Last updated: March 3, 2026
zigzag integrates with Google services to enhance your experience. This section specifically describes how we handle data obtained through Google APIs in compliance with the Google API Services User Data Policy.
When you connect your Google account to zigzag, we may access the following data:
We use Google user data solely to provide our core services:
Important: We do not use Google user data for advertising purposes, and we do not use Google user data to train AI/ML models unless you explicitly opt in.
We do not share, sell, rent, or trade Google user data with third parties except in the following limited circumstances:
We never sell Google user data. We never share Google user data with third parties for their marketing purposes.
We protect your Google user data with robust security measures:
Retention Period: We retain Google user data only as long as necessary to provide our services. OAuth access tokens are retained while your account is active. Basic profile information is retained for the duration of your account.
Data Deletion: You can request deletion of your Google user data at any time by:
Upon receiving a deletion request, we will delete your Google user data within 30 days, except where retention is required by law. We will also revoke our access to your Google account.
In addition to Google user data described above, we collect information you provide directly to us, such as:
We use your information to:
Our platform uses large language models from OpenAI to provide AI-powered features including lean canvas generation, Brand and Outreach creation, validation frameworks, and MVP requirements. When you use any of these features, the business inputs you enter (your startup idea, business description, and related content) are sent to OpenAI's API for processing.
We do not send your name, email address, or other personally identifiable information to OpenAI. OpenAI processes API inputs under a Data Processing Agreement and does not use API data to train its models. Inputs are retained by OpenAI for up to 30 days for abuse monitoring purposes only, then deleted. For full details, see OpenAI's Enterprise Privacy page.
The lawful basis for this processing is contract performance (Article 6(1)(b) UK/EU GDPR) — AI generation is the core purpose of the service you have signed up for. We do not use your business data to train our own AI models.
We may share your information in the following circumstances:
We never sell your personal information to third parties.
We implement industry-standard security measures including:
We retain your account data for as long as your account is active. Internal analytics events, error logs, API metrics, and LLM metrics are automatically deleted after 90 daysby a daily automated retention job. Payment records are retained for 7 yearsas required by HMRC regulations.
Self-service deletion: You can permanently delete your account and all associated personal data instantly from your profile settings (Data & Privacy → Delete My Account). Monitoring records containing your email are anonymised rather than deleted to preserve aggregate service statistics.
Deletion via email: You may also request deletion by emailing hello@gozigzag.com. We will delete your personal data within 30 days, except where retention is required by law.
You have the right to:
Most rights can be exercised instantly from your profile settings (Data & Privacy section) — including data export, account deletion, and marketing consent. For anything else, contact us at hello@gozigzag.com. We will respond within 30 days as required by Article 12(3) UK/EU GDPR.
We use strictly necessary cookies (session authentication via an httpOnly cookie) that do not require consent. We also offer optional first-party analytics — these only run if you click "Accept all" in the cookie banner. We do not use Google Analytics, Facebook Pixel, or any other third-party advertising or tracking cookies.
Declining optional cookies disables all non-essential tracking immediately. Your consent choice is stored in your browser's localStorage. You can change your cookie preference at any time from your Profile → Data & Privacy settings. For full details see our Trust Centre — Cookies & Analytics.
Your information may be processed and stored in countries other than your own. We ensure adequate protection through appropriate safeguards and compliance with applicable data protection laws.
Our service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware of such data collection, we will delete it immediately.
We may update this privacy policy periodically. Significant changes will be communicated via email or platform notifications. Continued use of our service after changes constitutes acceptance.
For privacy-related questions or to exercise your rights, contact us at: