Privacy Notice
Proposed date: 7 October 2026.
1. Controller and contact
zenture UG (haftungsbeschränkt), Dobelstrasse 5, 70184 Stuttgart, Germany, is responsible for the processing described in this Privacy Policy unless we state otherwise. You can contact us at [email protected].
We have not appointed a data protection officer because we are not currently legally required to do so.
2. Scope
This Privacy Policy applies to zenture websites, the authenticated web app, the iOS app, APIs, MCP Connections, native clients and related services. It explains which personal data we process, why we process it, which service providers may receive it and which rights you have.
For business customers, self-service organisations and team accounts are independent SaaS use and do not, by themselves, constitute a data processing agreement or processor engagement. Our data-protection role follows actual processing. Where we process personal data on behalf of a customer, a required data processing agreement must be concluded before that use; the self-service label does not replace this assessment. We do not currently provide a standard DPA through the website; if you require processor terms, contact us before using zenture for such processing. For account administration, security, billing, fraud prevention, legal compliance and platform improvement, we generally act as an independent controller.
3. Data categories
We process account and profile data such as user ID, email address, name, display name, optional company, address and profile settings; authentication and session data such as access tokens, refresh tokens, backend session IDs, device type, device name, client version, device key, IP address, user agent, timestamps and security events, Connection identifiers, requesting applications, permissions and Legal-version records; product data such as chats, prompts, speech dictation transcripts, uploaded files, documents, PDFs, images, screenshots, file names, file types, metadata, extracted text, OCR results, model outputs, temporary-chat metadata, input-wizard prompts, AI personality settings, chat folders, evaluations, Run tasks and requirements, submitted evidence, Run inputs, Run results, findings, coverage and status, source results, usage and Credit-consumption records and feedback; sharing data such as public or restricted share links, copied chat content and related access metadata; integration data such as connected Notion, Confluence or Slack interface metadata and encrypted access credentials; organisation data such as organisation names, roles, memberships, invites and audit events; billing data such as Stripe customer IDs, invoices, payment status, subscriptions, wallet and credit transactions, auto-recharge settings, tax/VAT metadata and chargeback information; referral and promotion data such as referral codes, invited email addresses, promotion codes, eligibility checks and fraud-prevention signals; support data such as ticket content, call metadata, contact details and notes from support requests; and website data such as cookie choices, page views, traffic source parameters and technical request logs.
The iOS app stores access token, refresh token and backend session ID in the device Keychain and may store non-secret preferences such as theme, language, client instance and runtime settings in UserDefaults. Apple's privacy manifest for the iOS app declares email address, user ID, other user content, product interaction data and performance data for app functionality and, where applicable, analytics.
4. Purposes and legal bases
We process personal data to create and manage accounts, authenticate users, maintain sessions, provide Chats, our own Run examinations and requested functions, process uploads, transcribe speech dictation into editable text, generate and evaluate AI outputs, preserve chat history, operate organisations and integrations, process payments and credits, show transactional or security notices in the web app or iOS app, provide support, maintain security, prevent fraud and abuse, enforce our terms, comply with legal obligations and improve reliability and usability.
The legal bases are performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR), legal obligations such as tax and accounting duties (Art. 6(1)(c) GDPR), our legitimate interests in operating, securing and improving the service, preventing abuse, enforcing claims and maintaining reliable infrastructure (Art. 6(1)(f) GDPR), and consent where required, especially for optional analytics cookies, microphone access or speech recognition permissions requested by the operating system (Art. 6(1)(a) GDPR where applicable).
To execute, diagnose and bill Runs, we also process technical metadata, such as Account and Run associations, timestamps, profile, status and result categories, the volume and types of sources processed, language identifiers, processing and queue times, retries, model and software versions, compute consumption and billing information. Where a Run refers to a predecessor, that relationship may also be stored. These details are personal data where they can be linked to a person or Account. Execution and billing are based on Art. 6(1)(b) GDPR; necessary diagnostics and aggregated operational and capacity analyses are based on our legitimate interest in reliable, secure and economical operation under Art. 6(1)(f) GDPR. These purposes are separate from the planned Learning features.
5. AI chats, dictation, uploads and model providers
When you use Chat functions with an external AI model provider, your prompts, selected context, uploaded files, model configuration, AI personality settings, previous conversation turns and generated outputs may be processed by us and by the selected third-party model provider. Depending on the selected Chat model, this can include OpenAI, Anthropic, Google/Gemini, Mistral AI or xAI. We use these providers to generate responses, process files, support tool use, calculate usage and provide the requested functionality.
