This Privacy Policy describes how Zephyr Cloud Inc. ("Zephyr Cloud," "we," "us," or "our") collects, uses, discloses, and protects personal information in connection with Labor0 websites, applications, hosted execution, AI-assisted engineering workflows, support, and related services (collectively, the "Services"). "Personal information" means information that identifies, relates to, describes, or could reasonably be linked to an individual or household. It does not include information that applicable law excludes from that definition, such as properly deidentified information.
1. Scope and roles
This Policy applies when Zephyr Cloud determines why and how personal information is processed through the Services. If you use Labor0 through an employer, customer, or other organization (an "Organization"), that Organization may control your account and Customer Content and may have its own privacy notice. For personal information in Customer Content that we process on an Organization's behalf, the Organization is generally the controller or business and Zephyr Cloud is generally its processor or service provider. Direct requests about Organization-controlled data should first be sent to the relevant Organization.
This Policy does not apply to third-party websites, model providers, repositories, tools, or other services that have their own privacy notices, even when they connect to Labor0.
2. Information we collect
We may collect the following categories of information:
- Account and identity information, such as name, email address, authentication identifiers, profile details, Organization membership, roles, and permissions.
- Professional and Organization information, such as employer, job title, team, workspace, project, and repository associations.
- Customer Content, such as prompts, instructions, source code, files, tasks, comments, knowledge, tool inputs and results, terminal or execution output, pull-request information, and other material submitted to or generated through the Services.
- Connection and integration information, such as provider choices, repository and tool metadata, OAuth grants and scopes, authorization decisions, configuration, and events needed to operate requested connections. We do not display secret credentials in this Policy, and we use credential material only to provide and secure the relevant connection.
- Billing and transaction information, such as plan, metered usage, usage charges, billing contact, invoices, payment status, tax information, and limited payment-method details. Payment card numbers are handled by payment processors rather than stored by us in full.
- Usage, device, and diagnostic information, such as IP address, approximate location inferred from IP, browser and device type, operating system, app version, pages and features used, request and session timestamps, performance events, error reports, security events, and audit records.
- Communications, such as support requests, feedback, survey responses, security reports, and related attachments.
Please do not submit sensitive or regulated information unless your Organization has determined that it is lawful and appropriate to process that information through the Services and has configured the relevant providers, connections, and controls accordingly.
3. Sources of information
We collect information:
- directly from you when you create an account, configure a workspace, submit Customer Content, purchase Services, or contact us;
- from your Organization and its administrators, including account, role, workspace, and access information;
- automatically from your browser, device, applications, and use of the Services;
- from repositories, AI model providers, collaboration tools, identity providers, payment providers, and other services that you or your Organization choose to connect; and
- from service providers, security partners, and lawful public sources, for example to prevent fraud, secure the Services, or verify business information.
4. How we use information
We use personal information to:
- provide, operate, maintain, and support the Services;
- authenticate users and administer accounts, Organizations, workspaces, projects, roles, permissions, and connected services;
- receive requests, build engineering context, route AI requests, execute authorized workflows, call selected tools, and return results;
- process subscriptions, usage-based charges, included allowances, invoices, taxes, and payments;
- monitor reliability, debug failures, measure performance and feature usage, and improve the safety and quality of the Services;
- detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service;
- communicate with you about transactions, support, security, service changes, and, where permitted, products or events;
- comply with law, enforce agreements, establish or defend legal claims, and protect users, Zephyr Cloud, and others; and
- create aggregated or deidentified information that cannot reasonably identify you, which we may use for lawful purposes.
5. AI and connected services
Labor0 may send prompts, source code, files, tool results, metadata, and other Customer Content to AI model providers, repositories, tools, or integrations selected or authorized by you or your Organization. Those third parties process information under their own terms, privacy notices, enterprise agreements, retention settings, and security commitments. Organization administrators are responsible for selecting providers and configuring permissions, data controls, and connections appropriate for their users and content.
We do not use Customer Content to train, improve, or develop artificial intelligence models or algorithms without the customer's express written consent. This restriction applies to Zephyr Cloud's own model-training activity; a third-party provider selected by you or your Organization may have separate terms and data-use settings that the Organization must evaluate.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use Customer Content for targeted advertising.
6. How we disclose information
We may disclose personal information to the following categories of recipients for the purposes described in this Policy:
- service providers and contractors that host, secure, analyze, support, bill for, or otherwise operate the Services;
- AI model providers, repositories, tools, and integrations selected or authorized by you or your Organization;
- your Organization's owners, administrators, members, and authorized collaborators according to workspace settings and permissions;
- payment processors, tax providers, and billing systems;
- professional advisors, auditors, insurers, financing sources, and corporate transaction counterparties subject to appropriate confidentiality restrictions;
- courts, regulators, law enforcement, and other parties when we reasonably believe disclosure is required by law or necessary to protect rights, safety, and security;
- a successor or prospective successor in connection with a merger, financing, reorganization, bankruptcy, sale of assets, or similar transaction; and
- other parties at your direction or with your consent.
We may disclose aggregated or deidentified information that cannot reasonably identify you, subject to applicable law.
7. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy. Retention depends on the type of information, the duration of the account or customer relationship, workspace and provider settings, contractual commitments, the need to provide or secure the Services, legal and accounting obligations, dispute resolution, and enforcement needs.
Organizations may be able to export or delete certain Customer Content. After deletion or account closure, limited information may remain in backups, security logs, billing records, or legal records until it is safely overwritten or no longer needed. We may retain deidentified information when it cannot reasonably be used to identify an individual.
8. Security
We use reasonable administrative, technical, and physical safeguards designed to protect personal information. No system or transmission method is completely secure, and we cannot guarantee absolute security. You and your Organization are responsible for protecting account credentials, API keys, repository permissions, provider settings, connected tools, and devices under your control. If you believe an account or connection has been compromised, contact us promptly.
9. Cookies and tracking technologies
We may use cookies, local storage, pixels, and similar technologies to authenticate users, secure sessions, remember preferences, understand use of the Services, measure site performance, and diagnose problems. Some technologies are set by service providers that support hosting, authentication, security, customer support, or analytics. Those providers may collect information about interactions with the Services over time and, depending on the provider, across websites or applications, subject to their own privacy notices and our contractual controls. We do not authorize those providers to use Customer Content or Services activity for cross-context behavioral advertising.
You can control cookies through browser or device settings, but blocking essential technologies may prevent parts of the Services from working. Because there is no uniform standard for browser "Do Not Track" signals, the Services do not currently respond differently to those signals. We do not sell or share personal information for cross-context behavioral advertising, so a Global Privacy Control signal does not change those practices; where applicable law requires a signal to be treated as a request, we will honor it.
10. Privacy rights and choices
Depending on your location and applicable law, you may have the right to request access to, correction of, deletion of, or portability of personal information; to object to or restrict certain processing; to withdraw consent; or to appeal a privacy-request decision. You may also opt out of marketing emails by using the unsubscribe link in the message. You will continue to receive necessary transactional, account, and security communications.
To submit a request, email legal@theaiplatform.app. Describe your request and the account or Organization involved. We may verify your identity, account, residence, and authority before acting. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and identity. We will not discriminate against you for exercising applicable privacy rights. Some rights are subject to exceptions, and Organization-controlled data requests may be referred to the relevant Organization.
11. California privacy notice
This section supplements the rest of this Policy for California residents. In the preceding 12 months, we may have collected the following statutory categories of personal information: identifiers; customer records information; commercial information; internet or other electronic network activity; approximate geolocation; professional or employment-related information; inferences based on Services activity; and sensitive personal information limited to account credentials and information a user chooses to include in Customer Content. We do not use or disclose sensitive personal information to infer characteristics about an individual.
We collect these categories from the sources in Section 3, use them for the business and commercial purposes in Sections 4 and 5, and disclose them to the recipient categories in Section 6. We retain them according to the criteria in Section 7.
California residents may have rights to know the categories and specific pieces of personal information we collected; request deletion or correction; receive information about sources, purposes, and recipient categories; opt out of sale or sharing; limit certain uses of sensitive personal information; and receive equal service and pricing when exercising their rights. We do not sell personal information or share personal information for cross-context behavioral advertising, including personal information of consumers under 16. We therefore do not offer a sale or sharing opt-out link. Submit other California requests using the process in Section 10.
California's "Shine the Light" law may allow residents to request information about disclosure of personal information to third parties for their own direct marketing. We do not disclose personal information to third parties for their own direct marketing purposes.
12. European Economic Area, United Kingdom, and Switzerland
Zephyr Cloud Inc. is the controller for personal information processed for its own purposes under this Policy. Our legal bases depend on the context and may include:
- performance of a contract, including providing the Services you or your Organization requested;
- our legitimate interests in operating, securing, supporting, and improving the Services, communicating with customers, and preventing abuse, where those interests are not overridden by your rights;
- your consent, for processing where consent is requested, which you may withdraw at any time; and
- compliance with legal obligations and protection of legal rights.
Subject to applicable law, you may request access, correction, erasure, portability, restriction, or objection, and may withdraw consent. You may also lodge a complaint with your local data protection authority. Where Zephyr Cloud processes personal information solely on behalf of an Organization, please direct your request to that Organization first.
13. International transfers
Zephyr Cloud and its service providers may process personal information in the United States and other countries that may have different data-protection laws from your country. Where required, we use appropriate safeguards for international transfers, such as contractual protections approved by relevant authorities, and provide additional information about those safeguards on request.
14. Children
The Services are for business users who are at least 18 years old and are not directed to children. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided personal information to us, contact us so we can investigate and take appropriate action.
15. Changes to this Policy
We may update this Policy prospectively. The effective date at the top identifies when the current version applies. If a change is material, we will take reasonable steps to provide notice, such as posting the updated Policy, displaying an in-product notice, or sending an email. We will obtain consent when applicable law requires consent rather than notice.
16. Contact us
For privacy questions or requests, contact:
Zephyr Cloud Inc.
1201 W Peachtree St NW, Ste 2625 PMB 308683
Atlanta, GA 30309, US
Email: legal@theaiplatform.app