Privacy Policy
Privacy Policy
At Zerus (zerus.app), we process personal data to operate the site, authenticate users, save documents, provide contracted features, and maintain operational security. This policy describes the current product and is not a legal certification or a claim of full regulatory compliance.
1. Data we process
The categories below depend on how you use the product. Anonymous visitors generate less data than authenticated users with an active account.
- Account and identity: name, email, profile image, user identifiers, and session metadata from Clerk.
- Workspace content: documents, notes, preferences, folders, calendar data, chat history when enabled, and editor settings.
- Subscription and billing: email, customer identifiers, subscription, checkout, and billing data processed by Stripe. We do not store full card numbers.
- AI and media processing: prompts, document or note excerpts, preferences, audio/video/image/PDF files, and extracted text when you use chat, rewrite, translation, SEO, summary, OCR, transcription, or converters.
- Telemetry and diagnostics: IP address, browser, device, visited page, product events, logs, errors, traces, and, when allowed by governance rules, replay or session data.
- Email and support: recipient, sender, shared content, generated attachments, user agent, page URL, and free-text fields sent through support or bug reports.
2. Purposes and legal basis
We use data to perform our contract with registered users, meet operational obligations, protect the platform, respond to requests, and improve the product within the limits of current governance.
- Operate login, sessions, synchronization, editing, storage, and retrieval of documents.
- Process payments, subscriptions, quotas, plan limits, and billing webhooks.
- Run requested AI, OCR, transcription, conversion, export, and email sharing features.
- Detect failures, prevent abuse, apply rate limits, investigate incidents, and support users.
- Measure product and marketing usage only under the telemetry rule applicable to anonymous visitors or authenticated users.
3. Telemetry, cookies, and user state
Non-essential tracking must not load too early for anonymous visitors. The product governance separates navigation analytics, authenticated product analytics, essential observability, and session replay.
Acceptance of the Terms of Use during sign-up supports processing needed for the authenticated service, but it is not unlimited permission for marketing tracking. Where law or internal rules require a specific choice, the product must respect that choice.
- Google Analytics: web analytics and navigation events when allowed.
- PostHog: product analytics, authenticated events, and activation metrics when allowed.
- Sentry: errors, traces, technical diagnostics, and replay only under the allowed configuration.
- Axiom: structured logs and operational metadata for diagnostics and security.
4. Third parties and subprocessors
We do not sell personal data. We share data with vendors when needed to provide the service, process an action you requested, maintain security, or operate infrastructure. These vendors may process data outside Brazil, including in the United States or the European Union, under their own contractual and technical controls.
Primary storage varies by flow: account and authentication data live in Clerk and in the application's main database via Prisma/Postgres; operational sessions and quotas may pass through Redis; files, emails, analytics, logs, and external processing may be stored temporarily or permanently by the vendors listed below depending on the feature used.
- Clerk: authentication, identity, sessions, and basic account data.
- Stripe: checkout, portal, subscriptions, payments, and billing webhooks.
- OpenAI / LLM provider: chat, rewrite, translation, summary, SEO, workspace questions, and transcription when you use those features.
- Vercel: hosting, application execution, edge/runtime, and web infrastructure.
- Upstash Redis: cache, quotas, operational sessions, and rate limits.
- Cloudinary: upload, temporary storage, and media processing.
- OCR.Space: image OCR and text extraction when used in converters.
- Stirling PDF: PDF processing, conversion, or extraction when used in converters/exports.
- Resend: transactional emails or requested sharing flows, including weekly agenda sharing.
- PostHog, Google Analytics, Sentry, and Axiom: analytics, observability, logs, errors, and diagnostics according to telemetry governance.
5. Retention, deletion, and current limits
We keep core account, subscription, and workspace data while your account exists and while needed to operate the service, comply with legal obligations, resolve disputes, prevent abuse, or preserve security evidence.
Some periods are already objective in the product: active editor session in Redis for up to 7 days; private dashboard, calendar, document, folder, note, and kanban caches for seconds or a few minutes; daily and monthly Redis quotas until period rollover; aggregated AI usage records for 3 months before automatic cleanup.
Content removed by the user stops being available in the interface, but technical copies, logs, backups, privacy trails, and external vendor records may follow their own retention cycles.
The product now provides authenticated data export and a formal account deletion request flow inside account settings. Full completion of deletion still depends on a later operational step across external vendors where applicable.
6. Your rights
You may request confirmation of processing, access, correction, deletion, portability where technically available, information about sharing, and review of applicable preferences. Some requests may require identity verification and may be limited by legal obligations, security, fraud prevention, or the need to keep contractual records.
To exercise rights or ask privacy questions, email contato@zerus.app.
Complaints, review requests, and disputes about data processing follow the same channel. If the first response does not resolve the matter, you may request a formal review in the same thread and, where applicable, escalate to the competent authority or legal channels available to you.
7. Security, changes, and contact
We use authentication, input validation, user-level segregation, access controls, and technical monitoring to reduce risk. No measure eliminates incidents completely, so we review product governance periodically.
We may update this policy when the product, vendors, or operational rules change. The last update date is recorded below.