Legal
Privacy Policy
What personal information Zanora LLC collects when you use the platform, why, who we share it with, how long we keep it, and the choices you have.
Effective date: September 30, 2026
This Privacy Policy explains how Zanora LLC (Zanora, we, us) handles personal information when you use the Zanora API (api.zanora.dev), the console (console.zanora.dev), this documentation site (docs.zanora.dev) and the Zanora software packages (the Services). It should be read with our Terms of Service.
Zanora is the controller of the personal information described here. For information about the people using a customer's agents or services, the customer is usually the controller and we act on their instructions.
In short
We collect as little as we can. We need an email address, an organisation name and a password to run your account. Wallet balances, ledger entries and receipts hold opaque ids, not names or emails. Card numbers go straight to Stripe and never reach us. We don't see the content of the API calls your agents buy. We don't sell personal information, and we don't use advertising or tracking cookies.
1. What we collect
Information you give us
| What | When | Notes |
|---|---|---|
| Email address | signup, password reset | used to confirm your address, sign you in and contact you |
| Organisation name and website | signup | shown to Zanora operators; a seller's name is shown to buyers |
| Password | signup, password change | stored only as a salted scrypt hash. We can't read it |
| Verification request — a note and a contact | when a seller asks to be verified | read by Zanora operators to decide on verification |
| Listing content — capability names, descriptions, prices, endpoint URLs | when a seller publishes | public to buyers once the seller is verified |
| Spending policies and approvals | when a buyer configures them | includes which person or key approved a held purchase |
| Payout destination — a USDC address on Base | when a seller registers one | used to send payouts, and screened against sanctions lists |
| Support messages | when you email us | whatever you choose to include |
Information created when you use the Services
| What | Notes |
|---|---|
| API keys and sessions | we store a one-way hash of each key, never the key itself, plus its label, scopes, and when it was created, used and revoked |
| Agent wallet public keys | the public half of each agent's signing key. The private key stays with you |
| Ledger entries and receipts | amounts, times, and opaque ids for wallets, sellers, capabilities and transactions. A receipt also holds a hash of the seller's response, not the response itself. These records contain no names or email addresses |
| Rail transactions | funding and payout records: amount, status, the payment provider's reference, and for USDC, the blockchain addresses involved |
| Ratings | the rating a buyer gives a seller, tied to the purchase it rates |
| Technical data | IP address, request times, routes, response codes and user agent, used for security, rate limiting and debugging |
What we don't collect
- Card numbers. When you pay by card, the card form is served by Stripe and your card details go directly from your browser to Stripe. We receive the payment's status and Stripe's reference for it.
- The content of purchased calls. When your agent calls a seller, the request and response travel between your agent and the seller's server. Zanora authorises and records the payment, but doesn't receive the request or the response body — only a hash of the response, for the receipt.
- Your agents' private keys. You generate them; we only ever see the public key.
Information from others
- Payment providers (Stripe, Circle) tell us when a payment succeeds, fails, is disputed or is returned.
- Sanctions-screening providers tell us whether a blockchain address appears on a sanctions list.
- Public blockchains — USDC transfers on Base are public, and we read them to credit deposits and confirm payouts.
2. How we use it
We use personal information to:
- provide the Services — create and secure your account, run discovery, process purchases, credit deposits, send payouts and produce receipts (legal basis: performing our contract with you);
- send service messages — email confirmation links, password resets, and notices about your account, security or changes to our terms (contract; legitimate interests);
- verify sellers and decide what appears in discovery (legitimate interests in a trustworthy marketplace);
- prevent fraud and abuse — rate limiting, detecting stolen credentials, holding earnings during card disputes, and alerting on unusual activity (legitimate interests; legal obligation);
- comply with the law — sanctions screening, keeping financial records, tax reporting, and responding to lawful requests (legal obligation);
- operate and improve the platform — debugging, capacity planning, and aggregate statistics such as call volumes and latency (legitimate interests); and
- provide support when you contact us (contract; legitimate interests).
We don't use your information for advertising, we don't build marketing profiles, and we don't make decisions about you based solely on automated processing that have legal or similarly significant effects. Our automated controls — spending rules, sanctions screening, circuit breakers — apply the rules you or the law set, and you can contact us to have a person review any outcome.
3. Who we share it with
We don't sell or rent personal information, and we don't "share" it for cross-context behavioural advertising.
