Legal
Privacy
How Zenith Cloud handles account, billing, and operational data.
Last updated: 9 August 2026 (v2026.08.09). These pages summarize current product behavior; they are not a substitute for a negotiated enterprise contract. Electronic acceptance records capture the exact version shown at checkout.
Who this covers
Zenith Cloud (hosted issuer and inference) and, where relevant, account records created so a customer can download a self-hosted gateway license. Self-hosted gateways you operate keep prompts and responses in your environment; Zenith Cloud does not receive those payloads from an activated gateway unless you explicitly integrate a managed feature that sends them.
Account data
We store the email and password hash for Cloud accounts, optional organization membership and invitation records, API key metadata (not plaintext secrets after issuance), wallet and ledger entries, billing transaction metadata, electronic contract acceptance records, and encrypted payment identity (government ID or passport number) used only for provider checkout.
Usage and operations data
Hosted inference stores usage ledgers and operational metrics needed to bill and operate the service. Audit and access records keep metadata only. Prompts and model responses are excluded from audit exports and metric labels.
Payment processing
Card data is handled by the payment provider (Tapsilat) and never reaches Zenith. We retain provider references, amounts, currency, status, fulfillment markers, and linked electronic acceptance evidence so we can verify checkout, renewals, refunds, and support disputes.
Retention (summary)
Governance audit events default to about one year with bounded cleanup. Contract acceptance evidence is retained for accounting and dispute defence according to operator retention policy. Payment identity remains while the account needs checkout or renewal and is removed with account soft-deletion from Account settings (or an equivalent support request). Database backups and the issuer master key form one recovery set and are retained according to operator backup policy, not indefinitely by default product design.
Contact
Privacy requests for hosted Cloud accounts: [email protected] or KEP [email protected]. Self-hosted deployments remain under your own privacy program for data that never leaves your network.