If you use speech dictation in the iOS app, the microphone captures your spoken input only after you start dictation. The audio may be processed through Apple Speech Recognition to convert it into editable text. zenture uses the resulting transcript like a typed prompt. We do not store raw dictation audio as a separate voice recording in zenture unless we explicitly introduce and disclose such a feature in the future.
If you upload documents, PDFs, images, screenshots or similar files, we may process the file content, file names, file types, metadata, extracted text, OCR results, previews or thumbnails to provide the requested AI workflow, answer your prompt, preserve chat context, enable downloads or support troubleshooting. Uploaded files may contain personal data about you or third parties. You are responsible for having the necessary rights and legal basis before uploading or otherwise processing third-party data through zenture.
We do not currently use your chats, prompts, dictation transcripts, uploads or outputs to train our own AI models. The proposed Learning features have not yet been implemented. Planned purposes and boundaries are described separately below; this does not create active Learning processing or advance consent.
For the third-party model providers currently connected to zenture, we use API, commercial, enterprise or paid configurations where provider terms state that API or business customer inputs and outputs are not used for model training by default, unless the customer explicitly opts in or a separate agreement says otherwise. We have not enabled provider opt-ins for model training. Provider-side abuse monitoring, safety processing, caching, audit logging, legal retention or zero-data-retention availability depends on the respective provider's current terms.
You are responsible for the content you enter into zenture. You must not submit special categories of personal data, confidential third-party data, unlawful content or data you are not authorised to process unless you have a valid legal basis and the necessary rights to do so.
Temporary chats are not shown in your visible chat history unless you publish them, but related prompts, outputs, uploads, metadata, billing records, security logs or provider-side processing may still occur where necessary to provide the service, prevent abuse, troubleshoot errors, comply with law or enforce our terms.
zenture Runs are not executed by external AI model providers. Run content is processed within zenture-operated processing using the designated infrastructure and service providers. Their functions and data categories are described at zenture.app/subprocessors.
For source verification, we may retrieve referenced websites and external source or archive services, such as Crossref, Unpaywall, arXiv, Wikimedia, GitHub or Internet Archive. The information needed for retrieval, in particular URLs or document identifiers, and technical request data from our infrastructure are sent to the respective service. URLs and identifiers may themselves contain personal or confidential information. Source retrieval is distinct from executing Run models and does not mean that the complete Run content is sent to every source provider. This processing serves the requested source verification under Art. 6(1)(b) GDPR; the necessary legal basis for personal data relating to third parties must be considered separately.
5a. Planned Learning and possible model adaptation
The Learning features described below are planned and have not yet been implemented. They are intended primarily to develop zenture’s decision logic and review rules; where applicable, this may also include targeted adaptation of AI models through fine-tuning.
Where corresponding Learning features are offered, personal Learning for the respective user and Learning within the respective organisation can be configured through the designated settings. Neither mode receives a Learning discount.
Use of Run results for general, collective Learning to further develop zenture requires separate express authorisation by the user. Run results may also include embedded text excerpts, contextual information and personal or confidential details. To the extent necessary for the described Learning purpose and legally permissible, these elements may be included in the separate authorisation. This authorisation does not include complete Run inputs or uploaded files. Your authorisation alone does not give zenture rights to process every third-party personal record, organisation secret or special category of data. The necessary rights, legal bases and safeguards must exist for the data actually affected. This voluntary authorisation receives a discount under the described participation conditions. Before authorisation, the affected data, purposes of use, participation conditions and withdrawal options are explained. Neither acceptance of these Terms nor configuration of personal or organisation Learning replaces that separate authorisation.
You can disable authorisation for general zenture Learning at any time through the designated settings. From that point, the authorised Run results are no longer analysed for general zenture Learning on the basis of that authorisation. This also applies to already collected results and queued analyses; there is no additional processing period based on the disabled authorisation. The participation discount applies only while participation is active, not for periods before activation or after deactivation. Discounts legitimately granted for active participation are not retrospectively reclaimed because of deactivation.
Run results used for Learning, development of decision logic and review rules, or any fine-tuning are used exclusively for zenture’s internal purposes. We do not sell or publish this data or provide it for independent training or exploitation by external providers. Processing by the infrastructure service providers involved takes place solely within the described processing for zenture.
