ZYLX.ai logoZYLX.ai

Privacy Policy

Effective date: August 9, 2026

1. Who we are

ZYLX ("Zylx", "we", "us") operates zylx.ai and the Zylx Studio application at zylx.studio, along with companion apps for content, outreach, and mail. This policy explains what data we collect, how we use it, and the choices you have. Questions? Reach us via our contact page.

2. Data we collect

  • Account data: your name, email address, and authentication details when you create an account.
  • Connected provider data:when you choose to connect your own accounts (for example Shopify, Google Search Console, Google Analytics, Google Ads, Stripe in read-only mode, and similar tools), we access the data those connections permit in order to build and keep your Business Brain current. You control every connection and can revoke access at any time from within the app or from the provider's own settings.
  • Site data: content from websites you ask us to crawl and analyze on your behalf.
  • Usage data: logs of how the service is used, including actions you approve or reject, which we keep so you have an auditable history.

3. How we use your data

We use your data to operate the service: building your Business Brain, generating recommendations and content, running diagnostics, and powering the integrations you enable. We do not sell your data, and we do not use your data to advertise to third parties.

4. AI processing

Zylx uses AI models provided by Anthropic and OpenAI via their APIs to generate recommendations and content from your connected data. Data sent to these providers is used to produce the requested output. Zylx does not train AI models on your customer data.

5. MCP and AI assistant access

You can connect AI assistants (such as Claude or ChatGPT) to your Business Brain via the Model Context Protocol (MCP). This access is authorized by you, uses scoped and revocable tokens, and can be revoked at any time. No assistant can reach your data unless you have explicitly connected it.

6. Storage and security

Your data is stored in Supabase (hosted Postgres) with per-account isolation enforced by row-level security. We use authentication cookies to keep you signed in. Access to production systems is restricted, and provider credentials are stored encrypted.

7. Billing

Payments are processed by Stripe. Stripe stores your payment card details — Zylx never sees or stores your full card number.

8. Subprocessors

We use the following service providers to operate Zylx:

  • Vercel — application hosting
  • Supabase — database and authentication
  • Stripe — payment processing
  • Resend — transactional and campaign email delivery
  • Anthropic — AI processing
  • OpenAI — AI processing

9. Data retention and deletion

We retain your data while your account is active. You can disconnect any provider at any time, and you can request deletion of your account and associated data by contacting us via the contact page. We will delete your data within a reasonable period, except where we are required by law to retain it.

10. Your rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal data. To exercise any of these rights, contact us via the contact page.

11. Changes to this policy

We may update this policy from time to time. Material changes will be posted on this page with an updated effective date.

Continue exploring