What we do with your data.
What we collect, what it is used for, who it is shared with and how you ask for deletion.
The summary, in four lines
- We collect what the account needs to work: name, email, phone, language and a description of your business.
- The text of your requests goes to the AI models that generate the content, in a mode that neither stores that text nor trains on it.
- We do not want sensitive data. If you work in healthcare, do not write a patient’s name inside a request.
- You can see, correct, take or delete your data whenever you want, by writing to [email protected].
This summary is here for a quick read. What holds legally is the full text below.
Who is responsible for your data
The controller of your data is ZapPost AI LLC, EIN 41-4219308, headquartered at 30 N Gould St, Ste R, Sheridan, WY 82801, United States.
Every request about your data, including the ones the law directs to the data protection officer (DPO), goes to [email protected].
What data we collect
- Account: name, email, phone and language.
- Your business: niche, audience and the descriptions you write to personalize the content.
- Usage and infrastructure: history of interactions, the requests you make to the AI and the IP address of the access.
What we do not collect
We neither ask for nor accept sensitive personal data, and we do not process data of anyone under 18.
If your niche is healthcare, do not write a patient’s name or clinical information inside the request you make to the platform. That text leaves here and reaches the API that generates the content.
What each piece of data is for
- Performance of the contract: keeping your account, managing the subscription and delivering use of the platform.
- Legitimate interest: sending the context of your business to the AI models that generate the content, without those models being trained on your material.
- Legal obligation: keeping access logs, as required by the Brazilian Internet Civil Framework.
Who we share it with
The platform depends on audited providers, and they are who the data is shared with:
- OpenAI: content generation by API, in no-training mode.
- Supabase and Hetzner: database and servers, on AWS sa-east-1 and in the European Union.
- Cloudflare: network protection.
- Hotmart, Eduzz and Stripe: payment processing.
Data leaving the country
By using the platform, you agree that the context of your requests crosses the border to the servers of the AI labs in the United States (OpenAI and Anthropic). That transfer is protected by standard contractual clauses and by zero retention mode, in which the text sent is not stored on the other side.
Your rights
Under article 18 of the LGPD and under the GDPR, at any time you can:
- access the data we hold about you;
- correct anything wrong or incomplete;
- ask for permanent deletion;
- ask for your data to be ported.
To exercise any of them, write to [email protected].
How long we take to answer
Your deletion request is reviewed by support within 15 calendar days for customers in Brazil and within 30 days for customers in the European Union.
How long we keep it
Access logs (IP) are kept for 6 months, the period set by article 15 of the Brazilian Internet Civil Framework for civil and police purposes. It is a legal period, not a choice of ours, so it cannot be shortened on request.
Cookies and security
All traffic between you and the platform is encrypted (TLS/HTTPS). Account access uses a signed token (JWT) with Supabase row-level isolation rules, which stop one account from reading another account’s content.
As for cookies, we use only the Meta pixel, and only on the sales page.