ZanaPrivacy
How Zana handles your data.
This notice covers Zana's current pilot and beta surfaces, including Zana STR and Zana Life. What Zana processes depends on the feature you use, the permissions you enable, and the processing path that feature actually requires.
Last updated: September 15, 2026
Zana is still in pilot and beta development and is not yet authorized for general live-private-data production use. Exact processors, retention periods, deletion behavior, and feature-specific notices may differ by workflow and may be supplemented by a written pilot or customer agreement.
1. Scope And Current Status
This notice describes Zana's current privacy approach for public access, pilots, beta features, and connected workflows. A feature being visible on the website or available in a demo does not mean every private-data workflow has been approved for general production use.
2. Information Zana May Process
Depending on the product and permissions you choose, Zana may process account and contact information, workspace and property information, messages, calendar events, documents, task and checklist data, travel details, evidence or photos, conversation records captured with appropriate permission, preferences you provide, connected-source metadata, session data, support communications, and technical or diagnostic information.
Do not place passwords, private keys, authentication secrets, payment-card data, or similar credentials into ordinary Zana text, memory, or AI fields.
3. Why Zana Uses Information
Zana uses information to provide the feature or workflow you request, authenticate and secure access, maintain relevant context, coordinate work, generate summaries or recommendations, operate connected services you authorize, troubleshoot the service, respond to support requests, and improve reliability and usability within the permissions and data-use boundaries that apply.
4. AI, Local Processing, And Cloud Processing
Some Zana features may use deterministic software, local models, hosted models, or approved external AI services. Zana describes processing as local only when the relevant implementation is technically proven to run locally.
Private or sensitive context is not automatically eligible for external AI processing. Where an external path is used, the information released should be limited to what the task requires and the exact deployment must satisfy the applicable privacy and data-use requirements. Zana does not promise that every request stays on your device.
Zana policy does not authorize private customer or pilot content to train a public or shared Zana model. See AI & Data for more detail about the current processing boundaries.
5. Connected Accounts And Third-Party Sources
Connections such as email or calendar are optional unless a workflow clearly says otherwise. Zana should request only the permissions needed for the feature you choose, and you can disconnect optional integrations subject to the provider's controls and any data that has already been lawfully retained.
You are responsible for having the rights, permissions, consents, or other lawful basis needed to provide information about other people, properties, workers, guests, household members, or counterparties.
6. Sharing And Disclosure
Zana may disclose data to authorized workspace participants, processors and service providers needed to operate the feature you requested, or authorities when disclosure is legally required. Zana does not authorize selling personal data as a standalone product.
Private personal context does not become shared workspace or community context merely because another person, organization, or sponsor pays for or participates in a Zana workflow. A separate authorized sharing path is required where private information is meant to cross that boundary.
7. Security And Operator Access
Zana uses safeguards appropriate to the feature, such as authentication, scoped access, restricted credentials, tenant or principal boundaries, and encrypted network transport where implemented. Security controls continue to evolve as the product is hardened.
Access to private content should be limited to what is necessary to operate, secure, or support the service. Zana does not claim that founder, administrator, or service-provider access is technically impossible, and broader production use remains gated until the relevant access and isolation controls are proven.
8. Retention, Correction, And Deletion
Retention depends on the type of data, the feature, security and audit needs, pilot requirements, and the processors involved. Zana does not currently promise one universal deletion deadline across application databases, backups, logs, connected services, and external processors.
You may request correction or deletion through the Zana contact channel or the email thread associated with your pilot or access invitation. Some information may need to be retained for security, legal, fraud-prevention, audit, or dispute purposes where permitted by law.
9. Your Choices
Where applicable, you may ask to access, correct, export, restrict, or delete personal data associated with your Zana use. You can also decline optional data collection or disconnect optional integrations. The rights available to you depend on applicable law and Zana's role in processing the data.
10. Cookies And Browser Storage
Zana may use essential browser storage and cookies for functions such as authentication, session continuity, consent state, and product operation. Non-essential analytics or similar technologies should be used only where disclosed and permitted. Removing browser storage may sign you out or reset preferences.
11. Age Eligibility
Current Zana pilots are intended for adults age 18 or older. Zana does not currently approve under-18 pilot use without a separate legal and product review.
12. Changes And Contact
Zana may update this notice as the product, processors, and controls change. Material changes should be reflected by a new update date and, where required, additional notice. For privacy questions or requests, use the Zana contact page or the email thread associated with your workspace, pilot, or access invitation.
Privacy Principle
Use the minimum data the job needs.
Zana's privacy approach is to keep data and authority bounded to the purpose of the workflow, and to avoid stronger claims than the deployed controls can prove.