The data categories, legal bases, recipients, retention and privacy rights relevant to actual introduction will be explained before processing begins. The classification of derived review rules or model adaptations and their treatment on withdrawal and deletion will be described against the technology actually used. Neither irreversibility nor anonymity is presumed.
6. Sharing, referrals, partner inquiries and third-party data
If you copy chat content, create or publish a share link, invite another person, use referral functionality or otherwise disclose content from zenture, you decide which information is shared and are responsible for having the necessary rights and legal basis. Anyone with access to a public or unrestricted share link may be able to view the shared content until the link is disabled or the content is deleted, subject to the available product controls.
When you invite or refer another person, we may process that person's email address, referral relationship, eligibility status, fraud-prevention signals and reward metadata. You must only provide third-party contact details where you are authorised to do so.
When you submit a Partner Program inquiry, we process the information needed to review and answer it, including your name, email address, partner type, optional company, channel or client base, message content, displayed Legal versions, CAPTCHA result, technical request metadata and related anti-abuse signals. We use this data to assess partner fit, communicate with you, prevent abuse, document inquiry handling and, if we later agree partner participation, administer the partner relationship and related eligibility or payout checks.
Referral benefits involve checking email verification and qualifying activity on two distinct UTC calendar dates. Manually entered codes are distinct from automatic link attribution through consent-dependent storage. Attribution, qualification, programme conditions, benefits and, for partners, qualifying revenue, adjustments and payment checks are processed to administer the respective programme. A partner inquiry alone is not confirmed participation or a remuneration promise. It is forwarded through designated communication channels for handling; this does not imply additional storage of the inquiry in a product database.
7. Payments, credits and billing
Payments, subscriptions, invoices, credit purchases, auto-recharge and chargebacks are processed with Stripe. We store only the data needed to operate billing and credit accounting, such as Stripe customer, subscription, invoice and payment identifiers, payment status, amounts, currency, plan, tax metadata, credit packages, consumption events and audit records. Full card details are handled by Stripe and are not stored by us.
8. Authentication, CAPTCHA and OAuth
Registration, login, password reset, session refresh, account deletion and other sensitive actions may require security checks. We use Cloudflare Turnstile for CAPTCHA protection where enabled. If you sign in with Apple, Azure/Microsoft or Google, the relevant identity provider processes authentication data according to its own privacy terms and provides us with the information needed to authenticate your account, such as provider identifiers, email address and profile metadata.
For an MCP or native client Connection, we process in particular the Account association, connection request, admitted client and permissions. A Connection requires express authorisation of described actions and does not automatically start a Run. The client receives credentials for the Connection. Deleting local credentials is not server-side revocation; revocation does not automatically cancel Runs already accepted. Technical sign-in, request and access-authorisation expiry and storage of Run content have distinct purposes and periods. New native storage or Device functions will be described with their actual offered scope when introduced.
8a. Guest access and connections with applications
If you use zenture as a guest without an account, we process a pseudonymous guest identifier, session and device data, the time of your consent including the version of the Terms and of this Privacy Notice, usage and quota data (such as the number of Runs started), the content and files you submit, the outputs generated, and security and abuse signals such as IP address, CAPTCHA result and rate limits. The legal bases are Art. 6(1)(b) GDPR (providing guest access) and Art. 6(1)(f) GDPR (our legitimate interest in security, enforcing quotas, preventing abuse and evidencing consents given). Without this data we cannot offer guest access.
For connections with our own clients and independent third-party applications such as ChatGPT, Claude or Claude Code, we process, in addition to the data described in section 8, the application’s name, the host the sign-in returns to, and the times of permission, use and revocation. Access tokens are not logged in plain text. This Privacy Notice applies to zenture’s own clients. For independent applications, the respective provider processes submitted content, files and returned results under the terms and privacy notices applicable to its processing; its specific data-protection role depends on that processing. The selection and confirmation steps offered by an external application depend on that application. A Connection alone does not cause blanket disclosure of all files or Account content. Revocation ends future access through the Connection but does not delete data already stored by the external provider.
