Privacy Policy
Last updated: September 6, 2026
Zozo AI, Inc., a Delaware corporation ("Zozo," "we," "us," or "our"), operates Zozo Chat, formerly known as Zodiac. We are responsible for the personal information we process to operate the Service and act as its controller where that term applies.
This policy covers Zozo Chat at chat.zozo.sh, its legacy domain during the transition, and the Zozo account services used with it. Other Zozo products may provide additional notices describing their own features and data handling.
The key distinctions:
- Without Cloud Sync, your chat library is stored in your browser.
- AI requests still send the content needed for a response to the services processing it.
- Cloud Sync encrypts supported content on your device; account and billing data are separate.
- Zozo does not use your chats or images to train models or sell your personal information.
- We use Google Analytics for site-usage analytics, not targeted advertising.
1. Information we process
- Account and profile information: email address, account identifier, authentication and security records, and profile information you provide, such as an avatar, username, preferred name, or additional instructions. Profile information is stored separately from the encrypted chat library. Public-facing profile fields, such as your username or avatar, may be visible when you use community features.
- Content and preferences: prompts, conversation context, personas, files, images, generated results, selected models, LoRAs, and customizations used by the features you choose. Where these are stored or transmitted depends on local storage, Cloud Sync, and the particular request.
- Billing and entitlements: Stripe customer, subscription, price, and transaction identifiers; payment or subscription status; plan and renewal information; credit balances; and usage allowances. Stripe processes payment details. We do not store full card numbers or card security codes.
- Operational information: IP address, browser and device information, request times and identifiers, errors, security events, activity timestamps, model selections, token counts, costs, fallback events, and storage usage. Some records are associated with your account identifier or email address.
- Communications and community activity: information you send us for support; public content, comments, and reports you choose to submit; moderation records; and whether an in-app announcement was shown, dismissed, or acted on.
We obtain information from you and your browser, from the features you use, and from service providers such as Stripe for payment events. Information stored only on your device is not automatically available to our support team.
2. AI requests and provider processing
When you send a message or request an image, relevant Input is transmitted to the services needed to produce the result. This can include the current prompt, earlier conversation context, persona and profile instructions, attached files, reference images, and model settings. Supporting requests for titles, summaries, suggestions, search, or file processing may also use relevant content. A fallback can use another model or provider.
For Zozo-provided AI features, our backend processes the request and forwards it primarily to OpenRouter or Runware and the model providers they use. OpenRouter requests can include a Zozo account identifier for usage and abuse management. Image editing may temporarily store input images on our infrastructure and provide a time-limited access link to the image provider.
When you choose a supported bring-your-own-key (BYOK) feature, requests can go directly from your browser to the selected provider, such as OpenRouter or Google for Gemini. That provider receives the request and connection information, including your IP address, and processes it under its terms and account settings.
Zozo does not use your chats or images to train AI models. This statement describes Zozo's own practices. The providers processing requests have their own retention, security, and model-training policies, which can depend on the model and account settings. We do not promise that every provider operates with zero retention or identical data-use rules. See OpenRouter's Privacy Policy, OpenRouter's provider data policies, and Runware's Privacy Policy.
Private chat storage is not a public feed. However, content submitted for generation is available in readable form to the systems processing that request. Operational logs can include diagnostic or provider error details; this service does not make a blanket "nothing is ever logged" promise.
3. Cloud Sync and encryption
Cloud Sync is optional and requires an eligible plan. It encrypts supported chats, personas, settings, and media on your device before uploading them. Your separate encryption password derives the key used to unlock this content; the Cloud Sync service does not receive that password or store the decryption key. We cannot recover the encryption password for you.
Some settings, including saved BYOK API keys, are included in encrypted settings sync. Locally saved settings and keys remain accessible to the browser profile and are not necessarily encrypted on the device. When Cloud Sync is enabled, chat and persona content is normally loaded into memory after unlocking rather than kept as a full permanent local copy. Turning sync off offers separate choices for retaining a local copy.
