ZOOMIES.
FormatsPricingFAQLog inStart with your website

Table of contents

01 Formats02 Pricing03 FAQ04 Log inStart with your website

Privacy policy

How Zoomies handles your brand, media, and connected social account data.

Zoomies creates, exports, schedules, and, where platform approvals permit, publishes short-form video through official social APIs. This policy explains the data involved and how connected credentials are handled.

Status
Current
Updated
August 3, 2026
Contact
privacy@usezoomies.com

On this page

01What Zoomies collects02Cookies and similar technologies03Analytics and product measurement04Crawling websites you submit05Social tokens, API credentials, and permissions06How Zoomies uses data07AI, media, and third-party providers08No engagement automation09Retention, export, and deletion10Your privacy rights11International transfers, security, and children12Changes and contact
01

What Zoomies collects

  • Account and workspace data: your name, email address, authentication records, workspace memberships, roles, plan details, billing state, and product settings.
  • Brand data: brand profiles, website URLs you submit, extracted positioning, tone, audience notes, benefits, logos, screenshots, color references, negative constraints, and other brand assets you upload or approve.
  • Generated and uploaded media: prompts, scripts, captions, hooks, rendered videos, carousel images, avatar selections, voiceover settings, uploaded source files, edit history, approval decisions, and export files.
  • Crawl data: public website content, metadata, screenshots, images, and derived brand analysis from URLs you ask Zoomies to inspect.
  • Scheduling and analytics data: approved queues, scheduled posts, platform targets, publish attempt logs, captions, hashtags, post status, performance metrics, metrics snapshots, and learning-loop summaries.
  • Technical data: device and browser details, request logs, product events, error reports, security logs, and session identifiers needed to run the service. For free-trial abuse prevention we deliberately store only hashed forms of IP address, user agent, and language, never the raw values.
02

Cookies and similar technologies

  • Session cookie (name authjs.session-token, or __Secure-authjs.session-token over HTTPS): keeps you signed in. Strictly necessary. Expires after 30 days or when you sign out.
  • zm_device_id: a first-party, HTTP-only identifier used to stop one browser from recycling unlimited free trials. Strictly necessary for fraud prevention. It is not used for advertising or shared with anyone.
  • zm_anon_id: a first-party, HTTP-only identifier that links marketing-site page views to a later signup so we can tell which pages actually help. Analytics, not strictly necessary.
  • OAuth state cookies: short-lived, scoped to a single connection flow, and used to protect the social account connection against cross-site request forgery. Strictly necessary, and deleted as soon as the connection completes.
  • PostHog cookies (names beginning ph_): set by our analytics provider in your browser to group page views into a session. Analytics, not strictly necessary. See the next section.
  • Zoomies does not use advertising cookies, retargeting pixels, or third-party ad networks on its own website.
  • You can block or delete cookies in your browser. Blocking the strictly necessary ones will stop sign-in from working.
03

Analytics and product measurement

  • We use PostHog as our product analytics provider to understand which parts of the product work and where people get stuck. PostHog acts as a processor for us under its own security and contractual terms.
  • Analytics reaches PostHog by two paths. Marketing-site events are posted to our own first-party endpoint and forwarded server-side. The product also loads the PostHog browser SDK, which captures page views and interactions directly. The PostHog project key used in the browser is a write-only ingestion key, which is how PostHog is designed to be used, and it cannot read any data back.
  • The browser SDK is configured so that anonymous visitors do not get a stored person profile. A profile is created only after you sign in and we identify you.
  • We measure to improve Zoomies. We do not sell analytics data, we do not use it for cross-context behavioural advertising, and we do not share it with advertising networks.
  • You can opt out of the browser SDK by enabling Do Not Track or a tracking blocker; our first-party server-side events, which are what we rely on for security, billing, and abuse prevention, will still be recorded.
04

Crawling websites you submit

  • Zoomies only visits a website when you ask it to, by submitting that URL as a brand source. We do not crawl the open web.
  • Before crawling we fetch and honour the site's robots.txt. A crawl reads a small number of pages, up to five, and captures public page content, metadata, screenshots, and images so the product can learn the brand's own words.
  • Submitting a URL is your representation that you are entitled to have that site analysed for marketing purposes. If you are not the owner, do not submit it.
  • If you run a site and want Zoomies excluded, disallow our crawler in your robots.txt and we will stop, or write to privacy@usezoomies.com.
05

Social tokens, API credentials, and permissions

  • When you connect TikTok, Instagram, YouTube, or Facebook, Zoomies stores OAuth access tokens, refresh tokens, account IDs, page IDs, expiry times, and related platform metadata for the connected brand.
  • Social tokens and API credentials are encrypted at rest. We use them only to perform actions you authorize inside Zoomies, such as reading account identity, checking token health, scheduling approved content, publishing through official platform APIs when access is approved, and reading post metrics where the platform grants that permission.
  • Zoomies requests only the social read and write permissions needed for the product workflow, such as publishing approved short-form videos, reading connected account or page details, and retrieving analytics for posts managed through Zoomies.
  • You can disconnect a social account from the product. We will stop using its tokens, revoke or delete stored credentials where supported, and may retain audit records needed for security, compliance, billing, or dispute handling.
06

