Privacy Policy
Last updated 27 August 2026
1Who is responsible
ZorQelis AI is the data fiduciary (under India’s Digital Personal Data Protection Act, 2023) and the data controller (under the UK and EU GDPR) for the personal data described here. Contact: privacy@zorqelisai.com.
2What we collect
- Account data. Your email address, a display name if you give one, a password hash if you set a password, and the Google account identifier if you sign in with Google. We never receive your Google password.
- Conversations. On the chat service, the messages you send and the replies you receive, so that a conversation persists between visits. Incognito chats are not stored.
- Files and images you attach, for as long as they are attached to a conversation or a document you uploaded.
- API metadata. For each API request: the key used, the model, token counts, latency and cost. Not the request body or the response — those are processed to answer you and not retained.
- Billing records. What you bought, when, how much and whether it succeeded. Card details are handled by our payment processor and never reach us.
- Technical logs. IP address, user agent, timestamps and error traces, kept to operate and secure the service.
3Why we use it, and on what basis
- To provide the service you asked for — performing our contract with you.
- To bill you accurately and keep the records tax law requires — contract and legal obligation.
- To detect and stop abuse, fraud and attacks on the service — our legitimate interest in keeping it running and safe for everyone.
- To reply when you contact us — contract and legitimate interest.
- To send transactional email such as sign-in codes and payment receipts — contract. We do not send marketing email without asking first.
4What we do not do
- We do not train models on your prompts, files or API requests.
- We do not sell personal data, and we do not share it with advertisers or data brokers.
- We do not use your conversations to build profiles of you for targeting.
- We do not read your conversations except where you report a problem and give us the specific exchange, or where an automated abuse signal requires a narrow, logged review.
5How long we keep it
- Conversations — until you delete them, or the retention period of your plan expires, whichever is first. Deleting a conversation removes it from the database rather than hiding it.
- API request and response bodies — not stored. They exist in memory long enough to produce your answer.
- API usage records — kept while the account is open, because they are the account of what you were charged.
- Billing records — kept for as long as tax and accounting law requires, typically eight years in India.
- Technical logs — 30 days, except where a specific entry is retained for an ongoing security investigation.
- Account data — until you close the account, then deleted within 30 days apart from what we must keep for the reasons above.
6Who else processes it
We use a small number of processors, each bound by contract to use the data only to provide their service to us:
- A cloud host, for the servers and database that run the service.
- GPU providers, which execute model requests. They receive the content of a request for the moment it is being answered and do not retain it.
- A payment processor, which handles card details we never see.
- An email provider, for sign-in codes and receipts.
- A web search provider, only when you turn search on for a message, and only the search query.
Some of these operate outside India. Where personal data is transferred abroad, we rely on the safeguards those transfers require, including standard contractual clauses where applicable.
We may also disclose data where the law compels it. Where we are permitted to tell you about such a demand, we will.
7Your rights
You can ask us to: give you a copy of your data; correct it; delete it; restrict or object to a particular use; or provide it in a portable form. You can also withdraw consent where consent is what we relied on, and complain to a supervisory authority — in India, the Data Protection Board.
Much of this is self-service: conversations can be deleted in the app, API keys revoked in the console, and the account closed from settings. For anything else, write to privacy@zorqelisai.com and we will respond within 30 days.
8Security
- Everything is served over TLS. Passwords are stored as scrypt hashes, never in plaintext.
- API keys are stored as SHA-256 hashes only. A key is displayed once, at creation, and cannot be recovered afterwards — including by us.
- Sign-in from an unrecognised device requires a code sent to your email as well as your password.
- Access to production data is limited to those who need it, and secrets are never sent to a browser — a build-time check fails the deployment if one would be.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the Data Protection Board as the law requires.
9Children
The service is not for people under 18, we do not knowingly collect their data, and we will delete an account we learn belongs to a child.
10Cookies
We set cookies only to keep you signed in and to remember interface preferences such as your theme. There are no advertising or third-party analytics cookies, so there is no consent banner to dismiss.
11Changes
We will announce material changes at least 30 days before they take effect. The date at the top of this page always reflects the current version.