LegalEffective: September 2, 2026

Zorveus Privacy Policy

This Privacy Policy explains how Zorveus ("Zorveus," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use our websites, APIs, SDKs, developer tools, dashboards, inference gateway, wallets, and related services (collectively, the "Services").

This Policy applies to developers, business customers, organization members, end users who interact with Zorveus-connected applications, and visitors to our websites.

1. Information We Collect

The information we collect depends on how you use Zorveus.

Account Information

We may collect name, email address, account identifiers, login and authentication information, organization membership and role information, profile information, and account settings.

Developer and Organization Information

If you create or manage a developer organization or application, we may collect organization name, application name and configuration, redirect URIs and allowed origins, developer contact details, API key metadata, model and permission settings, and spending and usage configurations.

Product-User Information

Businesses may provide identifiers for their own users so Zorveus can attribute AI usage and apply controls. This may include external user IDs, email addresses where provided, display names where provided, plan or tier information, usage allowances, credit balances and grants, and application-specific metadata. We recommend that customers provide only the information necessary for the intended purpose.

Wallet and Billing Information

Depending on the Services used, we may collect or generate wallet identifiers, balance information, funding and transaction history, credit grants, usage charges, spending limits, billing records, payment status, and payment-method metadata provided by payment processors. We generally do not store complete payment-card information where payments are processed by a third-party payment provider.

AI Inference Data

When you or an application uses Zorveus to access AI models, we may process prompts and messages, system instructions, uploaded content or files, model selections, model responses and outputs, token counts, request and response metadata, tool or function-call data, timing, latency, error, and provider information. The exact data processed depends on the application, API request, and model used.

Usage and Technical Data

We may automatically collect IP address, browser and device information, operating system, timestamps, API request metadata, log data, authentication events, error data, usage patterns, and security and fraud signals.

Cookies and Similar Technologies

Our websites may use cookies or similar technologies for authentication, session management, preferences, security, analytics, and performance measurement. Where required by law, we will obtain consent before using non-essential cookies.

2. How We Use Information

We may use information to:

  • Provide and operate the Services;
  • Authenticate users and protect accounts;
  • Process AI inference requests;
  • Route requests to AI model providers;
  • Calculate and attribute AI usage;
  • Enforce spending limits and model permissions;
  • Manage wallets, balances, credits, and transactions;
  • Process payments and billing;
  • Provide dashboards and analytics;
  • Maintain usage and financial ledgers;
  • Troubleshoot errors and improve reliability;
  • Detect abuse, fraud, security threats, or policy violations;
  • Communicate service notices and support responses;
  • Improve our products and developer experience;
  • Comply with legal obligations;
  • Enforce our Terms of Service.

We do not use customer or end-user data for purposes materially unrelated to providing and improving Zorveus without an appropriate legal basis.

3. AI Model Providers and Subprocessors

Zorveus may transmit relevant AI request data to third-party model and infrastructure providers in order to fulfill inference requests.

Depending on the model selected or routing configuration, these may include third-party providers of large language models, image, video, audio, embedding, or other AI models, cloud infrastructure, logging and observability, payment processing, authentication, analytics, communications, and fraud prevention or security.

These providers may process data under their own terms or under agreements with Zorveus. Where practical, Zorveus may provide controls that allow customers to restrict models, providers, or data-handling options.

4. Customer and End-User Roles

Where a business customer uses Zorveus to process data about its own users, the business may act as the data controller or equivalent responsible party, while Zorveus may act as a processor or service provider on its behalf.

In those cases:

  • The customer determines why and how its end-user data is processed;
  • The customer is responsible for providing required notices and obtaining required consents;
  • Requests concerning that customer's use of your personal data may need to be directed to the customer.

Zorveus may separately act as a controller or business for data we process for our own purposes, such as account administration, security, billing, and service operations.

5. Legal Bases for Processing

Where laws such as the GDPR or UK GDPR apply, we rely on one or more of the following legal bases:

  • Performance of a contract;
  • Legitimate interests, such as operating, securing, and improving the Services;
  • Compliance with legal obligations;
  • Consent, where required;
  • Establishment, exercise, or defense of legal claims.

6. How We Share Information

We may disclose information to:

  • Service Providers and Subprocessors: Companies that help us operate the Services, including hosting, AI model, payment, authentication, analytics, communications, and security providers.
  • Business Customers: Where you interact with Zorveus through a third-party application, we may share usage, spending, status, or account-related information with that application as authorized by you or necessary to provide the service.
  • Professional Advisers: Lawyers, accountants, auditors, insurers, and other advisers where reasonably necessary.
  • Legal and Safety Disclosures: Disclosures necessary to comply with law or legal process, enforce our agreements, protect rights, property, or safety, or investigate fraud, abuse, or security incidents.
  • Corporate Transactions: In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business or assets.

We do not sell personal information for money in the ordinary meaning of "sell." If applicable law defines "sale" or "sharing" more broadly, we will provide rights and disclosures required by that law.

7. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining financial and usage records, resolving disputes, enforcing agreements, preventing fraud and abuse, and complying with legal obligations.

Retention periods may vary by data type. Account information may be retained while an account is active. Billing and transaction records may be retained for legally required periods. Security logs may be retained for operational and fraud-prevention purposes. AI request or response content may be retained according to product configuration, provider requirements, customer settings, or applicable contractual commitments.

8. International Data Transfers

Zorveus and its service providers may process data in countries other than the country where you live. Where required, we use appropriate safeguards for international transfers, which may include standard contractual clauses, adequacy decisions, contractual protections, or other legally recognized transfer mechanisms.

9. Security

We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.

These measures may include encryption in transit, access controls, authentication mechanisms, infrastructure security controls, logging and monitoring, secrets management, least-privilege practices, and security review and incident response processes.

If you believe your account or data may have been compromised, contact us immediately at security@zorveus.com.

10. Your Privacy Rights

Depending on where you live, you may have rights to:

  • Access personal information we hold about you;
  • Correct inaccurate information;
  • Request deletion;
  • Restrict or object to processing;
  • Receive a portable copy of certain information;
  • Withdraw consent where processing is based on consent;
  • Opt out of certain forms of sale, sharing, or targeted advertising where applicable;
  • Lodge a complaint with a data protection authority.

To exercise a privacy right, contact us at privacy@zorveus.com.

11. California and Similar U.S. Privacy Rights

If applicable state privacy laws apply to you, you may have rights relating to access, correction, deletion, portability, opting out of sale or sharing, opting out of targeted advertising, limiting use of certain sensitive personal information, and non-discrimination for exercising privacy rights. Zorveus will honor applicable rights as required by law.

12. Children's Privacy

The Services are not intended for children under the minimum age required to consent to data processing in their jurisdiction. We do not knowingly collect personal information from children in violation of applicable law. If you believe a child has provided personal information to Zorveus without appropriate authorization, contact us at privacy@zorveus.com.

13. Third-Party Applications and Links

Zorveus may be integrated into third-party applications or websites. Those third parties have their own privacy practices, and this Policy does not govern how they independently collect or use information. You should review the privacy policies of applications you connect to Zorveus.

14. Changes to This Privacy Policy

We may update this Policy from time to time. If changes are material, we will provide notice where required by law. The "Effective Date" at the top of this Policy indicates when the current version became effective.

15. Contact Us

For privacy questions or requests:

Zorveus Inc.

Email: privacy@zorveus.com