Privacy Policy
This policy explains how Zenaian processes information across the website, Chrome extension, API, accounts, subscriptions, and privacy-support communications.
Who we are and scope
Zenaian is operated by [LEGAL OPERATOR NAME], [LEGAL FORM], Republic of Korea, with address [KOREAN BUSINESS ADDRESS]. Privacy contact: privacy@zenaian.com. Privacy responsible person / CPO: [NAME / TITLE / CONTACT].
This Privacy Policy applies to www.zenaian.com, the Zenaian Chrome extension, the Zenaian API, account and subscription functions, and privacy-support communications. Zenaian is designed and operated from Korea and uses the Personal Information Protection Act of Korea (“PIPA”) as its primary privacy baseline.
Zenaian does not use third-party behavioral analytics, cross-site advertising trackers, advertising profiles or sale of personal information. The public website is offered in English; the service does not intentionally target a particular foreign region.
Personal information we process
- Account information: Clerk user identifier, email address, name/display name, sign-in/account-security information and session state needed for authentication.
- Extension information: local custom instruction/preferences, local rotating device credentials, and server-side pairing/device-session identifiers and timestamps.
- Question content: only when you deliberately activate a capture, the visible screenshot or selected screen region and an optional instruction are processed to generate an answer.
- Usage information: plan, quota period, usage counts, operation identifiers, model identifier, status and limited timestamps needed to enforce allowances and prevent duplicate charging/usage.
- Subscription information: Whop checkout, membership, product/plan, renewal/cancellation, payment/refund/dispute identifiers and minimum payment-state information needed to grant access, support transactions and comply with law. Zenaian does not store full payment-card numbers.
- Operational/security information: request identifier, request method/path/status, safe error codes, timing and limited security events. We do not intentionally put screenshots, prompts, answers or authentication tokens in application logs.
- Privacy/support information: information you choose to include when contacting privacy@zenaian.com and minimal records showing how a privacy request or consumer complaint was handled.
Legal bases under Korean PIPA
The following quotations are Zenaian's working English translations of the relevant Korean statutory clauses for user readability. The Korean statutory text controls.
- PIPA Article 15(1)(4) permits processing where it is “necessary to perform a contract concluded with the data subject, or to take measures requested by the data subject in the process of concluding a contract.” Zenaian relies on this for account/authentication, requested screenshot analysis, usage allowances, subscription access and ordinary account support.
- PIPA Article 15(1)(6) permits processing where it is “necessary to achieve the controller's legitimate interests and those interests clearly take precedence over the data subject's rights,” provided the interest is substantially related and the processing remains within a reasonable scope. Zenaian relies on this narrowly for security, rate limiting, replay prevention, fraud/abuse prevention and short diagnostics.
- PIPA Article 15(1)(2) permits processing “where there is a special statutory provision, or processing is unavoidable in order to comply with a legal obligation.” Zenaian relies on this for transaction/complaint records that Korean law requires us to preserve and for other concrete legal duties.
- PIPA Article 21 requires personal information to be destroyed without delay when it becomes unnecessary because its retention period has expired or its purpose has been achieved. When another law requires continued retention, Article 21 requires that retained information be stored and managed separately. Zenaian therefore separates legally retained transaction records from ordinary live account data.
- PIPA Article 23 generally restricts processing of sensitive personal information unless a specific statutory exception applies. Zenaian is not designed to collect sensitive personal information and prohibits intentional submission of identifiable sensitive personal information in captures or instructions.
- PIPA Article 28-8 governs overseas provision, processing outsourcing and storage. Where overseas outsourcing/storage is necessary to perform the service, Zenaian uses the contract-performance route in Article 28-8(1)(3) and publishes the prescribed transfer information below.
Screenshot processing, sensitive information and xAI ZDR
Zenaian captures screen content only after you deliberately invoke a configured capture action. It is not designed to continuously record your screen, collect browsing history, or build a history of questions you view.
The captured image and optional instruction are transmitted over encrypted connections to the Zenaian API in Virginia, United States, and then to xAI for the requested generative-AI inference. Zenaian does not save the screenshot, instruction, question text or AI answer as a persistent application database record. The server clears the sensitive request body after completion, cancellation or timeout, and completed result state is retained only briefly for polling.
Our production xAI team is configured for Zero Data Retention (ZDR). xAI states that ZDR User Content is processed transiently and not retained as a durable content copy after processing under its current enterprise terms. Zenaian also verifies the xAI ZDR response header in production and is designed not to fall back to ordinary-retention inference if ZDR is not confirmed.
Do not submit screenshots containing identifiable sensitive personal information or credentials.
