Skip to content
On this page:Scope

legal

Privacy Policy

Last updated: July 19, 2026

This policy explains how ZSetup handles personal data when you use Zoho CRM AI Assistant, its Chrome side panel, auxiliary website, and API (together, the “Service”).

1 Scope

This policy applies to product accounts, assistant conversations, explicit page context, Zoho CRM connections and actions, subscription management, and support requests. Zoho, Stripe, and your browser also process data under their own policies when you use their services.

2 Data we process

Depending on how you use the Service, we process:

  • your name, email address, password credential, account settings, and sessions;
  • messages, assistant responses, action proposals, approvals, and action results;
  • Zoho organization and user identifiers, connected CRM records needed for your request, and encrypted OAuth tokens;
  • page title, URL, selected text, and a bounded visible-text excerpt only when you attach that context;
  • plan, subscription, invoice, payment-status, and aggregate usage information; and
  • security and operational metadata such as request identifiers, timestamps, response status, and payload sizes. Message bodies and page content are excluded from structured logs.

3 Page content and Zoho data

Page content and selected text are sent to our servers only when you explicitly invoke the assistant on them, are used only to answer that request, and are never passively collected. Your Zoho data is accessed only through actions you or your approval settings authorize. We never train models on your data.

The extension has no always-on content script. When you explicitly attach page context, it is sent with that request, used to produce the response, and retained in your chat history until you delete the conversation or your account.

Connecting Zoho uses OAuth so the Service can act on your behalf within the scopes shown on Zoho's consent screen. Refresh and access tokens are encrypted at rest with AES-256-GCM, are never sent to the extension, and are not logged. Disconnect in the side panel at any time; we attempt to revoke the token and delete the stored grant. You can also revoke access directly at accounts.zoho.com.

4 AI processing

We send the minimum request context needed to the model provider selected to answer your request. That may include your message, relevant conversation history, explicit page context, and Zoho results returned by authorized read actions. Anthropic is the selected production model provider. We do not use customer data to train models and will use a provider configuration and terms that prohibit training on customer data.

AI output may be inaccurate. The assistant's curated action set, server-enforced permission mode, and approval screen limit what generated instructions can do; they do not make every answer correct.

5 Billing

Stripe processes checkout, card details, invoices, subscription changes, and the billing portal. We receive customer and subscription identifiers, plan, status, billing period, and limited payment metadata needed to provide the selected plan. We do not store full card numbers or card security codes.

6 Retention and account deletion

Conversation content and its action history stay in your account until you delete the conversation or account. A deleted conversation is soft-deleted so the product can offer a brief undo window; account deletion permanently removes it. We retain account settings, Zoho connection data, and usage records while your account exists. Short-lived OAuth and password-reset tokens expire automatically.

When you delete your account, we verify your password, end the Stripe subscription and remove the Stripe customer when present, attempt to revoke Zoho access, and delete the local account. Database cascades remove sessions, encrypted Zoho tokens, chats, actions, settings, API keys, and usage rows. Stripe or legally required transaction records may be retained under Stripe's policy or applicable tax, accounting, fraud-prevention, and legal obligations.

7 Service providers and transfers

We use service providers only to operate the Service:

  • Google Cloud for application hosting, managed infrastructure, and databases;
  • Stripe for payments and subscription management;
  • Resend for transactional account email when configured; and
  • Anthropic for production AI model processing.

Providers may process data in countries other than yours. We will use contractual and transfer safeguards required for the launch jurisdictions.

8 Security

We use encrypted transport, hashed passwords, short-lived sessions and reset links, encrypted Zoho grants, least-privilege browser permissions, server-side authorization, structured-log redaction, and signed Stripe webhooks. No online service can promise absolute security.

9 Your choices, rights, and contact

You can remove attached page context before sending, change permission mode, disconnect Zoho, delete conversations, manage billing, and delete your account. Depending on where you live, you may also request access, correction, portability, restriction, objection, or deletion of personal data. We do not sell personal data or use it for targeted advertising.

Send privacy questions or requests to support@zsetup.com. We may need to verify your identity before completing a request.