zaatGet early access

zaat · Privacy

Privacy

Effective 7 September 2026 · Zaat

The short version

  • Everything you tell zaat, and everything it concludes, is encrypted with a key that belongs only to you. A stolen database is unreadable noise.
  • Signing in with Google gives us nothing but your name and email. Reading your mail or calendar is a separate permission, granted separately, and revocable on its own.
  • Anything we read is read-only. We cannot send, change, or delete anything in your Google account — not because we promise not to, but because we never asked for the ability.
  • We never sell your data, never use it for ads, and never use it to train AI models.
  • You can export everything at any moment and delete your account for real. The 30 days before deletion exist so you can take your data first.

This summary is accurate, and it is not a substitute for the sections below — those are what we are actually held to.

  1. 1.Who we are
  2. 2.What we collect
  3. 3.Google data: exactly what we ask for and why
  4. 4.How we use it
  5. 5.Why we are allowed to (legal bases)
  6. 6.How it is stored and protected
  7. 7.Who else touches it
  8. 8.Other people in your data
  9. 9.What you can do about it
  10. 10.How long we keep it
  11. 11.Where it goes
  12. 12.What this is not
  13. 13.Age
  14. 14.Changes to this policy
  15. 15.Contact

1Who we are

Zaat is both the product and the company behind it. It builds a structured, evidence-backed model of one person — you — from things you tell it and things you choose to connect to it.

On Google’s permission screens the app appears as Your Zaat. That is us.

This policy covers zaat.co and the zaat application. Questions, requests, and complaints: privacy@zaat.co.

2What we collect

Your account

Your email address and name, handled by our sign-in provider. If you sign in with Google, that provider receives your name, email address and profile picture from Google — and nothing else. Signing in with Google gives us no access to your mail or your calendar. That is a separate permission you grant separately, described in section 3.

What you tell us

Interview answers, voice notes, journal entries, decisions you log, files you upload, and your responses to what the model says about you. This is the material you volunteer, and it is stored verbatim so that everything the model later claims can be traced back to something you actually said.

What you connect

If — and only if — you connect a source, we read from it. Today that means Google Calendar and Gmail. Section 3 covers this in detail.

What we derive

From the above we produce evidence records, claims about you with confidence scores, contradictions between them, predictions, and the history of how each of those changed. This derived layer is personal data too, and everything in this policy applies to it.

Technical data

Ordinary server logs and error reports. We do not use advertising or cross-site tracking technology, and we do not run analytics that profile you.

3Google data: exactly what we ask for and why

Connecting a Google source is always a separate, deliberate act, made after you already have an account. Each source is its own connection, so you may connect your calendar and not your mail, or the reverse, and disconnect either without touching the other.

PermissionWhat it lets us doWhy we need it
calendar.readonlySee the events on your calendarsHow you actually spend your hours — what you moved, declined, protected, or let go.
gmail.readonlyRead your emailDecisions, commitments and turning points as they were actually written, not as recalled later.
userinfo.emailSee which Google account this isSo a connection is labelled with the address it belongs to and you can tell two apart.

Read-only, and not by promise

Every permission above is read-only. We cannot send email as you, reply, delete, label, or change anything in your mailbox; we cannot create, move, or delete calendar events. This is not a policy we have adopted — it is a capability we never requested, so it is not available to us or to anyone who compromised us.

Most of what we read is discarded from the model

Before anything from a connected source becomes part of your model, it is scored for whether it says something about you or merely something about the world. A flight confirmation is information; choosing the 6am flight to be back for a recital is evidence. The large majority of connector volume — receipts, newsletters, notifications, “sounds good” — never reaches the model.

Limited Use

zaat’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In concrete terms, and each of these is a commitment we hold ourselves to:

  • We use Google data only to provide the features you can see in the product — your memory, your map, and the model’s claims about you.
  • We do not sell it, and we do not transfer it to anyone except the service providers listed in section 6, who act on our instructions.
  • We do not use it for advertising of any kind.
  • We do not use it to develop, train, or improve general-purpose AI or machine-learning models. Your data is processed by models to produce your results; it is never training material, ours or anyone else’s. The providers who process it do so under zero-retention, no-training terms.
  • Humans do not read your Google data. The exceptions are narrow and standard: with your explicit permission for a specific item, where necessary for security, or where the law requires it.

4How we use it

One purpose: to build and maintain a model of you, and to show it to you with its evidence attached. Specifically, we use your data to extract dated pieces of evidence, weigh them, form claims with explicit confidence, surface contradictions, make and score predictions, and let you search your own history.

We also use your email address to send you transactional messages — sign-in codes, and notices about your account.

We do not optimise for your attention. Time spent in the product is not a metric we track or a goal we design toward, and the model’s version number is a function of what it knows, never of how often you visit. A working mirror should sometimes send you away.

5Why we are allowed to (legal bases)

Where the UK GDPR or EU GDPR applies, our legal bases are:

  • Contract — to provide the service you signed up for: your account, your model, and the features you use.
  • Consent — for each connected source. Consent is given per source, and you can withdraw it at any time by disconnecting that source, which also removes what it produced (section 7).
  • Legitimate interests — keeping the service secure and working, and communicating with you about your account.

Some of what you tell zaat may be sensitive personal data — about health, beliefs, or relationships. Where that is so, we rely on your explicit consent, given by choosing to tell us or to connect a source. You are never required to disclose anything to use the product.