Do not intentionally submit identifiable sensitive personal information, such as an identifiable person's medical/health record, political or religious information, sexual-life information, biometric/unique identifiers, authentication secrets, financial credentials, or other highly sensitive material. If such material is accidentally included, Zenaian's design is to process it only transiently through the requested ZDR inference path rather than create a persistent profile or history.
Why we use information
- create, authenticate, secure and support your account;
- pair and authenticate the extension;
- perform the screenshot analysis you request and return the answer;
- administer plan limits and prevent duplicate usage;
- create and reconcile subscriptions, payments, renewal cancellation, refunds and disputes;
- prevent abuse, secure the service and diagnose failures using minimized operational information;
- respond to privacy/consumer requests; and
- comply with transaction-retention, accounting, tax, consumer-protection and other legal duties.
Service providers and international processing
Zenaian uses service providers only for defined operational purposes. We do not sell captured content or personal information. Overseas transfer details are as follows:
| Recipient | Country/location | Information | Purpose | Timing/method | Retention |
|---|---|---|---|---|---|
| Render Services, Inc. | United States - Virginia | Account identifiers, extension-session/usage/billing metadata; transient screenshot/instruction in server RAM | API and PostgreSQL hosting, security and recovery | At service requests / continuous hosting over encrypted connections | Zenaian schedule; native logs up to 30 days depending plan; database recovery copies roll for the provider plan window. |
| Clerk, Inc. | United States; Clerk/subprocessors may process where they operate | Email/name/account identifiers, authentication/session/security information | Authentication and account management | Signup/login/session/account operations | Account lifetime and provider security/legal lifecycle; Zenaian initiates Clerk user deletion when account deletion completes. |
| X.AI LLC | United States; xAI public subprocessor list is mainly US and includes a UK support subsidiary | Transient screenshot, instruction/prompt and generated result; incidental ordinary personal information may appear | Generative-AI inference | Each deliberate capture over encrypted API | Zero Data Retention for User Content in production. |
| Whop, Inc. and payment/tax partners | United States and other locations used by Whop/partners | Whop directly collects buyer/payment/tax data at checkout. Zenaian sends provider-native checkout/membership/payment identifiers and subscription commands, and receives minimum transaction/access state. Whop may also share limited purchase/contact/profile information with Zenaian as seller under its own data-sharing/privacy terms. | Checkout, recurring billing, tax handling where supported, refunds/disputes | At checkout and subscription lifecycle | Provider/legal retention. Zenaian retains only the minimized operational and statutory records described here. |
| Google Workspace / Google LLC | [PLANNED CONFIGURATION: United States for covered data at rest; service/support processing may occur in countries on Google's current subprocessor list] | Privacy/support emails you choose to send | Privacy/support communications | When you email privacy@zenaian.com | Ordinary closed privacy email target: 365 days; minimized statutory complaint record separately where required. |
Domestic website hosting: www.zenaian.com is hosted through Hosting.kr / Megazone Co., Ltd. in the Republic of Korea. Hosting.kr describes its Linux hosting as AWS-based. On the current evidence, Zenaian treats this as domestic entrusted processing rather than a Zenaian overseas transfer. The host receives ordinary website requests and provider-native access/security logs; Zenaian does not place its account database, screenshot analysis data, or behavioral analytics on the website host. Visitor-statistics packages and raw-log archiving are disabled by Zenaian by default.
For the overseas processors above, Zenaian relies on PIPA Article 28-8(1)(3) where the processing outsourcing or storage is necessary to conclude or perform our service contract and the information required by Article 28-8(2) is published here. If you choose not to use the overseas processing required for account authentication, API hosting or AI inference, we cannot provide the corresponding core service. You may avoid further capture processing at any time by not invoking a capture and may delete your account as described below.
Whop checkout and taxes
Paid subscriptions are checked out through Whop. The product uses exclusive tax behavior: the product price is shown before tax and Whop may add applicable sales tax or VAT at checkout based on the transaction. Zenaian has selected Whop's Collects and Remits mode for supported jurisdictions. Whop's current Seller Terms state that Whop's merchant-of-record role is limited to payment/card-network settlement and, in Collects and Remits jurisdictions, specified transaction taxes; Zenaian remains the supplier responsible for the product, consumer obligations and taxes outside the scope Whop actually handles. Whop's Seller Terms also incorporate a Seller Data Sharing Addendum governing personal-data sharing between Whop and sellers. Whop's Privacy Policy states that it may share purchase confirmation, username, contact and certain account-profile information with the relevant seller to complete a purchase.
