← ZipLoom

Privacy Policy

Last updated: July 21, 2026

Who We Are

ZipLoom ("we", "our", "us") is a deployment platform for AI-generated code. We help developers deploy repositories to production platforms securely. Our service is operated from the United States.

Contact: privacy@ziploom.dev

What We Collect

Account data: Email address, name, and password hash (or GitHub OAuth identity) when you sign up.

GitHub data: When you connect GitHub, we receive your GitHub username, avatar, email, and an OAuth access token. We use this token to read repository contents for security scanning and to register deploy webhooks. We never store your source code — file contents are read into memory, scanned, and discarded.

Usage data: Deployment logs, build outputs, and AI composition session history. These are stored to show you your history and to power failure diagnosis.

Payment data: Billing is handled by Stripe. We never see or store your card number. We store your Stripe customer ID and subscription status.

Technical data: IP addresses (for rate limiting), browser type, and request logs retained for up to 30 days for security purposes.

What We Do Not Collect

We do not sell your data. We do not use your code or deployments to train AI models. We do not track you across third-party websites. We do not collect data from visitors who do not sign up.

How We Use Your Data

To provide and improve the service — running deployments, security scans, and AI assistance on your behalf.

To communicate — transactional emails about your deployments, billing receipts, and security alerts. You can opt out of non-transactional emails at any time.

To enforce our terms — detecting abuse, rate-limit violations, and unauthorized access attempts.

GitHub Repository Access

ZipLoom requests read access to your repository contents solely to perform security scanning before deployment. We do not clone or persistently store your source code. Webhook write access is used only to register the auto-deploy trigger on your chosen branch. You can revoke access at any time from your GitHub settings under Authorized OAuth Apps or Installed GitHub Apps.

AWS Account Access (BYOC)

If you use the Bring Your Own Cloud feature, you create an IAM role in your AWS account with a trust policy that allows ZipLoom to assume it temporarily. ZipLoom uses the temporary credentials only to deploy build artifacts to the S3 bucket and CloudFront distribution you specify. We never store your AWS access keys. Temporary credentials expire automatically (maximum 60 minutes).

Data Retention

Account data is retained while your account is active. You can request deletion at any time. Deployment logs are retained for 90 days. Audit logs are retained for 1 year for security compliance. Anonymized usage statistics may be retained indefinitely.

Data Sharing

We share data only with the following sub-processors, each bound by data processing agreements:

  • Supabase — database and authentication
  • Netlify — application hosting
  • Stripe — payment processing
  • OpenRouter, OpenAI, Anthropic, Google — AI model inference (prompts only, no persistent storage)

Your Rights

You have the right to access, correct, export, or delete your personal data. To exercise these rights, email privacy@ziploom.dev. We respond within 30 days.

Security

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access to production systems is restricted by role. All data mutations are audit-logged. We run the same security checks on our own codebase that we run on yours.

To report a security vulnerability, see our Security Policy.

Cookies

We use one session cookie to keep you signed in. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. Our analytics are privacy-first and do not set cookies.

Changes

We will notify you by email and post a notice on this page at least 30 days before any material change takes effect. Continued use after the effective date constitutes acceptance.