6How it is stored and protected

Every column that holds your words is encrypted at rest under a key that belongs only to you. Your interview answers, the excerpts we extract, every claim the model makes, your decisions, your transcripts, and the credential that lets us read a connected source — all of it is ciphertext in the database.

Each user has their own data key. That key is itself encrypted with a master key that is not stored in the database and lives in a separate secret store. The practical consequence is the one that matters: a stolen copy of our database — a leaked backup, an exposed connection string, a support query run against production — yields unreadable noise rather than anyone’s life. Each encrypted value is also bound to the exact person, table, column and row it belongs to, so a value cannot be moved from one person’s record into another’s and still be read.

The application refuses to connect to the database at all if encryption is not configured. We built that refusal after discovering the layer running inert on a misconfiguration, and it is the reason we are willing to make this claim in writing: a safeguard you have to remember is not a safeguard.

Data in transit is encrypted with TLS. No security measure is absolute, and we do not claim otherwise — what we claim is specific and checkable.

7Who else touches it

We do not sell your data, ever, to anyone. We do not share it with advertisers, data brokers, or model trainers. The only third parties involved are the service providers below, who process data on our instructions and for no purpose of their own.

ProviderRoleWhat they hold
NeonDatabase hostingEverything, encrypted — the columns holding your words are ciphertext to them.
VercelApplication hostingProcesses requests in memory. Stores no user content.
ClerkSign-in and account identityYour email address and name. No model content, no connected-source content.
AnthropicExtraction and synthesisExcerpts of your text at the moment of processing, under zero-retention terms.
OpenAIEmbeddings for searchExcerpts at the moment of processing, under zero-retention terms.
InngestBackground job schedulingJob names and record identifiers. No content.
ResendTransactional emailYour email address and the text of messages we send you.

Notably absent: any broker in the path when you connect a Google account. We run that connection ourselves, so the permission screen says our name and no other company holds the key. We considered using a third-party service for it and decided against it precisely because of what this product is.

We may disclose data if the law compels us to, or to protect the rights and safety of people. If we are ever acquired, this policy travels with your data, and you will be told before anything changes.

8Other people in your data

An inbox contains other people’s words, and those people did not agree to any of this. We take that seriously, and it produces three hard rules in the software:

  • Their words are treated as evidence about you — never as the beginning of a model of them.
  • We never present a claim about a sender. The model has opinions about one person, and it is the person who asked for it.
  • Their content is never exposed to any third-party application through our API.

If someone else’s data appears in your account and they want it removed, they can write to privacy@zaat.co.

9What you can do about it

Take everything with you

A full export, any time, in an open format — every source, every piece of evidence, every claim with its complete confidence history, your tensions, decisions, predictions and transcripts, decrypted on the way out. No request step, no approval, no queue. It is a link, not a favour.

Delete your account

Deleting starts a 30-day period whose stated purpose is to let you export first, and then everything is destroyed for real, including your encryption key. The order is the argument: take your data, then go. We do not send you anything during that window trying to change your mind — that is the moment a “we’ll miss you” email is most tempting and most dishonest. Cancelling takes one click, needs no reason, and has no conditions.

Disconnect one source

Disconnecting revokes our access at Google, removes the evidence that source produced, and recalculates every conclusion from what is left. If three of the four reasons behind some belief about you came from your inbox, that belief visibly weakens when the inbox goes. It does not quietly keep the conclusion and lose the receipts. You can also revoke our access directly at myaccount.google.com/permissions.

Argue with it

Every claim ships with the evidence behind it and a way to reject it. Rejecting adds weight against the claim rather than deleting it, and the rejection stays visible in its history — so if your behaviour later contradicts your rejection, the model can say so instead of quietly dropping the matter. That is a feature, and it is the honest way to hold a hypothesis.

Your legal rights

Depending on where you live, you have rights to access, correct, delete, port, restrict, and object to the processing of your personal data, and to withdraw consent. Most are self-service above; for anything else, write to us. We answer within 30 days. You may also complain to your data protection authority — in the UK, the Information Commissioner’s Office.

10How long we keep it

For as long as your account exists, because the whole point is a model that gets better over years — and because a model that cannot show you what it believed a year ago cannot show you that it was wrong. Nothing is silently discarded: superseded claims are retired and kept with their history rather than deleted.

When you delete your account, it goes 30 days later, permanently. When you disconnect a source, what it produced goes at once. Backups roll off within 30 days.

11Where it goes

Our providers operate in the United States and Europe, so your data may be processed outside your country. Where required, those transfers are covered by the European Commission’s Standard Contractual Clauses or an equivalent safeguard.

12What this is not

zaat is not a medical device, not a diagnostic tool, and not a substitute for a doctor, therapist, or any other professional. It produces hypotheses about a person, held with explicit confidence and open to challenge — not findings, and not advice.

If you are in crisis, please contact a local emergency service or a crisis line. Nothing in this product is designed for that, and we would rather say so plainly.

13Age

zaat is for adults. It is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has an account, tell us and we will remove it.

14Changes to this policy

If we change this policy in a way that materially affects you, we will tell you by email before it takes effect — not by quietly moving the date at the top. Every version carries its effective date.

15Contact

privacy@zaat.co reaches a person. Privacy requests, questions about anything above, or a challenge to something we have said here — all welcome at the same address.

Our terms of service cover the rest of the relationship.

zaat · ذات · the self

Terms of service Home