Privacy Policy
Last updated: July 31, 2026 · Effective: July 31, 2026
This Privacy Policy describes how Jaden Digital Pty Ltd (ABN 66 160 378 058) trading as zero8 ("we", "us", or "our") collects, uses, shares, and protects your personal information when you use our website at zero8.ai, our application, our APIs, and the websites we publish and host on behalf of our customers (collectively, the "Service"). This Privacy Policy should be read alongside our Terms of Service.
This policy covers two groups of people. Customers are people who create a zero8 account and use it to build, publish, and promote websites. Visitors are people who visit a website one of our customers published through zero8, and who may submit a form on it. For most visitor information, our customer decides what is collected and why, and we handle it on their behalf — see Section 8.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use the Service.
1. Information We Collect
1.1 Account Information
When you create an account, we collect your name, email address, and password (or authentication credentials from a third-party provider such as Google, LinkedIn, or Microsoft). We also store whether your email address has been verified and your profile image if you provide one.
1.2 Organisation Information
If you create or join an organisation, we collect the organisation name, logo, member roles, and invitation details (including the email addresses of people you invite).
1.3 Payment and Billing Information
When you subscribe to a paid plan, payment information is collected and processed by our third-party payment processor, Stripe. We store a reference to your Stripe customer ID and subscription details (plan, status, billing interval, and period dates) but do not store your full credit card number, bank account number, or other sensitive payment credentials on our servers.
1.4 Project and Content Data
We collect and store the content you create and upload through the Service, including:
- Project titles, design concepts, page layouts, style settings (colours, fonts), and page metadata (titles, descriptions, favicon).
- Files you upload (PDF, DOCX, TXT, images, and URLs), including text extracted from those files to generate your pages.
- Briefing conversation responses and brand kit information you provide during the AI-guided design process, including your business type, location, services, audience, and tone of voice.
- Published page content hosted on zero8.live subdomains, registered domains, or your custom domains, including blog posts.
1.5 Websites You Ask Us to Read
When you give us a website address — your own, a client's, or a reference site — we fetch that page and extract its branding, copy, and business context so we can build from it. We store what we extracted against your project.
1.6 AI Conversations and Generation Records
We store transcripts of your briefing, generation, editing, and promotion conversations with our AI, together with the prompts, tool calls, and model outputs involved, and a record of the tokens and credits each action consumed. See Section 12 for how AI providers handle this content.
1.7 Domain Information
If you connect or register a domain, we store the domain name, DNS configuration, nameservers, SSL certificate status, registration and expiration dates, and related technical identifiers necessary to serve your published pages.
Registering a domain through us additionally requires registrant contact details — name, postal address, email address, and phone number. We pass these to our domain registrar and, as ICANN requires, to the relevant domain registry. Depending on the top-level domain and the privacy settings available for it, some of these details may appear in public WHOIS records.
1.8 Form Submission Data
If you enable forms on your published pages, we collect and store submissions on your behalf, including the form fields, the submitter's IP address, user agent, referrer URL, UTM parameters, country, city, device type, browser, and a session identifier. We also run basic spam detection on submissions. You are the data controller for this information — see Section 8 for more details.
1.9 Published Page Analytics
Pages you publish through zero8 include privacy-friendly analytics that record aggregate visitor numbers, page views, referrers, device type, and country without setting cookies, without collecting personal information, and without tracking visitors across sites. We make these figures available to you in your dashboard.
1.10 Usage and Analytics Data
Where you have consented to analytics cookies (see Section 5), we collect information about how you interact with the Service, including:
- Pages visited, features used, clicks, form interactions, and navigation patterns, including automatically captured interface events, heatmaps, and signals such as repeated or unproductive clicks.
- Token and credit usage (which actions consume credits and when).
- Device type, browser type, operating system, and screen resolution.
- IP address, approximate geographic location, and referring URL.
- Session recordings, with all text you type into form fields masked, to help us understand and improve the user experience. These recordings may also include browser console output for debugging purposes.
If you decline analytics cookies, none of the information in this section is collected.
1.11 Anonymous Use Before Sign-Up
You can start a brief and generate a page before creating an account. When you do, we create an anonymous record so your work is not lost, and we link it to your account if you later sign up.