Expiry or revocation of a guest Connection ends the corresponding access permission. Deletion of guest content and cleanup of the guest identity are separate processes. Content is cleaned up under the retention period specified for guest access; the period for an inactive guest identity runs from the last relevant guest activity. Revocation therefore does not immediately delete all guest data. Data is retained further only for an independent lawful purpose under section 13, in particular necessary records or concrete abuse-prevention measures. If you register from guest access, guest data may be assigned to your Account where we technically offer this. Statutory deletion duties remain unaffected.
9. Support, calls and social media
Support requests may be handled through ticketing, email, messaging, video-call or similar communication tools and may include your contact details, account identifiers, issue descriptions, attachments, diagnostic context, call metadata and our internal notes. We do not record support calls by default. The respective communication providers process metadata and, where applicable, communication content under their own terms.
If you contact us or interact with zenture through social media platforms, the relevant platform also processes your data as an independent provider. We process social-media messages, comments, handles and related metadata only to respond, moderate, protect our rights or operate our public presence.
Email marketing and newsletters are not currently planned. Email addresses are used for necessary Account, security, billing, support and inquiry communication.
We use Mailjet for necessary Account and security emails. This involves processing the recipient address, subject, message content and technical data needed for sending and delivery. Messages may contain the confirmation or recovery information required for the respective Account process. Processing serves contract performance under Art. 6(1)(b) GDPR or protection of Account access under Art. 6(1)(f) GDPR. This does not imply use for newsletters or marketing.
9a. Feedback and product research
We may show in-app feedback requests to better understand product quality, feature usability and support needs. For this purpose we process account identifiers, product usage context, responses you submit voluntarily, and related metadata such as timestamps and client version. The legal basis is our legitimate interest in improving service quality and reliability (Art. 6(1)(f) GDPR).
We do not currently send proactive feedback emails for these purposes. You can still contact us voluntarily at any time if you want to provide feedback.
You can object to in-app feedback requests at any time. If you object, we stop using your data for further in-app feedback outreach and keep only the records required to document your objection and ensure compliance.
10. Cookies and analytics
We use essential cookies and similar storage for authentication, security, sessions, CSRF protection, language and cookie preferences and basic website functions. Optional automatic Referral attribution through corresponding storage requires the designated consent.
Google Analytics 4 is activated on the public website for optional usage analytics only following corresponding consent. If you allow only essential technologies or decline analytics, we do not activate Google Analytics; no cookieless analytics mode is used after rejection. You can reopen cookie settings through the website footer and change your choice. No additional analytics, session-replay or advertising-tracking services are currently planned.
Necessary storage technologies also include local and session browser storage for device association, interface settings and the respective usage process. The device cookie is set with a two-year lifetime and may be renewed when the service is used again. Corresponding local entries do not necessarily have the same expiry; they remain until the intended cleanup or deletion by the user. Session-specific entries are held in the browser’s session storage. Deleting browser data does not automatically terminate server-side Connections or delete Account content.
11. Recipients and subprocessors
We share personal data only where necessary to provide, secure, bill, support or legally operate the service. Recipients may include hosting and infrastructure providers, Supabase for database, authentication, storage and realtime functionality, Redis-backed infrastructure operated by us, AI model providers for respective Chat use, source and archive services for source retrieval, Apple Speech Recognition when iOS dictation is used, Stripe, Cloudflare including Turnstile, Mailjet for necessary emails, other support and communication providers, OAuth identity providers, Google Analytics following corresponding consent, professional advisers and authorities where legally required.
Our current overview of service providers and other recipients is available at zenture.app/subprocessors. Inclusion does not mean that every recipient acts as a processor for every processing activity. Roles, data scope and transfers depend on the respective service and the function actually used. We may update the overview when we add, remove or replace providers; existing contractual notification rights remain unaffected.
If you use zenture through an external host, platform or client, content you provide there and results or metadata returned through that access channel may also be processed by its operator. zenture’s own Run processing is distinct from this host or client processing. You should consider the scope, permissions and privacy notices of your chosen access channel; this does not imply blanket disclosure of all Account content to every host.
12. International transfers
The central Backend and Engine infrastructure operated by zenture, and the internal core processes performed there, are located in Germany. This is distinct from the separately described processing by external service providers and hosts or clients chosen by the user. They may process data outside the European Economic Area or allow access from there. Where personal data is transferred to third countries, the transfer is made on a basis permitted for that specific transfer under Chapter V GDPR, in particular an applicable adequacy decision or appropriate safeguards under Article 46 GDPR. Information about the relevant recipients, transfer bases and access to the applicable safeguards is available through the service-provider overview and on request at [email protected]. Data-processing agreements and any necessary transfer assessments or supplementary measures support the respective processing; they do not by themselves replace a required transfer basis. An EU processing region alone is not such a basis.
