Security First

Your Data,
Protected

We take security seriously. Here's exactly how we protect your memories.

Encryption Standards

How your data is secured at every step

πŸ” In Transit (TLS 1.3)

All data between your browser and our servers is encrypted using TLS 1.3, the latest security protocol. This is the same standard used by banks and financial institutions.

πŸ—„οΈ At Rest (AES-256)

Your memories are encrypted using AES-256 when stored in our database. This military-grade encryption ensures that even if someone gained access to our servers, they couldn't read your data without the encryption keys.

⚠️ Important Clarification

Server-side encryption: ZDRAVO uses server-side encryption (not end-to-end). This means we technically can access your data for operations like semantic search, auto-tagging, and generating summaries. We never do this except as required by law or to provide the service you requested.

Data Residency

Where your data lives

πŸ‡ΊπŸ‡Έ United States

Primary data center: AWS US-East (N. Virginia). All data is stored here by default.

πŸ‡ͺπŸ‡Ί EU Region (Coming Q2 2026)

GDPR-compliant EU data center option for Enterprise customers.Contact us for early access.

Compliance & Certifications

Our commitment to standards

βœ“

GDPR Compliant

Right to access, delete, and export your data. Data Processing Agreements available for Teams tier.

β†’

SOC 2 Type II (In Progress)

Audit scheduled for Q3 2025. Estimated certification: Q4 2025.

β—‹

CCPA (Planned)

California privacy compliance roadmap: Q1 2026

Privacy Policy

What we collect and why

We collect: Your saved conversations, email (for auth), usage analytics (anonymized), and payment info (via Stripe - we never see your card details).

We do NOT collect: Your browsing history outside AI platforms, personal identifiers beyond email, or sell any data to third parties.

Third parties: We use Supabase (database), Vercel (hosting), Stripe (payments), and OpenAI (embeddings for semantic search only - no conversation content sent).

Read Full Privacy Policy β†’

Service Level Agreement

Our uptime commitment

99.9%

Monthly Uptime Guarantee

βœ“ Max 43 minutes downtime per month

βœ“ Real-time status: status.zdravoai.com

βœ“ Service credits if we fall short (Pro/Teams only)

βœ“ Incident response: <15 minutes during business hours

Questions about security?

Contact security@zdravoai.com