1.12 Device Identifier for Abuse Prevention
When you sign up and when you generate pages, we calculate a device identifier from your browser and device characteristics. We use it solely to prevent abuse of free trials and generation limits. We do not use it for advertising and we do not use it to track you across other websites.
1.13 Server Logs and Performance Data
Our servers record request logs, error traces, performance metrics, and background job records. These include IP addresses, timestamps, the parts of the Service being called, and internal identifiers. We use them to operate, debug, and secure the Service.
1.14 Feedback
If you submit feedback through the Service, we collect the content of that feedback along with the identifiers needed to follow it up with you.
1.15 Session and Authentication Data
When you sign in, we create a session record that includes your IP address, user agent string, session token, and the organisation you are currently active in. Sessions expire automatically after a period of inactivity.
1.16 Support Interactions
If you contact us through our in-app support chat, we collect the messages you send and any associated session information to provide and improve our support.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service, including AI-powered design generation, page publishing, and domain management.
- Process payments and manage your subscription.
- Authenticate your identity and manage access to your account and organisations.
- Generate and optimise your website content using AI, based on the information and files you provide.
- Manage advertising campaigns and promotion features on your behalf, where you have enabled them.
- Send you transactional communications (account verification, password resets, billing receipts, and service notifications).
- Analyse usage patterns to improve, debug, and optimise the Service.
- Detect and prevent fraud, abuse, spam, and security threats.
- Comply with legal obligations and respond to lawful requests.
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area or the United Kingdom, we rely on the following legal bases for processing your personal data:
| Processing Purpose | Legal Basis |
|---|---|
| Providing and operating the Service (accounts, projects, publishing, domains) | Performance of contract |
| Processing payments and subscriptions | Performance of contract |
| Authentication and session management | Performance of contract |
| Transactional emails (verification, password resets, billing) | Performance of contract |
| Customer support | Performance of contract |
| Analytics and service improvement (including session recordings) | Legitimate interest |
| Fraud detection, abuse prevention, and security | Legitimate interest |
| Advertising campaign management and promotion features | Consent (you enable the feature) |
| Non-essential cookies (analytics, support) | Consent |
| Legal and regulatory compliance | Legal obligation |
4. How We Share Your Information
We do not sell your personal information. We share your information only in the following circumstances:
4.1 Service Providers
We use third-party service providers to help operate the Service:
- Stripe — payment processing and subscription management. Stripe receives your payment details and billing information. Stripe Privacy Policy
- Cloudinary — file and image hosting. Files you upload are stored and served through Cloudinary. Cloudinary Privacy Policy
- PostHog — product analytics and session recording. PostHog collects usage data including page views, clicks, and masked session recordings to help us understand how the Service is used. PostHog Privacy Policy
- Plausible Analytics — privacy- friendly web analytics for published pages. Plausible collects aggregate visitor data (page views, referrers, device type, country) without using cookies or collecting personal data. Plausible Privacy Policy
- Crisp — customer support chat. Crisp processes messages you send through the in-app support widget. Crisp Privacy Policy
- Cloudflare — DNS management, SSL certificates, and content delivery for published pages.
- Postmark — transactional email delivery (account verification, password resets, invitations).
- OpenRouter — the gateway through which we send your briefing responses, project content, and extracted file and website text to the AI models that generate your pages. See Section 12.
- Perplexity — AI research used during briefing and promotion, which receives your business context and the research questions we ask on your behalf.
- Firecrawl and our own crawling infrastructure — fetching and reading website addresses you give us.
- DataForSEO — keyword, ranking, and search research for promotion features, which receives your business, location, and keyword data.
- Google PageSpeed Insights — performance analysis of your published pages.
- Unsplash — stock image search, which receives search terms derived from your brief.
- Tucows / OpenSRS — domain registration and management, which receives the registrant contact details described in Section 1.7.
- Datadog — application monitoring, logging, and error tracing, which receives the server logs and performance data described in Section 1.13.
- Discord — internal routing of feedback you submit through the Service.
We keep this list current as our providers change. Each provider is bound by an agreement limiting them to processing your information only to deliver their service to us.
4.2 Authentication Providers
If you choose to sign in with a third-party provider (Google, LinkedIn, or Microsoft), that provider shares your name, email address, and profile image with us. We do not share your zero8 data back to these providers beyond what is necessary for authentication.
