ZOEY_OSTM
Meet Zoey Guide For Business Pricing Contact
Login Get Started
Meet ZoeyGuideFor BusinessPricingContact Login Get Started
Under attorney review — this policy may be updated.

Privacy Policy

Last updated: June 21, 2026 · Version 2.0

Plain-Language Summary

What this actually means for you:

Your AI team works for you — not for us. Your conversations, preferences, and everything your team learns about you stays in your account. We never use it to train AI models. We never aggregate it for company analytics. We never sell it.

We collect what we need to run the service (your email, billing info, and operational data like error rates). We do not run behavioral analytics or track how you use the app. Your personalization data — how your team knows you — is yours to view, edit, export, reset, or delete at any time.

You can view, control, or turn off personalization and adaptive learning in settings. You can export all your data. You can delete your account and we’ll wipe everything within 30 days (backups within 1 year).

We use trusted third-party providers for AI inference, speech processing, payments (Stripe), and security (Cloudflare). We never use your data to train AI models, and under their commercial terms, neither do they (see Tier 5 for how this works on BYO Claude Code). Full list at zoeyos.com/legal/subprocessors.

Questions? legal@zoeyos.com. No lawyers needed — just ask.

1. Introduction

This Privacy Policy describes how Zoey OS, LLC (“Zoey OS,” “we,” “us,” or “our”) collects, uses, stores, and protects your personal information when you use our platform, desktop application, and related services (the “Services”).

Global availability. Zoey OS is offered internationally. The Services are operated from and hosted in the United States, and your information is processed in the United States regardless of where you are located (see Section 11.3 on international transfers). The Services are not available in countries or territories subject to comprehensive U.S. or other applicable export sanctions, and we may block access from such regions. You are responsible for complying with the laws applicable to you in your location.

By using the Services, you acknowledge that you have read and understood this Privacy Policy. This Privacy Policy should be read together with our Terms of Service and Acceptable Use Policy.

Contact Information:

  • Privacy inquiries: legal@zoeyos.com
  • Abuse reports: support@zoeyos.com
  • General support: support@zoeyos.com
  • Zoey OS, LLC, 7901 4th St N, STE 300, St. Petersburg, FL 33702, United States

2. Our Data Collection Tiers

We organize data collection into clearly defined tiers, each with architectural enforcement preventing data from being used beyond its stated purpose.

Tier 1: Operational Telemetry (Always-On, Service-Required)

What it is: Data required to run and secure the service. No content access. No individual profiling.

Examples:

  • Login/logout timestamps
  • Error rates and crash reports
  • System performance metrics (response latency, dispatch counts)
  • Token consumption (for billing/cap enforcement)
  • Voice connection status

Legal basis: Contractual necessity (required to provide the Service).

Retention: 90 days for performance data; 7 years for billing-related records (legal requirement).

Your control: Included in data export. Deleted with account deletion.

Tier 2: Aggregate Analytics — Not Currently Collected

What it is: Anonymized, aggregated usage patterns that could be used to improve the product (for example, overall feature-adoption rates across the user base).

Status: We do not currently collect behavioral or aggregate usage analytics in the desktop application. No analytics or event-tracking tooling runs in the app. If we introduce privacy-preserving, fully anonymized analytics in the future, we will update this Policy and provide any applicable opt-out controls before any such collection begins.

Tier 3: Account-Scoped Personalization (Default-On, Settings Toggle)

What it is: How you individually use the system, used to make YOUR experience better. Strictly contained within your account.

Examples:

  • Communication style preferences
  • Interest selections from onboarding
  • Companion customizations
  • Terminology preferences

Legal basis: Performance of contract (Art. 6(1)(b)) — remembering you and personalizing your experience is part of the Service you sign up for — together with legitimate interest (Art. 6(1)(f)) for ongoing refinement. This is not behavioral tracking and is never aggregated across users. You may still control or turn it off (see Your control).

Critical guarantee: This data is NEVER aggregated for company analytics or model training. Tenant-level data isolation at the database level prevents any cross-user query.

Your control:

  • View all personalization data in Settings
  • Edit any field
  • Reset all personalization
  • Export (included in JSON data export)
  • Delete independently of account
  • Toggle OFF entirely in Settings > Privacy > Personalization

Tier 4: Account-Scoped Adaptive Learning (Default-On, Settings Toggle)

What it is: Per-user improvements the system learns over time to better serve you. Never aggregated.

