Privacy

Last updated 6 October 2026

Zinx Chat answers questions on a website using content that site's owner gave it. That means we hold two quite different kinds of data: the account of the person who set it up, and the conversations their visitors have. This describes both, who else handles them, and what we do not do with either.

Who is responsible for what

For your own account — your name, your email, your workspace and your billing — we are the controller.

When you run an assistant on your site, you decide what it reads and what it is asked. For your content and your visitors’ conversations, you are the controller and we process them on your behalf. The privacy notice your visitors are owed is yours to give, and it should say they are talking to an AI.

What we collect

  • Your account. Your name, email address and profile picture, from Google when you sign in. We never receive or store a password.
  • Billing. Your plan, its status and renewal date, your reply balance, and the customer and subscription references Dodo Payments gives us. We never see or store your card details.
  • What you train it on. The pages, files and text you add, and the passages and embeddings derived from them. We read only what you point us at.
  • Conversations. Questions visitors ask your assistant and the answers it gives, so you can read them back. If a visitor types personal information into the chat, it is stored with the conversation.
  • Usage counts. Questions asked, how many were answered from your sources, replies used and token usage — the numbers on your Analytics and Billing pages.

What we do not do

  • We do not sell data, or share it for advertising.
  • We do not use your content or your visitors’ conversations to train any AI model, ours or anyone else’s.
  • We do not track visitors across sites, use advertising identifiers, or build a profile of a visitor beyond the conversation they are having.

Information from Google

Sign-in uses Google with the basic openid, email and profile scopes. From Google we receive your name, email address, profile picture and whether the email is verified — nothing from Gmail, Drive, Calendar or any other Google service.

We use it only to create your account, sign you in, show who is in a workspace, and send billing to the right person. It is not sold, not used for advertising, not used to train AI models, and not shared except with the providers below, as needed to run the service.

Zinx Chat’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How the AI uses your data

Training your assistant. The text of each source is sent to the model provider to create embeddings — the numbers that let us find the right passage later.

Answering a question. Three things are sent: the question, the few passages retrieved for it, and the recent messages of that conversation. Never your whole knowledge base.

On our account, the provider is OpenAI. Under its API terms, data sent through the API is not used to train its models, and may be kept for up to 30 days to monitor for abuse. If you add your own provider key (OpenAI, OpenRouter or Vercel AI Gateway), requests go to your account with that provider instead, under your agreement with them.

Who else handles data

These providers process data for us, only for the purpose listed:

  • Convex — database, file storage and backend. Everything above is stored here.
  • Cloudflare — hosts and delivers the website and the widget.
  • Google — sign-in.
  • Dodo Payments — checkout, subscriptions, invoices and sales tax, as merchant of record. Your card and billing address go to Dodo, not to us. Dodo’s privacy policy covers what it does with them.
  • OpenAI — embeddings and answers, as described above.

These providers may process data in the United States and other countries where they operate. If this list changes, we will update it here before the change takes effect.

How long we keep it

  • Sources stay until you delete them. Deleting one removes its passages at the same time, so it stops being answerable immediately.
  • Conversations stay for as long as the workspace exists, so you can review them. A visitor sees only their five most recent chats; older ones are hidden from them, not deleted.
  • Test chats from your Playground and preview keep only the last two; older ones are deleted.
  • Deleting a workspace removes everything in it: sources, files, conversations, widgets, analytics, the reply ledger and invite links.
  • Deleting your account removes your memberships, and any workspace where you were the only owner.

Deletion is final; there is no archive we quietly keep. Invoices and payment records are kept by Dodo Payments for as long as tax law requires.

Cookies and browser storage

On this site, a session cookie keeps you signed in. Your theme and text-size preferences are kept in your browser and never sent to us.

On a site running the widget, the visitor’s browser stores three first-party values, and no cookie is set on the host page:

  • An experiment identifier, so a visitor sees the same version of an A/B test between visits.
  • The token of the current conversation, so reloading the page does not lose it. It expires a day after the last message.
  • A history key, so the visitor can reopen their earlier chats on that site.

None of these identify a person. On a shared computer, though, the next person at that browser could open those chats; clearing the site’s data in the browser removes them.

Your rights

You can delete any source, any workspace or your whole account yourself, at any time. To get a copy of your data, correct it, or ask us to delete it for you, write to us and we will reply within 30 days.

If you used somebody’s assistant and want your conversation removed, contact that site — they control it and can delete it. If they ask us, we will help.

Depending on where you live, you may also complain to your local data-protection authority.

Security

Provider keys are encrypted with AES-GCM before storage and are never sent back to a browser, not even to the person who saved them. Every workspace is isolated: one workspace’s widget cannot retrieve another’s content. All traffic is encrypted in transit.

No system is perfect. If you find a problem, tell us and we will fix it.

Children

Zinx Chat accounts are for businesses and people aged 18 or over. We do not knowingly collect data from children.

Changes

If this policy changes in a way that matters, the date at the top changes and we say what changed.

Contact

Privacy questions and requests: privacy@zinx.app.