Effective May 19, 2026.
Privacy Policy
Zethos is a software product owned and operated by Aevaric, Inc., a Delaware corporation.
1. Introduction
Aevaric Inc. (“Zethos,” “we,” “us,” or “our”) provides a commitment-tracking application that captures promises, follow-ups, and obligations from the communication services its users connect. This Privacy Policy describes the personal data we process when you use Zethos, the purposes for which we process it, the legal bases on which we rely, and the rights you have over that data.
This policy applies to all users of the Zethos macOS application, iOS application, and the services available through zethos.ai. By using Zethos, you acknowledge that you have read and understood this policy.
2. Data We Collect
We collect only what is necessary to provide the service. Personal data we may process includes:
- Identity data. The email address you use to sign in, and your display name where you provide one.
- Authentication tokens. OAuth access and refresh tokens issued by integrations you connect (Google Workspace, Microsoft 365, Slack, GitHub, Linear, and others), encrypted at rest and used only to access those services on your behalf.
- Source content. The contents of emails, calendar events, chat messages, and meeting transcripts from the accounts you have explicitly connected. We retrieve this content solely to extract commitments and generate the derived data described below.
- Derived data. The commitment ledger, contact profiles, and meeting notes produced by our processing of source content.
- Device and usage data. Application open events, integration connection events, feature usage, error logs, and approximate timezone. These records do not contain source content.
We do not collect data from any service you have not connected. We do not read your browser history, monitor your keystrokes, or capture your screen.
3. How We Use Personal Data
We process personal data for the following purposes:
- Providing the core commitment-tracking service, including ingesting connected sources and generating the derived ledger;
- Authenticating you and maintaining your session;
- Communicating with you in response to a support request or to provide service-critical notices;
- Detecting, preventing, and addressing technical issues, security incidents, and abuse;
- Improving the reliability and accuracy of our extraction models through aggregate and anonymized analysis;
- Complying with our legal obligations.
4. Legal Bases for Processing (EEA/UK Users)
Where the General Data Protection Regulation or the UK GDPR applies, we rely on the following legal bases:
- Contract. Processing necessary to provide Zethos to you under our Terms of Service.
- Consent. When you authorize an integration, you consent to our access of the data exposed by that integration’s OAuth scopes.
- Legitimate interests. Securing the service, preventing abuse, and improving reliability, where those interests are not overridden by your rights.
- Legal obligation. Compliance with applicable law.
5. AI Processing
We use Anthropic’s Claude API to extract commitments from source content and to summarize meetings. Source content is transmitted to Anthropic over TLS and processed under Anthropic’s Commercial Terms of Service.
Anthropic does not use API inputs or outputs to train its models. We do not authorize Anthropic or any other processor to use your data for marketing or model training.
6. Sub-processors
We engage the following sub-processors to operate the service. Each is bound by contractual obligations consistent with this policy.
- Anthropic, PBC. Language-model inference for extraction and summarization.
- Cloudflare, Inc. Application hosting, edge compute, and database (D1) storage.
- Recall.ai, Inc. Meeting-recording capture and transcription, where you elect to record a meeting.
- Resend, Inc. Transactional email delivery.
- Apple Inc. Push notification delivery via the Apple Push Notification service.
7. Third-Party Integrations
You may connect Zethos to third-party services. Each integration uses OAuth 2.0; we never receive or store your provider credentials. You may revoke any integration at any time through the application’s settings or directly with the provider, which causes the associated tokens to be deleted from our systems.
Your use of any third-party service remains governed by that service’s own terms and privacy policy. We are not responsible for the practices of third parties.
8. Data Retention
We retain personal data for as long as your account remains active. When you delete your account, we delete all of your data, including your commitment ledger, contact profiles, meeting notes, stored files, source-content cache, and OAuth tokens, within seven (7) days. This is not a soft delete: once deleted, your account cannot be restored.
We may retain limited records (such as billing records, where applicable, and security logs) for longer periods where required by law or for the establishment, exercise, or defense of legal claims.
9. Security
We implement administrative, technical, and physical safeguards designed to protect personal data. These include encryption in transit (TLS 1.3), encryption at rest, encrypted storage of OAuth refresh tokens, account-scoped query filtering, and least-privilege access controls. See our Security page for further detail.
No method of transmission or storage is perfectly secure. While we strive to protect personal data, we cannot guarantee its absolute security.
10. International Data Transfers
Personal data may be processed in the United States and other jurisdictions where our sub-processors operate. Where we transfer personal data out of the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses or an equivalent transfer mechanism.
11. Your Rights
Subject to applicable law, you have the right to access, correct, delete, or export the personal data we hold about you, to object to or restrict our processing, and to withdraw any consent on which our processing relies. To exercise any of these rights, email privacy@zethos.ai. We will respond within thirty (30) days.
If you are in the EEA or the UK, you have the right to lodge a complaint with your local supervisory authority.
12. California Residents
California residents have specific rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act. We do not sell personal data and do not share personal data for cross-context behavioral advertising. To exercise rights under California law, contact us at the address above.
13. Children
Zethos is not directed to children under the age of sixteen, and we do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us and we will delete it.
14. Changes to This Policy
We may amend this policy from time to time. The current version will always be available at this URL and will indicate the date on which it became effective. Material changes will be communicated by reasonable means before they take effect.
15. Contact
Questions, requests, or complaints regarding this policy should be directed to:
Aevaric Inc.