🔒 Legal Document

Privacy Policy

We only collect what's needed to power the service — and we never sell your data. Here's everything, plainly explained.

Last updated: May 2026  ·  Effective immediately

01

Who We Are

Zenva AI ("we", "our", "us") is an AI-powered Chrome extension and web service at zenvaai.xyz. We provide intelligent browsing assistance, smart autofill, meeting transcription, document memory, and real-time AI guidance.

We believe privacy is a right, not a feature. We collect only what's necessary, process it only as described here, and never monetise your personal data.

02

What We Collect

Account Information

👤

Name & Email

Provided at sign-up. Your email is used to identify your account and send transactional alerts.

🔑

Password

Stored as a one-way bcrypt hash only. We cannot read or recover your password.

🖼

Profile Avatar

Optional image uploaded by you. Stored solely to personalise the extension panel.

AI Interaction Data

💬

Chat Messages

Messages you send to the AI and responses generated — saved as your chat history.

🌐

Page Context

The URL, title, and up to 5,000 characters of visible page text sent alongside AI requests to provide context.

📸

Screenshots (not stored)

Screenshots from the Screen / Game Guide are sent to Claude for real-time analysis, then immediately discarded. We store no images.

🎙

Meeting Transcripts

Audio is transcribed in real time and the resulting text plus AI summary is saved to your account. No audio is stored.

Documents & Memory

📄

Uploaded Files

PDF, DOCX, or TXT files you upload (up to 5 MB each, max 5 per account). Stored to power Document Memory.

🧠

Memory Entries

Custom key/value facts you save for the AI to remember across sessions.

Payment & Technical

💳

Credit Balance & Transactions

Your current credit balance and payment transaction history. Transaction references from payment gateways only — we never store card numbers.

📱

Device Identifier

A random identifier generated by the extension on your device (not tied to your hardware or identity) and sent once at registration. Used solely to limit how many accounts can be created from one browser install, to prevent abuse of free-credit and referral rewards.

🛡

Security Logs

IP address and request timestamps used only for rate limiting and abuse prevention. Retained 90 days.

We do NOT collect: keystrokes, browsing history, passwords you enter on other sites, or any data outside of explicit Zenva AI interactions.
03

How We Use Your Data

Delivering the Service

Answering AI queries, filling forms, transcribing meetings, and providing screen guidance.

🎯

Personalisation

Using your saved documents and memory entries to give contextually relevant answers.

👤

Account Management

Authentication, credit balance tracking, and abuse prevention (e.g. per-device account limits).

🔒

Security

Rate limiting, brute-force prevention, and fraud detection.

📧

Communications

Email verification, password reset codes, low-balance reminders, and security notices. No marketing emails without your consent.

📊

Service Improvement

Aggregated, anonymised usage patterns to improve features — never linked back to you individually.

We do not use your data for advertising, behavioural profiling, or any purpose not listed here.

04

Data Sharing

We share data with third parties only as required to deliver the service:

🤖

Anthropic (Claude AI)

Your messages, page content, and screenshots are processed by Anthropic's Claude API to generate AI responses. Anthropic's own privacy policy governs their data handling.

💳

Payment Gateways

Paystack and Flutterwave. All payment data stays with these gateways — we receive only a transaction reference and success/fail status, never your card number.

📨

Email Delivery (Resend)

We share your email with Resend solely to deliver transactional emails (verification codes, password resets, low-balance reminders). They do not use it for any other purpose.

We never sell your data to advertisers, data brokers, or any third party for commercial gain.
05

Storage & Security

🗄

Encrypted Database

Data stored on secured servers using MySQL with encrypted connections between all services.

🔑

bcrypt Password Hashing

Passwords hashed with bcrypt (cost 12) — mathematically irreversible. Even our engineers cannot read them.

🎫

JWT + Revocation

Authentication via short-lived JWT tokens (7-day expiry) with a server-side revocation blacklist — logging out truly invalidates your session.

🌐

HTTPS Everywhere

All production traffic encrypted with HTTPS/TLS. No plaintext communication.

🚦

Rate Limiting

Strict rate limiting applied to all API endpoints to prevent brute force and abuse.

While we implement industry-standard security measures, no system is 100% guaranteed. In the event of a breach affecting your personal data, we will notify you promptly.

06

Cookies & Local Storage

The Zenva AI Chrome extension uses Chrome's local storage (not browser cookies) to store:

🎫

Authentication Token

Your JWT token, stored locally so you stay logged in across browser sessions.

🖼

Cached Profile Data

Your name and avatar for instant display when the panel opens — never transmitted externally on its own.

This data stays entirely on your device and is transmitted to our servers only when you actively use the extension. You can clear it instantly by logging out or uninstalling the extension.

Our website uses no third-party tracking cookies or analytics scripts.

07

Data Retention

👤

Account & Profile

Kept until you delete your account.

💬

Chat History

Kept until you delete sessions in the dashboard.

🎙

Meeting Transcripts

Kept until you delete them from your account.

📄

Uploaded Documents

Kept until you delete them (max 5 per account).

💳

Payment Records

Retained 7 years for accounting and legal compliance — required by law.

🛡

Security Logs

IP addresses and rate-limit logs — retained 90 days, then automatically purged.

When you delete your account, all personal data is permanently purged within 30 days, except payment records required by law.

08

Your Rights

📦

Access

Request a copy of your data via Settings → Export My Data.

✏️

Correction

Update your profile at any time in Settings.

🗑

Deletion

Permanently delete your account and all data via Settings → Delete Account.

📤

Portability

Download your chat history and documents in JSON format from the Settings dashboard.

Objection

Contact us to object to any specific use of your data — we'll review every request fairly.

To exercise any right, visit your Settings dashboard or email support@zenvaai.xyz. We respond within 5 business days.
09

Children's Privacy

Zenva AI is not directed at children under 13. We do not knowingly collect data from minors. If you believe a child has registered, contact us at support@zenvaai.xyz and we will delete the account immediately.

10

Policy Changes

We may update this policy as the service evolves. We will notify you of material changes via email or an in-app notice at least 7 days before they take effect. Continued use of the service after the effective date constitutes acceptance.

11

Contact Us

Privacy questions or data requests? We're here.

🔒

Privacy Enquiries

support@zenvaai.xyz

🛠

General Support

support@zenvaai.xyz

🌐

Website

zenvaai.xyz