1. Who we are
The service at zaatar.ai (the “Service”) is operated by PLACEHOLDER_LEGAL_ENTITY_NAME, PLACEHOLDER_REGISTERED_ADDRESS, registered under PLACEHOLDER_COMPANY_REGISTRATION_RCS(“Zaatar”, “we”, “us”). Zaatar is the data controller for the personal data described in this policy. For any privacy question or request, contact support@zaatar.ai.
2. What we collect
Account data
Sign-in is through Google. When you create an account we receive your name, email address, and profile picture from your Google account. If you join or create an organization we also store your role and membership in it.
Data from services you connect
The Service works by connecting to tools you already use, with your explicit authorization on each one:
- Google Search Console: search performance data for the properties you connect (queries, clicks, impressions, positions, indexed pages).
- Google Analytics: if you connect it, read-only traffic and audience reports for the GA4 properties you choose, used to inform the analysis and content we produce for you.
- GitHub: metadata and content of the repository you choose as your publishing destination, so agents can read your site and open pull requests against it.
Your website
We crawl the public pages of the website you register, the same way a search engine does, to audit and improve them.
Content produced in the Service
Audits, reports, article drafts, tasks, and pull requests generated for your projects, plus any input you write in the product (for example edits to a draft or your company profile).
Technical data
Standard server logs (IP address, browser type, timestamps, requested pages) and operational records of what the Service did on your behalf. We do not run advertising trackers.
3. Why we process it
- To provide the Service (performance of our contract): running audits, generating content and fixes, opening pull requests you approve, sending you the emails the product depends on (for example when work is ready for your review).
- To secure and improve the Service (legitimate interest): debugging, abuse prevention, capacity planning, and understanding which features are used.
- To comply with the law (legal obligation): accounting, tax, and responding to lawful requests.
- With your consent, where required: optional product communications. You can withdraw consent at any time.
4. AI processing
Zaatar’s agents use large language models to analyze your data and draft content. To do that, relevant excerpts of your project data (for example search queries, page content, or your company profile) are sent to our AI infrastructure subprocessors over encrypted connections and processed to produce the analysis or draft. We send what a task needs, not your whole account, and we never sell your data or use it for advertising.
5. Google user data
Zaatar’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google Search Console and Google Analytics data are accessed read-only, are used solely to provide the SEO and analytics features you see in the product, are never used for advertising, and are never sold. Humans at Zaatar do not read this data except with your consent, for security purposes, or where required by law.
6. Who we share it with
We share personal data only with the subprocessors that run the Service, under data processing agreements. We never sell personal data.
| Purpose | Provider | Location |
|---|---|---|
| Application and database hosting | Hetzner Online GmbH | European Union |
| AI model inference | OpenRouter, Inc. | United States |
| Transactional email | Mailjet SAS | European Union (France) |
| Search ranking data (SERP) | DataForSEO LLC | United States |
If we ever introduce paid plans, payment details will be handled by a dedicated payment provider and disclosed here before launch. We may also disclose data where the law requires it, or as part of a merger or acquisition, in which case this policy continues to apply to it.
7. International transfers
Some subprocessors may process data outside the European Economic Area. Where that happens, transfers are protected by an adequacy decision or by the European Commission’s Standard Contractual Clauses.
8. How long we keep it
Your data is kept for as long as your account is active. When you delete your account, deletion enters a 30-day grace period during which you can change your mind; after it, your personal data is deleted or anonymized. Server logs are kept for a limited period for security purposes, and residual copies in encrypted backups are purged on a rolling basis. Data we must keep for legal reasons (for example invoices) is retained for the legally required duration.
9. How we protect it
Data is encrypted in transit with TLS and the credentials to your connected accounts are encrypted at rest with AES-256-GCM, using an encryption key stored separately from the database. Access to your data is scoped to your organization on every request, and the permissions we request from Google and GitHub are the narrowest that support the product: read access to your search data, and repository access used to open pull requests that only you can merge.
A small, named group of our staff can open your account and see it as you see it, so that we can diagnose a problem you reported or find one before you hit it. These support sessions are limited to a fixed list of staff accounts, are read-only unless changing something is the only way to reproduce a fault, expire automatically after a short period, and are recorded: who opened the account, when, why, and anything they changed. We do not use this access for any purpose other than operating and supporting the Service.
10. Your rights
Under the GDPR you can ask us for access to, correction of, deletion of, or a portable copy of your personal data, ask us to restrict or object to processing, and withdraw any consent you gave. Write to support@zaatar.ai and we will respond within one month. You can also lodge a complaint with your supervisory authority; in France that is the CNIL (www.cnil.fr).
11. Cookies and local storage
Our marketing website uses Simple Analytics, a privacy-focused analytics service that uses no cookies and collects no personal identifiers. The application stores your session token in your browser’s local storage so you stay signed in; it sets no advertising or cross-site tracking cookies.
12. Children
The Service is built for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 15.
13. Changes to this policy
When we change this policy in a material way, we will update the date at the top and notify you in the product or by email before the change takes effect.
14. Contact
Privacy requests: support@zaatar.ai. Anything else: support@zaatar.ai.