Privacy Policy

How we collect, use, share, and protect personal data.

Last Updated: July 31, 2026

1. Introduction

This Privacy Policy is issued by Zeta AI, Inc., a Delaware corporation doing business under the commercial name of "Viktor" ("Zeta AI," "we," "us," or "our"). Zeta AI provides the Viktor service and related software, integrations, and documentation (collectively, the "Service"), which integrates with your communication workspace (such as Slack or Microsoft Teams) to help improve business operations using artificial intelligence ("AI").

This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use the Service, and outlines your rights and choices. By using the Service, you agree to the practices described in this Privacy Policy.

We review this Privacy Policy at least annually to ensure it remains accurate, complete, and compliant with applicable laws and our internal data governance standards.

Key definitions

Customer Data means data submitted to or processed by the Service on your behalf, including: connection credentials (e.g., OAuth tokens), basic workspace/user identifiers, workspace settings, files stored in Viktor, conversations and outputs generated in Viktor, scheduled tasks, approval decisions, and service logs.

2. Information We Collect

We collect only the information necessary to provide, maintain, and secure the Service.

A. Slack workspace and user information

When you install or use Viktor, we may store:

  • Slack workspace identifiers (e.g., workspace/team ID) and limited workspace metadata needed to operate the integration.
  • Administrator information for the person who installs Viktor (name and email address as provided by Slack).
  • User identifiers for users who interact with Viktor (e.g., Slack user ID, display name, and email address if provided by Slack).
  • Slack-to-internal user mapping data to associate actions/permissions with users (e.g., workspace/team ID, Slack user ID, email, username).

B. Connection credentials

We store credentials necessary to maintain integrations, including:

  • Slack OAuth tokens (access/refresh tokens), token scopes, and expiration metadata.
  • Credentials or tokens for other third-party integrations you enable (if applicable).
  • Integrations in Viktor are workspace-shared. Related credentials and tool settings may therefore be available for use by authorized members of that workspace through Viktor.

C. Content and records inside Viktor

We store content needed to provide continuity and run the Service, including:

  • Workspace files created or uploaded in Viktor (e.g., company notes, team profiles, run logs, reports, todo lists, and other documents).
  • Conversation threads and messages between users and Viktor, including agent outputs and tool calls.
  • Approvals/permission decisions (approval or rejection records) related to actions Viktor requests.
  • Scheduled tasks configurations (e.g., task name/title, schedule/cron configuration, dependencies, and configuration metadata).

D. Slack message content

When you use Viktor in Slack, we access message content from channels Viktor has been invited to or has joined — including messages sent in those channels while Viktor is a member, not only messages that mention Viktor — as well as direct messages with Viktor and thread replies. When Viktor joins a channel, it may retrieve up to approximately 90 days of that channel's prior history to establish context. Where an individual user separately grants Viktor Slack search permissions through Slack's OAuth consent screen, Viktor may search and read Slack content accessible to that user under the granted scopes (which may include private channels and direct messages). This data is used to process your requests, maintain conversation context, and provide the Service.

E. Service logs and usage data

We collect and store limited operational data, such as:

  • Service logs and audit/security logs (e.g., timestamps, error logs, request/response metadata).
  • Usage events needed to operate and improve reliability (e.g., tasks executed, approvals granted, feature usage signals).

F. Communications with us

If you contact us (e.g., support tickets or email), we collect the information you provide in those communications.

G. Website/app analytics, advertising, and attribution data

When you visit our website, use product surfaces, or begin checkout flows, we may collect:

  • Cookie, pixel, and similar online identifiers used for analytics, advertising measurement, and referral attribution.
  • Device and browser metadata, IP address, pages viewed, and interaction events.
  • Attribution and referral metadata associated with signup or billing events (for example, campaign/referral identifiers or partner discount metadata).

Sensitive data

We do not knowingly collect sensitive personal data (such as financial account numbers, health information, or children's data) unless necessary for the Service and provided by you.

3. How We Use Your Information

We use the information described above to:

A. Provide and operate the Service

  • Authenticate users and workspaces.
  • Maintain Slack and other integrations you enable.
  • Execute tasks, respond to requests, generate outputs, and provide context continuity in Viktor.

