legal
Privacy Policy
Last updated: September 21, 2026
1 Scope and roles
The Service is operated by Roman Shostak LLC, Sharjah Media City (Shams), Sharjah, United Arab Emirates (commercial licence no. 2429518.01), trading as ZSetup. We act in two different roles, and which one applies depends on whose data it is.
We are the controller of the personal data we need to run your relationship with us: your account, credentials, sessions, settings, subscription and billing status, support correspondence, and the security and operational metadata described in section 2.
We are a processor — and you, or the organization whose Zoho CRM account you connect, are the controller — for the content the assistant handles on your instructions: your Zoho CRM records and the personal data of your customers, leads, and contacts in them, the messages and files you send the assistant, the page context you attach, and the results of actions you authorize. We process that content only to carry out your requests, on your instructions as expressed through the assistant, your permission mode, and your approvals; we do not decide what it is used for. You are responsible for having a lawful basis to process it and for meeting your own obligations to the people it describes. A data processing agreement for organizations that need one is available on request.
This policy applies to product accounts, assistant conversations, explicit page context, Zoho CRM connections and actions, subscription management, and support requests. Zoho, Stripe, and your browser also process data under their own policies when you use their services; Zoho, not ZSetup, hosts your CRM.
2 Data we process
Depending on how you use the Service, we process:
- your name, email address, password credential, account settings, and sessions;
- messages, assistant responses, action proposals, approvals, and action results;
- Zoho organization and user identifiers, connected CRM records needed for your request, and encrypted OAuth tokens;
- page title, URL, selected text, and a bounded visible-text excerpt only when you attach that context;
- files you attach to a message — text, Markdown, CSV, and JSON files, spreadsheets (.xlsx), PDFs, and images (.png, .jpeg, .webp) — including the text extracted from them and, for images and for PDF pages that carry no text layer, a rendered image of the page;
- plan, subscription, invoice, payment-status, and aggregate usage information; and
- security and operational metadata such as request identifiers, timestamps, response status, and payload sizes. Message bodies and page content are excluded from structured logs.
3 Page content and Zoho data
Page content and selected text are sent to our servers only when you attach a page, allow the assistant’s request to read one, or ask about a page in Full access; they are used only to answer that request and are never passively collected. Your Zoho data is accessed only through actions you or your approval settings authorize. We never train models on your data.
The extension has no always-on content script. Page context is read in exactly three cases: you attach it with “Use this page” or the selection menu; the assistant asks to read the page you are viewing and you allow it on the card the panel shows; or, in Full access mode, the assistant reads the page you are viewing to answer a request you just sent, without asking first. Chrome’s own site-access consent is always required before the first read and is only ever requested from your click. Either way the page is sent with that request, used to produce the response, and retained in your chat history until you delete the conversation or your account.
Zoho CRM data is read and changed only through the curated actions the assistant runs for a request you made, within the permission mode you selected, and — for anything that changes or leaves the CRM — with the approval that mode requires. We do not synchronize, crawl, or keep a copy of your CRM records: the records a request needs are fetched for that request and the results are kept with the conversation as described in section 6. The only thing we cache is your CRM's structure — module, field, and related-list definitions — so the assistant can plan requests without re-reading it. Zoho remains the system of record and keeps its own copy, recycle bin, and audit trail under your agreement with Zoho.
Connecting Zoho uses OAuth so the Service can act on your behalf within the scopes shown on Zoho's consent screen. Refresh and access tokens are encrypted at rest with AES-256-GCM, are never sent to the extension, and are not logged. Disconnect in the side panel at any time; we attempt to revoke the token and delete the stored grant. You can also revoke access directly at accounts.zoho.com.
4 AI processing
We send the minimum request context needed to the model provider selected to answer your request. That may include your message, relevant conversation history, explicit page context, and Zoho results returned by authorized read actions. A file you attach is normalized on our servers before it reaches the model: its text is extracted and sent as text, and an image — or a PDF page with no usable text layer, which we render at 150 dpi — is sent as an image. The file itself is never handed to the model as raw bytes. On later turns of the same conversation the extracted text is sent again; attached images are not re-sent, and the assistant asks you to attach the file again if it needs to see it. We do not use customer data to train models, and we configure every provider under terms that prohibit training on customer data.
