← Zero AI

Privacy Policy

Last updated: July 17, 2026 · Effective immediately

BYOK Zero-Knowledge Commitment: Your API keys are encrypted with AES-256-GCM before storage. Zero AI staff cannot read, access, or transmit your keys. Decryption occurs only client-side in your browser. We never see your keys.

1. Who We Are

Zero AI (“Zero AI,” “we,” “our,” or “us”) is a sovereign AI operating system operated by Hanzala H Khan. Our platform is accessible at zeroasis.ai.

Contact: kingh.hanz@gmail.com

2. Information We Collect

Account information: Name, email address, and password (hashed with bcrypt, never stored in plaintext).

Usage data: Chamber activity, token counts, and session metadata — used solely for billing accuracy and platform improvement.

Payment data: Processed entirely by Stripe. Zero AI never stores card numbers, CVCs, or banking information.

BYOK API keys: Encrypted client-side with AES-256-GCM before reaching our servers. We store only the encrypted ciphertext. We cannot decrypt or read your keys.

3. How We Use Your Information

We use your information to: authenticate your account, deliver the Zero AI platform services, process billing via Stripe, communicate important product updates, and improve platform performance.

We do not sell your data, share it with advertisers, use it to train AI models without explicit consent, or transmit your API keys to any third party.

4. BYOK Data Handling

Zero AI’s Bring Your Own Keys (BYOK) architecture is designed for zero-knowledge storage:

  • Key encryption uses AES-256-GCM with a key derived via PBKDF2 (100,000 iterations, SHA-256)
  • Encryption occurs in your browser before any network transmission
  • The derived encryption key exists only in your browser session and is never sent to our servers
  • We store only the encrypted ciphertext — mathematically unreadable without your passphrase
  • Optional Upstash sync stores the same ciphertext — encrypted at rest and in transit

5. Data Retention

Account data is retained for the duration of your subscription plus 30 days following cancellation, after which it is permanently deleted.

AI-generated outputs stored in your Vault are retained until you delete them or close your account.

You may request immediate deletion at any time by emailing us or using the “Delete Account” option in /os/account.

6. Your Rights (GDPR / CCPA)

You have the right to: access all data we hold about you, correct inaccurate information, request deletion (right to be forgotten), export your data in a portable format, and withdraw consent at any time.

To exercise any right, contact kingh.hanz@gmail.com with subject line “Data Request.” We respond within 30 days.

7. Cookies

We use only essential cookies: a session authentication cookie (httpOnly, Secure, SameSite=Strict) and a theme preference cookie. No tracking pixels, advertising cookies, or third-party analytics cookies.

8. Third-Party Services

Zero AI integrates with: Stripe (payments — governed by Stripe’s privacy policy), Upstash (encrypted key/data storage — SOC 2 compliant), and Cloudflare (CDN and edge runtime).

When you add BYOK provider keys (OpenAI, Anthropic, etc.), your key is sent directly from your browser to that provider’s API for testing. Zero AI does not proxy or log these test calls beyond the pass/fail result.

9. Security

We implement: AES-256-GCM encryption for stored secrets, bcrypt password hashing, JWT authentication with 7-day expiry, HTTPS/TLS 1.3 everywhere, and Cloudflare DDoS protection.

To report a security vulnerability, email kingh.hanz@gmail.com with subject “Security Disclosure.” We respond within 24 hours.

10. Changes to This Policy

We will notify you of material changes via email and by updating the “Last updated” date above. Continued use of Zero AI after changes constitutes acceptance.