stated effective date. Continued use of the Service after that date constitutes acceptance of the revised document. Prior versions are available on request.
We encourage you to review this page periodically. If you disagree with a revision, you may stop using the Service and request deletion of your Account before the effective date.
16. Contact us
Questions, requests and complaints about privacy are welcome and are answered by a person.
- Privacy and data requests: legal@zagvo.com
- General support: help@zagvo.com, or the contact page on this website
- Data protection contact: Zagvo's legal and privacy team (legal@zagvo.com)
- Postal address: [Registered company address, to be confirmed]