ZenCore
Sign inMarketplace

Privacy Policy

How we handle personal data on zencore.solutions.

Privacy Policy

Effective date: July 25, 2026

Zencore AI Ltd ("ZenCore", "we", "us") operates zencore.solutions and related services. This Privacy Policy explains how we collect, use, and protect personal data when you use our website, ZenCore account, waitlist, marketplace, agent deployment, and checkout flows.

Contact: privacy@zencore.solutions

Postal address: 3rd Floor, 86-90 Paul Street, London EC2A 4NE, United Kingdom

1. Who this policy applies to

This policy applies to visitors and registered users of ZenCore, including:

  • Homepage waitlist signups
  • ZenCore account registration (email/password or Google)
  • Marketplace stack subscriptions and agent package flows
  • Agent 01 mint and add-on checkout (wallet connect applies only to Agent 01 products)

2. Data we collect

We may collect:

  • Account data: email address, display name, Supabase user ID, OAuth profile from Google when you choose Google sign-in
  • Waitlist data: name, email, optional wallet address
  • Usage and technical data: IP-derived country (via Cloudflare), browser type, pages visited, referral URLs
  • Payment data: Stripe processes card payments; we receive transaction IDs and billing metadata, not full card numbers
  • Wallet data (Agent 01 only): public wallet address when you connect a wallet for NFT mint or holder-gated add-ons
  • Security data: Cloudflare Turnstile verification tokens during signup and waitlist submission
  • Affiliate data: referral cookies when you arrive via an affiliate link
  • Google Calendar data (ZenCore OS1 only, optional): calendar event details and your Google account email, when you choose to connect Google Calendar — see section 3a

We do not store your account password in plain text. Passwords are hashed and managed by Supabase Auth.

3. How we use your data

We use personal data to:

  • Provide and secure ZenCore accounts and tenant identity
  • Process waitlist signups and send product updates
  • Deploy agents, manage packages, and fulfill marketplace subscriptions
  • Process payments through Stripe
  • Prevent abuse (Turnstile, rate limits)
  • Measure site usage with Google Analytics 4 when permitted by your region and cookie choices
  • Comply with legal obligations and respond to support requests

3a. Google user data (ZenCore OS1 and Google Calendar)

ZenCore OS1 (the OS1 Voice Agent, listed in our marketplace as Agent 03) can optionally connect to your Google Calendar. This connection is off by default and is only created when you click Connect Google Calendar in the ZenCore OS1 setup screen and grant access on Google's consent screen.

Scope we request: https://www.googleapis.com/auth/calendar.events (view and edit events on your calendars).

What we access and why:

  • Reading events — so the agent can tell you what is coming up, remind you before an event starts, and warn you when a new booking clashes with an existing one
  • Creating events — only when you ask the agent to schedule something
  • Deleting events — only when you ask the agent to cancel something
  • Your Google account email — shown in the ZenCore OS1 setup screen so you can confirm which calendar is connected

We do not read Gmail, Drive, contacts, or any other Google data, and we do not request those scopes.

Where tokens are stored: Google OAuth tokens are passed from the ZenCore platform API to your own agent instance and stored there, on the server instance provisioned for your account. They are not shared with other tenants.

Retention and revocation: Disconnecting Google Calendar in the ZenCore OS1 setup screen deletes the stored tokens from your instance. You can also revoke access at any time from your Google Account permissions page. Cached calendar event data on your instance is short-lived and is cleared when you disconnect or when your instance is deleted.

Limited Use: ZenCore's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, use it to train generalized AI or machine-learning models, or allow humans to read it except with your explicit consent, where required for security or to comply with applicable law, or where the data has been aggregated and anonymized and is used solely for internal operations in accordance with applicable privacy and other jurisdictional legal requirements.

4. Legal bases (EEA / UK visitors)

Where GDPR applies, we rely on:

  • Contract — providing services you sign up for (account, checkout, deploy)
  • Consent — analytics cookies in the EEA/UK, waitlist marketing where applicable, optional wallet connect
  • Legitimate interests — security, fraud prevention, and improving our services

You may withdraw analytics consent at any time by rejecting non-essential cookies in our banner (EEA/UK) or clearing site data.

5. Processors and sharing

We use trusted service providers:

  • Supabase — authentication and profile storage
  • Stripe — payments
  • Cloudflare — hosting, CDN, Turnstile, and geo headers
  • Google — OAuth sign-in, Analytics (when enabled), and the Google Calendar API when you connect a calendar to ZenCore OS1
  • Hetzner — platform API and provisioning infrastructure for deployed agents

We do not sell your personal data. We may disclose data if required by law or to protect rights, safety, and security.

6. International transfers

Our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses offered by our processors.

7. Retention

We retain account and billing records while your account is active and as needed for legal, tax, and security purposes. Waitlist entries are kept until you unsubscribe or request deletion. Analytics data retention follows Google's settings.

8. Your rights (EEA / UK)

You may have the right to access, rectify, erase, restrict, object to processing, and data portability. You may lodge a complaint with your local supervisory authority.

To exercise rights, email privacy@zencore.solutions from the address tied to your account.

9. Cookies and similar technologies

Essential cookies — required for authentication sessions and security (for example Supabase session tokens).

Analytics cookies — Google Analytics 4 measures traffic and page views. In the EEA/UK we load analytics only after you accept the cookie banner.

Affiliate cookies — short-lived referral tracking for our affiliate program.

You can control cookies through our banner (EEA/UK) and your browser settings.

10. Children

ZenCore is not directed at children under 16. We do not knowingly collect data from children.

11. Changes

We may update this policy. Material changes will be posted on this page with a revised effective date.

12. Contact

Questions about this policy:

Zencore AI Ltd

3rd Floor, 86-90 Paul Street, London EC2A 4NE, United Kingdom

Email: privacy@zencore.solutions

Privacy Policy·Terms of Use

ZenCore · Powered by PulseChain