
Privacy Policy
Your privacy is fundamental to us. This comprehensive policy explains how Alexzo collects, uses, protects, and manages your personal information across all our AI-powered services.
Last Updated: January 27, 2025
Effective Date: January 1, 2025
Table of Contents
Introduction
Welcome to Alexzo ("we," "us," or "our"). We are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, mobile applications, and services, including but not limited to:
- Zyfoox: Our AI-powered image generation platform
- LearnFlow: Our educational AI assistant application
- Alexzo Platform: Our main website and associated services
This policy applies to all users of our services worldwide and complies with applicable data protection laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other relevant privacy legislation.
1. Information We Collect
1.1 Personal Information You Provide
- Account Information: Name, email address, username, password
- Profile Information: Profile picture, bio, preferences
- Communication Data: Messages, feedback, support requests
- Payment Information: Billing address, payment method details (processed securely by third-party providers)
- Content Data: Text prompts, images uploaded, generated content
1.2 Automatically Collected Information
- Device Information: IP address, browser type, operating system, device identifiers
- Usage Data: Pages visited, features used, time spent, click patterns
- Technical Data: Log files, error reports, performance metrics
- Location Data: General geographic location based on IP address
1.3 Third-Party Information
- Social Media: Information from social media platforms when you connect accounts
- Analytics: Data from analytics providers about your interactions
- AI Processing: Data processed through third-party AI services (Google Gemini API, etc.)
2. How We Use Your Information
2.1 Service Provision
- Provide, operate, and maintain our AI-powered services
- Process your requests and generate AI responses
- Manage your account and provide customer support
- Process payments and manage subscriptions
2.2 Service Improvement
- Analyze usage patterns to improve our services
- Develop new features and functionality
- Train and improve our AI models (with anonymized data)
- Conduct research and development
2.3 Communication
- Send service-related notifications and updates
- Respond to your inquiries and provide support
- Send marketing communications (with your consent)
- Notify you about changes to our services or policies
2.4 Legal and Security
- Comply with legal obligations and regulations
- Protect against fraud, abuse, and security threats
- Enforce our terms of service and policies
- Resolve disputes and investigate violations
3. Data Sharing and Disclosure
We do not sell your personal information to third parties.
3.1 Service Providers
We may share your information with trusted third-party service providers who assist us in:
- AI Processing: Google Gemini API for AI-powered responses
- Cloud Services: Hosting, storage, and computing services
- Payment Processing: Secure payment and billing services
- Analytics: Website and application analytics
- Customer Support: Help desk and support services
3.2 Legal Requirements
We may disclose your information when required by law or to:
- Comply with legal processes, court orders, or government requests
- Protect our rights, property, or safety
- Protect the rights, property, or safety of our users
- Investigate fraud, security issues, or violations of our terms
3.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the business transaction, subject to the same privacy protections.
4. Data Security and Retention
4.1 Security Measures
- Encryption: Data encrypted in transit and at rest using industry-standard protocols
- Access Controls: Strict access controls and authentication mechanisms
- Regular Audits: Regular security audits and vulnerability assessments
- Secure Infrastructure: Secure cloud infrastructure with enterprise-grade security
- Employee Training: Regular security training for all personnel
4.2 Data Retention
- Account Data: Retained while your account is active and for a reasonable period after deletion
- Usage Data: Typically retained for 2-3 years for analytics and improvement purposes
- Content Data: User-generated content may be retained as specified in our terms of service
- Legal Requirements: Some data may be retained longer to comply with legal obligations
4.3 Data Deletion
When you delete your account or request data deletion, we will:
- Delete your personal information within 30 days
- Anonymize or aggregate remaining data
- Notify third-party processors to delete your data
- Retain only what is legally required
5. Your Privacy Rights
5.1 Universal Rights
- Access: Request access to your personal information
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your personal information
- Portability: Request a copy of your data in a portable format
- Opt-out: Opt-out of marketing communications
5.2 GDPR Rights (EU Residents)
- Right to Object: Object to processing based on legitimate interests
- Right to Restrict: Restrict processing in certain circumstances
- Right to Withdraw Consent: Withdraw consent for consent-based processing
- Right to Lodge Complaints: File complaints with supervisory authorities
5.3 CCPA Rights (California Residents)
- Right to Know: Know what personal information is collected and how it's used
- Right to Delete: Request deletion of personal information
- Right to Opt-out: Opt-out of the sale of personal information
- Right to Non-discrimination: Not be discriminated against for exercising rights
5.4 How to Exercise Your Rights
To exercise your privacy rights, you can:
- Email us at: privacy@alexzo.com
- Use our online privacy request form
- Contact us through your account settings
- Write to us at our mailing address (see contact section)
7. International Data Transfers
Your information may be transferred to and processed in countries other than your own. We ensure adequate protection through:
- Adequacy Decisions: Transfers to countries with adequate data protection
- Standard Contractual Clauses: EU-approved contractual protections
- Binding Corporate Rules: Internal data protection standards
- Certification Programs: Privacy Shield and similar frameworks
8. Children's Privacy
Our services are not intended for children under 13 years of age.
We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. We will take steps to remove such information and terminate the child's account.
For users between 13-18 years old, we recommend parental guidance when using our AI-powered services.
9. Third-Party Services
9.1 AI Service Providers
- Google Gemini API: Powers our AI responses and content generation
- OpenAI Services: Additional AI capabilities and processing
- Other AI Providers: Various specialized AI services as needed
9.2 Infrastructure Providers
- Vercel: Website hosting and deployment
- Supabase: Database and authentication services
- Cloudinary: Image and media processing
9.3 Analytics and Marketing
- Google Analytics: Website analytics and user behavior
- Social Media Platforms: Social sharing and authentication
- Email Services: Transactional and marketing emails
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you via email if you have an account with us
- Post a notice on our website for significant changes
- Provide additional notice as required by applicable law
Your continued use of our services after any changes indicates your acceptance of the updated Privacy Policy.
11. Contact Information
Data Protection Officer
Email: privacy@alexzo.com
General Contact: alexzomail@proton.me
Company Information
Response Time
We aim to respond to all privacy-related inquiries within:
- General Inquiries: 48 hours
- Data Subject Requests: 30 days (as required by law)
- Urgent Security Issues: 24 hours
12. Legal Basis for Processing (GDPR)
12.1 Contractual Necessity
Processing necessary for the performance of our contract with you, including:
- Providing our AI services
- Managing your account
- Processing payments
12.2 Legitimate Interests
Processing based on our legitimate interests, including:
- Improving our services
- Security and fraud prevention
- Analytics and research
12.3 Consent
Processing based on your explicit consent for:
- Marketing communications
- Optional features
- Cookies and tracking
12.4 Legal Compliance
Processing necessary to comply with legal obligations, including:
- Tax and accounting requirements
- Law enforcement requests
- Regulatory compliance
Questions About Your Privacy?
We're here to help. Contact our privacy team for any questions or concerns about how we handle your data.