Privacy Policy
Last updated: February 14, 2026
1. Introduction
ZeroDrift, Inc. ("the Company," "we," "us," or "our") operates zerdorift.com and the ZeroDrift AI compliance middleware service (the "Service"). ZeroDrift sits between your application and its AI model, intercepting every response and checking it against your active compliance policies in real time. This Privacy Policy explains what personal information we collect through the Service and this website, how we use it, and the choices available to you.
The Company is headquartered at 475 Brannan Street, Suite 220, San Francisco, CA 94107 and can be reached at [email protected].
This policy covers two distinct contexts: (a) information collected from visitors to zerdorift.com and prospective customers who contact the Company, and (b) data processed on behalf of enterprise customers who have deployed the ZeroDrift middleware and submit API requests through the Service. If you are an enterprise customer, your data processing relationship with the Company is also governed by the applicable Order Form and Data Processing Agreement you have entered with us.
2. Information We Collect
2.1 Information You Provide
We collect information you submit directly, including:
- Contact details (name, work email, phone) when you fill out a demo request, contact form, or subscribe to the Compliance Journal;
- Company information you choose to share (employer, role, technical context, use-case description);
- Account credentials (email and hashed password) when you create a ZeroDrift account;
- API integration details such as policy rule configurations you create within the Service;
- The content of any support messages or compliance inquiries you send us.
2.2 Information Collected Automatically
When you visit zerdorift.com, we automatically collect limited technical information:
- IP address and approximate location (city/region level);
- Browser type, operating system, device class;
- Pages visited, referring URLs, time on page;
- Cookie and similar identifiers (see Section 5 and our Cookie Policy).
2.3 Data Processed Through the Middleware API
When an enterprise customer's application routes AI model requests through ZeroDrift, the Service processes the prompt-and-response pairs submitted via the API in order to evaluate them against the customer's active compliance policies. This data is processed solely to perform policy evaluation, generate compliance decisions (pass, rewrite, or flag), and produce the tamper-proof audit log entries the customer has enabled. The Company does not use prompt-and-response content submitted through the middleware to train, fine-tune, or benchmark any AI or machine-learning model without explicit written consent from the enterprise customer. Data within the intercept window is not stored beyond the period necessary to complete the policy evaluation, unless the customer has enabled audit logging, in which case it is retained subject to the customer-controlled retention window configured in the account settings.
2.4 We Do Not Knowingly Collect Children's Data
zerdorift.com is not directed to children under 13. The Company does not knowingly collect personal information from children. If you believe a child has provided the Company with information, contact [email protected] and we will delete it promptly.
3. How We Use Information
ZeroDrift is an enterprise developer tool; we do not build consumer data profiles or monetize personal information. We use the information we collect to:
- Respond to sales inquiries, provide requested demos, and onboard enterprise accounts;
- Operate, maintain, and improve the middleware Service and API infrastructure;
- Deliver the Compliance Journal and (with your consent where required) product update communications;
- Generate and deliver audit log entries and policy violation reports to enterprise customers who have enabled those features;
- Detect, investigate, and prevent fraud, abuse, or unauthorized access to the API;
- Comply with applicable legal and regulatory obligations.
We do not sell personal information for monetary value. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see the California section below.
4. Sharing of Information
We share personal information only with:
- Infrastructure and service providers acting on our behalf (cloud hosting, transactional email, self-hosted analytics) under written contractual confidentiality obligations that prohibit them from using the data for their own purposes;
- Government or law enforcement authorities, when required by applicable law, court order, or legal process, or when necessary to protect the rights, safety, or property of the Company or others;
- A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy and any obligations under applicable law.
The Company does not sell personal information to third parties and does not share it with third parties for cross-context behavioral advertising.
5. Cookies and Tracking
We use cookies and similar technologies to operate this site, remember preferences, and measure usage with self-hosted, anonymized analytics. We do not use third-party advertising trackers or behavioral profiling on zerdorift.com. For details and opt-out options, see our Cookie Policy.
6. Data Retention
For website visitor data, the Company retains personal information only as long as needed for the purposes described, to comply with legal or accounting obligations, and to resolve disputes. Inactive marketing-list contacts are purged after 24 months. Server access logs are retained 90 days, then aggregated.
