This policy explains how Zenobia Pay, Inc. ("Method," "we," or "us") handles personal information when you use our websites, dashboard, and hosted services. Contact [email protected] with privacy questions or requests.
1. Information we collect
Account information. Our sign-in provider, WorkOS, supplies account details such as your user identifier, email address, name, and organization membership. Signing in with Google does not by itself give Method access to your Gmail inbox or Google Drive files.
Content you provide. We process prompts, conversations, workflow definitions, uploaded files and recordings, feedback, and support messages that you submit. Saved workflows can contain instructions, configuration, and references to connected tools.
Run records. When you sync a local run or use hosted features, Method may receive run inputs, outputs, checks, errors, timing, and workflow versions. These records can contain personal information from the task. Local execution can also send data to AI models and other services selected for the workflow.
Technical information. We and our service providers process information such as IP addresses, browser and device details, request logs, authentication events, and usage or performance measurements. Our own service records include dated account creation, saved Methods, run status changes, signed-in API calls, visible dashboard use, and download requests. Download records use a keyed hash of network and browser details to estimate distinct callers; they do not store the raw IP address or browser string in those records. These estimates do not identify individual people or prove completed installations. We use cookies and similar storage for sign-in, security, and saved interface state. When optional measurement or advertising tools are enabled and allowed by your choices, we and those providers may also collect page views, clicks, referral pages, campaign identifiers, approximate location, browser identifiers, and conversion events. Cookies, pixels, tags, local storage, and similar tools can be used for these purposes.
2. How we use information
We use information to authenticate users, provide and sync workflows and run records, process requested AI tasks, operate and improve the Service, evaluate outputs and improve features, respond to support requests, prevent abuse, and meet legal obligations. We may also use contact and usage information to communicate about Method, understand product demand, measure campaigns, and market the Service, subject to your choices and applicable law. You can opt out of marketing messages through their unsubscribe link or by contacting us. Essential account and service messages may still be sent. Where privacy law requires a legal basis, these uses rely on providing our service contract, legitimate interests in operating a secure service, legal obligations, or consent where required.
3. Service providers and sharing
We use WorkOS for authentication, Cloudflare for hosting, storage, delivery, and security, Modal for hosted compute, and OpenAI for certain AI features. We also use mcp-use to host our agent connection service and Resend to send account emails using your name and email address. These providers may use their own infrastructure providers. The information sent to each depends on the feature you use. Workflows may also send information to services you choose or connect. Those services handle information under their own terms and privacy policies.
Information in an organization's workflows and run records may be available to other authorized members of that organization. We may disclose information when required by law, to protect rights and security, or as part of a merger, acquisition, or transfer of the Service, subject to applicable protections.
Optional analytics and advertising providers are not connected. We do not send workflow files, prompts, report contents, or credentials to advertising partners.
4. Retention and security
We retain account information, saved content, and run records for as long as needed to provide the Service, maintain security, resolve disputes, or meet legal obligations. Retention depends on the type of information and how you use Method. Deletion from active systems and backups can occur on different schedules. We may retain records needed for security, disputes, or legal obligations, subject to applicable law. The sensitivity of the information, the purpose for keeping it, and any contractual or legal requirements guide our retention decisions.
We use access controls and other safeguards to protect information. No service can guarantee absolute security. Protect your connected accounts and avoid placing passwords or API keys directly in workflow prompts or other content intended to be shared.
5. Cookies and tracking
Essential storage supports sign-in, security, and saved interface state. Optional analytics and advertising providers are not connected, so there are no optional tracking controls to set. If we add a provider, we will identify it and provide the relevant choices before enabling its tools.
6. Other privacy rights
You can choose what content to submit and which tools to connect. To request access, correction, export, or deletion of your personal information or account, contact [email protected]. We may need to verify your identity and consider applicable legal obligations and the rights of other users. Deleting your account does not necessarily delete work owned by a shared organization.
Depending on where you live, you may also have rights to object to or restrict processing, withdraw consent, or complain to a privacy regulator. If we handle your information for an organization that uses Method, that organization may be responsible for responding to your request; we will help route it where appropriate.
7. International processing and children
Our service providers may process information in countries other than yours, including the United States. Transfers remain subject to applicable data-protection requirements. Contact us for information about the transfer arrangements that apply to your use. Method is intended for adults and is not directed to children under 18. Contact us if you believe a child has provided personal information.
8. Policy updates
We may update this policy as the Service changes. We will update the effective date and provide additional notice of material changes where required. For questions, contact [email protected].