Last updated September 24, 2026
Privacy Policy
This policy explains what Zephr collects when you use the website and the app, why, who processes it on our behalf, and what you can ask us to do with it.
What we collect
Account details. Your email address and, if you sign in with Google, the name and profile picture Google shares with us. We never see your Google password.
Workspace content. What you add to Zephr: aircraft and their details, compliance records and their history, notes and attachments, saved searches, folders and alert subscriptions.
Documents you upload for reading.When you create a project from a certificate of conformity, the file is read to pre-fill the aircraft details. Text-based PDFs are read on our servers; scans and images are sent to Google's Gemini API for extraction.
Billing details. Payments are handled by Stripe. We store your plan, subscription status and Stripe customer ID. Card numbers go to Stripe directly and never reach our servers.
Usage and technical data. Aggregated page views and performance measurements (Vercel Web Analytics and Speed Insights, which do not use cookies), and server logs with IP address and error details, used to keep the service running and secure.
How we use it
To provide the service: run your searches, keep your compliance records, send the alerts and reminders you subscribe to, and generate the reports you export.
To bill you for paid plans and to enforce plan limits.
To keep Zephr secure and working: detect abuse, investigate errors and measure performance.
To contact you about your account, billing or important changes to the service. We do not send marketing email without your consent, and we do not sell your personal data.
Who processes your data
We use a small number of service providers, each only for the purpose listed:
- Supabase: database, authentication and file storage.
- Vercel: hosting, web analytics and performance measurement.
- Stripe: payments and subscription management.
- Google: sign-in with Google, and the Gemini API for reading scanned certificates.
- Resend: transactional email (alerts, reminders, invites).
- Cloudflare: bot protection on sign-in forms, when enabled.
Some of these providers process data outside your country. Where that happens, they rely on recognised safeguards such as standard contractual clauses.
How long we keep it
Account and workspace data are kept while your account is active. When you delete your account or ask us to, we delete it within 30 days, except billing records we are required to keep for tax and accounting purposes.
Uploaded certificates are kept with the project they created and deleted with it. Server logs are kept for a limited period for security and troubleshooting.
Your rights
You can ask to access, correct, export or delete your personal data, or object to how we use it. Write to contact@zephr.com from the email on your account and we will reply within 30 days. You can also complain to your local data protection authority.
Security
Data is encrypted in transit (HTTPS with HSTS) and at rest. Workspace data is isolated per workspace by database-level access rules. No system is perfectly secure; if we learn of a breach affecting your data, we will tell you without undue delay.
Changes and contact
If we change this policy in a meaningful way we will tell you by email or in the app before it takes effect. Questions: contact@zephr.com.