Privacy Policy
Last updated: September 7, 2026
OpenZen (“we,” “us”) provides a subscription AI chat assistant with optional scheduled tasks and third-party connectors. This policy explains what we collect, why, and how it’s handled.
1. What we collect
- Account information: your email address, name, and password (stored as a salted hash, never in plain text).
- Conversation content: messages you send and the assistant’s replies, so your chat history is available across sessions.
- Usage and billing data: which models you use, token/request counts, and subscription tier, used to enforce plan limits and for internal reporting.
- Connector data: if you connect a third-party account (Google, Slack, Notion, or a custom MCP server), we store an encrypted access token so the assistant can act on that account when you ask it to.
2. How we use it
We use your data solely to operate OpenZen:
- Generating chat replies and running scheduled tasks you configure.
- Carrying out connector actions you explicitly request (e.g. searching your email, reading a calendar event, posting a Slack message) — we never access a connected account on our own initiative.
- Enforcing subscription limits and calculating usage.
- Maintaining and improving the reliability of the service (error monitoring, abuse prevention).
We do not sell your data, and we do not use your conversation content to train models.
3. Third-party sharing
Your data is shared only as needed to provide the service:
- Your messages are sent to our AI inference provider (OpenRouter) to generate a reply.
- If you connect Google, Slack, or Notion, requests you initiate are sent to that provider’s own API using your granted access token — subject to that provider’s own terms and privacy policy.
- We do not share your data with advertisers or data brokers.
4. Google user data specifically
If you connect a Google account, OpenZen requests access to Gmail (read and send), Google Calendar (view and create events), and Google Drive (read-only) — only the scopes needed for the features you use. OpenZen’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google account data is used only to fulfill requests you make in a chat or scheduled task, is not used for advertising, and is not shared with anyone except as necessary to serve that specific request. You can revoke this access at any time from the Connectors panel in OpenZen or from your Google Account permissions page.
5. Data retention and deletion
We retain your account and conversation history for as long as your account is active. Closing your account revokes any connected third-party access and disables further use; you can request full deletion of your data by contacting us (below). Disconnecting a connector immediately deletes its stored access token.
6. Security
Access tokens and API keys are encrypted at rest (AES-256-GCM). Passwords are hashed, never stored in plain text. Access to production data is restricted to the people operating the service.
7. Children’s privacy
OpenZen is not directed at children under 13, and we do not knowingly collect their data.
8. Changes to this policy
We may update this policy as the service evolves. Material changes will be reflected by updating the date above.