4.3 Advertising and Promotion Platforms
If you enable promotion features, we share relevant business and campaign information with third-party platforms such as Google Ads and Google Business Profile on your behalf. This sharing is initiated by you and governed by those platforms' respective privacy policies.
4.4 Legal Requirements
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4.5 Business Transfers
If zero8 is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.
5. Cookies and Tracking Technologies
We use cookies and similar technologies for the following purposes:
- Essential cookies — required for authentication, session management, and core Service functionality. These cannot be disabled.
- Analytics cookies — used by PostHog to collect usage data and session recordings. These help us understand how the Service is used and identify areas for improvement.
- Support cookies — used by Crisp to enable the in-app support chat and maintain your conversation history.
- Preference cookies — used to remember your settings, such as your preferred theme (light or dark mode).
Your choice comes first. We do not load analytics, session recording, or the support chat until you tell us we can. On your first visit we show a consent banner offering Accept and Reject as equally weighted, one-click choices. Rejecting is as easy as accepting, and your choice is remembered.
You can change your mind at any time using the Cookie settings link in the footer of the Service, which opens a preference centre where each category can be switched on or off individually. Withdrawing consent takes effect immediately: we stop collecting, end the relevant session, and clear that provider's stored data. You can also manage cookies through your browser settings. Disabling essential cookies will prevent the Service from working.
Published pages are different. Websites built and published with zero8 use cookieless analytics by default and set no tracking cookies on your visitors. If you are a customer and you add your own third-party scripts to your site, you can switch on a consent banner for your site in your site settings. It appears on every page, matches your site's design automatically, and holds non-essential scripts until your visitor accepts. What you choose to add to your site remains your responsibility — see Section 8.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. Specifically:
- Account data is retained for as long as your account exists. When you delete your account, we delete your personal data and take your published pages offline within 30 days. Some data may persist in encrypted backups for up to 90 days.
- Project and content data is deleted when you delete the associated project or your account.
- Form submission data is retained until you delete it or delete the associated project. As the data controller for form submissions, you are responsible for managing retention in compliance with applicable laws.
- Analytics data is retained in aggregated or anonymised form and may persist after account deletion.
- Payment records are retained for 7 years as required by Australian tax and financial reporting obligations.
- AI transcripts and generation records are retained with the project they belong to and are deleted with it.
- Domain registration records are retained for the life of the registration and afterwards for as long as the registrar and registry require.
- Session and security logs are retained for up to 12 months to detect and investigate security incidents.
- Support conversations are retained for as long as needed to handle your enquiry and to keep a history of your prior requests.
7. Data Security
We implement reasonable technical and organisational measures to protect your personal information, including encryption of data in transit (TLS/SSL), encryption of stored credentials and secrets, secure session management, role-based access controls, rate limiting, sanitisation of user-supplied content, and automated abuse detection. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
In the event of a data breach that is likely to result in a risk to your rights, we will notify affected users and relevant authorities (including the Office of the Australian Information Commissioner) as required by the Australian Privacy Act's Notifiable Data Breaches scheme and, where applicable, within 72 hours as required by the GDPR.
If you become aware of any unauthorised access to your account, please contact us immediately at [email protected].
8. Your Role as a Data Controller (Form Submissions)
When you use the form submission feature on your published pages, you are the data controller for any personal data collected from your visitors. We act as a data processor, storing and making that data available to you through the Service.
As a data controller, you are responsible for:
- Providing appropriate privacy notices to visitors of your published pages.
- Obtaining any necessary consent for data collection.
- Responding to data subject requests (access, deletion, rectification) from your visitors.
- Complying with applicable data protection laws, including GDPR, CCPA, and the Australian Privacy Act 1988.
To help you meet these responsibilities, your site settings include a cookie consent banner you can switch on for your published site, and we will assist you in responding to requests from your visitors where the law requires it. Contact us at [email protected] if you need help with a visitor request.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
9.1 General Rights
- Access — you can request a copy of the personal information we hold about you.
- Correction — you can update or correct inaccurate information through your account settings or by contacting us.
- Deletion — you can delete your account at any time through your account settings. You can also request deletion of specific data by contacting us.
- Data portability — you can request your data in a structured, commonly used format.
- Objection — you can object to certain processing of your data, such as processing for analytics purposes.
