Privacy Notice

Effective
4 September 2026
Last updated
21 September 2026
Version
2.0

This notice explains what personal data ZeroCredit AI processes, why, who else is involved, and what you can ask us to do. It covers our website, dashboard and API. We have written it to describe the product as it actually works rather than as a generic template.

1. Who we are

ZeroCredit AI operates an enterprise AI gateway at zerocreditai.com: one OpenAI-compatible API that routes each request to a compatible model and provider, measures cost and usage, and gives teams budgets and controls.

Legal entity: [LEGAL PLACEHOLDER – TO BE COMPLETED]. Registered office: [LEGAL PLACEHOLDER – TO BE COMPLETED].

Privacy requests: support@zerocreditai.com. Grievances: support@zerocreditai.com (see our grievance process). We have not appointed a Data Protection Officer, and we will say so here if that changes.

2. The five categories of data, and how they differ

This distinction matters more than anything else in this notice:

  • A. Customer Account Data — who you are and how your workspace is set up: name where you give it, email, authentication identifiers and sign-in events, organisation, team members and roles, projects, budgets, routing and optimization settings, billing and subscription records, and metadata about connected provider keys (provider, status, last verified).
  • B. Customer Content — what you or your team save in the product: prompt library entries, saved configurations, uploaded files for the cost audit, notes.
  • C. API Request Data — the prompts, messages, attachments and parameters your application sends through the gateway.
  • D. API Response Data — what the selected model returns, including any citations from provider-native web search.
  • E. Operational and Telemetry Data — per-request records such as timestamp, model requested and used, provider, token counts reported by the provider, latency, computed cost, cache-hit status, error and fallback information, plus IP address, device and browser characteristics and application and security logs.

Categories A, B and E are what the platform is built around. We do not collect or store card details — payment data goes directly to Razorpay.

3. What we do and do not do with your requests and responses

Stated plainly, for request and response content (categories C and D):

  • Used to provide the service: yes. Content is received, validated against the capabilities you asked for, and transmitted to the provider that executes the call.
  • Transmitted to third-party AI providers: yes — that is what a gateway does. See "AI processing" below.
  • Cached: only where you enable caching. Cached content is scoped to your organisation, expires automatically, and can be cleared from your dashboard.
  • Stored: only where a feature you use requires it — for example a prompt you save, or caching. Otherwise we store the telemetry about a request, not its body.
  • Logged: limited. Diagnostic and security logs may include request metadata and, for error investigation, fragments of a failing request. Logs are access- controlled and not used for product analytics.
  • Used for abuse, fraud and security monitoring: metadata, yes. Rate, spend and error patterns are monitored. We do not routinely read content.
  • Used for analytics: aggregate and derived only — token counts, cost, latency and model performance. Not the text of prompts.
  • Used to train models: no. We do not train, fine-tune or evaluate any model on your prompts, responses or files, and we do not licence them to anyone for that purpose.
  • Sold: no. We do not sell personal data.

The provider that executes a call applies its own handling and retention terms to the content it receives. Where you use your own provider keys, those are the terms of your own agreement with that provider.

4. Our role: fiduciary for some data, processor for other data

  • For our website visitors, account holders and billing — Customer Account Data and website telemetry — we decide the purposes of processing and act in our own right as the data fiduciary or controller.
  • For personal data your organisation submits through the platform, including anything contained in request content, your organisation decides the purposes and we process it on your instructions as a processor and service provider.
  • AI providers process request content either as our subprocessor (managed access under our provider account) or under your own direct agreement with them (your own keys). Analytics and payment providers also determine certain aspects of their own processing.
  • Where the precise legal role depends on your use case, we will characterise it in the contract rather than claim a single answer here. See our Data Processing Addendum.

5. Why we process data, and on what basis

  • To create and run your account and provide the service — performance of our contract with you.
  • To route, cache and optimize requests and report cost — performance of our contract.
  • To keep the service secure and prevent abuse, fraud and quota misuse — our legitimate interests and, in India, processing for specified lawful uses connected with providing the service you asked for.
  • To improve reliability, using aggregated statistics — our legitimate interests.
  • To provide support and send service messages (sign-in codes, billing and account notices) — contract and legal obligation.
  • To send product updates and marketing — only where you opted in; you may withdraw that consent at any time.
  • Analytics cookies — only where you accept them.
  • To meet tax, accounting and other legal obligations — legal obligation.

6. AI processing

When a request arrives, we check what it actually needs — the model or capability requested, whether attachments, tools, structured output or web search are involved — and select a provider and model that can perform it, based on your configuration, your connected credentials and your entitlements. If nothing compatible is available we return a clear error; we never silently downgrade a request to something the model cannot do, and we do not fabricate a result.