The models that may process your request are Claude (Sonnet) from Anthropic, and DeepSeek V4.1 Flash, an open-weight model from DeepSeek accessed through OpenRouter. When DeepSeek is used we pin execution to Modal, Together AI, or Novita under zero-retention terms, deny provider data collection, and permit fallback only inside that named list. We do not send customer data to DeepSeek's own endpoint or to any unnamed inference host. If you need your account restricted to a single model provider, contact us.
AI output may be inaccurate. The assistant's curated action set, server-enforced permission mode, and approval screen limit what generated instructions can do; they do not make every answer correct.
5 Billing
Stripe processes checkout, card details, invoices, subscription changes, and the billing portal. We receive customer and subscription identifiers, plan, status, billing period, and limited payment metadata needed to provide the selected plan. We do not store full card numbers or card security codes.
6 Retention and account deletion
Conversation content and its action history stay in your account until you delete the conversation or account. A deleted conversation is soft-deleted so the product can offer a brief undo window; account deletion permanently removes it. Files you attach are stored with the conversation you send them in — the extracted text and, where one was produced, the rendered image — and are deleted with that conversation or your account on the same terms; we do not keep them beyond it. We retain account settings, Zoho connection data, and usage records while your account exists. Short-lived OAuth and password-reset tokens expire automatically.
When you delete your account, we verify your password, end the Stripe subscription and remove the Stripe customer when present, attempt to revoke Zoho access, and delete the local account. Database cascades remove sessions, encrypted Zoho tokens, chats, message attachments, actions, settings, API keys, and usage rows. Stripe or legally required transaction records may be retained under Stripe's policy or applicable tax, accounting, fraud-prevention, and legal obligations.
7 Service providers and transfers
We use service providers only to operate the Service:
- Google Cloud for application hosting, managed infrastructure, and databases;
- Stripe for payments and subscription management;
- Resend for transactional account email when configured;
- Anthropic for AI model processing; and
- OpenRouter for AI model routing, pinned to Modal, Together AI, and Novita as the hosts that may execute an open-weight model on our behalf.
We operate the Service from the United Arab Emirates and host it in the United States: the application servers and the database run in Google Cloud's us-central1 region. AI requests also pass through OpenRouter and one of the named inference hosts in section 4; those and the other providers above may process data in the countries where they operate, each under the data processing terms we accept with that provider. We do not offer a choice of hosting region. If you need to know which transfer mechanism applies to your organization, ask us at support@zsetup.com.
8 Security
We use encrypted transport, hashed passwords, short-lived sessions and reset links, encrypted Zoho grants, least-privilege browser permissions, server-side authorization, structured-log redaction, and signed Stripe webhooks. No online service can promise absolute security, and we cannot guarantee that unauthorized third parties will never defeat these measures.
If we become aware of a security incident that affects personal data we hold for you, we will notify you without undue delay, as applicable law requires, with what we know about the incident and the steps we are taking, so that you can meet any obligations you have as controller of your CRM data. You are responsible for the security of your own credentials, devices, browser profile, and Zoho account.
9 Chrome Web Store Limited Use
Our use and transfer of information received from Google Chrome APIs complies with the Chrome Web Store User Data Policy, including its Limited Use requirements. We use this information only to provide or improve the extension's prominent user-facing purpose, and for security or legal compliance as permitted by that policy.
We do not sell this information, use it for targeted advertising, transfer it for creditworthiness or lending, or use it for unrelated purposes. Humans do not read this information except with your affirmative consent for support or security, when necessary for security or legal compliance, or when it has been aggregated and anonymized for internal operations.
10 Your choices, rights, and contact
You can remove attached page context before sending, change permission mode, disconnect Zoho, delete conversations, manage billing, and delete your account. Depending on where you live, you may also request access, correction, portability, restriction, objection, or deletion of personal data. We do not sell personal data or use it for targeted advertising.
If you are a customer, lead, or contact of one of our users and your data reached us through their Zoho CRM, that user or their organization is the controller of it: please direct your request to them, and we will assist them in responding as their processor.
Send privacy questions or requests to support@zsetup.com. We may need to verify your identity before completing a request.
We may update this policy from time to time. The current version is always published here with its effective date at the top, and we will notify you of a material change by email or in the Service before it takes effect.