Last updated: September 29, 2026 · Questions: security@zethos.ai
Security at Zethos
The trust is the entire product. This page is a plain description of how we handle it.
What we protect
Zethos ingests:
- Email metadata and content from Gmail and Outlook
- Calendar events from Google Calendar and Microsoft 365
- Slack and Teams messages you’ve granted access to
- Meeting transcripts you record via the desktop app
- The commitments we extract from all of the above
You choose what connects. Every source is opt in, per account.
Where your data lives
Zethos runs entirely on Cloudflare’s infrastructure.
- Application layer: Cloudflare Workers, running our own code in Cloudflare’s global edge network.
- Database: Cloudflare D1 (SQLite at the edge), storing your commitments, extracted metadata, and connection state.
- File storage: Cloudflare R2 for meeting recordings and generated exports.
- Region: Primary storage is in North America (Cloudflare’s WNAM region). Edge cache may briefly serve reads from other regions.
We do not use AWS, GCP, or Azure for user data. There is no self-hosted database. No user data touches Anthropic, OpenAI, or any other AI provider outside the specific, scoped inference calls described below.
Encryption
- In transit: All connections are TLS 1.3. HSTS enforced on zethos.ai and api.zethos.ai.
- At rest: OAuth refresh tokens (the credentials that let Zethos read your Gmail / Outlook / Slack / calendar) are encrypted at the application layer using AES-256-GCM before they hit the database. Encryption keys are held in Cloudflare’s secret store, separate from the database itself. Even a full read of the D1 database would not expose a usable token.
- Meeting audio + transcripts: Encrypted at rest in R2 with Cloudflare-managed keys. Deleted from Zethos storage after transcription completes (audio) and 90 days (transcript), unless you save the meeting to your ledger.
Third parties who see your data
We use three external services in the pipeline. Each is scoped tightly.
Anthropic (Claude API). We send email subjects, message bodies, and meeting transcript segments to Claude for commitment extraction, auto-completion detection, and daily digests. Anthropic’s zero-retention terms apply to our API traffic: no training on our data, deleted from Anthropic within 30 days of the API call. See Anthropic’s data privacy commitments.
Recall.ai. If you use the meeting bot to record calls, Recall handles the join and streams the audio to our backend. Recall’s retention on the recording is 30 days maximum; we typically delete within hours.
Google, Microsoft, Slack. OAuth providers whose scopes we request. We never share your data back to other users of the app.
We do not sell data. We do not share it with advertisers or data brokers. We do not have a marketing pixel that phones home about your commitments.
OAuth scopes: what we actually ask for
We ask only for the scopes we need to make the feature work. If you connect Gmail, we request:
gmail.readonly— read messages to extract commitmentsgmail.send— send emails only when you click a Compose or Reply action
We do not request gmail.modify or gmail.labels. We cannot delete your mail. We cannot mark it read. We cannot silently modify your inbox.
Analogous limits apply to Outlook, Slack, Teams, and calendar scopes. Full scope list at zethos.ai/scopes.
You can revoke Zethos’s access at any time from your Google, Microsoft, or Slack account settings. Revocation is honored immediately: Zethos’s token becomes invalid, syncs stop, and your data enters the deletion queue described below.
Access controls inside Zethos
- No employee reads customer email, transcripts, or commitments as a matter of routine. There is no debugging by grepping your inbox.
- Production database access is limited to the founder and requires a Cloudflare API token that is rotated on a schedule.
- Support escalations that require looking at a specific account require your explicit written consent (email suffices), scoped to the specific issue, and are logged.
- We do not employ third-party contractors with production access.
What we log
- API request logs (timestamps, endpoints, user IDs, response codes) for 30 days.
- Errors captured to Sentry, scrubbed of message content but retaining commitment IDs and account IDs.
- OAuth events (connect, disconnect, token refresh) for auditability.
We do not log the content of your emails, calendar events, or transcripts. Extraction results are stored (that’s the product) but the source content is not persisted in logs.
Data retention and deletion
- While your account is active: Commitments and metadata are retained indefinitely so your ledger stays complete. Raw email content beyond what’s needed for a commitment record (subject, sender, snippet) is discarded after extraction.
- Meeting recordings: Audio deleted within 24 hours of transcription. Transcripts kept for 90 days, or indefinitely if you save the meeting.
- On disconnect: When you disconnect a source (say, unlink Gmail), all cached content from that source is queued for deletion within 24 hours. Commitments already extracted remain on your ledger; you can delete them individually.
- On account deletion: Settings → Delete Account. All data, including OAuth tokens, commitments, meeting notes, and R2 files, is deleted within 7 days. This is not a soft delete. There is no way for us to restore your account after this.
You can export your data at any time from Settings → Export.
Compliance
We are honest here: Zethos is a small company. We do not currently hold SOC 2, ISO 27001, or HIPAA certification. Pursuing SOC 2 Type II is on our roadmap once we cross meaningful team size, likely in 2027.
We are GDPR and CCPA compliant in practice: we honor data access, correction, deletion, and portability requests. Email privacy@zethos.ai for any of these and we respond within 30 days.
Zethos is not designed for regulated data (PHI, financial records under GLBA, government classified information). Please do not connect accounts that contain that kind of data.
Vulnerability disclosure
If you find a security issue, please email security@zethos.ai with details. We commit to:
- Acknowledging your report within 48 hours
- A first assessment within 5 business days
- Coordinated disclosure timelines that we agree on with you
We do not currently run a paid bug bounty, but we publicly credit and thank researchers who report responsibly.
Incident response
If we detect an incident that materially affects your data, we will notify you by email within 72 hours of confirmation, along with a description of what happened, what data was affected, and what we’re doing about it. We keep an incident log at zethos.ai/status.
To date, Zethos has had zero customer-facing security incidents.
Contact
- Security disclosures: security@zethos.ai
- Privacy requests (GDPR, CCPA, deletion): privacy@zethos.ai
- General: hello@zethos.ai
Aevaric Inc, doing business as Zethos.