Zagvo
Legal

Privacy Policy

Zagvo is the AI product manager for people building software with AI. This policy explains what information we collect, why we collect it, who processes it on our behalf, how long we keep it, and the control you have over it. We have written it to be read, not skimmed past.

Effective date:
9 August 2026
Last updated:
9 August 2026

1. Introduction

Zagvo is a workspace where founders and product teams turn an idea into a specification and a build plan. You describe what you want to build, the workspace asks questions, and it produces documentation, tasks and prompts you can take to an AI builder. Doing that well requires holding a meaningful amount of information about your product, so we take the handling of that information seriously.

This policy applies to the Zagvo marketing website, the Zagvo web application, and the support and billing interactions connected to them (together, the Service). It does not apply to third-party products you choose to use alongside Zagvo, such as an AI builder you paste a prompt into, or a code host you deploy to. Those services have their own policies.

If any part of this policy is unclear, ask us before you rely on it. We would rather answer a question than have you assume.

2. Definitions

These terms carry the same meaning in every Zagvo legal document, the Terms of Service, Refund Policy, Cookie Policy and Acceptable Use Policy included.

Service
The Zagvo website, web application, APIs and supporting systems operated by us.
Account
The credentials and profile through which you access the Service, whether created with an email address and password or through Google sign-in.
Workspace
The authenticated area of the Service in which you create and manage Projects.
Project
A single product or initiative inside your Workspace, together with everything attached to it: discovery answers, build plan, tasks, conversations, documents, memory and uploaded files.
Customer Content
Anything you provide to or create in the Service: prompts, messages, discovery answers, project descriptions, tasks, notes, uploaded files, and the documents generated from them.
Output
Material the Service generates in response to your input, for example a product brief, PRD, technical specification, task list, builder prompt or mentor reply.
Personal Data
Information relating to an identified or identifiable individual, as defined under applicable data protection law.
Processing
Any operation performed on Personal Data, collection, storage, use, transmission, deletion and so on.
Sub-processor
A third party we engage to process Personal Data on our behalf in order to deliver the Service, such as our hosting, database, payment or AI providers.
AI Provider
A third-party provider of large language models that generates Output in response to requests we send on your behalf.

3. Data controller and scope

3.1 Who is responsible for your data

The controller for Personal Data processed through the Service is [Legal entity name, to be confirmed], registered at [Registered company address, to be confirmed]. Where this policy says "we", "us" or "Zagvo", it means that entity.

Our privacy contact is Zagvo's legal and privacy team (legal@zagvo.com), reachable at legal@zagvo.com. Where we are required to appoint a representative in the European Union or the United Kingdom, that representative is [EU / UK representative, to be confirmed].

3.2 Controller and processor roles

We act as a controller for account, billing, support and analytics data: we decide why and how that data is processed.

For Customer Content, we act primarily as a processor on your instructions: we store it, transmit it to AI Providers to generate the Output you ask for, and return it to you. If you place another person's Personal Data inside a Project, you are the controller of that data and are responsible for having a lawful basis to include it.

3.3 What this policy does not cover

This policy does not cover third-party AI builders, repositories, hosting platforms or analytics tools that you connect to or paste Zagvo Output into, nor websites we link to. Review their policies separately.

4. Information we collect

We collect three broad categories: information you give us, content you create in the Service, and information generated automatically when you use it. We do not collect special-category data (such as health or biometric data) and ask that you do not place it into a Project.

4.1 Account information

Your email address, and the password hash if you register with an email and password. We never store passwords in plain text. If you register through Google sign-in, we receive your email address, name and profile image from Google. We never receive your Google password.

4.2 Profile information

An optional display name, avatar image and workspace preferences such as notification and interface settings. All of these are optional and editable in settings.

4.3 Authentication data

Session tokens, refresh tokens, sign-in timestamps, IP address and user agent at sign-in, password reset tokens, and records of failed sign-in attempts. This data exists to keep your Account secure and to let us investigate suspicious access.

4.4 Project information

Project names and descriptions, discovery answers, build plans, phases and tasks, task status and progress, launch readiness state, and any notes you record. This is the substance of your Workspace.

4.5 AI conversations

Messages you exchange with the mentor and with guided discovery, the prompts we construct from your Project, and the replies returned. We retain these so conversations stay coherent, so your Project has continuity, and so you can return to earlier reasoning.

