Legal
Privacy
Last updated 23 August 2026 · ZynOps Solutions
This document is not final. The highlighted values below still need to be supplied, and the text should be reviewed by a qualified adviser before launch. Everything describing how the software behaves has been checked against the code; the parts that depend on how ZynOps Solutions is established have not been filled in.
ZynOps has two halves, and they handle data very differently. The hosted service — this site, your account, and the billing API — stores the minimum needed to run a subscription. The CLI runs on your own machine and, as shipped, sends your prompts straight to whichever model provider you configure, not to us.
The one thing worth reading carefully is Third parties, because the CLI ships with a prebuilt component that contacts services we do not operate.
What we store
All of it lives in our Supabase project. This is the complete list.
- Account
- Your email address, and a display name and avatar URL if your sign-in method provides them. Passwords are handled by Supabase Auth and are never visible to us.
- Subscription
- Your plan, subscription status, billing period dates, and the Stripe customer and subscription identifiers. We do not store card numbers — those exist only at Stripe.
- Daily usage
- A per-day counter of requests and credits used, so your plan limits can be enforced. Counters, not content.
- CLI sessions
- A SHA-256 hash of each CLI token, plus an optional device name and fingerprint, the last-seen time, and expiry or revocation times. The token itself is never stored on our side, so we cannot recover one — only invalidate it.
- Login authorization
- When you run zynops login we create a short-lived, single-use device code and record the IP address and user agent of the request, to rate-limit abuse. These rows expire on their own.
- Request metadata
- If you use the metered ZynOps API, we log the provider and model name, the request type, token counts, credits charged, and success or error status. Not the prompt, and not the response.
- Audit log
- Security-relevant account actions, such as approving or revoking a CLI session, with a timestamp.
What we do not store
We do not store your source code, your prompts, or the model’s replies. There is no column for them anywhere in our schema.
This is a consequence of how the CLI works rather than a promise we have to police. As shipped, it opens a connection from your machine to the provider you configured and talks to it directly. Your coding session does not pass through our servers, which is also why it keeps working when the account API is unreachable.
We also do not run analytics, advertising, or third-party tracking scripts on this website, and we do not sell personal data.
Third parties
Two services support the hosted account, and both receive only what they need to do their job.
- Supabase — authentication and the database described above.
- Stripe — subscription payments. Card details are entered on Stripe’s own checkout and never reach our servers.
The CLI contains a prebuilt component we did not write
The published CLI package includes a prebuilt agent core that powers the interactive coding session. Inspecting it shows client code for Anthropic’s API, the Statsig feature-flag service, and Sentry error reporting. When those paths are active they transmit data — which may include diagnostics, error reports, and usage telemetry — directly from your machine to those companies, governed by their privacy policies rather than this one. That traffic does not pass through ZynOps servers and we do not receive it.
We consider this a shortcoming rather than a feature, and replacing that component is on our roadmap. Until then, treat the CLI as software that may contact those third parties, and disclose it accordingly if you deploy it inside an organisation. If you need a fully local setup, point the CLI at a provider running on your own hardware — see the CLI documentation.
Your model provider
You choose which model provider the CLI uses, and you supply its API key. Whatever you send during a session — prompts, file contents, terminal output — goes to that provider under their terms and privacy policy. Read theirs; this policy cannot cover it.
If you point the CLI at a model running locally, on your own machine or your own network, that content does not leave your infrastructure at all.
Data on your machine
The CLI keeps its configuration in a .zynops directory in your home folder. Your session token is stored in your operating system’s keychain when one is available, and otherwise in a file with owner-only permissions. Running zynops logout removes the local copy and revokes the session on our side.
On first run the CLI copies settings from a .claude directory if one exists, so that an earlier installation keeps working. It copies rather than moves, and never deletes the original.
This website sets cookies for one purpose: keeping you signed in. There are no advertising or analytics cookies.
Retention and deletion
Account, subscription, and usage records are kept while your account exists. Login device codes and expired CLI sessions are short-lived by design. Ask us to delete your account and we will remove your profile and everything that references it; records Stripe must retain for financial and tax purposes stay with Stripe under their policy.
You can revoke an individual CLI session at any time from your account without deleting anything else.
Your rights
Depending on where you live, you may have the right to access a copy of your data, to correct it, to have it deleted, to restrict or object to how it is used, and to receive it in a portable format. We apply these to everyone regardless of location, because the data set is small enough that there is no reason not to.
To exercise any of them, write to the address below. The law that governs this relationship is [governing law — to be completed], and if you are in a region with a data-protection authority you may also complain to it.
Contact
Privacy questions and data requests go to [contact address — to be completed]. We will acknowledge a request within a reasonable period and, where the law sets a deadline, within that deadline.
If this policy changes we will update the date at the top of the page, and for a change that materially affects you we will say so on the site rather than rely on you noticing. See also our terms of service.