Skip to content

Privacy Policy

This policy explains what data we collect when you use Zolai, what we use it for, who we share it with, and the rights you and your website’s visitors have.

On this page

1.Who we are

Zolai (“we”, “us”) is an AI customer-support agent that businesses add to their websites as an embeddable chat widget. It answers visitors from the business’s own content, captures leads, and hands conversations to the business’s team when needed.

This policy covers our website, the Zolai dashboard, and the chat widget when it runs on our customers’ websites.

2.Our two roles

We play a different role depending on the data:

  • Controller — for your dashboard account, your visits to our website, and the billing details we receive.
  • Processor on behalf of a business — for the content a business adds to its workspace, the conversations with its website visitors, and its leads. The business is the controller of that data; we process it on its instructions and only to provide the service to it.

3.What we collect

Account data
Your name, email address, profile photo (from Google sign-in or one you upload), preferred language, and your role in each workspace you belong to. We don’t use passwords: you sign in with a code sent to your email or with Google.
Workspace content
Your business name, logo and settings, agent and widget settings, allowed domains, and lead destinations (email addresses and webhook URLs).
Knowledge sources
Website pages you ask us to crawl, files you upload (such as PDF, Word and text files), text you write, and product catalog feeds. We store the extracted text, split it into passages and turn them into embeddings so your agent can search them.
Conversations and visitor data
Messages from your website visitors, the agent’s replies and your team’s replies; a random visitor ID kept in the visitor’s browser; the page URL, page title and referrer when a conversation starts; browser language; approximate country; and any rating the visitor gives. If a visitor shares a name, email or phone number, we store it with the conversation.
Voice input
When a visitor uses voice typing, the recording is sent for transcription and then discarded. We never store or log the audio. Only the text is kept, and only if the visitor sends it as a message.
Leads
Name, phone number or email, and a summary of the request, as given by the visitor in the conversation, plus the follow-up status your team sets.
Billing data
Payments are handled by Polar as merchant of record. We never receive or store your card details. We receive only what we need to manage your subscription, such as your plan, subscription status, renewal date and the email used for the purchase.
Technical data
IP address, browser and device type, and request and error logs, used to run and secure the service, prevent abuse and apply usage limits.

4.How we use data

  • To provide the service: run your account and workspace, build your knowledge base, answer visitors, hand conversations to your team, and deliver leads to the destinations you choose.
  • To contact you: sign-in codes, invitations, lead notifications, and messages about your account and subscription.
  • For security and abuse prevention: checking allowed domains, rate limiting, blocking abusive visitors, and investigating incidents.
  • To improve the service: conversation-level usage measures (such as volume and the share of unanswered questions) that help you and help us improve the product.
  • For legal obligations: keeping what the law requires and responding to lawful requests.

We don’t sell personal data, we don’t use it for advertising, and we don’t use your content or your visitors’ conversations to train AI models.

5.AI processing

To write each reply, we send the visitor’s message, part of the conversation so far, and the most relevant passages from your knowledge base to a language-model provider: Google Gemini first, and OpenAI as a fallback when Gemini is unavailable. We also use Google to create embeddings of your content and to transcribe voice input.

We use these providers through their business APIs and send them only what is needed to produce the answer. AI answers can sometimes be wrong, which is why the product lets conversations be handed to your team.

6.Service providers we rely on

We share data with the following providers only as far as needed to run the service, under agreements that require them to protect it:

Supabase
Database, sign-in, file storage and realtime updates.
Google
Gemini models for answers, embeddings and voice transcription; Google sign-in; and Google Tag Manager to measure visits to our website.
OpenAI
A fallback language model when Gemini can’t be reached.
Trigger.dev
Background jobs: crawling pages, processing files, syncing catalogs and delivering leads.
Resend
Sending the service’s emails.
Polar
Selling subscriptions and handling payments and tax as merchant of record.
Our hosting provider
Hosting our website, the dashboard and the widget API.

When you turn on lead delivery, we send leads to the email addresses or webhook URLs you set, and those recipients follow their own policies. We may also disclose data when the law requires it, or as part of a merger or change of ownership of the service, in which case we’ll tell you first.

7.Where data is stored

Our main database and files are stored in the European Union (Frankfurt, Germany). Some of the providers above may process data in other countries, including the United States. We rely on providers that commit to appropriate contractual safeguards for cross-border transfers.

8.How long we keep data

  • Account data: for as long as your account exists; deleted when you delete it.
  • Workspace content, knowledge sources, conversations and leads: until the business deletes them or deletes the workspace. Deleting a knowledge source deletes its files and passages.
  • Backups: deleted data is removed from backups within 30 days.
  • Voice recordings: never stored.
  • Technical logs: for a short period, as needed for security and troubleshooting.
  • Billing records: as long as the law requires; Polar keeps its own records under its policy.

9.Your rights

Depending on the law that applies to you — including Saudi Arabia’s Personal Data Protection Law, the UAE’s Federal Decree-Law on Personal Data Protection, Egypt’s Personal Data Protection Law, and the EU GDPR where it applies — you have the right to:

  • Access your personal data and get a copy of it.
  • Correct inaccurate or incomplete data.
  • Ask us to delete your data.
  • Object to, or ask us to restrict, certain processing.
  • Withdraw your consent where processing relies on it.
  • Complain to the data protection authority in your country.

You can change most of your details yourself on your account page. For anything else, email [email protected]. We reply within 30 days and may ask you to confirm your identity first.

10.Visitors to our customers’ websites

If you chatted with a Zolai widget on a business’s website, that business is responsible for your data and we process it on its behalf. To access, correct or delete your data, contact the business directly. If your request reaches us, we’ll pass it to the business and help it respond.

11.A business’s responsibility to its visitors

A business that adds Zolai to its website is responsible for:

  • Telling its visitors that the site uses an AI assistant, and saying so in its own privacy policy.
  • Having a lawful basis to collect and process its visitors’ data and to contact them afterwards.
  • Not using the service to collect sensitive data (such as health or detailed financial data) except as the law allows.
  • Responding to its visitors’ requests about their data.

Our Terms of Service set out these obligations in full.

12.Cookies and local storage

Essential
Sign-in session cookies, a cookie that remembers your language, and the last workspace you opened. The service doesn’t work without them.
Preferences
Your choice of light or dark mode, kept in your browser’s local storage.
Chat widget
The widget sets no cookies on our customers’ websites. It keeps only a random visitor ID in local storage so a visitor can pick up their conversation.
Analytics
Our website uses Google Tag Manager to understand how the site is used. You can block these cookies in your browser settings without affecting the service.

13.Security

We encrypt data in transit, keep each workspace’s data separate and check access on every request, store files in private storage that is never exposed through public links, and limit our own staff’s access so they can’t read conversation text or lead details. No system is perfectly secure, though; if an incident affects your data, we’ll notify you as the law requires.

14.Children

Zolai is a service for businesses, and you must be 18 or older to create an account. We don’t knowingly collect children’s data through the dashboard. A business whose website is aimed at children must make sure it complies with the laws that protect them.

15.Changes to this policy

We may update this policy from time to time. We’ll change the effective date at the top, and tell you by email or in the dashboard before any material change takes effect.

16.Contact us

For any question or request about privacy or your data, email [email protected].