Last updated: May 23, 2025

Privacy Policy

Your privacy matters. Here's exactly what data we collect, why we collect it, and how we protect it.

The short version

๐Ÿ”’

Emails not stored

Full email bodies are processed in memory only โ€” never saved permanently.

๐Ÿ”‘

Keys encrypted

Your Gmail token and AI API key are AES-256-GCM encrypted at rest.

๐Ÿšซ

Zero data selling

We do not sell, rent, or share your data with advertisers or data brokers.

๐Ÿค–

No model training

Your emails and data are never used to train any AI model.

1. Overview

Zylos AI ("we", "us", "our") is a product of Galaxyium (https://galaxyium.space). This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the Zylos AI service.

We are committed to handling your data with transparency, minimal collection, and strong security. If you have any questions, contact us at [email protected].

2. What Information We Collect

We collect only what is necessary to provide the Service:

Account Information โ€ข Name, email address, and profile photo โ€” provided by Google when you sign in via Google OAuth.

Gmail Access โ€ข Your Gmail refresh token (used to access your inbox on your behalf). This is stored encrypted. โ€ข Email metadata: sender address, subject line, email snippet, and timestamp โ€” stored in your processing logs. โ€ข Email body content is processed in memory to generate a reply but is NOT permanently stored in our database.

Configuration Data โ€ข Business name, business type, email tone preferences, reply language, custom instructions, and meeting link โ€” exactly what you enter during onboarding and settings.

AI Provider Key โ€ข Your API key for your chosen AI provider (OpenAI, Gemini, Anthropic, etc.) โ€” stored encrypted using AES-256-GCM.

Usage Logs โ€ข Metadata about each processed email: detected intent, processing status (drafted/sent/failed), AI model used, processing time, and token count. This is used for your dashboard analytics.

Device & Technical Data โ€ข Standard server logs: IP address, browser type, and access timestamps. These are used for security monitoring and not linked to your profile for analytics purposes.

3. How We Handle Your Gmail Data

This section is important. Please read it carefully.

Zylos AI connects to your Gmail account to automate email replies. Here is exactly what we do and do not do with your Gmail data:

โœ“ We DO: โ€ข Read incoming emails to classify their intent and generate a contextual reply. โ€ข Create drafts or send replies on your behalf โ€” only based on the action mode you configure (draft / send / ignore). โ€ข Store email metadata (sender, subject, snippet, status) in your account's email logs for dashboard display. โ€ข Store your Gmail refresh token in encrypted form to maintain the connection without requiring you to re-authorize.

โœ— We DO NOT: โ€ข Store the full body of your emails permanently. โ€ข Share, sell, or transmit your email content to any third party. โ€ข Use your email content to train AI models (ours or anyone else's). โ€ข Read emails outside the automated processing workflow. โ€ข Access your Sent, Drafts, Spam, or other folders beyond your Inbox (unless specifically required for thread context). โ€ข Allow any human at Galaxyium to read your emails, except in rare cases where you explicitly share a support ticket.

Your Gmail access can be revoked at any time: โ€ข From your Google Account โ†’ Security โ†’ Third-party apps โ†’ Remove Zylos AI โ€ข Or from your Zylos AI account settings โ†’ Disconnect Gmail

4. Your AI Provider API Key

Zylos AI uses a Bring Your Own Key (BYOK) model. You supply your own API key from an AI provider of your choice.

Your API key is encrypted at rest (AES-256-GCM) before being saved to our database. It is decrypted only in server memory at the moment it is needed to make an API call to your AI provider. It is never logged, displayed in plaintext, or transmitted to any party other than your chosen AI provider.

We make API calls to your AI provider on your behalf. The content sent in these calls is the email text being processed, along with the context instructions you configured. Your AI provider's own privacy policy applies to how they handle these requests. We recommend reviewing the privacy policy of your chosen provider (OpenAI, Google, Anthropic, etc.).

