Trust Center
How we protect your data
- Encryption in transit for all data moving between the app and our servers.
- Screenshots and activity data are held in access-controlled storage in Frankfurt, Germany. Credentials and connection tokens are encrypted. Backups are encrypted, kept separately from the live systems, expire after 30 days, and restores are tested on a regular schedule.
- On-device stripping: passwords and other credentials are removed on your computer before anything is uploaded, for every account, and that cannot be turned off. On personal accounts, emails, phone numbers, card numbers and IP addresses are stripped too, by default; the account holder can turn that second layer off in Settings, Privacy, and is asked to confirm first.
- Least-privilege access inside our company: only people who need data to run the service can reach it.
- Staff actions are logged separately and are auditable.
- Certifications: none yet.
How we handle a security incident
If we become aware of a breach affecting your data, we notify affected customers without undue delay, and for enterprise customers no later than 24 hours after we become aware, per the Data Processing Addendum. We cooperate on remediation and any notifications the law requires.
Subprocessors: who else touches your data
- DigitalOcean - Hosting and storage. Frankfurt, Germany.
- Google (Gemini) - AI processing: classification, summaries, embeddings, chat, web search and meeting transcription. US.
- Composio - Integrations you connect, where you enable them. US.
- Resend - Email delivery. US.
- Sentry - Crash reporting. US.
- Telegram, WhatsApp, Slack - Messaging channels you choose to connect. Various. Governed by each platform's own terms.
We give 10 business days' notice before adding a new subprocessor that will handle enterprise customer data, and enterprise customers may object per the Data Processing Addendum.
What we do not do
- We do not sell or rent personal data.
- We do not show ads or use advertising SDKs in the product.
- We do not use your identifiable content to train our own AI models, and Google does not use API content to train its models either.
- We do not infer emotions from tracked activity, and have no plans to.
Questions
Security and privacy questions: support@zeami.io. Enterprise customers under a signed Data Processing Addendum have the fuller audit and assistance rights described there.