Encryption of synced content does not cover everything in your account. Account and profile fields, subscriptions, operational logs, and sync metadata remain separately processed. Sync metadata can include record and account identifiers, timestamps, deletion markers, encrypted file sizes, usage totals, and encryption verification information. Uploading a profile picture or submitting an image for editing is separate from encrypted Cloud Sync.
Cloud encryption also does not prevent the AI processing described above: sending a synced message for generation requires the app to decrypt the relevant content and submit it. Keep your device, login, and encryption password secure.
4. Takeout and the domain transition
Settings → Data Management lets you export selected data categories into a unified takeout file and import supported takeout or legacy chat/persona files. Exports are assembled in your browser; exporting from Cloud Sync first downloads and decrypts the selected information. A takeout is a readable backup, not an encrypted Cloud Sync copy. API keys are excluded by default and require a separate choice to include them.
Importing to local storage saves data in that browser. Choosing a Cloud Sync destination uploads the imported content through encrypted sync. Exporting does not itself publish content or delete the source. Anyone who receives a readable takeout may be able to read its contents and use any keys it contains.
Zozo Chat's new domain and Zodiac's old domain have separate browser storage and login sessions. Users with local data can use takeout to carry it across. Cloud Sync users can sign in and unlock their existing data at the new domain. The migration URL carries a flow indicator, not your chats, backup file, or authentication credentials. Moving to the new domain does not itself erase data stored under the old one.
5. Purposes and legal bases
We use the information described above to:
- Create and secure accounts and provide the features, AI requests, and storage you request.
- Process purchases, manage subscriptions and allowances, and resolve payment issues.
- Respond to support requests and send account or security messages.
- Maintain reliability, understand site usage, investigate errors, and prevent abuse.
- Operate community features, enforce service rules, and deliver relevant in-app notices.
- Meet legal obligations, maintain required records, and establish or defend legal claims.
Where the EEA or UK data-protection rules apply, the legal bases depend on the activity: performance of our contract for requested account, AI, billing, and sync services; legitimate interests in maintaining, securing, and improving the Service where those interests are not overridden by your rights; compliance with legal obligations; and consent where the law requires it, including for non-essential browser storage or analytics where applicable. You may withdraw consent without affecting earlier lawful processing.
We do not sell your personal information or share it for targeted advertising. Our Google Analytics use is for site-usage analytics only. Reading this policy, accepting our Terms, or dismissing an announcement is not a substitute for separate consent where the law requires it.
6. Who receives information
- Supabase: account authentication, profiles, databases, encrypted sync storage, backend processing, and associated operational records.
- Cloudflare and asset-delivery services: website hosting, delivery, security, and resources such as fonts and libraries. Those requests disclose connection information, including an IP address, to the service receiving them.
- OpenRouter, Runware, and their applicable providers: AI generation and supporting processing. Civitai may receive model or LoRA lookups, and Runware may receive the associated model references for an image request. A provider selected through BYOK receives the applicable direct requests.
- Stripe: payment processing, billing, fraud prevention, and subscription management.
- Resend and Proton Mail: account emails and correspondence, including email addresses, message content, and delivery information.
- Google Analytics: site-usage measurement as described below.
Our personnel and advisers may access information needed for support, operations, security, accounting, or legal work. Third-party services may act as our processors or independently for their own legal and service obligations. Their notices describe their own practices; using a provider does not remove our responsibility for our handling of your information.
We may disclose information where required by law or reasonably necessary to address fraud, protect people's rights and safety, enforce our agreements, or respond to legal claims. Information may also be transferred in a merger, reorganization, or sale of the Service, subject to applicable law, notice requirements, and the privacy commitments attached to it. Information you publish or share is also available to the people receiving it.
7. Browser storage and analytics
The app uses browser storage to remember sessions, chats, preferences, keys, and interface state. This includes IndexedDB, localStorage, and session-related storage. Some providers may also use cookies. Clearing browser data can sign you out and remove your only local copy of content; export anything you need first.
