Privacy Policy
Last updated October 8, 2026
Last Updated Date: October 8, 2026
1. Introduction
Welcome to Zentrix. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services. By accessing or using our services, you agree to the practices described in this policy.
2. Information We Collect
We collect both personal information that you provide and non-personal data automatically when you use Coach Z.
Personal Information You Provide:
Account Information: When you create an account, we collect account details such as your name and email address. Profile details and optional preferences help personalize the service.
User Content: This includes prompts, messages, saved context, research notes and uploaded images you enter when interacting with Coach Z. We store in-product conversation content to provide conversation history. We do not offer a model-training opt-out control in account settings.
Automatically Collected Information:
Usage Data: We collect data on how you interact with Coach Z, including pages visited, time spent, and features used.
Technical Data: This includes your IP address, device type, browser type, operating system, and similar technical details.
Cookies and Tracking Technologies: We use cookies and similar technologies (like pixels and web beacons) to enhance your experience, maintain session information, and analyze website engagement. For more details, please refer to our Cookie Notice.
3. How We Use Your Information
We use your information for the following purposes:
Providing and Improving Services:
To operate, personalize, and enhance Coach Z.
To analyze usage trends and improve functionality and user experience.
AI Context and External Clients:
Coach Z requests can use the context you explicitly save and research notes you allow in that context. Clearing a note or its permission removes it from future note-context reads; it does not delete a previous chat or a copy already sent to a provider. An external AI client manages its own conversation and retention under its policies. For new authenticated tool calls, Zentrix records only the tool name and time, without ticker, query or other argument values. Legacy stored tool activity may contain details such as a ticker or query; these existing details remain until explicit full-account erasure, with no automatic age-based purge currently enabled. Tool activity is different from storing the external client conversation. For questions about provider processing or a broader data request, contact us.
Communication:
To send you service-related messages (e.g., account updates, technical notices) and, with your consent, marketing communications.
Legal and Security Purposes:
To comply with legal obligations, prevent fraud, protect our rights and the safety of our users, and respond to security incidents.
4. Legal Bases for Processing Your Information
We process your information only when we have a valid legal basis under applicable law. These bases include:
Consent: When you provide explicit permission for specific processing activities.
Legitimate Interests: For improving our services, analyzing usage, and personalizing your experience, provided that your interests do not override your fundamental rights.
Legal Obligations: When required to comply with legal and regulatory requirements.
Vital Interests: To protect your life or the safety of others.
5. Data Sharing and Disclosures
We do not sell your personal information. We share information with service providers as described below and may disclose it in the following circumstances:
Service Providers: We share information only with trusted vendors who assist us in operating our services (e.g., hosting, analytics, payment processors). These vendors are contractually obligated to protect your data.
Account and Marketing Contact Processors: Account registration shares your email address and first and last name with HubSpot, including registration through a connected sign-in provider. Direct anonymous marketing contact requests send your email address to SendGrid. These processors can hold their own copies. Local account erasure does not prove deletion of HubSpot or SendGrid processor copies or confirm remote cleanup. Contact team@zentrix.ai for processor-copy requests; an accepted local erasure request is not evidence that a processor request has been completed.
Legal Requirements: When required by law, regulation, or legal process.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction.
With Your Consent: We may share your information if you provide explicit permission.
6. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this policy, or as required by law. When no longer needed, your data will be securely deleted or anonymized.
Account data and self-service controls
When enabled in account settings, self-service controls export retained account data and accept irreversible full-account erasure requests. The feature may be unavailable in some environments; contact team@zentrix.ai when it is unavailable. An earlier private portfolio erasure request covers only its stated private-intelligence scope and is not full-account deletion.