4.6 Project documentation and knowledge

Documents you generate (product briefs, PRDs, technical specifications, database schemas, API specifications, UX flows, QA checklists, security reviews and launch checklists) together with their version history, approvals, change events and the structured project knowledge derived from them.

4.7 Uploaded files

Files and screenshots you upload to a Project, their filenames, size, type and upload time, and any text extracted from them for analysis. Do not upload material you are not permitted to share, and do not upload secrets such as production credentials or private keys.

4.8 Usage analytics

Which pages and features are used, when key actions occur (for example creating a Project, generating a document or completing a task), feature adoption, error events, and aggregate credit consumption. We use this to understand what works and to size capacity, not to build advertising profiles.

4.9 Technical, browser and device information

IP address, approximate location derived from it at city or country level, browser type and version, operating system, device type, screen size, language, referring URL, and request timestamps. Our bot-protection and rate-limiting systems also process request metadata to distinguish legitimate traffic from automated abuse.

4.10 Cookies and similar technologies

Cookies and browser storage used for authentication, security and preferences, and, where permitted, analytics. Categories, purposes and durations are set out in full in our Cookie Policy.

4.11 Payment and billing metadata

Plan, subscription status, billing period, renewal and cancellation dates, invoice history, amounts, currency, tax status, credit allocations and credit consumption records.

We do not see your card

Card numbers, expiry dates and security codes are collected and processed directly by our payment processor. Zagvo receives only a payment token, the last four digits, card brand and the outcome of the transaction. Card details never reach our servers.

4.12 Support communications

Messages you send through the contact form or by email, and our replies, including any diagnostic detail you choose to share.

5. How we use information

We use the information described above for the following purposes, and no others.

  • Providing the Service. Authenticating you, storing your Projects, generating documents and plans, running the mentor, and keeping your Workspace consistent between sessions.
  • Personalising your Workspace. Using your Project history, documentation and memory so guidance is specific to what you are building rather than generic.
  • Billing and credits. Managing subscriptions, allocating and metering AI credits, issuing invoices, and preventing billing abuse.
  • Security and abuse prevention. Detecting fraud, credential stuffing, automated abuse and violations of our Acceptable Use Policy; enforcing rate limits.
  • Reliability and improvement. Diagnosing errors, monitoring performance, and improving features based on aggregate usage patterns.
  • Communication. Sending transactional messages such as verification, password resets, billing notices, security alerts and material service changes.
  • Support. Investigating and resolving the issues you report.
  • Legal compliance. Meeting tax, accounting and regulatory obligations and responding to lawful requests.

5.1 Marketing communications

We send product and marketing email only where you have opted in or where permitted by law for existing customers. Every marketing email includes an unsubscribe link. Transactional messages that are necessary to operate your Account cannot be unsubscribed from while your Account is active.

5.2 No automated decisions with legal effect

We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you. Automated systems do apply rate limits and flag suspected abuse, but enforcement decisions that suspend or terminate an Account involve human review, as described in the Acceptable Use Policy.

6. AI processing and model providers

6.1 How AI processing works

When you ask the Service to generate a document, plan, task breakdown or mentor reply, we assemble a prompt from your instruction and the relevant parts of your Project (such as discovery answers, approved documentation and project memory) and send it to an AI Provider over an encrypted connection. The Provider returns Output, which we store in your Project and display to you.

6.2 Who the providers are

We reach model providers through an AI gateway rather than contracting with each model vendor individually. Requests are transmitted under contractual terms that restrict use of the transmitted content to generating your response. A current list of AI Providers is available on request from legal@zagvo.com.

6.3 What we log about AI usage

For every AI action we record metadata: which Project it belonged to, the feature that triggered it, the model used, token counts, credits consumed, latency and whether the request succeeded. This supports billing accuracy, quality investigation and abuse detection.

6.4 Limits you should understand

AI Output can be inaccurate, incomplete or confidently wrong. Do not put information into a prompt that you would not be comfortable transmitting to a third-party processor, and review Output before relying on it. Section 15 of the Terms of Service sets out the limitations of AI Output in more detail.

7. AI training statement

Your content is not used to train models

We do not use your Customer Content or Output to train, fine-tune or otherwise improve any foundation model, whether ours or a third party's. We do not sell Customer Content, and we do not license it to model vendors for training.

Content is transmitted to AI Providers for one purpose only: producing the response you requested. Our arrangements with providers reached through our AI gateway are made on terms that exclude training on transmitted content.

