Privacy Policy
Last updated 15 August 2026
In short. We store the conversations people have with Agents built on Zephlo, because that is what makes the product work and what lets our customers review and improve their Agents. Conversation content is sent to third-party model providers to generate replies. We do not sell personal data, and we never see the passwords or session tokens of the people using your site.
1. Who this covers
Zephlo (“we”, “us”) provides a platform that lets organisations (“customers”) add an AI Agent to their website. This policy explains how we handle personal data in two different roles:
- —As a controller, for the account data of our own customers — the people who sign up for Zephlo.
- —As a processor, for data about visitors to our customers’ websites. There, the customer decides what is collected and why; we process it on their instructions. If you spoke to an Agent on someone else’s site, that organisation is your first point of contact.
2. What we collect
Conversations. We store the messages exchanged with an Agent — the text of each message, whether it came from the visitor, the Agent, or a human operator, and when it was sent. Conversations are grouped into sessions, which may include a visitor name if one is given or collected.
Details a visitor provides. If an Agent or form collects contact details, we store what is submitted — typically name, email address, phone number, company, and a description of what the person is looking for.
Content we crawl. To ground an Agent in a customer’s content, we fetch pages from the website they point us at and store the extracted text and its embeddings. Only publicly reachable pages are crawled.
Account and operational data. Names, email addresses and organisation membership for customer accounts; API keys; audit records of privileged actions; and usage counters used for metering and billing.
What we do not collect. We do not log visitors’ IP addresses or browser user-agent strings against their conversations. Because Agent tools run inside the visitor’s own browser session, we never receive the passwords, tokens or session cookies they use on our customers’ sites.
3. How we use it
We use this data to generate Agent replies, to show customers the conversations their Agent has had, to pass on the leads it captures, to meter usage for billing, to keep the service secure, and to diagnose problems. We do not sell personal data, and we do not use customer conversations to train our own models.
4. Who else processes it
To produce a reply, the relevant part of a conversation is sent to third-party large language model providers, which we reach through OpenRouter. They process it to return a response. We also rely on cloud hosting and infrastructure providers to run and store the service. Search embeddings are computed on our own infrastructure.
A current list of sub-processors is available on request, and Data Processing Agreements are available to customers who need one.
5. How it is protected
Traffic between visitors, Agents and the dashboard is encrypted in transit with TLS. Conversation data is encrypted at rest. Each organisation’s data sits in a logically isolated tenant, so conversations, embeddings and tool definitions do not cross customer boundaries. Access inside the product is role-based, and privileged actions are logged.
6. How long we keep it
Conversations are retained until the customer’s configured retention window expires or they delete them. Customers can purge conversations on demand and export their data in a portable format. Account data is kept while the account is open, and for a limited period afterwards where we need it for legal or accounting reasons.
7. Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to or restrict certain processing.
If you are a Zephlo customer, you can exercise most of these directly in the dashboard, or by contacting us. If you spoke to an Agent on another organisation’s website, please contact that organisation — they decide what happens to that data, and we will support them in responding to you.
8. Changes
We may update this policy as the product changes. When we do, we will revise the date at the top of this page, and we will tell customers directly if a change materially affects them.
9. Contact
Questions about this policy, or about data we hold, can go to [email protected].