- Withdraw consent — where we process your data based on consent (such as analytics cookies or promotion features), you may withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
9.2 For Users in the European Economic Area (GDPR)
If you are located in the EEA, you additionally have the right to:
- Restriction of processing — request that we limit how we use your data in certain circumstances.
- Object to automated decision-making — you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Our AI features generate design and content suggestions for your review, but do not make automated decisions that produce legal effects on you.
- Lodge a complaint — you have the right to lodge a complaint with your local data protection authority.
Our legal bases for processing your personal information are detailed in Section 3 above.
9.3 For Users in the United Kingdom (UK GDPR)
If you are located in the United Kingdom, you have equivalent rights to those described in Section 9.2 under the UK GDPR and the Data Protection Act 2018. You may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
9.4 For Users in California (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act and the California Privacy Rights Act:
- Right to know — you can request details about the categories and specific pieces of personal information we collect about you.
- Right to delete — you can request deletion of your personal information.
- Right to correct — you can request correction of inaccurate personal information.
- Right to opt out of sale/sharing — we do not sell or share your personal information for cross-context behavioural advertising. If this changes, we will provide an opt-out mechanism.
- Right to limit use of sensitive personal information — we do not collect sensitive personal information as defined by the CPRA beyond what is necessary to provide the Service.
- Right to non-discrimination — you will not be discriminated against for exercising your CCPA/CPRA rights.
CCPA Required Disclosures
The following table summarises the categories of personal information we collect, as defined by the CCPA:
| Category | Collected | Sources | Purpose | Sold/Shared |
|---|---|---|---|---|
| Identifiers (name, email, IP address) | Yes | You, automatic collection | Service operation, authentication | No |
| Customer records (billing details, subscription info) | Yes | You, Stripe | Payment processing | No |
| Commercial information (purchases, subscriptions) | Yes | You, Stripe | Service operation, billing | No |
| Internet activity (browsing, usage, interactions) | Yes | Automatic collection | Analytics, improvement | No |
| Geolocation data (approximate, from IP) | Yes | Automatic collection | Analytics, security | No |
| Professional information (organisation, role) | Yes | You | Service operation | No |
| Inferences (usage patterns) | Yes | Derived from activity | Service improvement | No |
| Sensitive personal information | No | — | — | No |
9.5 For Users in Australia (Privacy Act 1988)
If you are located in Australia, you have rights under the Privacy Act 1988 and the Australian Privacy Principles (APPs), including the right to access and correct your personal information. If you believe we have breached the APPs, you may make a complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days (or sooner if required by applicable law).
10. International Data Transfers
Your information may be transferred to and processed in countries other than Australia, including countries where our service providers operate (primarily the United States and the European Union). We ensure that appropriate safeguards are in place for any international transfers of personal data, including standard contractual clauses or other mechanisms approved by applicable data protection authorities.
11. Children's Privacy
The Service is not intended for use by anyone under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at [email protected].
12. AI and Your Data
The Service uses artificial intelligence to generate designs, page layouts, content suggestions, and promotional materials based on the information you provide. Your content (including briefing responses, uploaded files, and page content) is processed by AI models to deliver these features.
We reach these models through OpenRouter, and we use Perplexity for AI research during briefing and promotion. The content sent to them includes your briefing responses, text extracted from files you upload, text extracted from websites you ask us to read, and your page content.
We do not use your content to train general-purpose AI models. Your data is used solely to provide the Service to you. Third-party AI providers we use are bound by data processing agreements that prohibit them from using your data for model training.
AI output is a suggestion for you to review. Our AI does not make decisions that produce legal effects for you or similarly significantly affect you. Promotion features act only on changes you have approved, unless you explicitly turn on automatic optimisation.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. If we make material changes, we will notify you by email or by posting a prominent notice on the Service at least 14 days before the change takes effect. Your continued use of the Service after the updated policy takes effect constitutes your acceptance of the changes.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
- Privacy enquiries, data requests, and general support: [email protected]
- Postal address: Jaden Digital Pty Ltd, Level 22, Sydney Place, 180 George St, Sydney NSW 2000, Australia
We aim to acknowledge privacy requests within 5 business days and to respond substantively within 30 days, or sooner where the law requires.
15. Governing Law
This Privacy Policy is governed by the laws of New South Wales, Australia. This does not limit any rights you have under the data protection laws of the country in which you live.