We do analyse aggregate, de-identified usage signals (for example how often a document type is regenerated, or the distribution of plan sizes) to improve prompts, validation rules and product behaviour. These signals contain no Customer Content and cannot be used to reconstruct your Project.

If we ever intend to change this position, we will give advance notice, explain the scope, and make participation opt-in. It will never be applied retroactively to content created under this version of the policy.

8. Data storage and retention

8.1 Where data is stored

Application data is stored in a managed cloud database and object storage; the Service is delivered from a global edge network. Our primary hosting region is the United States (USA), with India as a secondary region. Edge delivery means static assets and request routing may be handled from a location near you, while your Project data remains in the primary region.

8.2 Retention periods

We keep data only as long as it serves the purpose it was collected for, or as long as the law requires.

CategoryRetentionReason
Account and profileFor the life of the Account, then up to 30 daysOperate the Account; short window to recover accidental deletion
Projects, documents, conversations, memoryUntil you delete them, or 30 days after Account deletionDeliver the Workspace; allow recovery from mistaken deletion
Uploaded filesUntil deleted by you or with the ProjectProvide document analysis and context
AI request metadataUp to 24 monthsBilling accuracy, abuse detection, quality investigation
Security and access logsTypically 12 monthsIncident investigation and account security
Billing records and invoicesAs required by tax and accounting law, typically 6–10 yearsStatutory retention
Support correspondenceUp to 24 months after resolutionContinuity of support and dispute handling
Analytics eventsUp to 14 months, then aggregatedProduct measurement

8.3 Backups

Encrypted backups are retained on a rolling schedule for disaster recovery. Deleted data may persist in backups for a limited period after deletion from the live system, and is overwritten as backups rotate. Backups are never used to resurrect data you deleted.

9. Security measures

No system is perfectly secure, and we will not claim otherwise. What follows is an honest description of the controls we operate.

9.1 Encryption

Data is encrypted in transit using TLS, and encrypted at rest by our database and storage providers. Passwords are stored only as salted hashes. Secrets and API keys are held in a managed secret store and are never committed to source code or exposed to the browser.

9.2 Access controls

The Service enforces row-level authorisation in the database: queries are evaluated against the identity of the signed-in user, so one Account cannot read another Account's Projects even if a request is manipulated. Administrative capability is separated from ordinary product use, and administrators do not gain automatic access to customer Project content or the ability to edit it.

9.3 Employee access

Access to production systems is limited to personnel who need it, granted on a least-privilege basis, protected by multi-factor authentication, and revoked promptly when it is no longer required. Personnel are bound by confidentiality obligations. We access Customer Content only to resolve a support request you have raised, to investigate a suspected violation or security incident, or where legally compelled.

9.4 Logging and audit trails

We log authentication events, administrative actions, billing changes, document lifecycle events such as generation, approval and version changes, and AI request metadata. Logs are retained for investigation and are protected against casual access.

9.5 Incident response

We maintain an internal process for triaging and responding to security incidents. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected users without undue delay and, where required, within 72 hours of becoming aware of it.

9.6 Your responsibilities

Use a strong, unique password, keep your credentials private, do not share Accounts, and tell us immediately if you suspect unauthorised access. Do not store production credentials, private keys or customer databases inside a Project.

11. International transfers

Our providers operate globally, so your information may be processed in countries other than your own, including the United States. Where data leaves the EEA, the UK or Switzerland, we rely on an appropriate transfer mechanism: an adequacy decision where one exists, or the European Commission's Standard Contractual Clauses (with the UK Addendum where relevant), supported by technical measures such as encryption in transit and at rest.

You can request information about the transfer mechanism applicable to a particular provider by contacting legal@zagvo.com.

12. Third-party services and sub-processors

We do not sell Personal Data and we do not share it for cross-context behavioural advertising. We share it only with the providers below, each engaged under a data processing agreement that limits them to processing on our documented instructions.

