Skip to content

Privacy Policy

Last updated · June 8, 2026

This Privacy Policy explains how Zeroset, Inc. ("Zeroset," "we," "us," or "our") collects, uses, discloses, and protects personal information. This Privacy Policy applies to Zeroset's websites, public research and documentation pages, marketing activities, events, communications, accounts, and hosted software platform, APIs, SDKs, developer tools, memory infrastructure, retrieval and indexing services, dashboards, and related services that link to this Privacy Policy (collectively, the "Services").

This Privacy Policy does not replace a Data Processing Addendum ("DPA"), Business Associate Agreement ("BAA"), enterprise agreement, or other written agreement between Zeroset and a customer. If Zeroset processes personal information in customer data on behalf of a customer, Zeroset generally acts as a processor, service provider, or business associate, and the customer's agreement with Zeroset controls that processing.

1. Roles and Scope

Zeroset may process personal information in different roles:

  • Website, account, billing, marketing, support, and business contact data. Zeroset generally acts as a controller or business for this data.
  • Customer Data submitted to the Services. Zeroset generally acts as a processor, service provider, or business associate when processing personal information in Customer Data on behalf of a customer.
  • Usage Data and security logs. Zeroset may process Usage Data and logs as a controller or business to operate, secure, support, and improve the Services, subject to customer agreements and applicable law.

"Customer Data" means data, content, prompts, messages, records, files, metadata, application data, personal information, embeddings, indexes, memory objects, retrieval results, outputs, and other materials that a customer or its users submit to, store in, or process through the Services.

2. Personal Information We Collect

We collect personal information in the following categories.

Information you provide

  • Account and profile information, such as name, email address, company, role, username, password or authentication information, workspace, team membership, and preferences.
  • Business contact and sales information, such as name, email address, phone number, company, job title, communications, meeting notes, demo requests, and procurement information.
  • Support and communications information, such as messages, tickets, chat logs, attachments, feedback, survey responses, and metadata about communications.
  • Billing and transaction information, such as billing contact details, tax information, subscription plan, invoice information, payment status, and payment method details processed by our payment providers.
  • Event, community, or research participation information, if you register for events, join waitlists, participate in studies, or communicate with us about research.

Customer Data and Service content

Depending on how customers use the Services, Customer Data may include prompts, messages, memory entries, application records, documents, metadata, embeddings, indexes, retrieval results, outputs, identifiers, end-user data, and other information submitted by or on behalf of customers. Customers decide what Customer Data they submit and are responsible for providing required notices and obtaining required rights and consents.

Information collected automatically

  • Device, browser, and network information, such as IP address, device identifiers, browser type, operating system, referring pages, pages viewed, time zone, and approximate location derived from IP address. See "Cookies and Similar Technologies" below for what this Website does and does not store on your device.
  • Product usage and telemetry information, such as API requests, timestamps, workspace identifiers, feature usage, latency, errors, diagnostics, logs, model or integration configuration metadata, token or memory usage, and performance metrics.
  • Security and fraud prevention information, such as authentication events, access logs, API key events, suspicious activity signals, and audit logs.

Information from third parties

We may receive information from customers, users, service providers, identity providers, payment processors, analytics providers, data enrichment providers, business partners, event organizers, public sources, and Third-Party Services that customers configure to interoperate with the Services.

3. How We Use Personal Information

We use personal information to:

  • provide, operate, maintain, secure, monitor, and support the Services;
  • create and manage accounts, workspaces, authentication, access controls, and billing;
  • process Customer Data in accordance with customer instructions and agreements;
  • respond to inquiries, support requests, demo requests, feedback, and communications;
  • personalize and improve the Website, Services, documentation, research content, and user experience;
  • analyze usage, troubleshoot issues, prevent abuse, debug errors, and improve performance and reliability;
  • develop new features, products, and services using Usage Data and other data permitted by this Privacy Policy and customer agreements;
  • send administrative, transactional, security, legal, and service-related communications;
  • send marketing communications where permitted, with choices to opt out;
  • manage events, waitlists, community programs, and research participation;
  • enforce agreements, acceptable use rules, and legal rights;
  • comply with legal, regulatory, tax, accounting, security, and compliance obligations; and
  • protect Zeroset, customers, users, and third parties.