For enterprise middleware customers, retention of API-processed data is governed by the customer-configured audit log retention window (configurable in account settings). The Company does not retain prompt-and-response content beyond that window. Account data is retained for the duration of the active account relationship and for a period of 90 days following account closure, after which it is deleted, except where a longer retention period is required by law.
7. Security
The Company uses administrative, technical, and physical safeguards designed to protect personal information. The Service runs on AWS (us-east-1) infrastructure with TLS 1.3 for data in transit, AES-256 encryption for data at rest, network isolation per tenant, and least-privilege access controls. No system is perfectly secure; the Company cannot guarantee absolute security and recommends that enterprise customers also review the security page at zerdorift.com/security.
8. Your General Rights
Depending on your jurisdiction, you may have rights including access, correction, deletion, and the ability to limit certain processing. To make a request, email [email protected] with the subject line "Privacy Rights Request." The Company will respond within the timeframe required by applicable law.
9. California Residents (CCPA / CPRA)
Under the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA"), California residents have specific rights regarding personal information collected about them. This section supplements the rest of this Policy.
9.1 Categories We Collect
In the past 12 months, the Company has collected the following categories of personal information as defined under Cal. Civ. Code §1798.140: identifiers (name, email, IP address); professional or employment-related information (employer, role, use-case context submitted through contact forms); commercial information (service inquiries and account subscription records); internet activity (browsing on zerdorift.com); and inferences drawn from the above for service-improvement purposes. The Company does not collect sensitive personal information as defined under CPRA §1798.140(ae) from California residents through this website or in the ordinary course of the Service.
9.2 Sources, Purposes, Disclosure
The Company obtains this information from you directly and through automatic site instrumentation. We use it to operate and improve the Service, communicate with you about the ZeroDrift compliance middleware, and meet legal obligations. We disclose it only to service providers under written contract as described in Section 4, and to legal authorities where required.
9.3 Your CCPA / CPRA Rights
- Right to Know: request the categories and specific pieces of personal information the Company has collected about you in the past 12 months.
- Right to Delete: request deletion of personal information the Company collected from you, subject to legal exceptions.
- Right to Correct: request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing: the Company does not sell personal information; the Company does not "share" it for cross-context behavioral advertising as defined under CPRA.
- Right to Limit Use of Sensitive PI: the Company does not use sensitive personal information for purposes beyond those permitted without authorization.
- Right to Non-Discrimination: the Company will not deny services, charge different prices, or provide a different level of service because you exercised a right.
9.4 How to Exercise
Submit a verifiable request by emailing [email protected] with the subject line "California Privacy Request." Include enough detail for the Company to verify you are the person whose information is the subject of the request. The Company responds within 45 days, with a possible 45-day extension for which it will notify you.
9.5 Authorized Agents
You may designate an authorized agent to make a request on your behalf. The agent must provide proof of authorization; the Company may also require you to verify your identity directly.
9.6 "Shine the Light"
California Civil Code §1798.83 entitles California residents to request information regarding the Company's disclosure of personal information to third parties for direct marketing. The Company does not disclose personal information for third-party direct marketing.
9.7 Do Not Track and Global Privacy Control
Under the California Online Privacy Protection Act (Cal. Bus. & Prof. Code §22575), we disclose how we respond to "Do Not Track" (DNT) browser signals. Because there is no common industry standard for interpreting DNT signals, we do not currently respond differently to them. We do not authorize third parties to collect personally identifiable information about your activity across different websites when you use the Service. We honor an opt-out preference signal sent by a platform or browser that complies with the CPRA, such as the Global Privacy Control (GPC); when we detect a GPC signal, we treat it as a valid request to opt out of the sale or sharing of personal information for that browser or device.
10. Changes to This Policy
The Company may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service.
11. Contact
Questions, requests, or complaints about this Privacy Policy can be sent to:
ZeroDrift, Inc.475 Brannan Street, Suite 220, San Francisco, CA 94107
Email: [email protected]
Phone: +1 (415) 490-0187