This policy explains how Zovaty ("we", "us") handles information when you use our AI website builder and related services.
This page is provided for transparency. It is not legal advice and does not create warranties or guarantees beyond what is stated.
Privacy Policy
Last updated: June 30, 2026
Overview
We aim to collect only what we need to operate the service, improve the product, and support you. This policy describes what we collect, why we use it, and the choices available to you.
Account data
When you register or sign in, we may process:
- Email address and display name
- Authentication identifiers from Supabase Auth
- Profile information from OAuth providers (e.g., Google, GitHub) if you choose social login
- Subscription tier and account status
- AI credit balance and usage summaries
Authentication is handled through Supabase Auth. OAuth providers process sign-in according to their own privacy policies.
Website content
Content you create in the builder — including site copy, structure, brand settings, published pages, and version history — is stored in our database (Supabase PostgreSQL) to provide editing, publishing, and backup functionality.
Published sites may be served from Zovaty-controlled infrastructure or subdomains you configure. You control what you publish publicly.
Payment provider data
When you purchase a subscription or credit pack, payment processing is handled by Lemon Squeezy (or another designated payment provider). We do not store full payment card numbers on our servers.
- We may receive billing status, subscription identifiers, purchase history, and customer email from the payment provider.
- Payment data is subject to the provider's privacy policy and security practices.
For billing questions: billing@zovaty.com
Analytics and usage data
We may collect technical and usage information such as:
- Pages visited, features used, and approximate performance metrics
- Browser type, device type, and general location (derived from IP)
- Error logs and diagnostic data to fix bugs and improve reliability
We use this information in aggregate where possible to understand how the product is used. We do not sell your personal information.
Cookies and similar technologies
We use cookies and similar technologies for essential functions such as keeping you signed in, remembering preferences, and protecting against abuse. Some cookies are strictly necessary for the service to work. We may also use analytics cookies to understand product usage.
You can control cookies through your browser settings. Disabling essential cookies may affect sign-in and core functionality.
AI provider usage
When you trigger AI generation or editing, we send relevant prompts and context to configured AI providers (such as OpenRouter or other model hosts) to produce output. Providers process data according to their terms and policies.
- Do not submit sensitive personal data in prompts unless you accept the associated risk.
- We configure server-side API keys so provider credentials are not exposed in the browser.
- We may log request metadata (not necessarily full prompts) for abuse prevention and debugging.
How we share information
We may share information with:
- Infrastructure providers (e.g., hosting, database, authentication)
- Payment processors for billing
- AI providers to fulfill your requests
- Professional advisers or authorities when required by law
We do not sell personal information to third parties.
Data retention
We retain account and project data while your account is active and as needed to provide the service. If you delete your account or request deletion, we will delete or anonymize personal data within a reasonable period, except where retention is required for legal, security, or billing purposes.
Backup copies may persist for a limited time before being overwritten.
Security
We implement technical and organizational measures designed to protect your data, including encryption in transit, access controls, and row-level security in our database. See our Security page for more detail. No method of transmission or storage is completely secure.
Your rights
Depending on your location, you may have rights to access, correct, delete, or export your personal data, or to object to certain processing. To exercise these rights, contact us at the email below. We will respond within a reasonable timeframe.
International transfers
Your information may be processed in countries other than your own, including where our service providers operate. We take steps designed to ensure appropriate safeguards where required by applicable law.
Children
The service is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate steps.
Contact
Privacy questions and requests: hello@zovaty.com