13. Storage and deletion
Account data, profile data, chats, prompts, dictation transcripts, uploads, outputs, Run inputs, Run results, folders, AI personality settings and related product data are generally stored until you delete the relevant content or your account, unless a shorter feature-specific retention period applies. Uploaded files and hidden temporary-chat related records remain stored until manual deletion unless cleanup, security or legal requirements require earlier or longer retention.
After an Account-deletion request has been successfully verified, further Account access is blocked and cleanup is initiated. Cleanup may continue afterwards; initiation does not mean every copy has been deleted immediately. Following Account or content deletion, data is retained only where a separate lawful purpose exists, such as necessary billing and tax records, specific security or fraud investigations, or establishing and defending legal claims. Billing and tax records follow statutory periods, typically 6, 8 or 10 years depending on document type. Security and abuse logs are retained only for the necessary purpose-specific periods; specific incidents, disputes or statutory preservation duties may justify longer retention. Backup and service-provider copies follow their associated retention and deletion procedures. Immediate deletion of all copies is not promised; statutory deletion duties remain applicable.
Run inputs and results in your Account are generally stored until content or Account deletion; no general fixed period applies to them. Guest data, Chat files and provider artifacts, technical intermediate records and access authorisations are separate categories. Shorter function-specific periods and separate deletion procedures may apply to them; continued Account storage does not automatically extend those periods. Expiry or revocation of access authorisation is different from deletion of the associated records. Ending an organisation membership alone deletes neither the personal Account nor owned Run content. Disabling general Learning ends further analysis based on that authorisation; ordinary Account storage follows its own purpose. For guest access, the retention rules in section 8a apply in addition.
Technical caches used for source retrieval have their own periods: full-text caches are designed for a maximum of 24 hours; stored source excerpts may be retained for up to 30 days after their last retrieval. Where source material forms part of a stored Run result, those portions follow the retention of that result. Person-linked Run metadata and predecessor relationships are generally cleaned up with the associated Run or Account unless an independent lawful retention purpose applies. Previously generated aggregated operational statistics are not automatically recalculated following an individual content or Account deletion. A minimum group size alone is not a promise of anonymity; where an aggregate remains personal data, data-protection rights and the necessary deletion or retention rules also apply to it.
14. Security and internal access
We use technical and organisational measures including HTTPS, HttpOnly cookies for web sessions, device-scoped backend sessions, Keychain storage on iOS, row-level security, authenticated database access, encryption for selected sensitive fields, access controls, structured redacted logging, rate limits, CAPTCHA on sensitive flows, audit trails and provider isolation through our backend and AI connector services.
Access to user content by our team is technically possible for users with a dedicated developer role, but organisationally restricted to urgent operational, security, support, debugging, legal or abuse-prevention needs. Such access is logged where technically supported and is not intended for routine review of user content.
Private Run content is protected when stored by the designated encryption measures. Content needed to perform a Run is decrypted and processed within authorised zenture processing. This is not a promise of end-to-end encryption or encryption of every operational metadata field.
A planned organisation feature is intended to provide administrators with summarised Insights, not complete individual Runs with inputs, files and detailed results. This feature is planned and is not currently available. Summaries are not automatically considered anonymous; actual data and access rights will be described before introduction.
15. Your rights
Subject to applicable law, you may request access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time with effect for the future. You may also lodge a complaint with a competent data protection supervisory authority.
To exercise your rights, contact us at [email protected]. We may need to verify your identity before acting on a request.
16. Additional notices for US residents
zenture is primarily directed at users in Germany and the European Union, but may also be accessed from the United States. We do not sell personal information for money and do not intend to share personal information for cross-context behavioural advertising as those terms are commonly used in US state privacy laws. Where required and technically feasible, we will honour applicable opt-out preference signals such as Global Privacy Control for non-essential tracking on the public website. US residents may contact us at [email protected] to request access, deletion, correction or opt-out rights available under applicable state law.
17. Children
zenture is not intended for children under 16. Users under 18 may use the service only with parental or guardian consent.
18. Changes
We may update this Privacy Policy from time to time, for example when the service, legal requirements or our providers change. Material changes will be communicated by website notice, in-product notice or email where appropriate.