Examples:

  • Your MarketingBot learning you prefer concise tone
  • Your companions learning you want proactive vs. reactive responses
  • Preferred working hours and interaction patterns

Legal basis: Performance of contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)) — adaptive learning is how your companions deliver the persistent, personalized service you sign up for. It is account-scoped and never aggregated across users. You retain the right to object and may turn it off at any time (see Your control).

Critical guarantee: What’s stored is per-user adaptation data. What’s NOT collected for company use is the underlying patterns. The user’s companions get better; we learn nothing aggregate from this.

Your control:

  • View what the system has learned in Settings
  • Reset (“reset my team’s learning”)
  • Toggle OFF entirely in Settings > Privacy > Adaptive Learning
  • Full audit trail of what was adapted and when
  • Export and delete independently

Tier 5: Training Data — We Do Not Train On Your Data

Zoey OS does not use your data to train AI models. We operate no training pipeline and have no infrastructure to repurpose your conversations, content, or personalization data for model training, and we do not share your data with any third party for the purpose of training their models. This is a brand commitment and an architectural enforcement.

We do use external AI providers to run the Service — Anthropic for chat and voice, and OpenAI for the embeddings that power semantic search. Sending your data to these providers to generate a response or index your content is inference, not training. How that data is handled depends on your billing mode:

  • Standard and BYO “All API”: inference and embeddings run through commercial API accounts. Under those providers’ commercial terms, your inputs and outputs are not used to train their models.
  • BYO “Claude Code”: chat inference runs on your own Anthropic subscription via Claude Code on your machine. That data is governed by your Anthropic account’s terms and training settings, which we do not control. Anthropic’s consumer plans may use data for model improvement unless you opt out in your account — we recommend reviewing those settings.

Special Categories of Personal Data (Article 9 GDPR)

Your companions process whatever you choose to share in conversation, which may incidentally include “special category” data under Article 9 GDPR — for example, data revealing health, religious or philosophical beliefs, political opinions, or sexual orientation. We want to be clear about how this is handled:

  • We do not solicit special-category data, and we do not use it to profile you, target you, or make automated decisions about you.
  • Any such data is processed only to provide the Service at your direction — so your companion can respond to what you tell it — and is held under the same account-scoped isolation, security, and deletion controls as all your other data.
  • We never aggregate it across users and never use it to train AI models.
  • By choosing to share such information with your companions, you provide your explicit consent to its processing for this purpose under Article 9(2)(a) GDPR. You can delete it at any time — per individual memory, or by deleting your account.

3. Categories of Personal Data We Collect

3.1 Account Information

  • Email address
  • Name (if provided)
  • Password (hashed using industry-standard algorithms, never stored in plaintext, excluded from data exports)
  • Billing information (processed by Stripe — we do not store full payment card numbers)
  • Account creation date
  • Subscription tier and status

3.2 Conversation and Content Data

  • Text conversations with your AI team
  • Voice transcripts
  • Files you upload or create
  • Notes, tasks, and workflow data
  • Integration data pulled from connected third-party services at your direction

3.3 Usage and Billing Metering

  • Voice minutes consumed (to enforce plan limits and for billing)
  • Token / inference consumption (to enforce plan limits and for billing)
  • Login and account-activity timestamps (for security and account management)

We collect this operational metering only to run, secure, and bill the Service. We do not collect behavioral product analytics, session-tracking, or feature-usage metrics.

3.4 Device and Technical Data

  • IP address (logged for security and, at the network edge, to determine country for sanctions/export-control screening — not used for behavioral tracking)
  • Approximate country/region derived from IP at the edge (for legal availability and tax determination)
  • Device type and operating system
  • App version
  • Browser type (for web-based interactions)
  • Hardware identifier (hashed, for device limit enforcement only)

3.5 Personalization Data

  • Interest selections from onboarding
  • Communication style preferences
  • Companion customizations and configurations
  • Adaptive learning data
  • Terminology and interaction preferences

3.6 Consent and Compliance Records

  • Timestamp and version of each legal document accepted (Terms of Service, Acceptable Use Policy) at signup
  • Age confirmation (18+) recorded at signup
  • Consent toggles and the time each was changed (personalization, adaptive learning, crash reports, marketing, “Do Not Sell or Share”)
  • Consent method (checkbox, settings toggle, verbal)
  • Withdrawal records

