Skip to main content

Privacy Policy

Last updated: June 2026

1. Data controller

Zenith (“we,” “our,” “us”) is the data controller for personal data collected through this platform. Contact us at privacy@zenithml.com.

2. Data we collect

  • Account data: email address, display name, and OAuth profile information (when signing in with Google).
  • Learning content: flashcard decks, cards, and study session data you create on the platform.
  • Usage data: page views, feature interactions, and performance metrics (only after cookie consent).
  • Technical data: IP address, browser type, and error logs necessary for platform operation.

3. Legal basis (GDPR Article 6)

  • Performance of a contract (Art. 6(1)(b)): processing your account and learning data to deliver the service you signed up for.
  • Legitimate interests (Art. 6(1)(f)): security monitoring, error logging, and fraud prevention.

4. Data processors

We share data with the following sub-processors, each bound by a Data Processing Agreement (DPA):

  • Supabase — database and authentication (EU region)
  • Google Cloud Platform (GCP) — machine learning infrastructure (EU region)
  • Stripe — payment processing, subscription management and VAT determination
  • Sentry — error monitoring
  • Google (Gemini) — AI features: card generation, reading translation and comprehension questions, conversation practice, and study-plan generation (text you submit for processing; no training on your data)

5. Data retention

In accordance with Article 5(1)(e) GDPR (storage limitation), we retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to comply with statutory legal obligations:

  • Learning & account content: Flashcards, decks, study histories, reading sessions, conversations, and plan goals are retained for the lifetime of your active account. When you delete your account, your data is erased from the live database within 30 days.
  • Operational logs & security records: Operational AI token usage records, security and moderation events, notification logs, and server diagnostic logs are automatically purged after 90 days.
  • AI model inference: Prompts, voice audio, and reading extracts submitted for AI generation are processed ephemerally in memory and discarded immediately upon completion (zero provider data retention or model training).
  • Financial & billing records: Invoices, payment transaction references, and VAT accounting records are retained for 5 years following the end of the applicable financial year in compliance with statutory requirements under the Danish Bookkeeping Act (Bogføringsloven §10).
  • Disaster recovery backups: When personal data is deleted from our live database, encrypted copies may persist in access-controlled disaster recovery backup files for a residual window of up to 90 days before being automatically overwritten or expired by storage lifecycle policies. Deleted data is never restored to live production except during catastrophic recovery, where subsequent re-erasure is mandatory.

Inactive accounts. If you do not sign in for 18 consecutive months, we delete your account and its data. Storage limitation under Article 5(1)(e) GDPR means we should not hold personal data once we no longer have a reason to, and an account nobody has opened in a year and a half is data we have no reason to keep.

We email your registered address three times over the 30 days before that deletion — at 30, 14 and 3 days — stating the exact date and offering a one-click link to keep the account. Signing in also cancels it and resets the clock. Accounts with an active, paused or Lifetime plan, accounts inside a payment grace period or a period already paid for, and accounts holding unspent AI credits are never deleted this way.

We keep a record that a deletion happened, containing a one-way hash of the account identifier and no other identifying data. We cannot use it to work out who was deleted; it exists so that we can confirm a deletion took place if you ask us, and so we can demonstrate that we honour this policy.

6. Your rights (GDPR)

Under GDPR you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Request erasure of your data
  • Restrict or object to processing
  • Data portability
  • Lodge a complaint with a supervisory authority

To exercise any of these rights, email privacy@zenithml.com.

7. Cookies

We use an essential cookie to keep you signed in. See our Cookie Policy for details.

This policy will be updated before any DPAs are finalised and before the platform processes real user data at scale. It is a stub for development purposes.