B. AI processing to generate outputs

  • Relevant portions of Customer Data may be processed by AI systems to produce responses, reports, and other outputs at your direction.
  • We do not use Customer Data for advertising.
  • We do not train our own or third-party foundation models on Customer Data, and we do not permit AI providers to do so.
  • We may use Customer Data to develop internal, service-specific quality models — for example, a model-selection router that chooses which AI provider serves a given request. These internal models are narrow classifiers used solely to operate and improve the Service, are not general-purpose AI models, do not generate content, and are never made available to third parties.

C. Maintain security, safety, and integrity

  • Detect and prevent fraud, abuse, and unauthorized access.
  • Investigate incidents and maintain audit trails where appropriate.

D. Service improvement (aggregated or de-identified)

We may use aggregated or de-identified data (that cannot reasonably identify you) to understand usage patterns and improve reliability and product experience.

E. Communications

  • Send service-related communications (e.g., product updates, security notices, billing/administrative messages).
  • Provide customer support.

F. Analytics, advertising, and attribution

  • Measure product and website usage, campaign performance, and conversion events.
  • Associate referrals, partner programs, and discount programs with subscriptions and billing records.
  • Prevent abuse, fraud, and misuse of marketing/referral programs.

G. Compliance and protection

Comply with legal obligations and enforce our Terms of Use, and protect the rights, safety, and property of our users and Zeta AI.

4. How We Disclose or Share Information

We do not sell your personal data for monetary consideration.

We may share certain identifiers and usage data with analytics, advertising measurement, and attribution partners to operate and improve the Service. Depending on your jurisdiction, this may be considered a "sale," "sharing," or "targeted advertising," and you may have rights to opt out.

We share information only as necessary to provide and support the Service, and subject to appropriate safeguards:

A. Service providers (subprocessors)

We use vendors to host and operate the Service and its infrastructure (for example, hosting, storage, monitoring, communications, support tooling, and billing). These providers may process Customer Data on our behalf solely to provide, secure, and support the Service.

Current subprocessors:

SubprocessorService / PurposeData Potentially Processed
SlackCore platform integration (OAuth, messaging, app functionality)Slack messages and metadata in channels/DMs where Viktor is used
AWS (Amazon Web Services)Underlying cloud infrastructure for certain providers; Amazon Bedrock model inferenceService data and prompts routed via Bedrock (as configured)
CloudflareCDN, DDoS protection, edge security, object storage (R2), and AI inference (Workers AI, where selected)Network metadata, request logs, stored files and generated artifacts, prompts for Workers AI-served models
ModalPrimary application compute, sandbox execution, and file storage volumesCustomer Data processed and stored by the Service (US regions)
VercelWeb hosting / frontend infrastructureRequest metadata, logs, and content required to serve the app
StripePayments and billingBilling contact info, transaction metadata (payment details handled by Stripe)
Google (Gmail/Drive/Calendar/Sheets/Docs)Integrations (if enabled by customer)Data accessed via integration scopes authorized by customer
Microsoft (Outlook/OneDrive)Integrations (if enabled by customer)Data accessed via integration scopes authorized by customer
HubSpotCRM integration (if enabled by customer)CRM records and metadata authorized by customer
Meta AdsAds integration (if enabled by customer)Ads account and reporting data authorized by customer
Google AdsAds integration (if enabled by customer)Ads account and reporting data authorized by customer
QuickBooksFinance/accounting integration (if enabled by customer)Accounting records authorized by customer
ShopifyE-commerce integration (if enabled by customer)Store, product, order, and customer data accessed via integration scopes authorized by customer
IntercomCustomer support tools (if used)Support communications, identifiers, troubleshooting content
NotionWorkspace/document integration (if enabled by customer)Notion content authorized by customer
Customer.ioCustomer messaging/notifications (if used)Contact details and messaging events (as configured)
MozSEO tooling/integration (if enabled)SEO-related data authorized by customer
BaremetricsMetrics/analytics (business performance)Subscription/usage metrics (typically aggregated)
PostHogProduct analytics (if enabled)Usage events and identifiers (as configured)
AxiomLogging/observabilityLogs and event data (may include identifiers and technical metadata)
BrowserbaseBrowser automationContent accessed during automated browsing tasks (as configured)
BrightDataWeb data access/proxying (if used)Data involved in web research tasks (as configured)
PlanetScaleManaged Postgres database (production)Customer Data stored by the Service: users, workspaces, conversations, tokens, scheduled tasks, billing records (US)
WorkOSSingle sign-on and authenticationAccount identifiers and authentication events
ResendTransactional email deliveryRecipient addresses and email content sent by the Service
PipedreamIntegration connectivity platform (for certain connected tools)OAuth credentials and data transiting customer-enabled integrations
ComposioIntegration connectivity platform (for certain connected tools)OAuth credentials and data transiting customer-enabled integrations
ZapierIntegration connectivity platform (for certain connected tools)Data transiting customer-enabled integrations; related OAuth credentials are held by Zapier
ConvexHosted backends for Viktor Spaces applicationsData stored by customer-created Spaces apps

B. AI technology partners

When you invoke AI features, relevant portions of data (e.g., the prompt/context needed to generate an output) may be sent to third-party AI providers to generate responses. We require these providers to use your data only to provide the requested service to you and not for advertising or training their general models.

AI provider details:

  • AI providers used: The Service routes AI workloads to the following providers, depending on the features used and the models selected for your workspace:
  • Anthropic — core language models (accessed directly and through Google Cloud Vertex AI and Amazon Bedrock).
  • OpenAI — language models, embeddings, image and video generation, and audio transcription (accessed directly and through Microsoft Azure OpenAI Service).
  • Google — Gemini language models and embeddings; Imagen and Veo image and video generation.
  • Together AI — optional or legacy chat models (used only if selected for your workspace).
  • Cloudflare Workers AI — optional or legacy chat models (used only if selected for your workspace).
  • fal.ai — image and video generation (used only when media-generation features are invoked).
  • xAI — video generation (used only when media-generation features are invoked).
  • Fireworks AI — image generation (used only when media-generation features are invoked).
  • ElevenLabs — voice synthesis and speech-to-text (used only when voice features are invoked).
  • Groq — audio transcription (used only when transcription features are invoked).
  • Current list: The authoritative, current list of AI providers is maintained in our Trust Center and updated in accordance with the subprocessor-change process in the DPA.
  • Data residency: AI providers process data in the United States or other regions used by those providers in accordance with their enterprise/API terms.
  • Data retention by AI providers: AI providers may temporarily retain data in accordance with their API retention policies for security and abuse monitoring. Data is not used for model training.
  • Data tenancy: Your data is processed in isolated API requests and is not shared with or visible to other customers.
  • No training: Your data is not used to train or improve AI provider models.

C. Analytics

We may use analytics, advertising measurement, and attribution tools (for example, PostHog, Google services, Meta, TikTok, Reddit, X, LinkedIn, and referral/attribution partners such as Dub and Rewardful, where enabled) to understand usage, attribute signups/subscriptions, and improve the Service. These tools may receive online identifiers, event metadata, and referral/campaign data. We do not use Slack message content for advertising. You can manage cookies through your browser settings and can contact us regarding workspace-level controls where feasible.

D. Slack platform

The Service integrates with Slack via Slack OAuth 2.0 and Slack APIs. Your use of Slack is subject to Slack's terms and privacy policy. We access Slack data only after you grant permission through Slack's OAuth consent screen, and you can revoke access at any time in Slack App Management. We affirm that Slack APIs are not used to develop, improve, or train generalized AI and/or ML models.

E. Legal compliance and protection

We may disclose information if required by law or valid legal process, or when we believe disclosure is necessary to:

  • Comply with legal obligations,
  • Protect the rights and safety of users and the public,
  • Prevent fraud or abuse, or
  • Enforce our Terms of Use.

F. Business transfers

If Zeta AI is involved in a merger, acquisition, restructuring, financing due diligence, bankruptcy, or sale of assets, information may be disclosed to advisors and successor entities, subject to appropriate confidentiality protections.

G. Third-party links

The Service may link to third-party websites/services. We are not responsible for their privacy practices.

H. Shopify platform

The Service integrates with Shopify via Shopify OAuth 2.0 and Shopify's Admin GraphQL API. Your use of Shopify is subject to Shopify's terms and privacy policy. We access Shopify data only after you grant permission through Shopify's OAuth consent screen, and you can revoke access at any time by uninstalling the Viktor app from your Shopify admin. We affirm that Shopify APIs are not used to develop, improve, or train generalized AI and/or ML models, and we do not sell or share Shopify data for advertising.

5. Data Storage and Security

A. Data center location

United States.

B. Data storage and hosting

Customer Data is stored with reputable cloud service providers in U.S. regions, using encryption at rest and in transit, access controls, and service monitoring appropriate to the nature of the data.

C. Security measures

We maintain industry-standard safeguards, including:

  • Encryption in transit (TLS 1.2+ / 1.3),
  • Encryption at rest (AES-256 with cloud-provider key management),
  • Access controls (RBAC, MFA, least-privilege access),
  • Audit logging and monitoring,
  • Incident response processes, including notification to affected customers and/or authorities where required by applicable law.

You are responsible for maintaining appropriate security in your Slack workspace (e.g., limiting channel access, managing Slack admin permissions).

6. Data Retention

We retain Customer Data only as long as needed to provide the Service, meet contractual obligations, and comply with law.

A. Active production systems

When an account is closed or we receive a validated deletion request, we delete Customer Data from active production systems typically within ~30 days.

B. Backups

Encrypted backups are used only for business continuity. Remaining copies are removed as encrypted backups age out on their normal rotation (currently ~35 days), after which they are automatically overwritten or purged.

C. Exports

Where legally permitted, customers may request an export prior to deletion.

D. Derived data

Derived or transformed data (such as indexes, embeddings, or other internal representations) will be deleted or disassociated from Customer Data when the underlying Customer Data is deleted, subject to backup retention and legal obligations.

7. Your Rights and Choices

Depending on your location, you may have the following rights:

A. Access and correction

You can request access to personal data we hold about you and request correction of inaccurate or incomplete data.

B. Deletion

You may request deletion of your personal data (including workspace files, conversation threads, and related records). For workspace-level Customer Data, we may require the request to come from an authorized workspace administrator or account owner, or we may direct individual members to their workspace administrator where appropriate.

Upon receiving a verifiable deletion request, we will delete Customer Data from active production systems typically within ~30 days, and backups will age out on their normal rotation (currently ~35 days).

C. Withdrawal of consent / disconnecting Slack

You can revoke Viktor's access to Slack at any time via Slack App Management. After revocation, we stop collecting new Slack data immediately. Revoking access or uninstalling does not by itself delete previously stored data. If your account is deleted or closed, or we receive a verifiable deletion request, we delete previously stored data in accordance with Section 6 (Data Retention). You can also contact us to request deletion.

D. Marketing preferences

If you opt in to marketing communications, you can opt out at any time via unsubscribe links or by contacting us. You will still receive essential service communications.

E. Data portability (where applicable)

Where required by law (e.g., GDPR), you may request a copy of your data in a machine-readable format.

F. Authorized agents (where applicable)

If permitted by law (e.g., certain U.S. states), you may designate an authorized agent to submit requests on your behalf; we will verify identity and authority as required.

G. U.S. state privacy rights (where applicable)

Residents of certain U.S. states may have rights to know, access, delete, correct, and opt out of certain data uses, including "sale," "sharing," or targeted advertising as defined under applicable law. You may exercise these rights by contacting us at support@viktor.com. We will not discriminate against you for exercising applicable privacy rights.

To help us process your request, please provide sufficient information for verification (and, if applicable, authorized agent authorization). After receiving a verifiable request, we will respond within the timeframe required by applicable law (typically within 45 days, or with a permitted extension where allowed by law and notice is provided).

If we deny your request in whole or in part, you may appeal by contacting support@viktor.com with "Privacy Appeal" in the subject line within the period required by applicable law. We will review and respond to appeals within the timeframe required by applicable law.

H. Additional EEA/UK rights (where applicable)

If you are located in the EEA or UK, you may also have the right to object to certain processing, request restriction of processing, and lodge a complaint with your local supervisory authority.

To exercise rights, contact us at support@viktor.com.

8. Children's Privacy

The Service is not intended for children and we do not knowingly collect personal data from anyone under the age of 18 (or the age of majority in their jurisdiction, if higher). If we learn we have collected such data, we will delete it promptly. Contact support@viktor.com if you believe a child has provided personal data.

9. International Users and GDPR/UK GDPR

Zeta AI, Inc. is based in the United States and may process personal data in the U.S. If you are located in the EEA/UK, we process personal data under one or more legal bases, including:

  • Performance of a contract (providing the Service you request),
  • Consent (e.g., Slack installation via OAuth and certain non-essential cookies/advertising technologies where required),
  • Legitimate interests (security, fraud prevention, and improving reliability and product analytics where permitted), balanced against your rights.

Where required for cross-border transfers, we use appropriate safeguards (such as Standard Contractual Clauses).

Our EU representative under Article 27 GDPR is identified in the Data Processing Agreement (Annex I). If required by applicable law, we will appoint a UK representative and update this Policy accordingly.

10. Slack Marketplace Compliance

Viktor accesses the following Slack data:

Data TypePurpose
Messages in channels where Viktor is invitedProcess requests and provide AI assistance
Direct messages to the botRespond to direct interactions
Thread repliesMaintain context for requested actions
User profile informationIdentify users and personalize responses
Channel informationUnderstand context and permissions
File metadata and files (if you request)Process attachments and uploads/downloads

Our commitments

  • We use Slack data only to provide and operate the Service.
  • We do not sell Slack data.
  • We do not use Slack data for advertising.
  • We affirm Slack APIs are not used to develop, improve, or train generalized AI/ML models.
  • We do not train our own or third-party foundation models on Customer Data.

Revoking access

You can uninstall Viktor or revoke access at any time in Slack App Management. After revocation, we stop collecting new Slack data immediately. Uninstalling or revoking access does not by itself delete previously stored data. If your account is deleted or closed, or we receive a verifiable deletion request, we delete previously stored data in accordance with Section 6 (Data Retention).

11. Shopify Marketplace Compliance

Viktor accesses the following Shopify data on behalf of merchants who have explicitly connected their Shopify store:

Data TypePurpose
Products, variants, inventory, locationsAnswer merchant questions about catalog and stock; perform updates the merchant requests
Orders, draft orders, fulfillments, returns, refundsOrder lookup, status questions, fulfillment and refund operations the merchant requests
Customer records (name, email, phone, addresses, marketing consent, order history)Customer service workflows the merchant requests (e.g., look up an order by email, update a shipping address, check consent status)
Store configuration (discounts, metaobjects, files, translations, markets, locales, themes)Merchandising and store-operations tasks the merchant requests
Aggregate analytics (ShopifyQL)Sales and operations questions from the merchant

Our commitments

  • We use Shopify data only to provide and operate the Service for the connected merchant.
  • We do not sell Shopify data.
  • We do not use Shopify data for advertising.
  • We affirm Shopify APIs are not used to develop, improve, or train generalized AI/ML models.
  • We do not train our own or third-party foundation models on Shopify data.
  • We do not persist Shopify customer, order, or store data. Each request fetches the data needed to answer the merchant's question, processes it in memory, returns the response, and discards it. Only OAuth tokens are persisted. Tokens are stored with strict access controls and encrypted at rest at the infrastructure layer, with retention aligned to Shopify's expiring offline tokens (60-minute access tokens, 90-day refresh tokens).

Compliance webhooks

Viktor implements the three GDPR-mandated Shopify webhooks (customers/data_request, customers/redact, shop/redact). Each webhook is verified against Shopify's HMAC-SHA256 signature before processing; unsigned or forged webhooks are rejected. Because Viktor does not persist Shopify customer data, its response to customers/data_request is "no stored customer data" and customers/redact is processed as a no-op. On shop/redact (sent 48 hours after uninstall), Viktor invalidates its stored OAuth tokens for that shop.

Revoking access

A merchant may uninstall Viktor or revoke access at any time from their Shopify admin. After revocation, Viktor stops collecting new Shopify data immediately. Uninstalling or revoking access does not by itself delete previously stored data (which for the Shopify integration is only OAuth tokens). If the account is deleted or closed, or a verifiable deletion request is received, previously stored data is deleted in accordance with Section 6 (Data Retention).

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by appropriate means (e.g., notifying workspace administrators and/or emailing the address associated with the account). The "Last Updated" date reflects the most recent revision. Your continued use of the Service after changes become effective indicates acceptance of the revised policy.

13. Contact Us

If you have questions or requests regarding this Privacy Policy or our data practices, contact:

Email: support@viktor.com

Address: Zeta AI, Inc. 2810 N Church St, PMB 20589 Wilmington, Delaware 19802, USA

Get Started for Free