Privacy Policy
Last updated 10 September 2026
Zephrys is a calendar app with an AI agent, Zephr. This policy says what we store, who processes it on our behalf, and how to have it deleted. It is written to be read; if anything is unclear, write to [email protected].
What we store
- Account. Your email address and sign-in method — Google, Microsoft, or a code by email, handled by Supabase Auth; a Google or Microsoft sign-in gives us the address and display name of that account and nothing else — and your preferences: theme, time zone, Zephr's autonomy level, and your plan.
- Calendar. Your calendars and events — title, description, location, times, recurrence, done state — including events mirrored from a connected Google or Outlook calendar.
- Conversations. What you say to Zephr, what it replies, the tools it called and what they returned, images you attach (plus a text transcription when the model in use cannot see images), the snapshots that make every change undoable, and the facts Zephr remembers about your preferences.
- Automations. The instruction as you wrote it, its compiled trigger, and the history and output of each run.
- Email you send to Zephr. The sender, subject, message ids and outcome, and the text of the message, which becomes a message in a conversation like anything typed in chat. Calendar attachments are summarised; image attachments are kept as chat images; any other attachment is recorded by name and not read.
- Email we send you. Recipient, purpose, subject, provider id and delivery status — never the body.
- Credits. A ledger of every metered operation: the kind of operation, tokens used per model, and cost. No content.
- Feedback. A thumbs rating on one of Zephr's replies with the reason you picked and any note, or a report you send from Settings, together with the page you were on, your browser and window size, your time zone, the Deep-thinking setting and the model that answered. The conversation up to the rated reply — images removed — is stored with a rating only when you tick Include this conversation, and un-rating the reply deletes it.
- Logs. The API keeps standard request logs (route, status, timing, requesting address) that rotate and are discarded automatically.
The app keeps your session and your theme choice in your browser's local storage. The website sets no cookies. If web analytics is enabled it is Cloudflare Web Analytics, which is cookieless and does not fingerprint visitors.
What we don't do
- No advertising, no selling or sharing data with advertisers, no data brokers.
- No tracking pixels: open and click tracking is switched off for every email Zephrys sends.
- Zephr never reads your inbox. It sees only mail you send or forward to its own address, from an address you have verified.
- Zephrys only ever emails the account holder. Addresses you verify are accepted as senders; nothing is sent to them.
- Operators see counts, statuses and ledger rows — never your events, conversations, run output, mail subjects or remembered facts, except a conversation you chose to send us with feedback, and every time one is opened is recorded. Every operator action requires a written reason and is audited.
- We do not train models on your data.
Who processes it
These providers process data on our behalf; each is bound by its own terms and privacy policy.
- Supabase — authentication and the database, hosted on AWS in the Canada (Central) region.
- Ollama (ollama.com) — the hosted language models that answer chat, automation and emailed requests. Each request sends the relevant part of your calendar, your preferences, remembered facts and the conversation so far, which is how the agent works.
- Resend — every email in and out.
- Cloudflare — hosts this website and the app, and provides the optional cookieless analytics above.
- Amazon Web Services (Lightsail, Canada Central) — runs the API.
- A web search provider (Tavily or Brave) — when web search is enabled and Zephr decides a request needs live facts, the search query it writes; the pages it then reads are fetched directly from their sites.
Google user data
When you connect a Google account in Settings → Calendars, we ask for permission to read your list of calendars and to read and write events (the calendar.readonly and calendar.events scopes). We use that access to mirror the calendars you tick into Zephrys and to keep both sides in step: changes flow back to Google only when made by you, by Zephr on your instruction, or by an automation you created, and never for a calendar you mark read-only. Access and refresh tokens are encrypted at rest and refreshed on demand; disconnecting the account deletes them and stops the sync.
Zephrys' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is transferred to the model provider above only to provide the user-facing features described on this site, is not used for advertising, is not sold, and is not used to develop, improve or train generalised AI or machine-learning models. No person reads it except with your explicit consent, for security purposes, or where the law requires.
The same applies to a connected Microsoft (Outlook) account under Microsoft's terms.
- Mail to Zephr's address is accepted only from your account email or an address you verified with a code. Mail from anyone else is dropped without a reply.
- If a message we send bounces, we stop sending to that address until you clear the notice in Settings → Email. If you report a message as spam, we additionally switch off email for all of your automations.
- Every email from an automation carries a one-click unsubscribe that turns that automation's email off. Verification codes and service notices are sent only when you trigger them.
Retention and deletion
We keep the data above for as long as your account exists. Deleting an event, conversation or automation in the app deletes it. Disconnecting a calendar account deletes its tokens.
There is no self-serve account deletion yet. To delete your account and everything listed above, email [email protected] from your account address; we delete it by hand and confirm by reply. Providers retain their own logs for the periods their policies state.
Security
Everything travels over TLS. Sign-in tokens are verified against Supabase's public keys, so no signing secret lives on our server. Every row in the database belongs to one user and is reachable only through the API. Calendar provider tokens are sealed with AES-GCM under a key that can be rotated. Operator access is an explicit allowlist and every operator action is audited.
Changes
When this policy changes, the date at the top changes with it. Questions and requests go to [email protected].