How Zoomies uses data

  • To create brand-aware ideas, scripts, captions, videos, carousel posts, thumbnails, voiceovers, and platform-ready export packages.
  • To operate calendars, queues, approval workflows, reminders, account connection flows, publish retries, failure alerts, and weekly performance digests.
  • To measure performance, build analytics dashboards, tune content suggestions for each brand, calculate momentum scores, and improve generation quality.
  • To secure the service, prevent abuse, debug failures, enforce plan limits, process payments, send transactional email, and satisfy platform review or legal obligations.
07

AI, media, and third-party providers

  • Zoomies may send prompts, brand context, uploaded assets, crawl results, generated drafts, and media instructions to AI generation providers to produce text, images, voice, avatar footage, and rendered video.
  • Zoomies may use storage, database, queue, analytics, observability, email, payment, video rendering, and AI infrastructure providers to run the service. These providers process data for Zoomies under their own security and contractual terms.
  • Zoomies may share the minimum data needed with social platforms when you connect accounts, request publishing, request metrics, or use OAuth login. Platform use is also governed by the terms and privacy policies of TikTok, Meta, Google/YouTube, Facebook, and any other connected platform.
  • Zoomies does not sell customer brand assets, generated media, social tokens, or post analytics.
08

No engagement automation

  • Zoomies does not provide bots, fake engagement, follower automation, mass commenting, auto-liking, auto-following, auto-DM, scraping for engagement, or other behavior intended to manipulate platform engagement systems.
  • Posting and analytics features are designed to use official APIs and platform-approved scopes only.
09

Retention, export, and deletion

  • Brand assets such as logos, screenshots, and approved brand profiles are kept while the brand or workspace remains active unless you delete them or request deletion.
  • Our retention policy for rendered media is: unscheduled or rejected renders are removed after 30 days, approved or scheduled renders are kept until publish plus 90 days, and published source video files are removed from Zoomies storage 7 days after publishing. A scheduled cleanup job enforces these windows. The copy already published on a social platform is outside our control and remains subject to that platform's rules.
  • Post metrics snapshots are retained for up to 2 years. Audit logs are retained for up to 1 year, then deleted according to operational and legal requirements.
  • You can export your data yourself. Settings, then Privacy, gives you a machine-readable copy of your account, workspace, brand, media, schedule, and analytics records without waiting for us.
  • You can delete your account yourself from the same screen. Deletion is scheduled rather than instant so it can be reversed if it was a mistake, and a background job then removes assets, generated media, stored credentials, schedules, and related records. Some records are retained where we must keep them for security, fraud prevention, billing, tax, legal, or platform compliance, and backups age out on their own cycle.
  • If you would rather we handled either request, or you no longer have access to the account, write to privacy@usezoomies.com from the email address associated with it.
10

Your privacy rights

  • Wherever you live, you can use the export and deletion tools described above, and you can ask us anything about this policy at privacy@usezoomies.com. We answer within 30 days.
  • If you are in the UK, the EU, or the EEA, the GDPR gives you the right to access your data, correct it, have it erased, restrict or object to processing, and receive it in a portable format. Our legal bases are: performing our contract with you (running the product you signed up for), legitimate interests (security, fraud and free-trial abuse prevention, product analytics), consent where we ask for it, and legal obligation. You can withdraw consent at any time and complain to your local supervisory authority.
  • If you are in California, the CCPA as amended by the CPRA gives you the right to know what we collect and why, to delete it, to correct it, and to opt out of sale or sharing. Zoomies does not sell personal information and does not share it for cross-context behavioural advertising, so there is nothing to opt out of, and we do not offer financial incentives for data. We will not discriminate against you for exercising any of these rights.
  • Residents of other US states with comprehensive privacy laws have equivalent rights and can use the same contact address.
  • We verify a rights request by requiring it to come from the account email or from an authenticated session, so that nobody can export or delete someone else's workspace.
11

International transfers, security, and children

  • Zoomies is operated from the United States and its infrastructure and service providers are primarily US-based. If you use Zoomies from outside the US, your data is transferred to and processed in the US. Where a transfer from the UK, EU, or EEA requires a safeguard, we rely on the European Commission's Standard Contractual Clauses with our providers.
  • We protect data with encryption in transit, encryption at rest for social tokens and API credentials, workspace-scoped access controls, and least-privilege access for the small number of people who operate the service.
  • No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant regulators where the law requires it.
  • Zoomies is not directed at children and we do not knowingly collect personal information from anyone under 13. If you believe a child has given us data, write to privacy@usezoomies.com and we will delete it.
  • Zoomies is operated by the independent operator of Zoomies, which is not yet incorporated, and the operator is the data controller for the purposes of this policy. The same operator is named in our Terms of Service. Write to privacy@usezoomies.com for anything covered by this policy. If you need a postal address for a formal privacy notice, ask at that address and we will provide the current one for service.
12

Changes and contact

We may update this policy as Zoomies moves from beta export mode into approved platform publishing. Material changes will be reflected on this page. Send questions, export requests, and deletion requests to our privacy team.

privacy@usezoomies.com
ZOOMIES.

For founders with a good product that nobody has found yet.

Comparevs Fastlanevs Arcadsvs Creatifyvs Buffer
IndustriesSaaSMobile appsE-commerceIndie hackers
CompanyAPI docsPartnershello@usezoomies.comPrivacyTerms
© 2026 ZoomiesFor the good product nobody found yet