Privacy Policy
Last updated: September 3, 2026
1. What we collect
When you create a Zetstack account or use the product, we collect:
- Account information — name, email, company, and password (hashed, never stored in plain text).
- Business data you provide — your website, product/service details, target keywords, and content you generate or publish through Zetstack.
- Connected-service data — if you connect Google Search Console or a CMS, we access only the scopes required to deliver rankings, traffic, and publishing features.
- Usage data — pages visited, features used, and AI token usage, for billing and product improvement.
2. How we use it
- To provide the core product — keyword research, content generation, publishing, and analytics.
- To generate AI content on your behalf via our AI providers (your prompts and business context are sent to those providers to produce results).
- To send account, billing, and product-related emails.
- To improve the product, using aggregated and anonymized usage patterns.
3. What we don't do
- We don't sell your data to third parties.
- We don't use your private business content to train third-party AI models beyond what's required to generate your own results.
4. Third-party services
Zetstack relies on a small number of infrastructure and AI providers to operate — including our AI model provider, hosting infrastructure, and (where connected) Google Search Console and your CMS. Each processes only the data necessary for the feature you're using.
5. Google user data
Zetstack can connect to Google Search Console using thewebmasters.readonly scope. This section describes that access specifically, and it governs Google user data in addition to everything above.
- What we access — read-only Search Console performance data for the properties you choose: queries, impressions, clicks, average position, and indexed page data. We request no write scopes and cannot change anything in your Search Console account.
- Why we need it — to show which keywords and pages actually rank, to measure whether published content worked, and to prioritise recommendations against real performance rather than estimates. Without it the product can only estimate.
- How it is stored — OAuth tokens are encrypted at rest and used only to refresh the data you asked for. Performance data is stored against your account so we can show trends over time.
- How to revoke — disconnect at any time from Settings, or revoke Zetstack's access directly at myaccount.google.com/permissions. Revoking deletes the stored tokens immediately, and the associated performance data is removed within 30 days.
Limited Use. Zetstack's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: we do not transfer Google user data to third parties except as necessary to provide or improve the features you requested, to comply with applicable law, or as part of a merger or acquisition; we do not use it for advertising, and we never sell it; we do not allow humans to read it except with your explicit consent, to resolve a support issue you raised, for security purposes, or where required by law; and we do not use Google user data to train generalised AI or machine learning models.
6. Data retention
We retain your account and business data for as long as your account is active. You can request deletion of your account and associated data at any time by contacting us.
7. Your rights
You can access, correct, export, or delete your data at any time from your account settings, or by contacting us at hi@zetstack.ai.
8. Security
We use industry-standard measures — encrypted connections, hashed credentials, and access controls — to protect your data. No system is perfectly secure, and we'll notify affected users promptly in the event of a breach.
9. Changes to this policy
We'll update the "last updated" date above whenever this policy changes, and notify active users of material changes.
10. Contact
Questions about this policy: hi@zetstack.ai