Privacy Policy
Last updated: September 2026
This Privacy Policy explains how Zentier (“we”, “us”, or “our”) collects, uses, shares, and protects your personal data when you use our platform. It applies to all users of Zentier, including visitors to our website, waitlist subscribers, and registered users.
1. Data Controller
The data controller responsible for your personal data is:
- Company: Opscale Group
- CVR-nr.: 44583216
- Registered address: Lyngbyvej 83A, 2100 København Ø, Denmark
- Email: privacy@zentier.ai
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at the email addresses above.
2. What Data We Collect
We collect and process the following categories of personal data:
Account Data
Email address, name, and profile picture, collected and managed via our authentication provider (WorkOS).
Waitlist Data
Email address, name, when you confirmed your email, and referral information (who invited you, and how many people joined through your link and confirmed their email), collected when you join our waitlist.
Project Data
Source code, configuration files, database content, and chat messages that you create within the platform.
Workspace Drive and Memory
Files and documents you add to your workspace drive, the text we extract from them so the AI can search and read them, and the notes you or the AI save to memory.
AI Interaction Data
Prompts and instructions you send to the AI agent, AI-generated code and responses, and model selection preferences. User prompts are personal data per EDPB Opinion 28/2024 when they contain or can be linked to identifying information. Prompts are sent to AI model providers (see Section 4) for processing and are not used for model training.
Billing Data
Email address, workspace ID, subscription plan and top-up purchases, and the billing details you give when you buy, such as your business name, address and VAT number. Payments are processed by Stripe. You enter payment card details on Stripe's checkout page, and they never reach our servers. Stripe processes billing data on our behalf to take payments and issue invoices, and also uses some of it for its own purposes, such as preventing fraud and meeting its legal obligations, as described in Stripe's privacy policy. We check EU VAT numbers with the European Commission's VIES register, which confirms whether a number is valid.
Usage Data
How much of your plan’s allowance each operation consumed, token counts, and feature usage events.
Product Analytics Data
Daily counts of your own activity in each workspace: how many messages you sent, and how many agent chats and tasks were created for you. One row per day, stored in our own database. No content, no IP address, no device data, and no record of individual actions or their times.
Referral Data
If you arrive through a Zentier share link, an invitation, or a remix of a published project, we record which of those brought you here and which account it belonged to. This is one row on your account: the referral surface, the referring account, and how we identified it. No browsing history, no cross-site tracking.
Technical Data
IP address, user agent, and browser type, collected when you sign in and in error reports. We also use the country and region our hosting provider derives from your IP address to refuse access from places where Zentier is not available because of sanctions or because we cannot take payment there (see our Terms, section 2).
Collaboration Data
Display name, avatar URL, presence status, and user agent, collected via real-time collaboration features.
Communication Data
Email delivery status and drip email history for transactional and marketing communications. If you turn on browser notifications, the push address your browser gives us, used only to tell you about your own work (finished research, chats and builds) and deleted when you turn them off.
Consent Records
Your consent choices, timestamps, IP address at the time of consent, and the policy version, retained for compliance proof as required by Article 7(1) of the GDPR.
3. Legal Basis for Processing
Under Article 6 of the GDPR, we process your personal data on the following legal bases:
Contract Performance: Article 6(1)(b)
- Account and project data: Necessary to provide and maintain the Zentier service.
- AI interaction data (prompts, responses): Necessary to provide the AI code generation service you have requested.
- Billing data: Necessary to process payments and manage subscriptions.
- Collaboration data: Necessary to provide real-time collaboration features.
Legal Obligation: Article 6(1)(c)
- Billing records: We retain certain billing data as required by Danish tax and bookkeeping regulations.
Consent: Article 6(1)(a)
- Product analytics (PostHog): In the EU, EEA and UK, only with your consent. Elsewhere it can be on by default on our website, based on our legitimate interest in improving the service, and you can turn it off at any time in Cookie Settings.
- Session replay (Sentry Replay): only if you turn on analytics yourself.
- Marketing emails: Sent only with your explicit consent. You can withdraw consent at any time.