The app includes Google Analytics to measure visits and use of the website. Depending on configuration and browser settings, this can involve cookies or similar identifiers, page and interaction information, referral information, browser/device details, and approximate location derived from connection information. We use it for site-usage analytics, not targeted advertising. See Google's Privacy Policy and its Analytics opt-out browser add-on.
Browser privacy controls can restrict cookies and other storage, although they may affect features. The Analytics opt-out add-on applies only to supported browsers. These options do not replace any consent or opt-out mechanism required by the laws that apply to you.
8. Retention and deletion
- Local data and takeout files: remain in your browser or wherever you save them until you or your device removes them. We cannot remotely retrieve or erase a backup you have downloaded.
- Cloud Sync: encrypted content remains until you delete or wipe it, close the account, or it is removed under the subscription-expiry process, subject to necessary legal retention. Disabling sync alone does not erase the cloud copy. The current expiry flow provides seven days from an ended subscription's recorded period end for final download, after which its cloud data is eligible for deletion.
- Temporary processing files: image-editing inputs are uploaded for the request and the service attempts to remove them after processing. Provider-hosted files follow that provider's retention rules. Expiration of an access link is not the same as deletion of the underlying file.
- Account, usage, support, and moderation records: are retained for as long as needed to operate the account, manage entitlements, resolve support or abuse matters, and meet legal obligations. The period depends on the record's purpose, ongoing account activity, unresolved incidents or disputes, and applicable recordkeeping requirements.
- Financial and legal records: may be retained after account closure for tax, accounting, fraud prevention, and legal obligations. Deletion does not require us to remove records that law requires us to keep.
Deletion from the active interface is not always immediate erasure from every system. Sync deletion markers, scheduled cleanup, and backups can persist until cleanup or backup rotation completes. Copies held independently by a provider or a person with whom you shared information may require a separate request.
9. International processing
Zozo AI, Inc. is a US corporation. Our current primary Supabase project is hosted in the European Union, but hosting, support, email, payment, analytics, and AI providers may process information in the United States and other countries. Hosting the database in the EU does not mean that all AI requests or other processing remain there.
Where applicable law restricts international transfers, the transfer must use an appropriate legal mechanism, such as an applicable adequacy decision or contractual safeguards. Contact us for information about the safeguards applicable to your data. Accepting the Terms or this notice does not itself waive these protections.
10. Your choices and rights
You can update account information, use the export/import controls, delete local items, or manage encrypted sync using the available app controls. To request account closure or help with information held by us, email support@chat.zozo.sh. A shared Zozo account may be used by more than one product, so tell us whether you want to remove Chat data or close the entire account.
Depending on your location, you may have rights to know about and access personal information, correct it, request deletion or a portable copy, restrict or object to processing, withdraw consent, or opt out of sale, sharing, or targeted advertising. Where applicable, you may act through an authorized agent or appeal our response. We will consider requests under the law that applies to you and will not discriminate against you for exercising protected rights.
We may need information reasonably necessary to verify your identity or an agent's authority. Some requests are subject to exceptions, including other people's rights and records we must retain. We cannot decrypt your Cloud Sync content without the encryption password, which you should not send to support. Use the app's unlock and takeout controls for a readable copy.
You may complain to your local data-protection authority, including an EEA supervisory authority or the UK Information Commissioner's Office where applicable. You can also contact contact@zozo.sh about a privacy concern.
11. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Users must also meet any higher minimum age that applies where they live. If you believe a child has provided information contrary to these requirements, contact us so we can investigate and take appropriate action, including deletion where required. Where parental permission is required by law, use of the Service must meet that requirement.
12. Changes to this policy
We will update the date above when revising this policy and provide a prominent in-app banner or dialog for material changes, with notice before they take effect where required. We will obtain consent where required for a new use of information. A change of company name, product name, or domain does not by itself authorize unrelated new uses of previously collected data.
13. Contact
Privacy and product support:
support@chat.zozo.sh
Company correspondence:
contact@zozo.sh
Mailing address:
2810 N Church St STE 90635
Wilmington, DE 19802
United States