ZexirAI · Account & Security

Security is a shared responsibility.

This policy explains account eligibility, credential and multi-factor safeguards, session handling, shared-device precautions, incident reporting, recovery, and the controls that protect your chats, projects, subscription, and profile.

If you suspect compromise: change the password for your ZexirAI account and its email account, enable or reset multi-factor authentication, sign out of shared devices, review billing activity, and contact support promptly.

1. Scope and shared responsibility

This policy applies to ZexirAI account registration, login, authenticated sessions, multi-factor authentication, profile and billing access, saved chats, project workspaces, data exports, support verification, and security controls. It supplements the Terms of Service and Privacy Policy. It describes safeguards and responsibilities, not a guarantee that incidents can never happen.

ZexirAI is responsible for using reasonable safeguards appropriate to the Service, maintaining server-side access controls, protecting password verifiers, limiting access to user-owned records, responding to credible security reports, and selecting service providers with relevant protections. You are responsible for protecting the credentials, devices, email accounts, networks, integrations, and content under your control and for reviewing sensitive actions before approving them.

Security depends on context. A password can be technically strong but unsafe if reused on a breached site. Multi-factor authentication can be defeated if a user shares a one-time code. Private mode can keep a chat out of ZexirAI history but cannot prevent someone nearby from seeing the screen. Use the combined protections in this policy rather than relying on a single control.

2. Registration and account ownership

Provide a working email address you control, an accurate age, and registration information that is not deceptive. You must be at least 13; there is no upper age limit. Children under 13 may not use ZexirAI, even with parental or guardian permission. A higher local minimum age or guardian authorization may apply to eligible users aged 13 or older. Usernames must comply with product rules and may not impersonate another person, falsely imply affiliation, contain unlawful material, or reserve a name for abusive or speculative purposes. We may require email verification before account creation or sensitive changes.

An individual account belongs to the person or organization authorized to use the verified email and credentials. Paying for another person’s subscription does not automatically transfer ownership. When ownership is disputed, we may consider verified email access, account history, payment records, organization authorization, prior support contacts, and other reliable evidence. We may temporarily restrict sensitive changes while investigating.

Do not create accounts to evade a suspension, obtain duplicate promotional access, bypass quotas, obscure prohibited conduct, or automate activity at a scale not authorized by your plan. Do not buy, sell, lease, or transfer an account without written approval. If your email address, name, or organizational relationship changes, update the account or contact support before you lose access to the existing verification channel.

3. Passwords and authentication credentials

Use a long, unique password that is not used for email, banking, work, or any other service. A reputable password manager can generate and store it. Do not include a password in a prompt, file, screenshot, project, support email, or bug report. ZexirAI personnel should never ask for your password or one-time authentication code. Treat any such request as suspicious.

Password verifiers are protected in the account system so the Service does not need to store ordinary readable passwords. That safeguard does not protect a password stolen from your device, reused elsewhere, captured by phishing, shared with another person, or exposed by malicious browser software. Keep devices patched, use screen locks, review browser extensions, and avoid signing in through links from unexpected messages.

If you use Google or another federated sign-in provider, secure that provider account and review its connected-app permissions. A compromise there may permit access to ZexirAI. Changing a federated-provider password or revoking its sessions may be necessary in addition to ZexirAI actions. Recovery depends on continuing access to verified channels, so maintain current recovery information with the sign-in provider.

4. Multi-factor authentication

Enable multi-factor authentication (“MFA”) when available, particularly if your workspace contains private files, business material, or paid access. MFA adds a second proof beyond the password. ZexirAI may support an authenticator-based secret or another method shown in settings. Store setup secrets and recovery information in a secure password manager or protected offline location, not in the same unprotected file as the password.

Never approve an unexpected sign-in or give a code to someone claiming to be support. A legitimate support process can verify account information without asking you to disclose a current authenticator code. If repeated prompts appear unexpectedly, deny them, change credentials, inspect the device for compromise, and report the event.

Disabling or resetting MFA is a security-sensitive action. We may require fresh authentication, email control, backup proof, billing details that do not expose full card information, or a waiting period. We may decline a reset when evidence is insufficient or conflicting. Recovery convenience cannot take priority over a credible risk of transferring the account to an attacker.

5. Sessions, cookies, browsers, and shared devices

ZexirAI uses authenticated session credentials, including an HTTP-only cookie, so you do not have to send a password with each request. A session has a limited lifetime and may be refreshed, invalidated, or revoked. Anyone who controls an unlocked authenticated browser may be able to read chats, export account data, change settings, use subscription capacity, or reach billing controls.

