Zynkex — Privacy Notice
Effective date: May 27, 2026
Last updated: May 27, 2026
This Privacy Notice describes how Zynkex, Inc. ("Zynkex", "we", "us", "our") collects, uses, shares, and otherwise processes personal information when you visit our website, create an account, or use our services (collectively, the "Service"). It also describes your rights and how to exercise them.
By using the Service, you acknowledge this Privacy Notice. If you do not agree with how we handle personal information as described here, do not use the Service.
1. Who We Are
Zynkex is the data controller (or "business," for purposes of California law) responsible for the personal information described in this Notice. You can reach us at:
Email: privacy@zynkex.com
Postal address: Zynkex, Inc., 1209 N Orange Street, Wilmington, DE 19801, USA
2. Information We Collect
We collect the following categories of personal information:
2.1 Information you provide directly
Account information: name, email address, password (stored as a salted hash), email-verification status.
Profile information: any optional details you add to your profile (display name, organization name, role, time zone, etc.).
Session content: everything you submit during a brainstorming session — your idea, your responses, your edits, and any context you carry forward across sessions ("session memory"). This is the primary content the Service exists to process.
Project data: structured project records including session history, generated Directives, and outline documents associated with each project.
Uploaded files: documents, brand assets, logos, design tokens, color palettes, fonts, PDFs, images, and any other files you upload (for example, into the Theme Studio feature).
Payment information (when paid plans launch): processed directly by our payment processor (Stripe). Zynkex receives only limited billing metadata (e.g., last four digits of card, country, billing email, subscription status) — never full card numbers.
Support communications: the contents of any email or message you send us (questions, bug reports, feedback).
2.2 Information we collect automatically
Device and connection information: IP address, browser type and version, operating system, referring URL, language settings, and approximate location (derived from IP).
Usage information: pages viewed, features used, session counts, button clicks, time spent in the Service, error events, and similar interaction data.
Cookies and similar technologies: see Section 6.
2.3 Information from third parties
Authentication providers: if and when we add SSO/OAuth login (e.g., "Sign in with Google"), the provider passes us basic profile information (name, email, profile picture) per its standard policies.
Payment processors: Stripe shares limited billing metadata (subscription status, card brand) so we can show your plan correctly.
Error and analytics services: stack traces, page state, and limited request metadata when an error occurs (via Sentry).
2.4 Information we do NOT collect
We do not collect government-issued identification numbers, biometric data, precise geolocation, or financial-account details beyond what is necessary for billing.
We do not knowingly collect personal information from children under 13.
We do not collect "sensitive personal information" as defined by CPRA/GDPR special categories unless you voluntarily include it in your session content (which we strongly recommend you avoid — see Section 3.4).
3. How We Use Personal Information
We use the personal information we collect to:
3.1 Provide and operate the Service
Authenticate you and maintain your session.
Run the brainstorm flow and generate Directives, including by transmitting your session content to our AI inference provider (currently Anthropic).
Save your projects, sessions, brand assets, and Directives to your account.
Surface your past sessions and apply session memory when you return to a project.
Process subscription payments and maintain your billing records.
3.2 Communicate with you
Send transactional email (account creation, email verification, password reset, billing receipts, security alerts, service-status notices, policy updates).
Respond to your support requests, refund requests, and other communications.
Send marketing email only if you opt in. You may opt out at any time using the unsubscribe link in any marketing email or by emailing us.
3.3 Improve, secure, and protect the Service
Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms.
Analyse aggregate, de-identified usage patterns to improve features, pricing, and reliability.
Debug errors and reproduce bugs (using Sentry stack traces).
Comply with legal obligations and enforce our Terms.
3.4 How Anthropic processes your session content
We use Anthropic's API to process your session content in order to generate responses and Directives. Under Anthropic's standard API terms, Anthropic may use API inputs and outputs for model improvement purposes. Zynkex does not currently have a zero-data-retention agreement with Anthropic.
We recommend you avoid submitting highly confidential or sensitive personal information through the Service until we can offer enhanced data-handling commitments. If your use case requires a higher level of data protection, please contact us before use.
Zynkex itself does not train any machine-learning model on your session content, Directives, or any other personal information. We do not use your content to train models on behalf of any third party.
