01Who we are
Zevian (“Zevian”, “we”, “us”) is operated by Kishan Ashokbhai Kushwaha, a sole proprietor based in Umang Flats, Kanakpur Kansad, Sachin, Surat 394230, Gujarat, India. For the purposes of the Digital Personal Data Protection Act, 2023 (India) we are the data fiduciary, and for the GDPR we are the controller of the personal data described here.
This policy covers the marketing site at zevian.tech and the Zevian application at app.zevian.tech. Contact: support@zevian.tech.
02What we collect
Account data
When you sign in with GitHub or Google we receive your name, email address, profile picture, and the account identifier from that provider. We do not receive or store your password.
Data from services you connect
- GitHub. Through the GitHub App you install, we read the repositories you select (files, branches, and pull request metadata) and open branches and pull requests on them. We only access repositories you grant.
- Google Search Console and Bing Webmaster Tools. Read-only performance data for properties you connect: queries, pages, clicks, impressions, click-through rate, position, and indexing status.
- Cloudflare. With an API token you create, we read the zone that serves your site and its AI bot settings, and change only the AI crawler policies you apply in Zevian and one custom rule Zevian manages. Disconnecting removes that rule and deletes the token.
- Your website. Public pages of the domains you add, fetched by our crawler to run SEO, GEO, and AEO checks.
Workspace and usage data
Workspace and project names, domains, prompts you choose for AI visibility tracking and the answers returned, audit results, pull request history, invitations, and the actions taken in your workspace.
Billing data
Payments are handled by Dodo Payments, our Merchant of Record. Dodo collects your card or other payment details, billing name, address, and tax information. We never see or store your full card number. We keep the subscription status, plan, billing email, and payment references Dodo sends back to us so we can grant access and support you.
Technical data
IP address, browser and device type, pages requested, timestamps, and error logs. We use these to keep the service secure, diagnose problems, and limit abuse.
Messages you send us
Your name, email address, and message when you use the contact form, write to our support address, or sign up for product updates.
03How we use it
- To provide the service: run audits, prepare and open pull requests, and measure impact.
- To create and secure your account, and to administer your subscription with Dodo Payments.
- To answer support requests and send service messages such as audit results, pull request notices, and billing or security alerts.
- To detect, prevent, and investigate abuse, fraud, and security incidents.
- To meet legal, tax, and accounting obligations.
- To improve the product using aggregated or de-identified usage information.
We do not sell your personal data, we do not use it for third-party advertising, and we do not use your repository contents or Search Console data to train AI models.
Legal bases (GDPR). Performance of a contract (providing the service), legitimate interests (security, abuse prevention, product improvement), legal obligation, and consent where we ask for it. Under the DPDP Act we process data with your consent or for the legitimate uses the Act permits.
04Who we share it with
We share personal data only with service providers that help us run Zevian, under terms that limit their use of it:
| Provider | Purpose |
|---|---|
| Dodo Payments | Merchant of Record: checkout, payments, taxes, invoices, refunds, and fraud screening. |
| GitHub, Google | Sign-in and access to the repositories and Search Console properties you connect. |
| Google (Gemini API) | Generates fix proposals and answers to the AI visibility prompts you choose. We send only the content needed for that task. |
| Microsoft (Bing Webmaster Tools) | Search performance data for properties you connect. |
| Cloudflare | AI crawler settings for the zone you connect. |
| Email delivery provider | Sends service messages and delivers contact and support messages. |
| Hosting and infrastructure providers | Servers, databases, backups, and background job processing. |
We may also disclose data when required by law or a valid legal request, to protect rights and safety, or as part of a business transfer, in which case we will tell you.
05International transfers
We are based in India, and our providers may process data in other countries, including the United States and the European Union. Where required, we rely on contractual safeguards or on the transfer mechanisms of the relevant provider. Transfers of personal data outside India are made only to the extent permitted under the DPDP Act and its rules.
06How long we keep it
- Account and workspace data: while your account is active, then deleted or anonymised within 30 days of a verified deletion request.
- Audit and measurement history: while the project exists, and removed with the rest of your data on a verified deletion request.
- GitHub access: Zevian stores no GitHub access tokens. It creates a short-lived token for each job and keeps only a record of the installation, until you uninstall the GitHub App.
- Billing and tax records: as long as the law requires (typically up to 8 years in India).
- Security and server logs: up to 90 days.
- Contact and support messages: up to 2 years.
Backups are overwritten on a rolling schedule, so removed data may persist in backups for a short time before it is destroyed.
08Security
We protect data with encryption in transit (HTTPS), encryption of stored access tokens, access controls limited to what each person needs, audit logging of administrative actions, and multi-factor authentication for the admin console. No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority as the law requires.
Zevian never merges code on its own. Every change reaches your repository as a pull request that you review, and you can revoke our access at any time.
09Your rights and choices
Depending on where you live (including under the DPDP Act, the GDPR, and the CCPA), you may have the right to:
- access a summary of the personal data we hold about you and how it is used;
- correct or update inaccurate or incomplete data;
- have your data erased, subject to legal retention duties;
- withdraw consent at any time, which does not affect earlier processing;
- object to or restrict certain processing, and receive your data in a portable format;
- nominate another person to exercise your rights in the event of death or incapacity (DPDP Act);
- complain to a data protection authority, including the Data Protection Board of India.
To exercise a right, email support@zevian.tech from the address on your account. We may ask you to verify your identity, and we respond within 30 days.
Disconnecting services
You can remove our access at any time: uninstall the Zevian GitHub App in your GitHub settings, revoke access under “Third-party access” in your Google account, or disconnect the integration inside the app. To delete your account and workspace data, email us from the address on your account.
10Children
Zevian is a business tool for people aged 18 and over. We do not knowingly collect personal data from children. If you believe a child has given us data, email us and we will delete it.
11Grievance officer
In line with the Information Technology Act, 2000 and the DPDP Act, 2023, you can raise a complaint about how your data is handled with our grievance officer:
Kishan Ashokbhai Kushwaha
Umang Flats, Kanakpur Kansad, Sachin, Surat 394230, Gujarat, India
Email: support@zevian.tech
Phone: +91 63554 49195 (Monday to Saturday, 10:00 to 18:00 IST)
We acknowledge complaints within 48 hours and aim to resolve them within 30 days.
12Changes to this policy
We may update this policy as the product or the law changes. The date at the top shows the latest version. For material changes we will email account holders or show a notice in the app before they take effect.