4. How We Use Your Information

Purpose Data Used Legal Basis
Provide the Services Account info, conversations, integrations Contractual necessity
Process payments and calculate tax Billing info, billing address (via Stripe) Contractual necessity; legal obligation
Personalize your experience and remember you Tier 3 & 4 data Performance of contract; legitimate interest
Respond to support requests Account info, relevant conversations Contractual necessity
Detect abuse and prevent fraud Operational and security signals, IP, device info Legitimate interest
Determine legal availability (sanctions/export screening) Edge country from IP Legal obligation
Meet legal obligations As required Legal obligation
Send transactional communications Email address Contractual necessity
Send marketing communications Email address Consent (opt-in only)

5. What We Do Not Do

  • We do not sell your personal data
  • We do not use your conversations to train AI models (ours or anyone else’s)
  • We do not run behavioral analytics or track how you use the application
  • We do not aggregate your personalization data for company analytics
  • We do not share personal data with third parties for their marketing purposes
  • We do not create or store biometric voiceprints
  • We do not profile you for advertising purposes
  • We do not provide data to data brokers

6. How We Share Your Information

We share your information only in the following circumstances:

6.1 Subprocessors (Required for Service Delivery)

We use third-party service providers to deliver the Services. Each operates under contractual obligations limiting their use of your data to service provision only. A complete, up-to-date list is maintained at zoeyos.com/legal/subprocessors. We will notify you by email at least 30 days before adding any new subprocessor.

6.2 Legal Requirements

We may disclose your information if required by law, subpoena, court order, or government request. We will notify you of such requests unless legally prohibited from doing so.

6.3 Business Transfers

If Zoey OS is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.

6.4 With Your Consent

We may share your information for other purposes with your explicit consent.

7. Data Retention and Deletion

7.1 Active Accounts

Data Type Retention
Operational telemetry 90 days
Personalization data Until you reset or delete
Adaptive learning data Until you reset or delete
Conversation history Retained for companion persistence until account deletion
Voice transcripts Retained for companion persistence until account deletion
Billing records 7 years (legal requirement)

7.2 Account Deletion

When you delete your account:

  • We offer you a configuration export file before deletion (so you can restore your team if you return)
  • All user data is wiped from production within 30 days
  • All user data is removed from backups within 1 year as backup retention cycles expire
  • A deletion confirmation email is sent to your registered address
  • Billing records may be retained for 7 years per legal requirements (anonymized)

7.3 Subscription Cancellation (Without Account Deletion)

  • Data retained for 90 days for potential reactivation
  • After 90 days without reactivation: full deletion procedure begins
  • You may request immediate deletion at any time by deleting your account

8. Your Rights

Regardless of your location, we provide the following rights to all users:

8.1 Right to Access

You can view and download all data we hold about you through Settings > Privacy > Export My Data.

8.2 Right to Correction

You can edit your profile, personalization data, and account information at any time through Settings.

8.3 Right to Deletion

You can delete your account and all associated data through Settings > Account > Delete Account.

8.4 Right to Portability

Your data export is provided in machine-readable JSON format.

8.5 Right to Restrict Processing

You can disable Tier 3 personalization and Tier 4 adaptive learning independently without deleting your account.

8.6 Right to Withdraw Consent

You can withdraw consent for non-essential processing (marketing emails) at any time without affecting your access to core Services.

8.7 Right to Object

You can object to specific processing activities by contacting legal@zoeyos.com.

9. Children’s Privacy

9.1 Age Requirement (18+)

The Services are intended only for adults. You must be at least 18 years of age to create an account or use the Services. We confirm your age at signup and do not knowingly permit anyone under 18 to register. The Services are not directed to children, and we do not knowingly collect personal information from minors.

9.2 Voice Data and Minors

Voice interaction data, including audio characteristics, is classified as personal information under applicable law. We do not create biometric voiceprints, and voice features require an active adult account.

9.3 Discovery of Underage Users

If we discover that we have collected personal information from anyone under 18, we will delete that information promptly (and within 48 hours of discovery for any user under 13). If you believe a minor has provided us personal information, please contact legal@zoeyos.com immediately.

10. United States — State Privacy Rights (CCPA/CPRA and Similar)

If you are a resident of California or another U.S. state with a comprehensive consumer privacy law (e.g., Virginia, Colorado, Connecticut, Utah, Texas, and others), you have the following rights.

10.1 Right to Know / Access

You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collection, and the categories of third parties with whom we share it.

10.2 Right to Delete

You may request deletion of your personal information, subject to legal exceptions.