4. Legal Bases for Processing (EEA, UK, Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, our legal bases for processing your personal information are:
You may withdraw consent or object to processing based on legitimate interests at any time. Withdrawal does not affect the lawfulness of processing performed before the withdrawal.
5. How We Share Personal Information
We share personal information only as described below.
5.1 Service providers ("processors" under GDPR; "service providers" under CCPA/CPRA)
We use third-party companies to operate the Service. These providers process personal information on our behalf, under contractual obligations to safeguard it and use it only for our purposes.
Each provider may engage its own sub-processors to deliver its services. We are not responsible for sub-processors engaged independently by our providers, but we take reasonable steps to ensure our providers maintain appropriate data-protection standards.
We may add, remove, or replace service providers from time to time. Material changes will be reflected in this Notice.
5.2 Legal compliance and protection
We may disclose personal information if we believe in good faith that disclosure is reasonably necessary to:
(a) comply with applicable law, regulation, legal process (e.g., subpoena, court order), or government request;
(b) enforce our Terms of Service, including investigation of potential violations;
(c) detect, prevent, or otherwise address fraud, security, or technical issues;
(d) protect against harm to the rights, property, or safety of Zynkex, our users, or the public.
Where legally permitted, we will attempt to give you advance notice of any compelled disclosure.
5.3 Business transfers
If Zynkex is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, we may share or transfer personal information as part of that transaction. We will notify you of any such transfer that materially changes how your data is handled.
5.4 With your direction or consent
We may share personal information with third parties when you direct us to do so or with your specific consent.
5.5 Aggregate or de-identified information
We may share aggregate or de-identified information (information that cannot reasonably be used to identify you) for any purpose, including analytics, research, and marketing of the Service.
5.6 Sale of personal information; cross-context behavioral advertising
We do not sell personal information (as "sell" is defined under the CCPA/CPRA). We do not share personal information for cross-context behavioral advertising. We do not sell or share personal information of consumers under 16 years of age.
6. Cookies and Similar Technologies
We use a small number of cookies and similar technologies. We do not use cookies for advertising or cross-site tracking.
Most browsers let you delete cookies, block them, or warn you before they are set; consult your browser's documentation. Disabling essential cookies will break the Service.
We honour Global Privacy Control (GPC) signals in California and other jurisdictions where legally required to do so. We do not respond to "Do Not Track" browser signals at this time.
Counsel: please advise on whether a cookie banner is required for our user base and how it should differentiate between essential, functional, and (if added) analytics cookies.
7. Data Retention
We retain personal information for as long as it is needed for the purposes described in this Notice and to comply with our legal obligations.
Deletion timelines are best-effort and may be extended where reasonably required to investigate fraud, security incidents, or legal claims.
8. Your Rights
Depending on where you live, you may have some or all of the following rights regarding your personal information:
Access — request a copy of the personal information we hold about you.
Correction — request correction of inaccurate or incomplete information.
Deletion — request deletion of personal information.
Portability — request a structured, machine-readable copy (JSON or equivalent commonly used format) of personal information you provided to us.
Restriction — request that we limit how we use your information.
Objection — object to processing based on legitimate interests, including direct marketing.
Withdraw consent — for processing based on consent, withdraw consent at any time.
Opt out of marketing — at any time, via the unsubscribe link or email.
Opt out of sale or sharing of personal information (CCPA/CPRA) — N/A, because we do not sell or share for behavioral advertising.
Lodge a complaint with your local data-protection authority if you believe we are processing your information unlawfully.
Non-discrimination — we will not discriminate against you for exercising any of these rights.
To exercise any of these rights, email us at privacy@zynkex.com. We will respond within the time required by applicable law (generally 30 days for GDPR; 45 days for CCPA, extendable by 45 days where reasonably necessary).
We will need to verify your identity before responding to a rights request. If you are submitting a request through an authorized agent, we will require proof of authorisation.
9. International Data Transfers
Zynkex is based in the United States, and our service providers are primarily located in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, which may have data-protection laws different from those in your country.
For transfers from the EEA, UK, or Switzerland to the United States, we rely on:
Standard Contractual Clauses (SCCs) approved by the European Commission, with our service providers; and/or
Other transfer mechanisms as permitted by applicable law (e.g., the EU–US Data Privacy Framework where applicable).
