zaat · Privacy
Effective 7 September 2026 · Zaat
The short version
This summary is accurate, and it is not a substitute for the sections below — those are what we are actually held to.
Zaat is both the product and the company behind it. It builds a structured, evidence-backed model of one person — you — from things you tell it and things you choose to connect to it.
On Google’s permission screens the app appears as Your Zaat. That is us.
This policy covers zaat.co and the zaat application. Questions, requests, and complaints: privacy@zaat.co.
Your email address and name, handled by our sign-in provider. If you sign in with Google, that provider receives your name, email address and profile picture from Google — and nothing else. Signing in with Google gives us no access to your mail or your calendar. That is a separate permission you grant separately, described in section 3.
Interview answers, voice notes, journal entries, decisions you log, files you upload, and your responses to what the model says about you. This is the material you volunteer, and it is stored verbatim so that everything the model later claims can be traced back to something you actually said.
If — and only if — you connect a source, we read from it. Today that means Google Calendar and Gmail. Section 3 covers this in detail.
From the above we produce evidence records, claims about you with confidence scores, contradictions between them, predictions, and the history of how each of those changed. This derived layer is personal data too, and everything in this policy applies to it.
Ordinary server logs and error reports. We do not use advertising or cross-site tracking technology, and we do not run analytics that profile you.
Connecting a Google source is always a separate, deliberate act, made after you already have an account. Each source is its own connection, so you may connect your calendar and not your mail, or the reverse, and disconnect either without touching the other.
| Permission | What it lets us do | Why we need it |
|---|---|---|
| calendar.readonly | See the events on your calendars | How you actually spend your hours — what you moved, declined, protected, or let go. |
| gmail.readonly | Read your email | Decisions, commitments and turning points as they were actually written, not as recalled later. |
| userinfo.email | See which Google account this is | So a connection is labelled with the address it belongs to and you can tell two apart. |
Every permission above is read-only. We cannot send email as you, reply, delete, label, or change anything in your mailbox; we cannot create, move, or delete calendar events. This is not a policy we have adopted — it is a capability we never requested, so it is not available to us or to anyone who compromised us.
Before anything from a connected source becomes part of your model, it is scored for whether it says something about you or merely something about the world. A flight confirmation is information; choosing the 6am flight to be back for a recital is evidence. The large majority of connector volume — receipts, newsletters, notifications, “sounds good” — never reaches the model.
zaat’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In concrete terms, and each of these is a commitment we hold ourselves to:
One purpose: to build and maintain a model of you, and to show it to you with its evidence attached. Specifically, we use your data to extract dated pieces of evidence, weigh them, form claims with explicit confidence, surface contradictions, make and score predictions, and let you search your own history.
We also use your email address to send you transactional messages — sign-in codes, and notices about your account.
We do not optimise for your attention. Time spent in the product is not a metric we track or a goal we design toward, and the model’s version number is a function of what it knows, never of how often you visit. A working mirror should sometimes send you away.
Where the UK GDPR or EU GDPR applies, our legal bases are:
Some of what you tell zaat may be sensitive personal data — about health, beliefs, or relationships. Where that is so, we rely on your explicit consent, given by choosing to tell us or to connect a source. You are never required to disclose anything to use the product.
Every column that holds your words is encrypted at rest under a key that belongs only to you. Your interview answers, the excerpts we extract, every claim the model makes, your decisions, your transcripts, and the credential that lets us read a connected source — all of it is ciphertext in the database.
Each user has their own data key. That key is itself encrypted with a master key that is not stored in the database and lives in a separate secret store. The practical consequence is the one that matters: a stolen copy of our database — a leaked backup, an exposed connection string, a support query run against production — yields unreadable noise rather than anyone’s life. Each encrypted value is also bound to the exact person, table, column and row it belongs to, so a value cannot be moved from one person’s record into another’s and still be read.
The application refuses to connect to the database at all if encryption is not configured. We built that refusal after discovering the layer running inert on a misconfiguration, and it is the reason we are willing to make this claim in writing: a safeguard you have to remember is not a safeguard.
Data in transit is encrypted with TLS. No security measure is absolute, and we do not claim otherwise — what we claim is specific and checkable.
An inbox contains other people’s words, and those people did not agree to any of this. We take that seriously, and it produces three hard rules in the software:
If someone else’s data appears in your account and they want it removed, they can write to privacy@zaat.co.
A full export, any time, in an open format — every source, every piece of evidence, every claim with its complete confidence history, your tensions, decisions, predictions and transcripts, decrypted on the way out. No request step, no approval, no queue. It is a link, not a favour.
Deleting starts a 30-day period whose stated purpose is to let you export first, and then everything is destroyed for real, including your encryption key. The order is the argument: take your data, then go. We do not send you anything during that window trying to change your mind — that is the moment a “we’ll miss you” email is most tempting and most dishonest. Cancelling takes one click, needs no reason, and has no conditions.
Disconnecting revokes our access at Google, removes the evidence that source produced, and recalculates every conclusion from what is left. If three of the four reasons behind some belief about you came from your inbox, that belief visibly weakens when the inbox goes. It does not quietly keep the conclusion and lose the receipts. You can also revoke our access directly at myaccount.google.com/permissions.
Every claim ships with the evidence behind it and a way to reject it. Rejecting adds weight against the claim rather than deleting it, and the rejection stays visible in its history — so if your behaviour later contradicts your rejection, the model can say so instead of quietly dropping the matter. That is a feature, and it is the honest way to hold a hypothesis.
Depending on where you live, you have rights to access, correct, delete, port, restrict, and object to the processing of your personal data, and to withdraw consent. Most are self-service above; for anything else, write to us. We answer within 30 days. You may also complain to your data protection authority — in the UK, the Information Commissioner’s Office.
For as long as your account exists, because the whole point is a model that gets better over years — and because a model that cannot show you what it believed a year ago cannot show you that it was wrong. Nothing is silently discarded: superseded claims are retired and kept with their history rather than deleted.
When you delete your account, it goes 30 days later, permanently. When you disconnect a source, what it produced goes at once. Backups roll off within 30 days.
Our providers operate in the United States and Europe, so your data may be processed outside your country. Where required, those transfers are covered by the European Commission’s Standard Contractual Clauses or an equivalent safeguard.
zaat is not a medical device, not a diagnostic tool, and not a substitute for a doctor, therapist, or any other professional. It produces hypotheses about a person, held with explicit confidence and open to challenge — not findings, and not advice.
If you are in crisis, please contact a local emergency service or a crisis line. Nothing in this product is designed for that, and we would rather say so plainly.
zaat is for adults. It is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has an account, tell us and we will remove it.
If we change this policy in a way that materially affects you, we will tell you by email before it takes effect — not by quietly moving the date at the top. Every version carries its effective date.
privacy@zaat.co reaches a person. Privacy requests, questions about anything above, or a challenge to something we have said here — all welcome at the same address.
Our terms of service cover the rest of the relationship.