On a device where you recently signed in, ZexirAI may show the account in a “Choose an account” list. Selecting it can restore the account directly with a signed, purpose-limited browser credential for up to four weeks after authentication. When that four-week period has passed, the credential is missing, invalid, or the account details have changed, ZexirAI requires sign-in again. Remove the remembered account or clear the site’s data to remove this shortcut from the device.

On a shared or public device, use a private browser window if appropriate, do not save the password, avoid downloading sensitive exports, and sign out when finished. Closing a tab may not sign you out. Clear site data if you cannot confirm logout, and remove downloaded files from the device through an appropriately secure process. On your own device, use a screen lock and a separate operating-system profile when others share the hardware.

Do not copy authentication tokens from developer tools, logs, or browser storage or send them to another person. Treat tokens like passwords. Local browser storage may retain interface preferences, selected models, guest identifiers, or other workspace state even after a page is closed. Clearing it can reset the interface, but it does not delete server-stored account content.

6. Protecting chats, files, memory, and exports

Before uploading or pasting content, remove secrets and personal information that the task does not require. Redact access keys, authentication cookies, private keys, passwords, one-time codes, government identifiers, full payment-card data, medical records, client confidences, precise locations, and information about uninvolved people. If a secret is accidentally submitted, rotate or revoke it; deleting a chat is not an adequate substitute for credential rotation.

Standard signed-in chats are saved and appear in history. Project folders and files are also associated with the account. Shared-memory features may insert selected material from another chat into the current model request. Review the selection before sending it to a different context. A generated response can repeat sensitive information supplied earlier, so inspect Output before sharing, presenting, publishing, or copying it into another system.

Private mode prevents creation or update of ordinary saved chat history for that conversation, but the live request still passes through ZexirAI servers and relevant providers. It does not encrypt your screen, hide traffic from your organization or internet provider, prevent browser or device logging, delete screenshots or copied text, or stop a provider from retaining information when legally or operationally required. Use a properly authorized environment for regulated or highly confidential work.

Account exports can contain extensive chat and project content in a portable file. Download them only to a trusted device, store them securely, and delete unneeded copies. Once exported, the file is under your control and is no longer protected by ZexirAI account access controls.

7. Providers, integrations, and generated links

Model, search, authentication, billing, email, hosting, and other providers process information needed for their functions. ZexirAI applies its own access checks before sending a request, but each external service has separate systems and risks. Review a provider’s terms before using a feature for data subject to unusual confidentiality, localization, or contractual restrictions.

Do not paste third-party API keys into chat unless an expressly supported secure connection flow requests them. A generated form, plugin, website, script, or terminal command can be malicious or mistaken even when it appears inside an otherwise useful answer. Confirm the destination domain, requested permissions, exact command, file paths, and expected side effects. Never disable device security or grant administrative access solely because Output tells you to.

When connecting an external account, grant the narrowest permissions needed and revoke the connection when no longer used. Review actions involving email, cloud files, calendars, payments, repositories, production systems, or public posts before execution. ZexirAI support cannot reverse every change made in an independent service.

8. Security, abuse prevention, and service integrity

We use technical and operational measures designed to protect accounts and the Service. These may include authentication checks, per-user ownership checks, signed identifiers, rate limits, input validation, secure transport, session revocation, multi-factor settings, access logging, fraud and abuse signals, provider controls, database backups, software updates, and restricted administrative tools. Specific controls may change as threats and product architecture evolve.

We may examine metadata or content reasonably necessary to investigate abuse, diagnose a fault, respond to support, enforce policies, prevent unauthorized access, or comply with law. Access is limited according to role and purpose. We may temporarily block requests, revoke sessions, require reauthentication, reset a credential, delay a sensitive action, restrict a feature, or suspend an account when signals indicate material risk.

You may not probe, scan, exploit, load test, or attempt to bypass security without written authorization. Do not access another user’s records even if a bug appears to allow it. Stop testing, preserve minimal evidence, and report the issue. Avoid copying personal content into a vulnerability report; use redacted identifiers and a controlled proof of concept.

9. Suspected compromise and security incidents

Signs of compromise include an unexpected verification email, changed profile details, unfamiliar chats, missing projects, a new MFA configuration, unknown billing activity, repeated login prompts, or a security notice you did not trigger. First secure the email or federated sign-in account, because it may control recovery. Then change the ZexirAI password if applicable, enable or reset MFA, sign out of untrusted devices, review subscription status, and contact support.

Tell us the account email, approximate time, device and browser, observed actions, and steps already taken. Do not send passwords, live tokens, one-time codes, full card details, or unrelated personal records. Preserve relevant emails, timestamps, and screenshots without publicly posting exploitable details. If payment fraud is involved, contact the card issuer as well as ZexirAI.