You can request a copy of the SCCs or other transfer mechanism by contacting us at the address above.
10. Children's Privacy
The Service is not directed at children under the age of 13, and we do not knowingly collect personal information from anyone under 13. If we learn that we have collected information from a child under 13, we will delete it promptly. If you believe we may have collected such information, contact us immediately.
For users between 13 and 17, the Service is permitted only with the consent and supervision of a parent or legal guardian, and the guardian agrees to be bound by our Terms of Service on the user's behalf.
11. Security
We use commercially reasonable administrative, technical, and organizational measures to protect personal information against unauthorised access, alteration, disclosure, or destruction. These include:
Encryption in transit (HTTPS/TLS for all traffic; TLS for database connections).
Encryption at rest for our primary database (Supabase Postgres).
Hashed and salted passwords (using bcrypt or equivalent).
Access controls limiting personal-information access to personnel who need it.
Audit logging of administrative access where supported by our infrastructure.
Regular review of third-party providers' security postures.
No method of transmission or storage is 100% secure. While we work to protect your information, we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential.
In the event of a personal-data breach affecting your information, we will notify you and any required regulator within the timeframes required by applicable law — for EEA and UK users, this means notifying the relevant supervisory authority within 72 hours of becoming aware of the breach, and notifying affected individuals without undue delay where the breach is likely to result in high risk to their rights and freedoms.
12. Automated Decision-Making
We do not engage in solely automated decision-making that produces legal or similarly significant effects on you. The AI-generated outputs you see in the Service are content produced for your review; they are not used by Zynkex to make decisions about you.
13. California-Specific Disclosures (CCPA/CPRA)
This section provides additional disclosures required for California residents.
13.1 Categories of personal information collected, disclosed, and shared
In the past 12 months, Zynkex has collected the following categories of personal information (as defined in the CCPA):
Identifiers (name, email address, IP address)
Customer records information (account information, billing metadata when applicable)
Internet or other electronic network activity (usage logs)
Geolocation data (approximate, derived from IP)
Inferences (rare; only as needed to operate the Service — e.g., session-tier classification)
Other personal information you voluntarily include in session content
We have disclosed the categories above to the service providers listed in Section 5.1, for the purposes described.
We have not sold personal information and have not shared personal information for cross-context behavioral advertising in the past 12 months.
13.2 Sources of collection, business purposes, retention
See Sections 2 (sources), 3 (purposes), and 7 (retention) above. The purposes apply equally to information collected from California residents.
13.3 California rights
California residents have the rights listed in Section 8 plus:
The right to know specific pieces of personal information collected about them.
The right to limit the use and disclosure of "sensitive personal information" — though we do not knowingly collect sensitive personal information from users.
The right to opt out of sale or sharing — N/A (we don't).
To exercise any right, email us at privacy@zynkex.com. You may also designate an authorized agent to make a request on your behalf, with proof of authorisation.
For the purposes of California Civil Code § 1798.83, California residents may request information regarding our disclosures of personal information to third parties for the third parties' direct-marketing purposes by writing to the address in Section 1. We do not currently make any such disclosures.
14. Other US State Privacy Laws
For Virginia, Connecticut, Colorado, Utah, Texas, Oregon, Montana, and other state-specific privacy regimes, you have rights substantially similar to those listed in Section 8. To exercise any state-law right, contact us at the address above. We will verify your identity before responding and will respond within the time required by applicable law.
We do not engage in profiling that produces legal or similarly significant effects on consumers. We do not sell personal information.
15. Changes to This Notice
We may update this Notice from time to time. The "Last updated" date at the top reflects the most recent revision. For material changes, we will provide reasonable advance notice — typically by email to the address on file or via in-product notice — at least 30 days before the change takes effect.
If you do not accept a change, your remedy is to stop using the Service and (if you wish) delete your account.
16. Contact
Questions about this Privacy Notice, or to exercise any privacy rights:
Email: privacy@zynkex.com
Postal address: Zynkex, Inc., 1209 N Orange Street, Wilmington, DE 19801, USA
If you are in the European Economic Area or the United Kingdom, you may also lodge a complaint with your local supervisory authority.