Privacy Policy
How The AI Platform and Miniapp SDK ecosystem process and protect personal information across apps, workspaces, hosts, publication, and marketplace workflows.
Effective July 15, 2026
Overview
This Privacy Policy explains how Zephyr Cloud Inc. collects, uses, discloses, and protects personal information when you use The AI Platform website, apps, hosted services, workspaces, model routing, specialists, mini apps, the @theaiplatform/miniapp-sdk package (the "Miniapp SDK"), miniapp hosts, developer and publication tools, marketplace features, and related services.
Customer workspace content belongs to the customer. We process it to provide the services, keep them reliable, support requested integrations, and comply with applicable law.
Information we collect
We collect information you provide, information generated by use of the services, and information from connected services.
- Account information, such as name, email, authentication identifiers, profile details, and organization membership.
- Workspace content, such as messages, prompts, files, specialist instructions, mini apps, tool results, comments, tasks, and shared knowledge.
- Provider and integration information, such as selected models, provider configuration, OAuth grants, connected tools, and metadata needed to operate integrations.
- Billing information, such as plan, invoices, payment status, tax metadata, and billing contact details. Payment card data is handled by payment processors.
- Usage, diagnostics, and device data, such as app version, operating system, crash logs, performance events, feature usage, download events, IP address, and approximate location inferred from IP.
- Miniapp development and host metadata, when provided to or processed by a Zephyr Cloud-operated service, such as developer or publisher identity, package and miniapp identifiers, declared capabilities, authorization decisions, versions, compatibility results, build or publication status, integrity and provenance records, security or abuse signals, and diagnostics.
- Support and communications, such as messages you send us, feedback, bug reports, and related attachments.
Miniapp SDK, package, and host processing
Installing the Miniapp SDK package does not by itself create an Account or cause Zephyr Cloud to receive your source code, miniapp content, end-user content, or local SDK activity. The package includes local build, packaging, compatibility, and integrity functionality. We receive information only when it is sent to a Zephyr Cloud-operated service through a host, marketplace, publication workflow, support request, or other configured integration.
Depending on the features a developer, operator, workspace admin, or end user enables, a Miniapp SDK workflow or miniapp host may process information locally or transmit technical events to a configured service. Those events may support authentication and authorization; host and workspace access controls; artifact security, integrity, and provenance checks; diagnostics; version and compatibility validation; marketplace review and publication; and fraud, misuse, or abuse prevention. A developer-controlled endpoint or third-party host processes information under that operator's terms and privacy notice, not this Privacy Policy, unless Zephyr Cloud operates the endpoint or host.
How we use information
We use personal information to:
- provide, maintain, secure, debug, and improve the services;
- authenticate users and manage accounts, organizations, workspaces, roles, and permissions;
- route AI requests, execute specialist workflows, call tools, and return model output;
- process billing, enforce plan limits, and prevent fraud or abuse;
- authorize miniapps and hosts, validate package compatibility, integrity, and provenance, operate publication and marketplace workflows, diagnose failures, and investigate security or abuse signals;
- analyze reliability, performance, usage, and product quality;
- send transactional notices, support replies, security alerts, and service updates;
- comply with law, enforce terms, and protect users, us, and others.
AI processing and providers
The AI Platform can route prompts, files, messages, tool results, metadata, and related workspace content to model providers or tools selected by your workspace configuration. These providers and tools may process that content under their own terms, privacy policies, enterprise agreements, retention settings, or zero-data-retention commitments.
Workspace admins should configure providers, permissions, tools, and specialist access according to the sensitivity of the content users submit. Do not submit secrets, regulated information, or confidential third-party data unless your organization is authorized to process it through the selected services.
Developer and operator responsibilities
Miniapp developers, publishers, and host operators are responsible for providing legally required privacy notices, obtaining required consent, limiting collection to information necessary for the stated purpose, selecting appropriate retention periods, securing credentials and data, and honoring applicable privacy rights. They must accurately describe their own collection and any third-party services their miniapp or host uses.
Developers and operators should request only the minimum host capabilities and information needed, avoid placing secrets or unnecessary personal information in package metadata or diagnostics, and use authorization and access controls appropriate to their users and use case. Additional rules are in ourDeveloper and Marketplace Policy andAcceptable Use Policy.
Regulated and high-impact use
We do not prohibit a use merely because it is regulated or high-impact, but developers, operators, and users undertake those uses at their own risk. They are responsible for determining whether processing is lawful and appropriate, protecting sensitive information, obtaining required notices, consent, agreements, and professional authorization, and using qualified professional review and meaningful human oversight before relying on AI output for consequential decisions.
Retention
We keep personal information for as long as needed to provide the services, meet legal and accounting obligations, resolve disputes, enforce agreements, maintain backups, prevent abuse, and support security. Retention periods may vary by data type, workspace settings, plan, provider configuration, and legal requirements.
Workspace admins may be able to delete or export certain workspace content. Some data may remain in backups, logs, or records for a limited period after deletion.
Security
We use reasonable technical and organizational measures designed to protect personal information. No method of transmission or storage is perfectly secure. You are responsible for protecting credentials, API keys, workspace membership, provider settings, and connected tools under your control.
Security researchers and users can review ourSecurity and Responsible Disclosure Policy for reporting instructions.
Your choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or appeal of a privacy decision. You may also have rights to opt out of certain sale, sharing, targeted advertising, or profiling practices where applicable.
We do not sell customer workspace content. We do not use customer workspace content for targeted advertising. To make a privacy request, contactlegal@theaiplatform.app. We may need to verify your identity and authority before acting on a request.
Regional notices
For users in the European Economic Area, United Kingdom, or Switzerland, our legal bases may include performance of a contract, legitimate interests, consent, and compliance with legal obligations. You may have the right to lodge a complaint with your local data protection authority.
For California residents, applicable law may require notice of categories of personal information collected, sources, purposes, disclosures, retention, and rights. The sections above provide those disclosures. We do not knowingly sell personal information or share customer workspace content for cross-context behavioral advertising.
International transfers
We and our service providers may process information in the United States and other countries. Where required, we use appropriate safeguards for international transfers.
Children
The services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided personal information to us, contact us so we can take appropriate action.
Changes to this policy
We may update this Privacy Policy prospectively. A new version applies no earlier than its stated effective date, and we retain dated prior versions at the version links on this page. If changes are material, we will take reasonable steps to notify users, such as posting an updated effective date, showing an in-product notice, or sending email. We will obtain consent when applicable law requires consent rather than notice.
Contact
Privacy questions and requests can be sent tolegal@theaiplatform.app.