1. Scope and who we are
Zyan Labs, Inc. (“Zyan,” “we,” “us,” or “our”) operates the Zyan platform at zyan.ai and its verified workspace subdomains. Zyan provides agency operations, website building, client portal, project, CRM, advertising, analytics, content, messaging, billing, and related tools. This policy applies when you visit our public site or use the platform.
2. Information we collect
Account and workspace information
We process names, email addresses, authentication records, workspace membership, roles, permissions, billing contacts, and settings needed to provide and secure your account. Passwords are handled by our authentication provider and are not stored in readable form.
Business and client data
Depending on the features you use, Zyan processes project files, websites, tasks, approvals, contacts, leads, sales records, messages, content, analytics, invoices, campaign information, and other material you or authorized workspace members submit.
Connected-platform data
When an owner connects a third-party service, we receive the data and credentials needed to provide the requested integration. This may include Meta Pages and professional Instagram accounts, messages and comments, advertising campaigns and leads, Google analytics or advertising data, calendar or mailbox data, and provider account metadata. Credentials are protected in scoped secret storage. Authorized provider dialogs, such as Google Picker, may receive a short-lived access token for that specific connection flow.
Usage and device information
We collect IP address, browser and device details, request logs, security events, feature interactions, and diagnostic information needed for reliability, fraud prevention, and support.
3. How we use information
- Provide, maintain, secure, and improve the services you choose to use.
- Authenticate users and enforce workspace roles and permissions.
- Sync, display, publish, or send data through integrations you explicitly connect.
- Process projects, leads, campaigns, content, communications, billing, and reports.
- Respond to support requests and send essential service notices.
- Detect abuse, investigate security incidents, and comply with legal obligations.
Zyan does not sell personal information or connected-platform data. We do not use customer content to train general-purpose AI models. AI features are invoked only through enabled product workflows and are subject to the workspace controls shown in the product.
4. Google data and Limited Use
Zyan's use and transfer of information received from Google APIs follow the Google API Services User Data Policy, including its Limited Use requirements. Google Workspace data is also subject to the Google Workspace user data and developer policy.
Connected Google features
Gmail connections process mailbox identity, message and thread metadata, bodies, and requested attachments for your inbox, drafting, review, and enabled email workflows. Calendar connections use events and availability for the calendar and meeting operations you configure, including Meet links. Analytics, Search Console, and Google Ads connections use authorized property or ad-account identifiers and metrics for reporting and their enabled management features.
The Google Drive import feature lists and searches files using read access, then copies files you select into Zyan Files. The separate Google Sheets connector uses Google Picker and selected-file authorization: it reads the selected spreadsheets' names, worksheet metadata, and first-row headers, and appends the values mapped in your enabled workflows. Connecting Sheets does not enable incoming spreadsheet synchronization or general Drive access.
AI-assisted features
The Drive import dialog offers a Readable by Zyan AI option, enabled by default; you can turn it off before importing. When enabled, readable file text is stored in the workspace's AI document library. When you use enabled AI features, such as document questions, email drafting, or inbox triage, relevant file or message content and context may be processed by the AI providers listed on our Security page to provide that feature, subject to your workspace controls. Zyan does not use Google Workspace data to train or improve general-purpose or non-personalized AI or machine-learning models.
Sharing, access, and your controls
We do not sell Google Workspace data or use it for advertising. Transfers and human access are limited to user-authorized features and the exceptions permitted by Limited Use, including necessary security investigations and legal obligations. Human access to specific messages or files for support requires your explicit permission.
Disconnect a Google service in Settings → Integrations or revoke access in your Google Account connections to stop future access. Previously synchronized records or imported copies remain subject to the retention rules below until deleted. You can manage them in Zyan or follow our Data Deletion instructions.
5. Meta and Instagram data
If you connect Facebook or Instagram, Zyan uses Meta APIs to access only the accounts and permissions you authorize. Depending on your configuration, this can include Page and professional-account identity, messages, comments, campaign metrics, creatives, lead-form submissions, and audience insights. We use this information only to provide the connected Zyan features, do not sell it, and restrict it to authorized members of the same workspace. You can disconnect an account in Zyan or revoke Zyan in Meta at any time.
Instructions for removing account and Meta-derived data are available on our Data Deletion page.
6. Sharing and subprocessors
We share information only as needed to operate Zyan, at your direction, or when legally required. This includes infrastructure, authentication, hosting, payment, communications, analytics, and AI providers acting on our behalf; members and client users inside the workspace scopes configured by an owner; and authorities when disclosure is required by law or necessary to protect users and the service. Our current operational subprocessor summary appears on the Security page.
7. Security and retention
We use encryption in transit and at rest, tenant isolation, role-based access controls, secret storage, logging, and other safeguards described on our Security page. No system is perfectly secure, but we review and improve these controls as the platform evolves.
We retain information while an account is active and as needed to provide services, maintain security and transaction records, resolve disputes, and satisfy legal duties. After a verified deletion request, eligible personal data is deleted or de-identified from production systems within 30 days; limited records or encrypted backups may remain for a longer period where law, fraud prevention, accounting, or backup rotation requires it.
8. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, or receive a copy of personal information, or to object to certain processing. Workspace owners can manage connected accounts and member access in Zyan. You may also contact team@zyan.ai. We may verify your identity and authority before fulfilling a request.
9. Cookies, children, and changes
We use essential cookies and browser storage for authentication, security, preferences, and core service operation. Zyan is not directed to children under 18, and we do not knowingly collect their personal information. We may update this policy as Zyan changes; the date above identifies the current version, and material changes will be communicated through an appropriate service notice.