Legitimate Interest: Article 6(1)(f)
- Error monitoring (Sentry): Maintaining service reliability and diagnosing issues.
- Security and fraud prevention: Protecting the platform and users from abuse, supported by Recital 49 of the GDPR.
- App access sessions: Securing access to apps you open from your workspace.
- Consent record storage (IP at consent time): Necessary to demonstrate valid consent as required by Article 7(1).
- Product analytics (daily activity counts in our own database, described above): Understanding how the service is activated, used and retained so we can improve it and measure what it costs to run. Reported in aggregate; not used to evaluate individual users, and not used for automated decisions about you.
- Referral attribution (which share link, invitation or remix brought you here): Understanding how people find Zentier. The share-link code travels in the address of the page you land on and is carried through sign-up; it identifies the share link, not you or your device, and it is not read back from anything stored on your device. While analytics is allowed (see “Consent” above), the same code is also kept in the
zentier_refcookie so a later return can still be attributed — see our Cookie Policy.
4. Third-Party Processors
We use the processors below to deliver our service, each under its data processing terms, except the AI model providers, which OpenRouter engages under its own terms (explained after the list). Our Sub-Processor List shows the current list and how we tell you about changes.
- WorkOS (United States): Authentication and user management
- Convex (European Union): Database and backend
- Cloudflare (Global edge network): Hosting, storage, and edge compute
- Vercel (Global edge network): Web application hosting
- Polar (United States): Payment processing and subscriptions
- Stripe (European Union and United States): Payment processing and invoicing
- Resend (United States): Email delivery
- PostHog (European Union): Product analytics
- Sentry (European Union): Error monitoring
- OpenRouter (United States): AI model API routing
- AI model and web search providers (through OpenRouter) (Various): AI model inference, and web search for agents
- Brave Search (United States): Web search
- Fly.io (Matches workspace region): Compute infrastructure
- Depot.dev (Matches workspace region): Software build infrastructure
- GitHub (United States): Source code integration (user-initiated)
- Amazon Web Services (AWS KMS) (European Union): Encryption key management
- Composio (United States): Third-party integration connections (user-initiated)
- Google (PageSpeed Insights and Chrome UX Report APIs) (United States): Speed and real-user performance data for the website audit
For AI features, we route requests through OpenRouter, which forwards each one to a provider serving the model in use. We route model requests only to providers that do not retain prompts or responses and cannot train on them; a request that no such provider can serve fails rather than being sent to one that does. OpenRouter publishes the providers it works with at openrouter.ai/providers and its own sub-processors at openrouter.ai/authorized-sub-processors.
5. Data Residency
When you create a workspace, you choose a data region (EU, US, or Asia Pacific). That choice determines where your app databases, file storage, and build and development environments are placed. It does not move every service; the lists below say where the main parts of the service run, and Section 4 lists every processor and its location. The region cannot be changed after workspace creation.
Placed in your workspace region:
- Project databases (Cloudflare D1). EU workspaces get a jurisdictional guarantee; US and Asia Pacific get best-effort regional placement.
- File storage (Cloudflare R2). EU workspaces use EU-jurisdiction buckets; US and Asia Pacific use regional buckets with best-effort placement.
- Development environments (Fly.io: pinned to your workspace region).
- Build infrastructure (Depot.dev / Fly.io: regional build machines).
Always stored in the EU, whichever region you choose:
- Your account, workspaces and projects, your chat history with the AI, text extracted from files you add to your workspace drive, and your consent records (Convex: Ireland). This is our primary datastore and it is EU-only for every customer, including US and Asia Pacific workspaces.
- Product analytics (PostHog: EU, Frankfurt).
- Error monitoring (Sentry: EU, Frankfurt).
- Encryption key management (AWS KMS: EU).
Global or United States, whichever region you choose:
- Authentication (WorkOS: United States). Minimal PII: email, name, session tokens.
- AI inference (OpenRouter: United States). Prompts are then processed by the AI model provider OpenRouter routes them to, which may be in the United States or another country outside the EU (see Section 4).
- Web hosting (Vercel: global edge network, which receives every request, including your IP address).