| Data class | Purpose and actual lifecycle |
|---|---|
| Identity, profile and sign-in links | Account identity, contact and optional profile details, saved Coach Z context and connected OAuth sign-in links support authentication and personalization. Full-account erasure immediately revokes account sessions and Zentrix access through connected OAuth accounts, then queues removal of private profile data. A minimal identity record remains for the local security barrier described below; revocation of a grant at an external OAuth provider is not certified. Secret credentials and tokens are excluded from exports. |
| Holdings, imports and watchlists | Holdings, watchlists and followed symbols support portfolio relevance and remain until changed, removed or full-account erasure. Import rollback receipts, their saved positions and manual holding-change receipts have a 7-day recovery window with bounded cleanup; the existing 10-receipt cap may remove older receipts sooner. Account erasure also removes this evidence. |
| Research notes | Owner-authored text, up to 2,000 characters, with explicit permission for future Coach Z context. Notes persist until deleted, private portfolio erasure or full-account erasure. |
| Chats, uploaded images and stored tool activity | In-product conversation threads and messages, stored image content or references, tool activity and usage counters support the requested features. New authenticated tool calls record only the tool name and time. Legacy stored activity may include ticker or query details if present. Chats and images remain until removed or full-account erasure. Image references remain pending cleanup if deletion at the configured storage provider is unavailable; an accepted request does not certify that those blobs have been removed. Legacy tool activity and usage counters have no automatic age-based purge currently enabled. Full-account erasure removes these private records in bounded batches. Tool activity is different from the external AI client’s complete conversation. |
| Event actions and retained briefing snapshots | Read, save and snooze state and historical facts support follow-up. Event state and briefing payloads have a maximum 90-day retention, earlier when their source deadline requires it; erasure also removes private artifacts. |
| Delivery preferences, private emails and receipt metadata | Consented delivery, suppression and duplicate prevention. Private email bodies and delivery receipt metadata become eligible for purge after 30 days or an earlier source deadline. Only minimal deduplication hashes tied to a retained snapshot may remain until that snapshot deadline, capped at 90 days, to prevent repeat delivery. This anti-repeat record does not retain the private email body. Erasure revokes private access and delivery immediately and queues a bounded, retryable purge. |
| Consent audit history | Delivery preference and legacy digest consent have a 730-day retention deadline for the minimal type, version, date, source and owner binding used to establish the recorded choice. Erasure purge removes email and arbitrary metadata. Preference audit expiry runs automatically; legacy digest audit has no automatic purge currently enabled. These are the implemented consent rules, not a claim that law requires this duration. |
| Scheduled tasks, task runs and alerts | Schedules, runs, price alerts, concentration preferences and notifications support requested monitoring. Account erasure revokes task execution and queues removal. Legacy scheduled-run history has no automatic age-based purge currently enabled. These private records are removed by explicit full-account erasure; existing notification-specific deadlines remain separate. |
| Paper trading, portfolio history and licenses | Paper accounts and trades, trading portfolios, portfolio plans, trades, snapshots and decisions, signal journal entries, and license assignments support the relevant account features. These account records remain until removed or full-account erasure. |
| Product journey and engagement metadata | New account journey observations support service operation and become eligible for bounded purge after 30 days or an earlier deadline. Legacy journey events and engagement day records have a 90-day retention window. New journey observations use server-derived owner, UTC date and origin; private prompts, notes, holdings, source URLs and credential values are excluded from telemetry. Full-account purge removes owner-linked journey and engagement records. The separate minimal account evidence-origin binding remains until full-account erasure, with no automatic expiry; only its capacity timestamp is cleared after 30 days. Anonymous sample views, sample CTA actions and auth intents are recorded as bounded daily accepted request counts without a person or account identifier, IP address, URL or content. These counts include retries and cannot measure unique people or sample-to-auth conversion; anonymous aggregate rows become eligible for purge after 30 days. |
| Optional usefulness feedback and returned targets | Explicit Useful, NotUseful or Unsure ratings on an authorized event version or returned follow-up are optional and self-reported; they do not establish benefit or successful follow-up. The owner-bound rating, a minimal returned-target record and bounded mutation replay records support safe feedback access and prevent stale updates. You can update or remove a rating through the feedback form; removal retains a minimal revision marker to prevent stale replay for the remaining retention window. Account erasure also removes these records. They become eligible for bounded purge after 30 days or an earlier source deadline. |
| Erasure security barrier | A durable opaque erasure barrier, minimal identity record and SHA-256 email/OAuth fingerprints prevent local replay or recreation from restoring erased access. These security records are separate from private payloads. This control does not set an automatic expiry for the barrier. |
| Billing state and event receipts | Provider identifiers, subscription status, provider event IDs, payload hashes and minimal receipt outcomes support access reconciliation and replay protection. Minimal signed invoice evidence distinguishes initial payment from renewal; a checkout redirect or account role is not payment proof. This payment evidence becomes eligible for bounded purge after 30 days and is included in account export and erasure. Minimal billing state, provider event IDs, payload hashes and receipt outcomes remain for signed subscription reconciliation and replay protection, including after erasure and termination. No automatic age-based billing expiry is currently enabled. These are operational exceptions, not an assertion of a statutory retention period. Full-account erasure does not cancel a subscription or stop provider charges. |
The account export downloads bounded JSON pages for each available section, covering the retained data classes above. Export all desired pages before erasing; each page reflects current retained rows, and data can change between pages. This is not a frozen account archive. Long legacy text spans bounded content parts; download every part before advancing to the next row page. The textChunks metadata carries offsets, total character counts and authoritative base64-encoded little-endian UTF-16 code units. Concatenating those decoded code units for the same row and field reconstructs the original string without truncating long text, trailing spaces or characters split between parts. Keep every downloaded part. Downloads contain private data and should be stored securely. The application does not persist these export payloads in browser storage. Secret credentials, deleted data, expired source-bound payloads and another provider’s copies are excluded.