For new production checkouts, Zenaian is designed to send no Zenaian user-identifying custom metadata to Whop. Whop collects buyer/payment information directly under its own terms and may share limited purchase/contact/profile information with Zenaian as the seller where necessary to complete the purchase. Zenaian maps provider events using Whop's checkout_configuration_id and other provider-native checkout/membership/payment identifiers, and stores only the fields reasonably necessary for service access, support and legal records. Whop may independently retain its buyer/payment/tax records according to its own legal obligations; Zenaian account deletion cannot erase records Whop independently must keep.
Retention
| Category | Retention |
|---|---|
| Screenshot / instruction | No persistent application storage; transient until completion/cancel/timeout. |
| AI answer/result job | Brief polling window, normally about 2 minutes after completion. |
| Pairing grants | Minutes; expired/consumed cleanup normally within about 1 hour. |
| Extension device session | Active credential lifetime (currently up to 30 days) plus short ordinary cleanup; deleted immediately on account deletion. |
| Per-analysis quota operation | 30 days after settlement. |
| Usage-period summary | 90 days after the period ends. |
| Failed/expired checkout | 7 days; consumed checkout operational record 30 days. |
| Sanitized Whop webhook/provider event | 30 days. |
| Terminal live membership | Up to 90 days where needed for reconciliation; deleted sooner on account deletion. |
| Live user-facing payment history | Up to 12 months while the account exists; legally required transaction copy is separately archived. |
| Render logs | Provider-native 7/14/30-day retention depending workspace plan; Zenaian does not stream launch logs to a third-party log warehouse. |
| Legally required contract/withdrawal records | 5 years where the Korean E-Commerce Act applies. |
| Legally required payment/supply records | 5 years where the Korean E-Commerce Act applies. |
| Consumer complaint/dispute records | 3 years where the Korean E-Commerce Act applies. |
| Privacy-request audit | 1 year after completion, unless an actual dispute/legal duty requires longer. |
| Ordinary privacy mailbox message | Target 365 days after receipt; legally required complaint facts are minimized and stored separately. |
Korean e-commerce rules also require certain advertising records to be preserved for six months. Zenaian can satisfy this through versioned offer/pricing records without attaching them to individual users.
Account deletion
You can request account deletion from the authenticated account page. Before deletion, we require explicit confirmations explaining its consequences. Once confirmed, Zenaian immediately blocks further service use, cancels in-flight analysis where possible, revokes extension sessions, removes your Zenaian entitlement, requests cancellation of future Whop renewal, separates any transaction information that must be preserved by law, deletes ordinary Zenaian account/usage/billing records, and deletes the Clerk user account.
Our engineering target is to initiate deletion immediately and normally complete deletion from active systems under Zenaian's control within 24 hours. This target does not mean every provider recovery copy or legally required record is physically erased within 24 hours. Narrow statutory records remain isolated until their legal retention period expires, and rolling provider recovery copies age out according to the provider's recovery schedule. If a database recovery copy is restored, Zenaian reapplies completed deletion records before reopening the restored system to production.
Account deletion ends remaining Zenaian access and unused question allowance immediately. It requests cancellation of future renewal but is not itself a request for a refund and does not waive any mandatory withdrawal/refund right you have under applicable law.
Your rights and requests
Subject to applicable law, you may request access, correction, deletion, suspension of processing/withdrawal where applicable, and information about processing under Zenaian's control. The account page provides a human-readable privacy view and JSON export, plus account deletion. You may also contact privacy@zenaian.com.
We use proportionate identity verification. Normally, an authenticated account is sufficient. We do not ask for a passport or government ID merely because you make a privacy request. Where deletion or correction is restricted by a specific legal retention duty, we will explain the basis and continue to isolate the retained record from ordinary service use.
Security and incident handling
Zenaian uses encrypted connections, production authentication, exact-origin controls, rotating extension credentials, server-authoritative quotas, signed billing webhooks, bounded request sizes/timeouts, database access controls and data minimization. No online service can guarantee absolute security.
If a qualifying personal-information leak occurs, Zenaian follows the notice/reporting duties under Korean law, including the current 72-hour rules where applicable.
Age
Zenaian is available only to users who are at least 19 years old. We do not intentionally offer accounts or paid subscriptions to persons under 19. If we learn that an under-19 person created an account contrary to this requirement, we may suspend/delete it and handle any legally required consumer/privacy steps.
Changes and contact
We may update this policy when the service, providers, law or data practices change. Material changes will be identified by a revised date and any notice/consent required by law. Contact: privacy@zenaian.com. Operator: [LEGAL OPERATOR NAME / ADDRESS / BUSINESS REGISTRATION]. Privacy responsible person: [CPO DETAILS].