10.3 Right to Opt Out of Sale / Sharing

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, so no opt-out is necessary. Our marketing website nonetheless honors the Global Privacy Control (GPC) browser signal as a valid opt-out of any analytics, and you may direct any related request to legal@zoeyos.com.

10.4 Right to Correct

You may request correction of inaccurate personal information, and you can edit most information directly in Settings.

10.5 Right to Non-Discrimination

We will not discriminate against you for exercising any of your privacy rights.

10.6 Sensitive Personal Information

We do not use or disclose sensitive personal information for purposes that would require a separate “Limit the Use of My Sensitive Personal Information” right beyond the controls already described.

10.7 Authorized Agents

You may designate an authorized agent to submit requests on your behalf. We may require verification of the agent’s authority.

To exercise any of these rights, use the self-service tools in your account Settings or contact legal@zoeyos.com.

11. European Union, EEA, United Kingdom & Switzerland (GDPR / UK GDPR / revFADP)

If you are located in the European Union, European Economic Area, United Kingdom, or Switzerland, you have the following additional rights and protections.

11.1 Roles

For personal information you provide as a consumer user, Zoey OS acts as a controller. For business/organization customers, Zoey OS acts as a processor for content their authorized users submit; those arrangements are governed by our Data Processing Addendum.

11.2 Legal Bases for Processing

Processing Activity Legal Basis
Providing the Services Performance of contract
Billing, payments and tax Performance of contract; legal obligation
Personalization & adaptive learning (Tier 3 & 4) Performance of contract; legitimate interest
Security and fraud prevention Legitimate interest
Sanctions/export screening Legal obligation
Legal compliance Legal obligation
Marketing communications Consent

11.3 Your Rights Under GDPR / UK GDPR

In addition to the rights in Section 8, you have the right to:

  • Lodge a complaint with your local data protection supervisory authority (in the UK, the Information Commissioner’s Office; in Switzerland, the FDPIC)
  • Object to processing based on legitimate interest
  • Restrict processing under certain circumstances
  • Receive your data in a structured, commonly used, machine-readable format
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not carry out such decision-making)

11.4 International Data Transfers

The Services are hosted in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) (EU Modules and, for the UK, the International Data Transfer Addendum / IDTA; for Switzerland, the FDPIC-recognized clauses) with our subprocessors and, where applicable, the EU-US Data Privacy Framework and its UK extension, together with supplementary technical and organizational measures and contractual commitments equivalent to GDPR protections for all users regardless of location.

11.5 Data Subject Requests

We will respond to verified data subject requests within 30 days (extendable as permitted by law). Contact legal@zoeyos.com.

12. Cookies and Tracking

12.1 What We Use

The desktop application does not use third-party advertising cookies, cross-site tracking cookies, social media tracking pixels, or fingerprinting techniques (beyond the hashed hardware identifier for device limits disclosed in our Terms).

12.2 Essential Cookies (Web)

Cookie Purpose Duration
Session cookie Maintain your login state Session
CSRF token Prevent cross-site request forgery Session
Preferences Store your display preferences 1 year

12.3 Cookie Consent and Privacy Signals (Web)

Our website’s cookie consent banner lets you accept or reject non-essential cookies. How our privacy-focused analytics behave depends on where you are: for visitors in the EU, EEA, and UK, no analytics load at all until you explicitly accept, and no cookies are set beforehand. For visitors elsewhere, we load anonymous, cookieless analytics when the page loads (before you make a choice); these set no persistent identifiers, and we only set persistent analytics cookies if you accept. Rejecting stops that analytics for you. We honor the Global Privacy Control (GPC) signal — when present, no analytics load anywhere — and treat it as a valid opt-out of any “sale” or “sharing.” We do not respond to legacy Do Not Track (DNT) headers.

12.4 Analytics

We do not currently collect behavioral or aggregate usage analytics within the desktop application (see Tier 2). Error and crash reporting used to keep the Service secure and working is covered under Tier 1.

