Zoperate

Privacy Policy

Effective date: July 31, 2026

Zoperate is an AI services marketplace. Builders create AI agents, resellers customize and resell them, and businesses subscribe to agents that run automatically on Zoperate's infrastructure. This policy explains what data we collect, why we collect it, who it is shared with, and how you can remove it. It applies to zoperate.com and the Zoperate application.

1. Information we collect

We collect only what is needed to operate the service.

  • Account information. Your email address, authentication identifiers, and the role you use on the platform (builder, reseller, or customer). Accounts are authenticated through our identity provider, Supabase.
  • Agent configurations. The instructions, knowledge, model selection, trigger settings, and customizations that builders and resellers save to define how an agent behaves.
  • Run logs. A record of each agent execution: the time it ran, the trigger that started it, the input the agent received, the output it produced, and any error message. Run logs are how you audit and troubleshoot what your agents did.
  • Google account data. Collected only if you choose to connect Gmail. See section 2.

We do not collect advertising identifiers, and we do not use tracking cookies for advertising purposes.

2. Gmail data and how it is used

Connecting Gmail is entirely optional. Nothing in your Google account is accessed unless you explicitly connect it by signing in with Google and granting consent on Google's own consent screen.

  • Scope requested. We request a single read-only scope, gmail.readonly. Zoperate cannot send, delete, or modify email, and cannot change any Gmail setting.
  • What is accessed. For agents you have connected to a Gmail trigger, we read newly received messages — sender, subject, date, and message body — so the agent can act on them.
  • Why it is accessed. Solely to execute the agents you connected. Gmail data is never used for advertising, never used to build advertising or marketing profiles, never sold, and never used to train machine learning models.
  • How it is processed. When a message triggers an agent, its content is sent to Anthropic's Claude API to generate that agent's output. The message content and the resulting output are then written to the run log for that agent so you can review what the agent received and what it did. We do not maintain a separate copy or mirror of your mailbox, and we do not index your mail for any other purpose.
  • Optional forwarding you configure. If an agent is configured with a forwarding destination, that agent's output and the input that triggered it are sent to the URL configured for it. This happens only when the destination has been set up for the agent, and you control whether it is used.
  • Token storage. Google OAuth access and refresh tokens are encrypted at rest using AES-256-GCM with a key held outside the database. Tokens are decrypted only in memory, at the moment an agent run needs them.

3. Google API Services User Data Policy

Zoperate's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. How we share data

Zoperate does not sell personal data, and does not share it with data brokers or advertisers. Data is shared only with the service providers needed to run the product:

  • Anthropic (Claude API). Agent instructions and the input an agent receives — including email content when an agent is triggered by Gmail — are sent to Anthropic's Claude API solely to generate that agent's output.
  • Supabase (database and authentication). Stores account records, agent configurations, run logs, and encrypted tokens.
  • Destinations you configure. Any webhook or forwarding URL you or your reseller sets up for an agent receives that agent's output and triggering input.
  • Legal requirements. We may disclose data if required to do so by law or valid legal process.

Resellers can see the run activity for agents they have activated for their clients. Builders can see aggregate usage of the agents they published, but not the Gmail content of a customer's runs.

5. Retention and deletion

  • Disconnecting Gmail. You can disconnect Gmail at any time. Disconnecting revokes the stored OAuth tokens, and Zoperate immediately stops reading any new mail. You can also revoke Zoperate's access directly from your Google Account at myaccount.google.com/permissions, which takes effect right away.
  • Run logs. Run logs are retained so you can audit agent activity. You may request deletion of your run logs at any time by writing to the address in section 8.
  • Account deletion. When you delete your account, your account record, agent configurations, run logs, and stored Google tokens are deleted from our systems. Encrypted backups are cycled out on a rolling basis.

6. Security

  • Google OAuth tokens are encrypted at rest with AES-256-GCM, an authenticated encryption mode that detects tampering; the encryption key is stored in the application environment, not in the database.
  • All traffic to and from Zoperate is served over HTTPS/TLS.
  • Database access is protected by row-level security, so one account cannot read another account's agents, connections, or run logs.
  • OAuth tokens are decrypted only in memory for the duration of an agent run and are never written back in plaintext or exposed to the browser.
  • Access to production systems is limited to personnel who need it to operate the service.

No system is perfectly secure. We work to protect your data but cannot guarantee absolute security.

7. Your choices

You can review and edit your agent configurations, disconnect an integration, request a copy of your data, or request deletion of your data at any time. Connecting Gmail is never required to use Zoperate — agents can also be triggered by webhooks or run manually.

8. Changes and contact

If this policy changes in a way that materially affects how we handle your data, we will update the effective date above and notify account holders. Questions, data requests, and privacy concerns can be sent to support@zoperate.com.