Privacy Policy
Last updated: July 13, 2026. This policy describes how AffZero collects, uses, and protects your information.
1. Introduction
AffZero ("we," "our," or "us") is committed to protecting your privacy. AffZero is operated by AffZero LLC, a company registered in Wyoming, United States. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use our affiliate marketing automation platform and related services. By using AffZero, you agree to the practices described in this policy.
2. Information We Collect
We collect the following categories of information:
- Account data: Email address, name, company name, and billing address when you create an account.
- User-configured data: API connections (names, base URLs, API keys), automations (names and workflow configurations), email templates (names, subjects, body content, HTML), and invoice templates (names, HTML content, editable content). All of this data is encrypted before storage.
- Google integration data (optional): OAuth tokens (encrypted), email address, display name, and profile picture—collected only if you choose to connect your Google account for Drive or Gmail. These integrations are entirely optional; the core platform (affiliate tracking API connections and automations) works without them. We do not store Gmail message content or the contents of Google Drive files unless they are rendered outputs generated as part of your automation history.
- Billing and payment data: Subscription plan and billing cycle. Paid billing has not yet launched, so the Service does not currently charge for subscriptions. When paid billing launches, transaction history will be recorded and payments will be processed by Paddle.com Market Limited ("Paddle"), which will act as the Merchant of Record. We will not store full credit card numbers or payment method details ourselves—those will be held by Paddle. See Paddle's privacy policy for how they handle payment information once billing is live.
- Automation and communication data: Automation execution history and step-by-step logs (including data pulled from your connected tracking platforms and content passed between steps, such as inbound email bodies), records of emails sent through automations (sender, recipients, subject, and body), content awaiting your approval before being sent ("Approve to Continue" steps), and inbound webhook payloads used to trigger automations. All of these categories are encrypted at rest — see Section 4.
- Agent Zero (AI agent) data: Chat conversation history and the tool actions Agent Zero performed on your behalf, encrypted at rest. See Section 13 and our Terms of Service §17 for details.
- Uploaded invoice files: PDF or other invoice files you upload are stored in Supabase Storage and protected by our cloud provider's infrastructure-level encryption; parsed/extracted data derived from them is encrypted at the application layer (see Section 4).
- Agent Zero chat attachments: Files you upload to an Agent Zero chat session — CSV, Excel, PDF, Word (.docx), PNG, JPG/JPEG, and WebP — are stored for up to 24 hours. Tabular data extracted from spreadsheets and text extracted from documents are encrypted in our database; the original document or image bytes are stored in a private Supabase Storage bucket and automatically deleted after expiry (or immediately if you delete your account). Images are re-encoded to strip EXIF/GPS metadata before storage or use in AI features. If your uploads contain third-party personal or financial data, you act as the data controller for that data (see Section 14).
- Operational and security data: IP address, browser/user-agent string, and timestamps of account activity — collected for security, fraud prevention, and audit purposes (see Section 12).
We do not store raw statistics from third-party affiliate tracking platforms outside the context described above; such data is processed in-memory during automation runs and, where retained, is limited to the encrypted execution history described above.
3. How We Use Your Information
We use your information to provide, operate, and improve our services; to authenticate you and enforce security; to run automations and integrations you configure; to send transactional emails; and to comply with legal obligations. We do not sell your personal information. When you connect third-party APIs (e.g., affiliate tracking platforms), we act as a conduit only—we do not use that data for purposes beyond executing your configured workflows. We do not use data obtained from Google APIs for advertising, profiling, or resale purposes.
4. Data Security & Encryption
We implement industry-standard security measures to protect your data:
- Encryption at rest: We encrypt sensitive content with AES-256-GCM before writing it to our database. Encrypted categories include: API credentials and automation configurations; email and invoice templates and generated invoice content; Google OAuth tokens; Agent Zero chat history (messages and tool-call records); email send history (sender, recipients, subject, and body); content awaiting send-approval; inbound webhook payloads; automation execution context (data pulled from your connected platforms and passed between automation steps); and report analysis runs (sources, plan, and results). Your account identity data — such as your name, email address, and the personal or company details you configure in your profile — is stored in plaintext, as it is needed for account management and communication. The AES-256-GCM encryption key is stored only in secure environment variables and is never exposed to the browser or included in source code.
- File storage: Uploaded invoice files and Agent Zero chat attachment originals are stored in private Supabase Storage buckets and protected by our cloud infrastructure provider's storage-level encryption at rest. We do not currently apply an additional application-layer encryption to the raw file bytes themselves. Chat attachment objects are automatically deleted after approximately 24 hours.
- Encryption in transit: All traffic is transmitted over HTTPS. API credentials use password-type inputs with autocomplete disabled so browsers cannot autofill or save them.
- Access control: Row Level Security is enabled on every database table. Users can only access data belonging to their organization. All sensitive operations are performed server-side; there are no client-side direct database writes.
- Authentication: We use Supabase Auth (SOC 2-compliant) with asymmetric JWT signing keys. Access tokens expire after 1 hour. Google OAuth tokens are encrypted before storage and never sent to the browser.
5. Third-Party Services
We use the following third-party services to operate our platform:
- Supabase: Database, authentication, and file storage.
- Google APIs: Drive (file-level access via the
drive.filescope), Gmail—used only with your explicit authorization. - Resend: Transactional emails sent on your behalf. We also support sending via a custom SMTP server or your own Gmail account, which you configure and control yourself.
- Anthropic: Powers Agent Zero and other AI features (see Section 13).
- OpenAI: Powers voice-to-text transcription for Agent Zero's voice input.
- Paddle: Payment processing and subscription management once paid billing launches. Paddle will act as the Merchant of Record for all paid transactions and may collect billing details, payment method information, and transaction data in accordance with their own privacy policy.
- Vercel: Hosting and scheduled jobs.
- Google Analytics (GA4): Website analytics to understand how visitors interact with our marketing site. GA4 collects anonymized usage data such as pages visited, session duration, and traffic source. We use Google's Consent Mode—analytics data is only collected after you accept cookies via our banner. See Google's privacy policy for details on their data handling.
When you configure connections to affiliate tracking or stats platforms (e.g., Affise, Binom, Voluum), we act as a conduit to execute your automations. We do not control those platforms' privacy practices; please review their respective policies.
Google API disclosure (required for OAuth verification): Per Google's API Services User Data Policy, your privacy policy and in-product privacy notifications must thoroughly disclose the manner in which your application accesses, uses, stores, or shares Google user data. We comply with this requirement: this policy and our in-product disclosures thoroughly describe how AffZero accesses, uses, stores, and shares Google user data (see Sections 2, 3, 4, and 5).
6. Google User Data & Limited Use Disclosure
Connecting a Google account to AffZero is entirely optional. The core platform—including affiliate tracking API connections and automations—does not require Google access. If you choose to enable Google integrations, we request access to specific Google APIs (Google Drive file-level access and/or Gmail) solely to provide the functionality you explicitly enable.
We access Google user data only as follows:
- Google Drive (
drive.filescope): We access only the specific files that you explicitly select or create through the Google Picker within AffZero. This scope grants access solely to those individual files—we do not scan, index, or access any other files in your Google Drive. We process only user-provided file references and variables/placeholders explicitly configured by you for automations. - Gmail: We use Gmail access only to send emails on your behalf as part of automations you configure. We do not read your inbox, monitor your conversations, or access your contacts unless explicitly required for a feature you enable.
We do not read or index full Google Drive file names or full file contents. For variable-based workflows, we operate on user-provided file references and the specific variables/placeholders configured by you.
We do not delete user Google Drive files or Gmail data. Any file updates are limited to variable insertion or replacement and output generation explicitly configured by you. We apply technical safeguards and limits to data insertion operations.
- We store Google OAuth access and refresh tokens in encrypted form.
- We do not sell, rent, or trade Google user data.
- We do not use Google user data for advertising purposes.
- We do not use Google user data to train artificial intelligence or machine learning models.
- We do not transfer Google user data to third parties except as necessary to provide the service (e.g., secure cloud infrastructure providers).
AffZero's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You may revoke AffZero's access to your Google account at any time by visiting https://myaccount.google.com/permissions. Revoking access will disable related integrations within Aff Zero.
7. Data Retention
We retain your data only as long as necessary:
- Automation execution logs and records: Automatically deleted after 90 days.
- Uploaded invoice files: Automatically deleted after 365 days (both storage files and database records).
- Agent Zero chat sessions: Up to 100 sessions retained per account; older sessions are pruned automatically (oldest first) once the cap is reached.
- Report analysis runs: Up to 25 runs retained per account; older runs are pruned automatically once the cap is reached.
- Account and configuration data (including email send history, approval records, and webhook event records): Retained until you delete your account.
Google OAuth tokens are deleted immediately when you disconnect your Google account or delete your AffZero account.
AffZero does not delete or replace user files in Google Drive or user mailbox data in Gmail. If an automation updates a file, those updates are limited to user-configured variables/placeholders and outputs defined by you.
After you delete your account, we may retain certain information where required by law, to resolve disputes, enforce our agreements, or protect our legitimate interests (for example, billing records and limited audit data), for the period permitted by applicable law.
8. Your Rights
We support your rights under applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA):
- Right to access and portability (GDPR Art. 20): You can download an export of your account and configuration data from Settings → Profile → "Download My Data." The export is a ZIP archive containing a CSV file per data category — profile and organization details, connections, automations, email and invoice templates, execution history and logs, email send history, and uploaded invoice metadata. API keys and Google OAuth tokens are redacted from the export, as they are security credentials rather than personal data. Report analysis runs, Agent Zero chat history, and administrative activity logs are not currently included in this export; contact us if you need these.