4. No Training on Customer Data

Zeroset will not use Customer Data to train, develop, or improve artificial intelligence or machine learning models, algorithms, or systems, except with the customer's express written permission or as expressly agreed in a written customer agreement. This does not prevent Zeroset from using Customer Data to provide, secure, support, troubleshoot, or maintain the Services for the applicable customer.

5. How We Disclose Personal Information

We may disclose personal information as follows:

  • Service providers and subprocessors. We disclose information to vendors that provide hosting, cloud infrastructure, storage, databases, security, monitoring, logging, analytics, support, communications, payment processing, customer relationship management, contract management, compliance, and other services for us.
  • Customer administrators and authorized users. For customer accounts, workspace administrators and authorized users may access information associated with their workspace, users, logs, and Customer Data.
  • Third-Party Services configured by customers. If a customer configures the Services to interoperate with a Third-Party Service, we may transmit relevant Customer Data and metadata to that Third-Party Service as instructed by the customer.
  • Professional advisors. We may disclose information to lawyers, auditors, insurers, bankers, accountants, and other professional advisors.
  • Legal and safety reasons. We may disclose information to comply with law, legal process, court orders, subpoenas, government requests, or to protect rights, safety, security, and integrity.
  • Business transfers. We may disclose or transfer information in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar corporate transaction.
  • With consent or instructions. We may disclose information with your consent or at your direction.

6. Selling, Sharing, and Targeted Advertising

Zeroset does not sell Customer Data. Zeroset does not share Customer Data for cross-context behavioral advertising or targeted advertising. Zeroset does not use Customer Data to train AI or machine learning models except with the customer's express written permission or as expressly agreed in a written customer agreement.

Zeroset does not intend to sell personal information as the term "sell" is commonly understood. Some privacy laws define "sale," "sharing," or "targeted advertising" broadly to include certain analytics or advertising technologies. If Zeroset uses technologies that constitute sale, sharing, or targeted advertising under applicable law, Zeroset will provide required notices and choices, which may include a "Do Not Sell or Share My Personal Information" link or recognition of legally required browser-based opt-out signals.

7. Cookies and Similar Technologies

This Website sets no cookies. It runs no analytics, no advertising or marketing tags, and no third-party tracking, and it does not ask you to accept anything in order to read it.

The Website stores one value on your device: your light or dark theme preference, kept in your browser's local storage and written only if you choose a theme. It never leaves your browser, and clearing your browsing data removes it.

One page group makes a third-party request. Role pages under /careers load the MathJax typesetting library from cdnjs.cloudflare.com so that mathematical notation renders. That request discloses your IP address and the page you are on to that provider, as any request to a third party does. It sets no cookie.

The Services — the Nebula application, at a separate domain — do require a session for you to stay signed in, and use cookies or equivalent storage for authentication and security. Those are strictly necessary: without them you could not log in. The Services set no advertising cookies.

You can view, block, and delete cookies and local storage through your browser settings. Doing so will not affect your use of this Website, and will sign you out of the Services.

8. Retention

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, prevent abuse, and maintain business records.

Customer Data is retained in accordance with the applicable customer agreement, DPA, BAA, Documentation, account settings, and customer instructions. Deletion from active systems may not immediately delete copies from backups or logs, which are retained for a limited period and protected from ordinary use until deleted or overwritten. Customers should confirm applicable retention periods in their agreement or account settings.

9. Security

We maintain commercially reasonable administrative, technical, and organizational safeguards designed to protect personal information. No method of transmission or storage is completely secure. Customers are responsible for securely configuring their accounts and applications, protecting credentials and API keys, managing user access, and using the Services in accordance with the Documentation and security guidance.

10. International Transfers

Zeroset is based in the United States, and personal information may be processed in the United States and other countries where Zeroset, its service providers, or subprocessors operate. These countries may have data protection laws different from those in your jurisdiction. Where required, we use appropriate safeguards for international transfers, such as standard contractual clauses, data processing terms, or other lawful transfer mechanisms.