- Edge caching and configuration (Cloudflare KV: globally replicated). Contains encrypted secrets and operational metadata, not user content.
- Observability metrics (Cloudflare Analytics Engine: globally distributed).
- Video delivery (Cloudflare Stream: globally replicated). The original file stays in your region; the streaming copy does not.
- Real-time coordination state (Cloudflare Durable Objects) outside the EU.
Outside the EU, Cloudflare offers placement hints rather than jurisdictional guarantees, so US and Asia Pacific placement is best-effort. We do not guarantee that all data remains exclusively within your selected region. We disclose all international transfers and the safeguards in place for each.
6. International Data Transfers
For EU workspaces, project databases, file storage, development environments, and build infrastructure are hosted within the EU. User account data and project metadata are stored in the EU via Convex (Ireland). Some services process data outside the EU under the safeguards described below, including authentication (WorkOS), AI inference (OpenRouter), email delivery (Resend), payments (Stripe), and edge networks (Vercel, Cloudflare). Section 4 lists every processor and where it processes data.
For US and Asia Pacific workspaces, your app databases, file storage and build and development environments are placed in your chosen region, but your account, projects, chat history, workspace drive text and consent records are stored in the EU (Convex, Ireland), as set out in section 5. If you selected a region to meet a data-localisation requirement of your own, please read that list carefully: our primary datastore is EU-only and does not follow your region.
We ensure adequate protection for international transfers using the following mechanisms:
- EU-US Data Privacy Framework (DPF): Where processors are certified under the DPF (Cloudflare, Stripe, Resend, PostHog, Sentry, GitHub, Amazon Web Services (AWS KMS), Google (PageSpeed Insights and Chrome UX Report APIs)), transfers are covered by the European Commission's adequacy decision.
- Standard Contractual Clauses (SCCs): For processors not covered by the DPF, we rely on the 2021 Standard Contractual Clauses (Commission Decision 2021/914) as included in each processor's standard DPA terms.
7. Your Rights
Under the GDPR (Articles 15–22), you have the following rights regarding your personal data:
- Right of access (Article 15): Request a copy of your personal data. You can also download it yourself from your account settings.
- Right to rectification (Article 16): Update your profile information via Settings → Profile.
- Right to erasure (Article 17): Delete your account via Settings → Account → Delete account, or by writing to privacy@zentier.ai. There is a 7-day grace period during which you can cancel the deletion.
- Right to restrict processing (Article 18): Contact us at privacy@zentier.ai to request restriction of processing.
- Right to data portability (Article 20): Receive your data in a machine-readable format.
- Right to object (Article 21): Object to processing we base on legitimate interest by writing to privacy@zentier.ai.
- Right to withdraw consent: You can withdraw consent at any time, for analytics in Cookie Settings and for marketing email through the unsubscribe link in any marketing email. Withdrawal does not affect processing that took place before it.
To exercise any of these rights, contact us at privacy@zentier.ai. We will respond within 30 days (or the applicable statutory period). We may ask you to verify your identity before processing your request.
8. Cookies & Tracking
We use cookies and similar browser storage as described in our Cookie Policy, which also explains how to change your choices.
9. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law:
- Active accounts: Data is retained while your account is active and the service is in use.
- Deleted accounts: After you initiate account deletion, there is a 7-day grace period during which you can cancel. After the grace period, your account data is permanently deleted, except as described in the items below.
- Waitlist entries: Retained until converted to a full account or 12 months after last interaction, then anonymized.
- Chat messages: Retained with the associated project, and erased with it (below).
- Projects you delete: A deleted project stays in Recently deleted for 30 days so you can restore it. When those 30 days end, its code, version history, data, database backups and chats are erased from our storage, and the copies of its code in our backups expire in the same period.
- Deleting a workspace or your account: Its projects go offline at once, and you have 7 days to cancel. After that everything in it is erased, including projects still in Recently deleted, without waiting for their 30 days. The one exception is the history of your code: we lock it against deletion for 28 days so that an attacker cannot destroy it, and it is erased when that lock ends, at most 29 days after you asked.
