Zover privacy policy
Effective date: 14 July 2026.
Zover is a context layer for professional operators (agencies, consultants, portfolio operators): it syncs the client sources an operator explicitly connects and serves that content back to the operator's own AI tools as grounded, cited context. This policy explains what we process, how, and your choices. Plain language on purpose.
Who is responsible for what
Two roles apply under the GDPR, and they matter for your rights below.
- Zover is the controller for operator account data (your email, login, usage telemetry): we decide how it is processed.
- Zover is a processor for connected client context: the operator who connects a source is the controller of any personal data inside it, and we process it only to provide the service to that operator.
Data we process
- Account data: your email address and login credentials (managed by our authentication provider, Supabase).
- Connected client context: the content of sources you explicitly connect, per client brain: Google Drive folders, Gmail labels or searches, Notion pages and databases. Access is read-only. We never write into your tools.
- Usage telemetry: queries your AI tools send to your brains (hashed by default), retrieval quality signals, and a per-client audit log of every context access.
Google user data
If you connect Google Drive or Gmail, Zover requests read-only access (drive.readonly, gmail.readonly) via Google OAuth, scoped by you at connect time to specific folders, labels, or searches.
- What we access: only the folders you pick (Drive) and the labels or searches you define (Gmail). Spam and trash are always excluded. Attachments are not ingested.
- What we use it for: indexing that content into the one client brain you connected it to, so your own AI tools can retrieve it with citations. Nothing else.
- Where it lives: content is stored encrypted at rest in the EU (eu-central-1, Supabase). Your Google OAuth tokens are stored encrypted in Supabase Vault and are only ever used to perform the read-only sync you configured.
- What we never do: we do not sell Google user data, do not use it for advertising, do not use it to train AI or machine-learning models, and no human at Zover reads it except with your explicit consent for support, for security investigation, or where the law requires it.
- Deletion: disconnecting a Google account or removing a folder or label removes its synced content from the brain. You can also revoke Zover's access at any time in your Google account security settings, which cuts off all further reads.
Zover's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Sub-processors
Zover runs on Supabase (database and authentication, EU) and Vercel (application hosting; compute in the EU region, with a global CDN edge serving static assets only). Two named AI sub-processors handle retrieval steps in transit: Cloudflare Workers AI (text embedding) and Voyage AI (relevance reranking). They process query text and retrieved fragment text to perform each retrieval and are not EU-hosted. Per Cloudflare's published terms, Cloudflare does not train on these inputs and does not share them across customers. We have opted out of Voyage AI's data training and retention program: content sent to Voyage is deleted immediately after processing (zero-day retention) and is not used to train models.
One analytics sub-processor: PostHog (EU cloud, hosted in Frankfurt) receives product usage measurements so we can improve the product. This is a different category from the retrieval processors above: PostHog never receives your clients' content, your documents, your queries, or anything derived from connected sources such as Google Drive or Gmail. It receives behavioral events only (for example "a source was connected" or "a query was answered, grounded: yes"), identified by a random account identifier, never by name or email. The authenticated workspace runs no third-party analytics scripts at all, and no session recordings or heatmaps are used. On public pages, analytics run cookieless: nothing is stored on your device, on the legal basis of legitimate interest. A data processing agreement (GDPR Art. 28) is in place with PostHog.
Security
Every client brain is isolated at the database layer with enforced row-level security; cross-client isolation is covered by automated tests. Credentials are stored encrypted, never in code or logs. Every context access is written to a per-client audit log you can review.
Your rights
For operator account data (where Zover is the controller): you can request access to, correction of, or deletion of your data by contacting us; we respond within 30 days. Disconnecting sources and deleting brains are self-service.
For personal data inside a connected client brain (where Zover is a processor): please direct your request to the operator who connected the source; they are the controller for that data. We support operators in fulfilling such requests, including deletion, which cascades through everything synced from a source.
Contact
Zover · privacy@zover.app
Changes
If this policy changes materially we will note it here with a new effective date and inform active operators by email.