  • Your own keys (BYOK). Your provider credentials are stored encrypted and used only to execute your calls on your own provider account.
  • Managed access. Where your plan includes models we make available, calls run under our provider account and that provider acts as our subprocessor.
  • Failover. Where permitted by your settings, a request may be retried on another compatible provider if the first is unavailable, so a different provider may receive it.
  • Caching and prompt optimization operate only where you enable them, within your organisation.
  • Web search runs on the selected model's own provider-native search mechanism; your query goes to that provider.
  • Measurement. Usage and cost are computed from the token counts the provider reports, multiplied by the model's rates.

Routing is automated, but it affects how your request is served — not your legal rights — and you can constrain or pin it in your settings. We do not disclose our internal scoring logic. Model output is probabilistic: it can be wrong, incomplete or inconsistent between runs, and you should review it before relying on it. ZeroCredit AI does not make autonomous financial, legal, medical, credit or employment decisions about anyone.

7. Who we share data with

  • AI providers — as described above.
  • Infrastructure — managed hosting, database, authentication and email delivery, which process data on our instructions.
  • Payments — Razorpay Software Private Limited, for checkout, cards, UPI, netbanking and refunds.
  • Analytics — Google Analytics 4, only after you accept analytics cookies.
  • Professional advisers — legal, accounting and audit advisers, where needed.
  • Authorities — where required by law, or to establish, exercise or defend legal claims.

Named third parties and what each one processes are listed on our Subprocessors page.

8. International transfers

We do not claim that your data stays in India. Our infrastructure and the AI providers you select may process data in other countries, including the United States and the European Economic Area. Where personal data is transferred across borders we rely on the safeguards required by the law applicable to the transfer, such as contractual protections with the recipient. Under Indian law, transfers are subject to any restrictions the Government notifies from time to time, and we will comply with those as they take effect.

9. Retention

  • Account and workspace data — kept while your account is active, because it is the account.
  • Billing and tax records — kept for the period Indian tax and company law requires, even after an account closes.
  • Request and response content [RETENTION PERIOD TO BE CONFIRMED] Content is retained only for the purposes and the period necessary to provide, secure, operate, troubleshoot and support the service and to comply with legal obligations, subject to your own configuration (for example cache lifetime) and to the selected provider's retention terms. We have not yet fixed and technically enforced a single retention period, so we do not publish a number we could not stand behind.
  • Usage and cost telemetry — kept for your analytics history and for reconciliation and abuse investigation afterwards.
  • Security and audit logs — kept for a limited period for investigation and integrity purposes.
  • Support records — kept while needed to handle your issue and for a reasonable period afterwards.
  • Backups — the database is backed up daily with approximately two weeks of retention. Backups are rotated as a whole and are not individually edited, so deleted data can persist in backups until its backup expires.
  • Legal and compliance records — including records of deletion and privacy requests, kept as long as needed to show we handled them.

When we no longer need personal data we delete or anonymise it. Deleting your account removes or anonymises associated personal data within 30 days of live systems, except where retention is legally required, with backups expiring as above.

10. Your rights and how to exercise them

Subject to the law that applies to you, you can ask us to:

  • tell you what personal data of yours we process, and give you access to it;
  • correct data that is inaccurate, or complete data that is incomplete;
  • delete data we no longer need, or that you gave consent for and have withdrawn;
  • withdraw consent, where processing relies on it — including marketing and analytics cookies;
  • nominate another person to exercise your rights in the event of death or incapacity, where Indian law provides for this;
  • raise a grievance, and escalate it if you are not satisfied.

Much of this is self-service: your dashboard lets you edit your profile, export usage data, clear cached content, revoke API keys and delete your account. For anything else, email support@zerocreditai.com. We aim to respond within 30 days, and we may need to verify your identity first.

If your data reached us through a company using ZeroCredit AI, that company decides why it is processed. We will refer your request to them and help them answer it; contact them first where you can. Nothing here limits your right to complain to the competent data protection or consumer authority.

11. Security

We implement technical and organisational measures including encryption in transit, encrypted storage, encrypted provider credentials, database row-level access controls scoped to your organisation, role-based administrative access, audit logging of privileged actions, and rate limiting. The full description is on our Security Overview, which also states plainly which certifications we do not hold. No system is perfectly secure; where a breach affecting your personal data occurs we will notify you and the competent authorities as the law requires.

12. Cookies and similar technologies

We use strictly necessary cookies and browser storage for sign-in, security and preferences, and Google Analytics 4 only if you accept analytics. We use no advertising cookies. The full list, and the control to change your choice, is in our Cookie Policy.

13. Age and children

ZeroCredit AI is an enterprise product sold to businesses. It is not intended for or marketed to children, and you must be at least 18 and able to enter a contract to hold an account. We do not knowingly create accounts for children. We cannot inspect what your application sends us, so if your use case could involve children's data you are responsible for the additional obligations that applies — including verifiable parental consent where Indian law requires it — and you should not send such data without addressing that first.

14. Changes to this notice

We may update this notice. The effective date, last-updated date and version at the top will change, and we will notify you by email or in the product where changes are material.