We share it only as follows:
| With | What | Why |
|---|---|---|
| Stripe | payment amount, wallet reference, and what you enter into Stripe's card form | processing card payments and disputes |
| Circle | deposit and payout addresses, amounts | holding USDC and making transfers |
| Sanctions-screening providers (such as Chainalysis) | blockchain addresses — never your name or email | checking addresses before a payout |
| Resend | your email address and the message | delivering account emails |
| Google Cloud | everything we store, encrypted at rest | hosting the Services and our backups |
| Google Fonts | your IP address and browser details, when a page loads its typefaces | displaying the console and docs |
| Other users | a seller's name, listings and ratings are visible to buyers. A seller sees the receipts for its sales, which identify the buyer's wallet by an opaque id, not by name | running the marketplace |
| Authorities and advisers | what the law requires, or what is needed to protect rights and safety | legal compliance, enforcing our terms |
| A successor | the information we hold | a merger, acquisition or sale of assets, under this policy |
Our service providers may use your information only to provide their services to us. Stripe and Circle are also independent controllers of the information they collect under their own privacy policies.
Blockchain transactions are public. A USDC deposit or payout is recorded permanently on the Base network. Anyone can see the addresses and amounts. We don't publish which Zanora account an address belongs to.
4. Cookies and browser storage
We use a small number of storage items, all needed for the Services to work. We don't use analytics, advertising or tracking cookies.
| Name | Where | Purpose | Lasts |
|---|---|---|---|
zanora_console cookie | console.zanora.dev | keeps you signed in. It's httpOnly, so page scripts can't read it | until you sign out, or the session expires (at most 12 hours) |
| operator key in session storage | admin.zanora.dev | holds the operator's admin key for that tab only | until the tab is closed |
zd-theme in local storage | docs.zanora.dev | remembers light or dark mode | until you clear it |
Stripe may set its own cookies when its card form loads, for fraud prevention. See Stripe's privacy policy.
5. How long we keep it
| Information | How long |
|---|---|
| Account details (email, organisation, password hash) | while your account is open, then deleted within 90 days of closure (see Account deletion) |
| Unconfirmed signups (an email address that was never confirmed) | kept so that a link can be re-sent and repeated signups limited. Deleted on request |
| Ledger entries, transaction records, receipts and other financial records | as long as necessary to meet legal, accounting, fraud-prevention, dispute-resolution and compliance requirements. They're append-only records that buyers, sellers and auditors rely on, and they contain opaque ids rather than names or emails |
| API key records | while the account is open. Revoked keys are kept as records, never as usable secrets |
| Technical logs | only as long as needed for security and debugging |
| Database backups | up to 90 days, after which they're deleted automatically |
Account deletion
When you delete your account, we delete your account details within 90 days. We may retain ledger entries, transaction records, receipts, and other financial records for as long as necessary to meet legal, accounting, fraud-prevention, dispute-resolution, and compliance requirements. Where reasonably practicable, retained financial records are de-linked from your name and email address.
We may retain a cryptographic hash of your email address after account deletion to prevent fraud, enforce platform restrictions, and maintain the integrity of our records. The original email address is deleted.
6. Security
We protect your information with measures appropriate to a payments platform, including:
- TLS for every connection;
- one-way hashing for API keys, passwords and email tokens;
- signed receipts that can be checked independently;
- a database that rejects edits and deletions of ledger entries;
- encrypted, access-restricted backups;
- keys scoped to the least access needed, and alerts on high-risk changes such as a new payout address.
No system is perfectly secure. If we become aware of a breach that affects your personal information, we'll tell you and the relevant authorities as the law requires.
7. Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct it if it's wrong;
- delete it;
- restrict or object to how we use it;
- receive a copy in a portable format; and
- withdraw consent, where we rely on consent.
To use any of these rights, email support@zanora.dev from the address on your account. We'll respond within 30 days (or sooner where the law requires) and may need to verify your identity first. We won't treat you differently for exercising your rights.
Some limits apply. We may keep ledger entries, receipts and other financial records as described in Account deletion; where reasonably practicable we remove the link between them and you. We also can't delete what's recorded on a public blockchain.
California residents have the rights above under the CCPA/CPRA, including to know, delete, correct and opt out of sale or sharing. We don't sell or share personal information as those terms are defined.
If you're in the EEA, UK or Switzerland, you can complain to your local data protection authority. We'd appreciate the chance to address your concern first.
8. International transfers
Zanora is based in the United States, and our service providers may process information in the United States and other countries. Where we transfer personal information from the EEA, UK or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
9. Children
The Services are for businesses and are not directed at anyone under 18. We don't knowingly collect personal information from children. If you believe a child has given us information, contact us and we'll delete it.
10. Changes to this policy
We may update this policy. We'll change the effective date above, and for material changes we'll tell you by email or in the console before they take effect.
11. Contact
Zanora LLC · support@zanora.dev