Privacy Policy.
Effective date: July 6, 2026
1. Introduction
Zurvo Inc. (“Zurvo”, “we”, “us”, “our”) provides an AI-powered customer support chatbot platform. Our customers — the businesses that sign up for Zurvo — embed a chat widget on their own websites, train it on their own content, and use our dashboard to manage conversations, leads, and analytics.
This Privacy Policy explains what personal information we collect, why we collect it, how we use and share it, and the choices and rights you have. It covers:
- Our websites: zurvo.ai (marketing) and app.zurvo.ai (the product dashboard).
- Our customers’ accounts: the information businesses give us when they sign up and use Zurvo.
- End users of our customers’ widgets: if you chat with a Zurvo-powered widget on someone else’s website, Section 3 is written for you.
If you do not agree with this policy, please do not use our services.
2. The two roles we play: controller and processor
Zurvo handles personal information in two distinct roles, and your rights depend on which role applies:
-
Zurvo as a data controller. When you visit our own websites, request a demo, create a Zurvo account, subscribe to a plan, or contact us, we decide how and why your information is processed. This policy governs that processing directly.
-
Zurvo as a data processor (service provider). When you chat with a Zurvo-powered widget on a customer’s website, that business — not Zurvo — decides why your chat data is collected and how it is used. The business is the data controller of your conversation, and we process it on the business’s behalf and under its instructions. In that situation, the business’s own privacy policy governs, and your privacy rights should be exercised with that business (see Section 3).
We make data processing terms available to our customers to govern our processing of their end users’ data. A Data Processing Agreement (DPA) is available upon request from privacy@zurvo.ai.
3. If you chat with a Zurvo-powered widget on someone else’s website
This section is for visitors who use a chat widget powered by Zurvo on a business’s website.
Who is responsible for your data. The business whose website you are visiting controls your conversation data. Zurvo stores and processes it on that business’s behalf so the widget can answer your questions, hand you off to the business’s team, and let the business review its own customer conversations.
What we process on the business’s behalf when you use the widget:
- Your chat messages and the AI assistant’s responses.
- Contact details you choose to share — such as your name, email address, or phone number — if you fill in a contact form in the widget or offer them in conversation so the business can follow up.
- Photos you choose to upload in the chat, if the business has enabled photo upload. Images are stored in a private storage bucket and analyzed by an AI vision model so the assistant can respond to them.
- A visitor identifier stored in your browser’s localStorage on the business’s site, so the widget can remember your conversation between page loads. This identifier is scoped to that business’s widget; we do not use it to track you across unrelated websites.
- The address (URL) of the page you were viewing when you sent a message, so the assistant can understand context and the business can see where conversations start.
- Your IP address and browser information (user agent), used for rate limiting, abuse prevention, and security logging, and to derive an approximate location (such as country and city) that is shown to the business so it can see where its conversations come from. We do not use your IP address to build an advertising profile of you or to track you across unrelated websites.
- Feedback you give on answers (thumbs up / thumbs down).
What happens with AI. Your messages (and any photos you upload) are sent to third-party AI model providers to generate the assistant’s responses, as described in Section 7. They are not used by Zurvo to train AI models.
How to exercise your rights. Because the business controls your conversation data, please direct requests to access, correct, or delete your chat data to the business whose website you used. If you contact us directly at privacy@zurvo.ai, we will refer your request to the relevant business and assist that business in responding, as required by law and our agreement with them.
Do not share sensitive information in a chat widget. The assistant is designed to discourage sharing of passwords, government ID numbers, or full payment card numbers, but you should never type this kind of information into a chat.
4. Information we collect as a controller
4.1 Account and profile information
When a business creates a Zurvo account, we collect the account holder’s email address and password (managed through our authentication provider), name, organization/company name, website URL, and business type. Team members invited to a workspace provide their email address and name.
4.2 Billing information
We use Stripe to process payments. When you subscribe, Stripe collects your payment card details directly; we never receive or store your full card number. We store references such as your Stripe customer ID, subscription ID, and plan, and we receive limited billing metadata from Stripe (such as subscription status). Stripe’s handling of your payment data is described in Stripe’s own privacy policy.
4.3 Customer content
To power your chatbot, we store the content you provide: pages crawled from your website, documents you upload, content you edit in the dashboard, your business profile, and the vector embeddings we derive from that content for search and retrieval.
4.4 Usage, log, and diagnostic data
We keep usage records (for example, message counts for billing and plan limits), audit logs of significant actions in your workspace (including the acting user’s IP address and browser user agent), and error and diagnostic logs, to operate, secure, and troubleshoot the service.