- Right to erasure (GDPR Art. 17): You can permanently delete your account from Settings → Profile → "Delete My Account." This deletes your personal data and, if you are the owner of an organization, your organization's shared data (connections, automations, templates, and execution history); other members of that organization are notified and lose access to the shared workspace. If you are not an organization's owner, only your personal data and membership are removed — data shared with the rest of your organization remains intact. Deletion also removes files you own in Storage (e.g., uploaded invoices, Agent Zero chat attachments, and inbound email attachments). This action is irreversible. No admin intervention is required. Limited records may be retained after deletion as described in Section 7.
Both flows are self-service. If you have additional requests or questions about your data, please contact us.
If you are in the EU or EEA, you have the right to lodge a complaint with a supervisory authority in your member state if you believe our processing of your personal data infringes applicable law.
California (CCPA) — Do Not Sell: We do not sell your personal information. We have not sold personal information in the past 12 months and do not intend to sell it in the future.
10. Data Residency & International Transfers
Our primary database and storage are hosted in secure cloud infrastructure in AWS eu-central-1 (Frankfurt). This is the Supabase region used for AffZero.
Our infrastructure may be located outside your country of residence. By using AffZero, you consent to the transfer of your data to these locations. We rely on appropriate safeguards (including Standard Contractual Clauses where applicable) to protect your data in transit and at rest.
11. Data Processing Agreements (DPA)
We use subprocessors (e.g., Supabase) that provide standard Data Processing Agreements. Enterprise customers who require a signed DPA under GDPR Article 28 or equivalent requirements may request one from us. Contact us to obtain our DPA template.
12. Activity & Audit Logs
We maintain audit logs for administrative and security purposes, including the IP address and browser/user-agent string associated with certain account actions. End users do not currently have access to view their own activity history within the app. If you need information about actions taken on your account, please contact us.
We do not manually access user email content or Google Drive file contents unless explicitly requested by you for support purposes.
13. How We Use AI Features
We use AI models to power several features: the AI Extract and AI Analyze automation steps, the "Generate with AI" text and email buttons, Agent Zero (our in-app AI agent), and AI-assisted report analysis.
When you use these features, the following data may be sent to our AI model providers:
- Your automation stats data (affiliate names, conversion IDs, revenue figures, etc.)
- Email content you ask AI to generate or improve
- Chat messages (or transcribed voice input) you send to Agent Zero
- Your name and company name (from your profile) may be used to personalize AI-generated email sign-offs
- When you use the AI Extract step, the full text of the source document or email (up to 60,000 characters) is sent to the AI model so it can extract the fields you configured
- When you use the AI Analyze step, up to 100 full rows of your pulled stats data (not just column headers) are sent to the AI model to generate the requested analysis
- The Describe It assistant may include a list of your recent email recipients as context to help match your request to the right data
- When you upload a file to Agent Zero chat: for CSV or Excel files, only the column headers and a small sample of rows are sent to the model — full rows stay encrypted on our servers; for PDF or Word files, extracted text (up to 60,000 characters) is sent to the model; for images and scanned or image-based PDFs, the file bytes are sent to Anthropic's multimodal/vision models. Images have EXIF/GPS metadata stripped before transmission.
We do not use your data to train AI models. Data sent to AI providers is processed in accordance with their respective API data usage policies. For full details on which AI models power which features and what is never sent, see our Terms of Service §17.
AI usage is tracked per account for billing and quota purposes (calls per month, stored in our database). AI call counts are stored in your account's usage record and reset monthly. We do not store raw AI prompts or responses on our servers beyond what is described in Section 4 (encrypted chat and execution history).
14. Third-Party Websites and Data You Control
Our website may contain links to third-party sites. We do not control those sites and are not responsible for their content or privacy practices. We encourage you to read their policies before providing personal information.
When you connect affiliate tracking platforms, networks, or other third-party services, data about publishers, advertisers, or end users may flow through AffZero as part of automations you configure. For that data, you act as the controller (or equivalent) under applicable law; you are responsible for lawful processing, notices to data subjects, and responding to their rights requests. Individuals who wish to exercise privacy rights regarding data collected by those third parties should contact you or the relevant platform, not AffZero, unless the request relates solely to data we hold about you as our customer.
15. Marketing Communications
We may send you transactional and service-related emails (for example, account notices, security alerts, and billing). With your consent or where permitted by law, we may also send product updates or marketing messages. You can opt out of marketing emails at any time by using the unsubscribe link in those messages or by contacting us. Opting out of marketing does not affect essential service communications.
16. Security and Data Breaches
We implement appropriate technical and organizational measures to protect your personal data. However, no method of transmission over the Internet or electronic storage is completely secure; we cannot guarantee absolute security.
If we become aware of a personal data breach that poses a risk to your rights and freedoms, we will notify you and, where required, the relevant supervisory authority, in accordance with applicable law.
17. Children
Our services are not directed to individuals under 16. We do not knowingly collect personal information from children. If you believe we have collected such information, please contact us and we will delete it promptly.
18. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Your continued use of AffZero after such changes constitutes acceptance of the revised policy.
19. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
AffZero LLC
30 N Gould St, Ste R
Sheridan, WY 82801, United States
You can also reach us through the app or visit our Contact page.