Provider categoryPurposeData involved
Google (sign-in)Optional authentication via Google sign-inEmail address, name, profile image
Payment processor (Stripe)Card processing, subscriptions, invoices, tax calculationCard data collected directly by the processor; billing metadata
Database, authentication and storage providerStoring Accounts, Projects, documents and uploaded filesAccount data and Customer Content
Edge hosting and CDN providerServing the application, routing, DDoS and bot protectionIP address, request metadata
AI gateway and model providersGenerating documents, plans and mentor repliesPrompt content drawn from your Project
Transactional email providerVerification, password reset, billing and security emailEmail address, message content
Error monitoring providerDiagnosing crashes and runtime errorsError traces, technical metadata, Account identifier
Product analytics providerAggregate usage measurementPseudonymous usage events and device metadata

12.1 Other disclosures

We may disclose information where required by law, to respond to a valid legal process, to protect our rights or the safety of users, or in connection with a merger, acquisition or sale of assets. In a corporate transaction we will give notice before your data becomes subject to a different privacy policy, and the acquirer will be bound by commitments no less protective than these.

12.2 Changes to sub-processors

We may add or replace sub-processors as the Service evolves. Where required by contract or law, we will provide notice and an opportunity to object before a new sub-processor begins processing your data.

13. Your rights and choices

Your rights depend on where you live, but we extend the core controls (access, export, correction and deletion) to every user regardless of location.

13.1 Rights under the GDPR and UK GDPR

  • Access: obtain confirmation of whether we process your data and a copy of it.
  • Rectification: have inaccurate or incomplete data corrected.
  • Erasure: have your data deleted where we no longer have grounds to keep it.
  • Restriction: limit how we process your data while a dispute is resolved.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent: where processing relies on consent, withdraw it without affecting prior processing.
  • Complain: lodge a complaint with your local supervisory authority. We ask that you contact us first so we can try to resolve it.

13.2 Rights under the CCPA/CPRA and US state laws

If you are a California resident, you have the right to know what Personal Data we collect and the purposes for it, to request deletion, to request correction, to opt out of sale or sharing, to limit use of sensitive personal information, and not to be discriminated against for exercising these rights.

We do not sell Personal Data and we do not share it for cross-context behavioural advertising, so there is no opt-out to exercise. We do not use or disclose sensitive personal information beyond the purposes permitted without a right to limit. Residents of other US states with comparable laws have equivalent rights and may exercise them the same way.

13.3 Export requests

You can export individual documents from your Workspace in Markdown, PDF or DOCX at any time. For a complete export of your Account and Project data, contact us and we will provide a machine-readable archive.

13.4 Correction requests

Account and profile details can be corrected directly in settings. For information you cannot edit yourself, contact us and we will correct it or explain why we cannot.

13.5 Deletion requests

You can delete individual Projects, documents and files at any time. To delete your entire Account, contact us. Deletion removes your Personal Data and Customer Content from the live Service, subject to backup rotation described in Section 8.3.

What we must keep

We retain invoices, tax records and a minimal record of the Account's existence and enforcement history where required by law or necessary to defend legal claims. We also retain records necessary to prevent a terminated Account from being immediately recreated to continue abuse.

13.6 How to exercise your rights

Email legal@zagvo.com from the address associated with your Account, or use the contact page. We respond within 30 days and may extend by a further 60 days for complex requests, telling you if we do. We may need to verify your identity before acting. Authorised agents may submit requests with written proof of authority. Exercising these rights is free unless a request is manifestly unfounded or excessive.

14. Children's privacy

The Service is intended for business use by adults. It is not directed at children, and we do not knowingly collect Personal Data from anyone under 16, or under the higher minimum age required in your jurisdiction.

If you believe a child has provided us with Personal Data, contact legal@zagvo.com and we will delete the Account and its data promptly. Eligibility requirements are set out in the Terms of Service.

15. Changes to this policy

We may revise this document from time to time to reflect changes in the Service, our providers, or applicable law. When we make material changes we will update the “Last updated” date, publish the revised document on this page, and (where the change materially reduces your rights or materially expands your obligations) notify account holders by email or in-product notice before the change takes effect. Changes are effective on the stated effective date. Continued use of the Service after that date constitutes acceptance of the revised document. Prior versions are available on request.

We encourage you to review this page periodically. If you disagree with a revision, you may stop using the Service and request deletion of your Account before the effective date.

16. Contact us

Questions, requests and complaints about privacy are welcome and are answered by a person.

  • Privacy and data requests: legal@zagvo.com
  • General support: help@zagvo.com, or the contact page on this website
  • Data protection contact: Zagvo's legal and privacy team (legal@zagvo.com)
  • Postal address: [Registered company address, to be confirmed]

Your next product starts with an idea.

Describe what you're building and let Zagvo create your roadmap, organise your work and guide you from your first prompt to launch.