ZZeph

Legal

Privacy Policy

Last updated 2026-08-14 · v1

This policy explains what personal data Zeph collects, why, and your rights over it. It covers the Zeph website (zephclick.com), the Zeph web app (app.zephclick.com), the Zeph companion app for macOS, and the Zeph devices.

Who we are

Zeph is operated by Zeph Click Ltd (company number 15274277), registered at 20 Wenlock Road, London, United Kingdom, N1 7GU. We are the data controller for the processing described here. You can reach us about privacy at privacy@zephclick.com.

As a UK company we process personal data under the UK GDPR and the Data Protection Act 2018, and under the EU GDPR for our users in the EU.

The short version

  • The device firmware itself has no account, no cloud, and no telemetry.
  • Our analytics are privacy-minimised: on the website they are cookieless by default, and in the companion app they carry only metadata (durations, counts) — never your audio, transcripts, or message content.
  • AI features use a provider you connect with your own API key, so your prompts go to that provider under your agreement with them, not through us.
  • We send product updates only to people who opt in, and you can unsubscribe at any time.

What we collect, why, and our lawful basis

The website (zephclick.com)

DataPurposeLawful basis
Anonymous usage + page views (via PostHog, cookieless by default)Understand which pages helpLegitimate interest; consent once you accept cookies
Marketing/attribution signals for our ad measurement (Reddit pixel) — only after you accept cookiesMeasure campaignsConsent
Your email address and any name you give (via our email tool, Kit) when you join a waitlist, subscribe, or downloadSend you the updates you asked forConsent
Payment details for the £1 reservation (handled entirely by Stripe)Take your reservationContract

The web app (app.zephclick.com)

DataPurposeLawful basis
Account details: name, email, whether your email is verified, profile image, usernameRun your accountContract
Authentication data: password hash, or the tokens from signing in with Google; two-factor secret and backup codes if you enable itSign you in securelyContract
Session records including your IP address and browser user-agentKeep you signed in, and secure the accountLegitimate interest
Billing records if you buy a plan (subscriptions, orders, and the underlying Stripe events; usage credits)Provide and bill the serviceContract
AI conversation history you create in the appProvide the AI features (see below)Contract / consent
Files you upload (avatars, organisation logos)Provide the featureContract
Product analytics tied to your account (PostHog) and error diagnostics (Sentry), only after you accept cookiesImprove reliabilityConsent / legitimate interest
A CAPTCHA challenge on sign-in/sign-up (Cloudflare Turnstile)Stop abuseLegitimate interest

We use your email to send transactional messages (verify your email, reset your password, security and billing notices). Product updates are separate: we send them only to people who opt in, either by subscribing to our newsletter or choosing "email me product updates" when you create an account, or by confirming the subscription email we send after you give us your email to download the app or reserve a device. Those product-update emails include a small tracking pixel and tagged links, so we (through Kit) can measure opens and clicks and gauge what's useful; this is tied to your subscription and stops when you unsubscribe. You can unsubscribe from product updates at any time, and unsubscribing does not affect the transactional messages your account needs.

AI features (bring your own key)

Zeph's AI features work with a model provider you connect using your own API key. When you use them, your prompts and inputs are sent to that provider, under your agreement with them — Zeph is not the provider and does not resell it. We may store your conversation history in your account so you can return to it; you can delete it. We do not sell it or use it to train models.

The companion app (macOS)

DataPurposeLawful basis
Product analytics (PostHog): a random per-install ID, a salted hash of the device serial (never the raw serial), and metadata-only events — durations, latency, bucketed counts, which provider kind you use. No audio, no transcripts, no message content.Improve the appLegitimate interest, opt-out (see below)
Crash and error reports (Sentry), with no personal identifiers attachedFix crashesLegitimate interest, opt-out
"Report a problem": your description, an optional email if you provide one, the last portion of the app log, and the app versionSupport the issue you reportConsent (per submission)

Companion analytics and crash reporting are on by default but opt-out: nothing is sent until you pass the first-run privacy step, and you can turn both off at any time in Settings → Privacy. Speech-to-text and AI go to your chosen provider, not to us. Your device pairing identity, local logs, and provider keys stay on your machine.

The devices and the command-line tool

The Zeph device firmware has no account, no cloud connection of its own, and no telemetry. The command-line tool sends no analytics.

Who we share data with (our processors)

We use a small number of service providers who process data on our behalf under contract. We do not sell your personal data.

ProviderWhat forWhere
PostHogProduct analyticsEU
RedditAd measurement pixel (website, after consent)United States
Kit (ConvertKit)Marketing email, incl. open/click measurementUnited States
StripePayments and billingUnited States / global
SentryError monitoring, including session replay on the web appEU region
CloudflareAnti-abuse CAPTCHA (Turnstile) and DNSUnited States / global
ResendTransactional emailEU
GoogleSign-in with Google, and our own company emailUnited States
HetznerHosting of our servers and databaseGermany (EU)

Session replay on the web app: to diagnose problems, Sentry records a sample of web-app sessions and all sessions where an error occurs. These recordings are held in Sentry's EU region.

International transfers

Our core systems and database are hosted in Germany (EU), and our analytics, error monitoring, and transactional email run in the EU. Some providers listed above are in the United States; where we transfer personal data to them we rely on appropriate safeguards (such as Standard Contractual Clauses or the UK International Data Transfer Agreement, and the EU-US / UK-US Data Privacy Framework where the provider is certified). [TO CONFIRM: data-processing agreements / SCCs in place with each US processor.]

How long we keep it

We keep personal data only as long as we need it for the purposes above.

  • Account data: kept while your account exists, and removed after you delete your account, subject to short-lived backup rotation. [TO CONFIRM: exact backup-retention window.]
  • Server and session logs: [TO CONFIRM: retention period — proposed default 30–90 days.]
  • Analytics and error data (PostHog, Sentry): [TO CONFIRM: retention period — proposed default up to 12 months.]
  • Marketing email records (Kit): until you unsubscribe.

Your rights

Under UK/EU data protection law you have the right to access your data, to correct it, to erase it, to restrict or object to how we use it, to data portability, and to withdraw consent at any time (which does not affect processing already done). To exercise any of these, email privacy@zephclick.com; we will respond within one month.

You also have the right to complain to a supervisory authority. In the UK that is the Information Commissioner's Office (ICO), ico.org.uk. If you are in the EU you may complain to your local supervisory authority.

EU / UK representative

[TO CONFIRM: appointment and named contact of our Article 27 EU representative — required because we, a UK company, offer services to and monitor users in the EU.]

California privacy rights

If you are a California resident, you may request the categories and specifics of personal information we hold, ask us to delete it, and opt out of any "sale" or "sharing" of personal information. Our advertising pixel (Reddit) can count as sharing for cross-context behavioural advertising; you can opt out by declining cookies. We honour the Global Privacy Control (GPC) browser signal. To exercise a Do Not Sell or Share My Personal Information request, email privacy@zephclick.com or decline cookies.

Children

Zeph is not directed to children under 16, and we do not knowingly collect their personal data.

Changes to this policy

We version this policy: any material change bumps the version and effective date shown at the top. We will make a reasonable effort to notify you of significant changes.

Contact

Questions or requests: privacy@zephclick.com, or Zeph Click Ltd, 20 Wenlock Road, London, United Kingdom, N1 7GU.