Full-account erasure first revokes account access, existing sessions, Zentrix access through connected OAuth accounts and private delivery. It does not certify grant revocation at an external OAuth provider. Physical removal follows in bounded background batches with retries; an accepted request is not proof that all batches have finished, and no fixed completion deadline is promised. The request is irreversible. Minimal consent audit, limited billing reconciliation records and the separate durable security barrier follow the rules described above. Time-based retention windows mark eligibility for bounded, retryable purge; they do not promise a fixed physical deletion deadline. Account erasure does not cancel a paid subscription: manage and cancel billing through account settings before erasing because account access to the billing portal will be lost afterward.
Copies already downloaded, delivered, backed up or held by another service have separate lifecycles. Removing Zentrix account data does not erase an external AI client’s conversation or revoke unrelated access at that provider. Contact team@zentrix.ai for information about provider or backup copies, retained records, billing or a data request outside these controls. We do not describe a support request as completed deletion.
Aggregate operator reports separate delivery, authenticated return, explicit usefulness, initial payment and renewal. Live reports exclude fixtures and unknown provenance. Account-based metrics require at least five distinct owners and suppress small cells and complements; absent instrumentation and missing retained proof are unavailable, not zero. Reports use retained evidence only, so expiry or account erasure can change later counts without reconstructing deleted history. Anonymous request counts have no people or conversion denominator.
7. Security Measures
We implement commercially reasonable technical, administrative, and organizational measures to protect your information. These include encryption of data in transit and at rest, regular audits, and secure data storage practices. While no method is 100% secure, we strive to safeguard your data against unauthorized access, loss, or misuse.
8. International Data Transfers
Your data is stored on servers located in the United States and is subject to U.S. laws. If you are accessing our services from outside the United States, please be aware that your information may be transferred internationally under legally valid mechanisms.
9. Children’s Privacy
Our services are not directed to children under 13. We do not knowingly collect personal information from individuals under 13. If you believe that we have inadvertently collected data from a child under 13, please contact us immediately so that we can take appropriate steps.
10. Your Rights and How to Exercise Them
Depending on your jurisdiction, you may have rights regarding your personal data, including:
Access: The right to request copies of your personal data.
Correction: The right to correct inaccurate or incomplete data.
Deletion: The right to request deletion of your personal data.
Data Portability: The right to receive your data in a structured format.
Restriction and Objection: The right to restrict or object to certain processing activities.
Withdrawal of Consent: If processing is based on your consent, you can withdraw it at any time.
To exercise these rights, please contact us at team@zentrix.ai or via our data subject request process outlined on our website.
11. Cookies and Tracking Technologies
We use cookies and similar technologies to:
Enhance your website experience.
Maintain session information.
Analyze website performance and user engagement.
You can manage your cookie preferences through your browser settings or via our Cookie Notice on our website. Note that disabling cookies may affect certain functionalities of our services.
12. Updates to This Privacy Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify you via a prominent notice on our website or through email. We encourage you to review the policy periodically.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: team@zentrix.ai