What Zoomies collects
- Account and workspace data: your name, email address, authentication records, workspace memberships, roles, plan details, billing state, and product settings.
- Brand data: brand profiles, website URLs you submit, extracted positioning, tone, audience notes, benefits, logos, screenshots, color references, negative constraints, and other brand assets you upload or approve.
- Generated and uploaded media: prompts, scripts, captions, hooks, rendered videos, carousel images, avatar selections, voiceover settings, uploaded source files, edit history, approval decisions, and export files.
- Crawl data: public website content, metadata, screenshots, images, and derived brand analysis from URLs you ask Zoomies to inspect.
- Scheduling and analytics data: approved queues, scheduled posts, platform targets, publish attempt logs, captions, hashtags, post status, performance metrics, metrics snapshots, and learning-loop summaries.
- Technical data: device and browser details, request logs, product events, error reports, security logs, and session identifiers needed to run the service. For free-trial abuse prevention we deliberately store only hashed forms of IP address, user agent, and language, never the raw values.
Analytics and product measurement
- We use PostHog as our product analytics provider to understand which parts of the product work and where people get stuck. PostHog acts as a processor for us under its own security and contractual terms.
- Analytics reaches PostHog by two paths. Marketing-site events are posted to our own first-party endpoint and forwarded server-side. The product also loads the PostHog browser SDK, which captures page views and interactions directly. The PostHog project key used in the browser is a write-only ingestion key, which is how PostHog is designed to be used, and it cannot read any data back.
- The browser SDK is configured so that anonymous visitors do not get a stored person profile. A profile is created only after you sign in and we identify you.
- We measure to improve Zoomies. We do not sell analytics data, we do not use it for cross-context behavioural advertising, and we do not share it with advertising networks.
- You can opt out of the browser SDK by enabling Do Not Track or a tracking blocker; our first-party server-side events, which are what we rely on for security, billing, and abuse prevention, will still be recorded.
Crawling websites you submit
- Zoomies only visits a website when you ask it to, by submitting that URL as a brand source. We do not crawl the open web.
- Before crawling we fetch and honour the site's robots.txt. A crawl reads a small number of pages, up to five, and captures public page content, metadata, screenshots, and images so the product can learn the brand's own words.
- Submitting a URL is your representation that you are entitled to have that site analysed for marketing purposes. If you are not the owner, do not submit it.
- If you run a site and want Zoomies excluded, disallow our crawler in your robots.txt and we will stop, or write to privacy@usezoomies.com.
How Zoomies uses data
- To create brand-aware ideas, scripts, captions, videos, carousel posts, thumbnails, voiceovers, and platform-ready export packages.
- To operate calendars, queues, approval workflows, reminders, account connection flows, publish retries, failure alerts, and weekly performance digests.
- To measure performance, build analytics dashboards, tune content suggestions for each brand, calculate momentum scores, and improve generation quality.
- To secure the service, prevent abuse, debug failures, enforce plan limits, process payments, send transactional email, and satisfy platform review or legal obligations.
AI, media, and third-party providers
- Zoomies may send prompts, brand context, uploaded assets, crawl results, generated drafts, and media instructions to AI generation providers to produce text, images, voice, avatar footage, and rendered video.
- Zoomies may use storage, database, queue, analytics, observability, email, payment, video rendering, and AI infrastructure providers to run the service. These providers process data for Zoomies under their own security and contractual terms.
- Zoomies may share the minimum data needed with social platforms when you connect accounts, request publishing, request metrics, or use OAuth login. Platform use is also governed by the terms and privacy policies of TikTok, Meta, Google/YouTube, Facebook, and any other connected platform.
- Zoomies does not sell customer brand assets, generated media, social tokens, or post analytics.
No engagement automation
- Zoomies does not provide bots, fake engagement, follower automation, mass commenting, auto-liking, auto-following, auto-DM, scraping for engagement, or other behavior intended to manipulate platform engagement systems.
- Posting and analytics features are designed to use official APIs and platform-approved scopes only.
Retention, export, and deletion
- Brand assets such as logos, screenshots, and approved brand profiles are kept while the brand or workspace remains active unless you delete them or request deletion.
- Our retention policy for rendered media is: unscheduled or rejected renders are removed after 30 days, approved or scheduled renders are kept until publish plus 90 days, and published source video files are removed from Zoomies storage 7 days after publishing. A scheduled cleanup job enforces these windows. The copy already published on a social platform is outside our control and remains subject to that platform's rules.
- Post metrics snapshots are retained for up to 2 years. Audit logs are retained for up to 1 year, then deleted according to operational and legal requirements.
- You can export your data yourself. Settings, then Privacy, gives you a machine-readable copy of your account, workspace, brand, media, schedule, and analytics records without waiting for us.
- You can delete your account yourself from the same screen. Deletion is scheduled rather than instant so it can be reversed if it was a mistake, and a background job then removes assets, generated media, stored credentials, schedules, and related records. Some records are retained where we must keep them for security, fraud prevention, billing, tax, legal, or platform compliance, and backups age out on their own cycle.
- If you would rather we handled either request, or you no longer have access to the account, write to privacy@usezoomies.com from the email address associated with it.
Your privacy rights
- Wherever you live, you can use the export and deletion tools described above, and you can ask us anything about this policy at privacy@usezoomies.com. We answer within 30 days.
- If you are in the UK, the EU, or the EEA, the GDPR gives you the right to access your data, correct it, have it erased, restrict or object to processing, and receive it in a portable format. Our legal bases are: performing our contract with you (running the product you signed up for), legitimate interests (security, fraud and free-trial abuse prevention, product analytics), consent where we ask for it, and legal obligation. You can withdraw consent at any time and complain to your local supervisory authority.
- If you are in California, the CCPA as amended by the CPRA gives you the right to know what we collect and why, to delete it, to correct it, and to opt out of sale or sharing. Zoomies does not sell personal information and does not share it for cross-context behavioural advertising, so there is nothing to opt out of, and we do not offer financial incentives for data. We will not discriminate against you for exercising any of these rights.
- Residents of other US states with comprehensive privacy laws have equivalent rights and can use the same contact address.
- We verify a rights request by requiring it to come from the account email or from an authenticated session, so that nobody can export or delete someone else's workspace.
International transfers, security, and children
- Zoomies is operated from the United States and its infrastructure and service providers are primarily US-based. If you use Zoomies from outside the US, your data is transferred to and processed in the US. Where a transfer from the UK, EU, or EEA requires a safeguard, we rely on the European Commission's Standard Contractual Clauses with our providers.
- We protect data with encryption in transit, encryption at rest for social tokens and API credentials, workspace-scoped access controls, and least-privilege access for the small number of people who operate the service.
- No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulators where the law requires it.
- Zoomies is not directed at children and we do not knowingly collect personal information from anyone under 13. If you believe a child has given us data, write to privacy@usezoomies.com and we will delete it.
- Zoomies is operated by the independent operator of Zoomies, which is not yet incorporated, and the operator is the data controller for the purposes of this policy. The same operator is named in our Terms of Service. Write to privacy@usezoomies.com for anything covered by this policy. If you need a postal address for a formal privacy notice, ask at that address and we will provide the current one for service.
Changes and contact
We may update this policy as Zoomies moves from beta export mode into approved platform publishing. Material changes will be reflected on this page. Send questions, export requests, and deletion requests to our privacy team.
privacy@usezoomies.com
Social tokens, API credentials, and permissions