- Workspace drive files and memory notes: Kept until the workspace is deleted. Files and notes you remove are kept in the trash for 30 days, then deleted. Your private memory notes are deleted when your account is deleted.
- Agents and automations you deploy: The step-by-step record of each run (its individual steps, tool calls and full output) is deleted after 30 days, or after a longer period the workspace chooses. A short record of each run, which can include an excerpt of its result, is kept until the workspace is deleted.
- Unpaid workspaces: If a paid workspace's usage stays unpaid, it is suspended. We email you before deleting its stored media, app databases and drive files. We do not delete its source code or settings for non-payment.
- AI requests: We route AI model requests only to providers that do not retain them (see Section 4).
- Usage events: Deleted 12 months after they are recorded, or earlier when the project or workspace is deleted.
- Product analytics (daily activity counts): Retained for 14 months, then deleted. Deleted immediately when your account is deleted. Aggregated figures derived from them contain no user identifier and are kept longer.
- Referral data: Held on your account for as long as the account exists, and deleted with it. Aggregated figures derived from it contain no user identifier and are kept longer.
- Error logs (Sentry): Sentry's default retention period (90 days).
- Session replay recordings (Sentry): Sentry's default retention (90 days), only captured with your consent.
- Analytics (PostHog): PostHog's default retention period.
- App access sessions: Deleted after they expire (7 days). Expired sessions are cleaned up hourly.
- Consent audit log: Kept while your account exists, as proof of consent (Article 7(1)). IP addresses in it are removed three years after the entry was made. Entries from deleted accounts are kept without a link to the account and deleted three years after they were made.
- Billing records: Invoices and payment records are kept for 5 years from the end of the financial year they relate to, as the Danish Bookkeeping Act requires, including after your account is deleted (Article 17(3)(b)).
- Database backups: We keep daily backups of our main database for 30 days, then delete them. A backup taken before you deleted your account can still contain your data until it expires. If we ever restore from a backup, we re-apply the account deletions recorded since it was taken.
- Collaborator presence data: Deleted shortly after you stop being active.
- Typing indicators: Deleted after 1 hour of inactivity.
10. Automated Decision-Making & AI
Our AI agents produce code, text and images from your prompts. You review and control what you deploy, so this processing does not produce legal effects or similarly significant effects on you as described in Article 22 of the GDPR.
- You are told when you are talking to AI. Assistant messages in our chat interfaces are labelled as AI. How requests reach AI model providers is described in Section 4 above.
- Automated processing we do run: the order in which waitlist invites go out uses an automated score based on referrals (people who join through your link and confirm their email), and we run automated checks to detect abuse of the platform. Where an automated check leads to suspension or removal, we tell you the reason, and you can write to support@zentier.ai to have a person review it.
- Human oversight: you can override, modify or reject anything the AI produces.
11. Children
Zentier is a professional software development tool and is not directed at children. Our Terms of Service explicitly require users to be at least 16 years of age (GDPR Article 8 default threshold). By using the platform and accepting our Terms of Service, you affirm that you meet this age requirement.
If we learn that an account belongs to someone under 16, we will delete it.
12. When You Deploy Apps
When you deploy applications via Zentier (using Workers for Platforms), your deployed app may process your own end-users' personal data. In this relationship:
- You are the data controller for your app's end-user data.
- We act as a data processor, providing the infrastructure on which your app runs.
This is distinct from our role as controller of the platform's own data (user accounts, billing, etc.). You are responsible for your own app's privacy compliance, including having your own privacy policy for your end-users.
13. Changes to This Policy
We may update this Privacy Policy. Before a material change takes effect, we will tell you by email. The “Last updated” date above shows when it last changed.
14. Contact
If you have questions about this Privacy Policy or wish to exercise your data protection rights:
- General privacy inquiries: privacy@zentier.ai
You have the right to lodge a complaint with your local data protection authority (supervisory authority) if you believe your personal data has been processed in violation of applicable data protection law. Our lead supervisory authority is the Danish Data Protection Agency (Datatilsynet): datatilsynet.dk.