13. Data Security

13.1 Technical Measures

  • Encryption in transit (TLS 1.2+) for all data communications
  • Encryption at rest (AES-256) for all stored data; field-level encryption for credentials and secrets
  • Tenant-level data isolation at the database level preventing cross-user data access
  • Regular security patching and dependency updates
  • Network segmentation between production and development environments
  • Audit logging of authentication, billing, and administrative actions

13.2 Organizational Measures

  • Multi-factor authentication available, and enforceable for organization accounts
  • Password management with no shared credentials
  • Regular backup testing (at least one tested restore per 90 days)
  • Documented incident response plan
  • Security awareness practices

13.3 Breach Notification

In the event of a data breach affecting your personal information, we will notify affected users without undue delay and, where required, within 72 hours of becoming aware; describe what data was affected and the steps we are taking; provide guidance to protect yourself; and notify relevant regulatory authorities as required by applicable law.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email to your registered address (at least 30 days before changes take effect), by prominent notice within the Services, and by posting the updated policy with a new effective date and version. Where changes materially reduce your privacy rights, we will obtain your explicit consent before the changes take effect.

15. Contact Us

Zoey OS, LLC
Privacy: legal@zoeyos.com
Abuse: support@zoeyos.com
Support: support@zoeyos.com
Address: 7901 4th St N, STE 300, St. Petersburg, FL 33702, United States

We aim to respond to all privacy inquiries within 5 business days.

16. Additional Regional Privacy Rights (Addenda)

These addenda supplement the Policy for residents of specific countries. Where an addendum grants a right or protection greater than the body of this Policy, the addendum controls for residents of that jurisdiction.

16.1 Canada (PIPEDA & Quebec Law 25)

  • Consent: We collect, use, and disclose personal information with your knowledge and consent, except where permitted or required by law. You may withdraw consent for non-essential processing at any time.
  • Access & correction: You may request access to, and correction of, your personal information by contacting legal@zoeyos.com or using the in-app tools.
  • Quebec residents: You also have the right to data portability and to be informed of automated decision-making (we do not engage in such decision-making). We have designated a Privacy Officer reachable at legal@zoeyos.com.
  • Complaints: You may complain to the Office of the Privacy Commissioner of Canada (OPC) or, in Quebec, the Commission d’accès à l’information (CAI).
  • Breach: We report breaches of security safeguards involving a real risk of significant harm to the relevant commissioner and to affected individuals as required.

16.2 Brazil (LGPD)

  • Your rights: confirmation of processing; access; correction; anonymization, blocking, or deletion of unnecessary or excessive data; portability; information about sharing; and withdrawal of consent.
  • Legal bases: we rely principally on execution of a contract, legitimate interest, compliance with legal obligations, and consent (for marketing).
  • DPO (Encarregado): reachable at legal@zoeyos.com.
  • Authority: you may petition the Autoridade Nacional de Proteção de Dados (ANPD).
  • International transfer: processing in the United States occurs under contractual safeguards consistent with LGPD Art. 33.

16.3 Australia (Privacy Act & Australian Privacy Principles)

  • We handle personal information in accordance with the Australian Privacy Principles (APPs).
  • Access & correction: available via the in-app tools or legal@zoeyos.com.
  • Cross-border disclosure (APP 8): your information is processed in the United States under contractual safeguards.
  • Notifiable Data Breaches: we comply with the NDB scheme and will notify the OAIC and affected individuals of eligible data breaches.
  • Complaints: you may complain to us first and then to the Office of the Australian Information Commissioner (OAIC).

16.4 United Kingdom

UK residents are covered by Section 11 (UK GDPR). You may complain to the Information Commissioner’s Office (ICO). International transfers rely on the UK IDTA and/or the UK extension to the EU-US Data Privacy Framework. Our UK representative will be identified in Section 1.

16.5 Switzerland

Swiss residents are covered by Section 11 (revFADP). You may contact the Federal Data Protection and Information Commissioner (FDPIC). Transfers rely on FDPIC-recognized standard clauses and the Swiss-US Data Privacy Framework where applicable.

16.6 Other Jurisdictions

Residents of other countries with data-protection laws (e.g., South Africa’s POPIA, Japan’s APPI, South Korea’s PIPA) may exercise the universal rights in Section 8 and contact legal@zoeyos.com to exercise any additional rights granted by local law. We honor applicable local requirements to the extent they apply to our provision of the Services.

Last updated: June 21, 2026 · Version 2.0

ZOEY_OSTM

Your World. Your AI.

Product

What is Zoey OS For Business Pricing

Partners

Affiliates

Community

Discord X Instagram TikTok

Legal

Terms Privacy Acceptable Use
© 2026 Zoey OS hello@zoeyos.com

We use analytics cookies to understand how you use our site. You can accept or reject them — essential cookies needed to run the site are always on. See our Privacy Policy.