4.5 Marketing website and communications
Our marketing site, zurvo.ai, is a static website. It does not run advertising trackers, and it currently does not run third-party analytics scripts. If you request a demo, we collect the email address you submit and use it to respond to you; the message is delivered through our email provider (Resend). If you email us, we keep the correspondence.
4.6 Message feedback and product signals
We store answer ratings and related quality signals so our customers can evaluate and improve their own chatbot’s answers.
5. Information we process on behalf of our customers
As described in Section 3, when end users interact with a customer’s widget, we process on the customer’s behalf: chat messages and AI responses, contact details the end user shares (name, email, phone), uploaded photos, a per-widget visitor identifier, page URLs, feedback ratings, security data such as IP addresses and user agents used for rate limiting and abuse prevention, and an approximate location (country and city) derived from the IP address so the customer can see where its conversations originate. Our customers control this data; we use it only to provide the service to them and as permitted by our agreements, and we do not sell it or use it for advertising.
6. How we use information
We use personal information to:
- Provide, operate, and maintain the service, including generating AI responses grounded in a customer’s own content;
- Create and manage accounts, authenticate users, and enforce role-based access;
- Process subscriptions and payments and enforce plan limits;
- Hand off conversations from the AI assistant to the customer’s human team, including notifications by email;
- Provide analytics and insights to customers about their own chatbots and conversations;
- Secure the service: rate limiting, abuse and fraud prevention, audit logging, and incident investigation;
- Respond to support requests and communicate about the service;
- Comply with legal obligations and enforce our terms.
We do not use personal information for third-party advertising, and we do not sell personal information.
7. AI processing and model providers
Zurvo is an AI product. To generate responses, we send conversation content — and, where applicable, uploaded images and customer knowledge-base content — to third-party AI model providers via their APIs:
- Anthropic (chat responses and content extraction);
- OpenAI (text embeddings used for search and retrieval);
- OpenRouter, an API routing service through which we access additional models (for example, Google’s Gemini models for image understanding and other models for chat).
Training. Zurvo does not use your data, or your end users’ data, to train AI models. Under the API terms of our direct model providers, Anthropic and OpenAI do not use API inputs and outputs to train their models by default. Requests routed through OpenRouter are subject to OpenRouter’s policies and those of the downstream model provider that serves the request.
Model providers may retain API data for a limited period for abuse monitoring under their own policies. We select providers whose API terms restrict use of customer data, and we list them as subprocessors in Section 8.
8. How we share information; subprocessors
We do not sell personal information and we do not share it with third parties for their own marketing. We share personal information only with:
Service providers (subprocessors) that help us run Zurvo, under contracts limiting their use of the data:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | United States |
| Vercel | Application hosting and delivery | United States |
| Stripe | Payment processing | United States |
| Resend | Transactional email delivery | United States |
| Anthropic | AI model provider (chat, extraction) | United States |
| OpenAI | AI model provider (embeddings) | United States |
| OpenRouter | AI model routing (including Google models for image understanding) | United States |
This table is the authoritative list of our current subprocessors. We may update it from time to time, and we will announce material changes by updating this policy with a revised effective date.
Our customers. Conversation data belongs to the customer whose widget produced it; customers and their authorized team members can view their own conversations, leads, and analytics in the dashboard.
Legal and safety. We may disclose information when required by law, to respond to lawful requests, to protect the rights, safety, and property of Zurvo, our customers, or others, or to enforce our agreements.
Business transfers. If Zurvo is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this policy’s commitments.
With your consent, in any other case.
9. Cookies and local storage
Our product dashboard (app.zurvo.ai) uses essential cookies for authentication and security (for example, session cookies from our authentication provider and anti-forgery protections). Our payment provider, Stripe, may set cookies in connection with checkout and billing.
Our marketing site (zurvo.ai) does not currently use third-party analytics or advertising cookies.
The embedded chat widget on customers’ websites uses browser localStorage (not cookies) to remember your conversation and widget state on that site, as described in Section 3.
See our Cookie Policy for details.
10. Data retention
- Account data and customer content are retained for as long as the customer’s account is active. When an account is deleted, we delete the associated organizations, chatbots, knowledge content, embeddings, conversations, messages, leads, and related records. Customers can also export their data from the dashboard before deletion.