11. Your Choices

Depending on your location and relationship with Zeroset, you may have rights to access, correct, delete, port, restrict, or object to processing of personal information, or to opt out of certain processing. You may also have the right not to be discriminated against for exercising privacy rights.

You can make a privacy request by contacting privacy@zeroset.com. We may need to verify your identity and authority before responding. If your request concerns personal information in Customer Data, we may refer your request to the customer that controls that data or assist the customer in responding as required by applicable law and our customer agreement.

You may unsubscribe from marketing emails by using the unsubscribe link in the email or contacting us. You may still receive transactional, administrative, security, legal, and service-related communications.

12. California and U.S. State Privacy Notice

This Section provides additional information for residents of California and other U.S. states with consumer privacy laws. Depending on applicable law, you may have rights to know/access, delete, correct, port, opt out of sale, opt out of sharing or targeted advertising, limit certain uses of sensitive personal information, appeal a privacy decision, and not be discriminated against for exercising your rights.

In the preceding 12 months, Zeroset may have collected the following categories of personal information:

  • Identifiers, such as name, email address, IP address, account ID, device identifiers, and online identifiers.
  • Customer records and commercial information, such as company, role, billing information, subscriptions, invoices, and transaction records.
  • Internet or network activity information, such as log data, product usage, pages viewed, interactions, API events, and diagnostics.
  • Geolocation information, such as approximate location derived from IP address.
  • Professional or employment-related information, such as company, job title, and work contact information.
  • Audio, electronic, or similar information, such as call recordings or support communications if recorded with notice where required.
  • Inferences, such as account preferences, product interests, or usage patterns.
  • Sensitive personal information, such as account login credentials, payment information handled by payment providers, and PHI or other regulated data only if expressly authorized by contract.

We collect these categories from you, customers, users, devices, browsers, service providers, identity providers, payment processors, Third-Party Services configured by customers, and public or business sources. We use and disclose these categories for the purposes described in this Privacy Policy. We may disclose these categories to service providers, subprocessors, customer administrators, Third-Party Services configured by customers, professional advisors, authorities, business transaction parties, and others described in this Privacy Policy.

We do not use sensitive personal information to infer characteristics about you. We do not knowingly sell or share the personal information of children under 16. To exercise applicable state privacy rights, contact privacy@zeroset.com. Authorized agents may submit requests where permitted by law, and we may require proof of authorization.

13. European, UK, and Swiss Privacy Notice

If European, UK, or Swiss data protection law applies, Zeroset's legal bases for processing may include performance of a contract, legitimate interests, consent, compliance with legal obligations, and protection of vital or public interests. Our legitimate interests include providing, securing, improving, and marketing the Services; preventing abuse; communicating with users and customers; and managing business operations.

Depending on applicable law, you may have rights to access, rectify, erase, restrict, object, port personal information, withdraw consent, and lodge a complaint with a supervisory authority. Where Zeroset processes personal information in Customer Data as a processor, please direct requests to the relevant customer unless otherwise required by law.

14. Children

The Website and Services are not directed to children under 13, and we do not knowingly collect personal information directly from children under 13. Customers may not submit children's personal information to the Services unless expressly authorized in a written agreement with Zeroset and subject to any legally required notices, consents, and safeguards. If you believe a child has provided personal information to Zeroset in violation of this Privacy Policy, contact privacy@zeroset.com.

15. HIPAA and PHI

Zeroset may process Protected Health Information ("PHI") only for customers that have entered into a signed BAA with Zeroset and only in products, accounts, environments, or configurations expressly authorized for PHI. Unless those requirements are satisfied, customers must not submit PHI to the Services. If a BAA applies and conflicts with this Privacy Policy regarding PHI, the BAA controls.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If changes are material, we will use reasonable efforts to provide notice, such as by posting the updated Privacy Policy, updating the "Last Updated" date, sending email, or providing in-product notice. The updated Privacy Policy is effective when posted unless stated otherwise.

17. Contact

Questions or requests about this Privacy Policy may be sent to privacy@zeroset.com or to Zeroset, Inc., San Francisco, California 94104, United States.