5. How We Use Your Information

We use your information for the following purposes only:

To Provide the Service: Process your incoming emails, generate replies, and display your email logs and analytics in the dashboard.

To Maintain Your Account: Store your preferences, configuration, and authentication credentials so you don't need to reconfigure on every login.

To Improve Reliability: Use error logs and processing metadata to identify and fix bugs, improve processing speed, and monitor system health.

To Communicate With You: Send transactional emails related to your account (subscription receipts, cancellation confirmations, important service notices). We do not send marketing emails unless you explicitly opt in.

We do not use your data for advertising. We do not build behavioral profiles. We do not sell your data.

6. Data Sharing & Third Parties

We share your data with as few parties as possible, and only as necessary:

Supabase: Our database provider stores your account data, configuration, and email logs. Data is stored in their secure cloud infrastructure.

Firebase (Google): Used for authentication only. We use Firebase Auth to verify your identity via Google Sign-In.

Your AI Provider: When processing an email, the email content and your configured context instructions are sent to your chosen AI provider's API (e.g., OpenAI, Google Gemini, Anthropic). This is inherent to the product's function.

Razorpay: Handles payment processing for subscriptions. We share only what is necessary for billing (your email address). We do not share Gmail or AI key data with Razorpay.

We do not use any advertising networks, analytics trackers (e.g., Google Analytics, Meta Pixel), or data brokers.

7. Data Security

We take security seriously and implement the following measures:

Encryption at Rest: Gmail refresh tokens and AI API keys are encrypted using AES-256-GCM before storage.

Encryption in Transit: All communication between your browser, our servers, and third-party services is encrypted via TLS/HTTPS.

Row-Level Security: Our database enforces row-level security (RLS) policies so that your data is accessible only to your authenticated session โ€” not to other users.

Principle of Least Privilege: Server-side processes use scoped credentials with only the minimum permissions required.

No Plaintext Secrets: Sensitive credentials are never stored in plaintext, never logged, and never exposed in client-side code.

While we take strong precautions, no system is 100% immune to breaches. In the event of a data breach affecting your account, we will notify you promptly in accordance with applicable law.

8. Data Retention

We retain your data as follows:

Account & Configuration Data: Retained for as long as your account is active.

Email Processing Logs: Retained for as long as your account is active, and visible in your dashboard. You can clear your logs from your account settings.

Gmail Refresh Token: Retained until you disconnect Gmail or delete your account. It is invalidated and deleted upon disconnection.

AI API Key: Retained until you remove it from your settings or delete your account.

On Account Deletion: All your data โ€” including profile, configuration, email logs, and stored credentials โ€” is permanently deleted from our systems within 30 days of account deletion.

9. Your Rights

You have the following rights regarding your personal data:

Access: You can view your account data and email processing logs from within the Zylos AI dashboard at any time.

Correction: You can update your profile, business information, and configuration at any time from your settings.

Deletion: You can delete your account at any time. This will permanently delete all your associated data.

Portability: You may contact us to request an export of your account data.

Revocation of Gmail Access: You can disconnect Gmail at any time from your settings or directly from your Google Account.

To exercise any of these rights, contact us at [email protected].

10. Cookies & Session Data

We use a minimal set of cookies:

Session Cookie (zylos_session): A secure, HTTP-only cookie used to maintain your authenticated session. It contains a signed token with your user ID and subscription status. It does not contain your email content, Gmail token, or AI key.

We do not use advertising cookies, tracking pixels, or third-party analytics cookies.

11. Children's Privacy

Zylos AI is not directed at children under the age of 13 (or 16 in the European Union). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at [email protected] and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or an in-app notice and update the "Last Updated" date at the top of this page. Your continued use of the Service after changes take effect constitutes your acceptance of the updated policy.

13. Contact & Data Controller

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:

Galaxyium Website: https://galaxyium.space Email: [email protected]

We will respond to all privacy-related inquiries within 7 business days.

Zylos AI is a product of Galaxyium