01What we collect
Zoe collects three kinds of data for a case. From connected systems: only the metadata needed to compute the diagnostic, meaning who communicates with whom, how often, in what cadence, and across which channels. The analysis is on patterns, not paragraphs. Message bodies are never stored, what is extracted from a granted source is discarded by default, and personal identifiers are stripped at ingestion. From the investor: the target company’s pitch deck, any data-room PDFs or CSVs, and the founder call transcript, which are read in full to build and test the Claim Ledger. From the target company: its acceptance of the data processing agreement, logged as a consent event, and its read-only OAuth grants; Zoe never holds the target’s credentials. We also collect basic account information (name, email, company) when you sign up, and technical telemetry (page views, clicks) for product analytics.
02How we use it
Case data is used only to build the Claim Ledger, check its claims against connected systems, generate and score founder call questions, compute the Zoe Score with its confidence percentage and coverage tier, answer Ask Zoe questions from your own report, and produce the readout package for your engagement. Account information is used to operate the service and communicate with you. Technical telemetry is used to improve the product. We do not sell, rent, or share personal data with third-party advertisers, ever.
03How we store it
All data is encrypted in transit and at rest. Each case runs in an isolated workspace with its own encryption key. What is extracted from connected systems is discarded by default. When a case is sealed, the normalized metrics, uploaded documents, and transcripts behind it are destroyed 30 days later, with a destruction certificate issued to the grantor. If a customer keeps a case open for monitoring on the Portfolio package, retention runs until the case is sealed. The readout package persists for the customer. See our /security page for the per-connector data handling table.
04Who we share with
Nobody. Zoe does not share customer data with third-party advertisers, data brokers, or affiliates. We use a small number of vetted infrastructure providers (cloud hosting, email delivery, analytics) under strict data processing agreements. We will disclose data only when required by law or to protect against fraud or imminent harm. Two exceptions by design: the target company that granted access receives the destruction certificate for its case, and Zoe presents its data processing agreement to the target and logs acceptance before any system is connected.
05Your rights
You have the right to access, correct, export, or delete your personal data at any time. To exercise these rights, email privacy@zoediagnostics.com. We respond within 30 days. We honor these rights for every user, regardless of jurisdiction.
06Cookies and tracking
We use a minimal set of cookies for authentication and product analytics. We do not use third-party advertising cookies or cross-site tracking pixels. You can disable cookies in your browser settings; the site will continue to work with the exception of features that require login.
07International transfers
Zoe operates from the United States. If you access the service from outside the US, your data will be transferred to and processed in the US under standard contractual clauses or equivalent safeguards. EU customers can request that diagnostic data be processed in EU regions on request.
08Changes to this policy
We may update this policy as Zoe evolves. Material changes will be communicated to active customers via email at least 30 days before they take effect. The "last updated" date above reflects the most recent revision.