- Conversation data processed on behalf of customers (chat messages, leads, uploads) is retained while the customer’s account is active or until the customer deletes it, whichever comes first. We do not otherwise apply an automatic expiration to conversation content.
- Operational logs (error and usage logs) are retained for up to 90 days for security, billing, and troubleshooting needs. Audit logs are retained for up to 365 days. Logs are deleted on a periodic schedule.
- Uploaded chat photos are stored in a private bucket; access links expire after 7 days, and the files are removed when the associated account data is deleted.
- We may retain limited information longer where required for legal, tax, accounting, or security purposes.
11. Security
We describe our security posture plainly and do not claim certifications we do not hold:
- Tenant isolation. Every customer’s data is logically isolated. Access is enforced at the database layer with row-level security policies, so one customer’s content cannot surface in another customer’s chatbot or dashboard.
- Access controls. Dashboard access is governed by role-based access control; team members see only what their role permits.
- Encryption. Data is encrypted in transit using TLS. Data at rest is encrypted by our managed infrastructure providers, and certain sensitive configuration values receive additional application-level encryption.
- Audit logging. Significant actions are recorded in audit logs to support investigation and review.
- Payment data. Card details are handled entirely by Stripe, a PCI-DSS-compliant processor, and never touch our systems.
- What we do not have yet. Zurvo does not currently hold SOC 2, ISO 27001, or similar third-party certifications. We will not represent otherwise. Our Security page explains what is built today versus what is on our roadmap.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we learn of a security incident affecting your personal information, we will notify affected customers and regulators as required by applicable law.
12. International data transfers
Zurvo is operated from the United States, and our subprocessors listed in Section 8 process data in the United States. If you access the service from outside the U.S. (including the EEA, the United Kingdom, or Switzerland), your personal information will be transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.
Where required, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) as the safeguard for such transfers. Data is hosted in the United States.
13. Your privacy rights (EEA, UK, and similar jurisdictions)
Where the GDPR, UK GDPR, or similar laws apply and Zurvo acts as the controller, we process personal information on these lawful bases:
- Performance of a contract — to provide the service you or your organization signed up for;
- Legitimate interests — to secure and improve the service, prevent abuse, and communicate with business contacts, where those interests are not overridden by your rights;
- Consent — where we ask for it (for example, optional marketing communications), which you may withdraw at any time;
- Legal obligation — where processing is required by law.
You may have the right to: access the personal information we hold about you; correct inaccurate information; request deletion; restrict or object to processing; receive a portable copy of your information; withdraw consent; and lodge a complaint with your local supervisory authority.
To exercise these rights, contact privacy@zurvo.ai. We will verify your request and respond within the timeframe required by law. If your request concerns chat data from a business’s widget, we will refer it to that business as described in Section 3.
We have not appointed a Data Protection Officer or an EU or UK representative. For any privacy matter, including questions about our processing or the exercise of your rights, contact us at privacy@zurvo.ai.
14. US state privacy rights (California and other states)
If you are a resident of California or another US state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, or Utah), you may have rights to know, access, correct, delete, and obtain a portable copy of your personal information, and to opt out of certain processing.
- Categories we collect (as a controller): identifiers (name, email, IP address); commercial information (subscription and billing records); internet activity (usage and log data); professional information (company, role); and any content you choose to provide. The sources, purposes, and recipients are described in Sections 4, 6, and 8.
- No sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months.
- Sensitive personal information. We do not seek to collect sensitive personal information, and we do not use or disclose it for purposes requiring a right to limit under the CPRA.
- Service-provider role. For end-user chat data, we act as a “service provider”/“processor” to the business whose widget you used; please direct requests to that business.
- Non-discrimination. We will not discriminate against you for exercising your rights.
- Exercising rights. Email privacy@zurvo.ai. You may use an authorized agent; we will verify the request as permitted by law.
15. Children’s privacy
Our services are not directed to children under 13 (or under 16 in the EEA), and we do not knowingly collect personal information from children under those ages. If we learn that we have collected such information, we will delete it. Our customers are responsible for ensuring their own websites and widget deployments comply with children’s privacy laws applicable to their audiences.
16. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page with an updated effective date, and for material changes we will provide additional notice to account holders (such as by email or an in-dashboard notice) before the changes take effect.
17. How to contact us
For privacy questions or to exercise your rights:
- Email: privacy@zurvo.ai
- Mail: Zurvo Inc., 4712 Penn Ave, Unit 7090, Sinking Spring, PA 19608, USA
If you are in the EEA or UK and believe we have not resolved your concern, you may contact your local data protection authority.