We assess reports based on available evidence and may lock changes while investigating. We cannot promise restoration of every deleted item or reversal of every provider-side action. Where a confirmed breach triggers a legal notice obligation, we will notify affected people or authorities as required and provide available steps to reduce harm.

10. Recovery and identity verification

Account recovery balances access with the risk of handing an account to an attacker. We may verify control of the account email or federated identity, prior usernames, approximate creation or activity dates, payment-processor references, subscription details, device history, MFA setup, or prior support interactions. We will not ask for a full payment-card number or current password by email.

Supplying one matching fact may not be enough. Public profile details, leaked passwords, receipts, and email addresses can be available to attackers. We may ask for multiple independent signals, delay the change, notify an existing channel, or refuse recovery when evidence conflicts. Support discretion does not guarantee recovery, especially if the registered email and MFA recovery information are no longer available.

Organizations should establish their own offboarding and ownership procedures before an employee or contractor leaves. Individual consumer support cannot adjudicate complex corporate ownership based only on who paid one invoice. A separate business agreement or verified domain administration may be needed for centralized organizational control.

11. Deletion, closure, and suspension

You may delete supported chats and project files through product controls. You may export supported workspace data before closure. To request full account deletion when no self-service control is available, contact support from the registered email. Cancel a paid subscription first or ask support to confirm how closure affects billing. Removing the app or clearing browser data does not cancel a subscription or delete the server account.

We may require verification before deletion, especially when a request comes from an unfamiliar channel. We may retain limited information needed for security, fraud prevention, billing, legal compliance, dispute resolution, or an active legal hold. Backup copies are removed through ordinary rotation rather than an instantaneous purge. The Privacy Policy provides more detail.

We may suspend access when credentials appear compromised or activity threatens users or the Service. A protective suspension is not necessarily a finding of wrongdoing. We may require a password reset, reauthentication, removal of malicious content, or other remediation before restoring access. Repeated or serious violations can result in termination under the Terms.

12. Reporting and updates

Report an account issue or suspected vulnerability to mail@zexiry.com. Use a clear subject, provide reproducible steps, describe the likely impact, and minimize personal data. Do not exploit beyond what is needed to demonstrate the issue, access another person’s content, alter production data, demand payment through threats, or publicly disclose an unpatched vulnerability.

We may update this policy as authentication methods, providers, threats, and legal obligations change. The effective date identifies the current version. Material changes receive additional notice when required. You should review account security settings periodically and after any device loss, credential breach, suspicious message, or change in the people authorized to use the workspace.

1. Account Creation: detailed guidance

This section explains how the policy applies to account creation. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on account creation, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to account creation. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns account creation, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of account creation as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

2. Email Verification: detailed guidance

This section explains how the policy applies to email verification. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on email verification, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to email verification. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns email verification, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of email verification as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

3. Federated Sign-In: detailed guidance

This section explains how the policy applies to federated sign-in. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on federated sign-in, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to federated sign-in. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns federated sign-in, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of federated sign-in as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

4. Password Security: detailed guidance

This section explains how the policy applies to password security. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on password security, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to password security. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns password security, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of password security as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

5. Multi-Factor Authentication: detailed guidance

This section explains how the policy applies to multi-factor authentication. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on multi-factor authentication, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to multi-factor authentication. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns multi-factor authentication, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of multi-factor authentication as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

6. Session Management: detailed guidance

This section explains how the policy applies to session management. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on session management, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to session management. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns session management, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of session management as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

7. Device Security: detailed guidance

This section explains how the policy applies to device security. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on device security, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to device security. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns device security, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of device security as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

8. Recovery Methods: detailed guidance

This section explains how the policy applies to recovery methods. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on recovery methods, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to recovery methods. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns recovery methods, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of recovery methods as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

9. Shared Devices: detailed guidance

This section explains how the policy applies to shared devices. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on shared devices, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to shared devices. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns shared devices, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of shared devices as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

10. Organizational Access: detailed guidance

This section explains how the policy applies to organizational access. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on organizational access, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to organizational access. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns organizational access, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of organizational access as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

11. Credential Sharing: detailed guidance

This section explains how the policy applies to credential sharing. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on credential sharing, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to credential sharing. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns credential sharing, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of credential sharing as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

12. Phishing Defense: detailed guidance

This section explains how the policy applies to phishing defense. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on phishing defense, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to phishing defense. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns phishing defense, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of phishing defense as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

13. Malicious Extensions: detailed guidance

This section explains how the policy applies to malicious extensions. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on malicious extensions, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to malicious extensions. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns malicious extensions, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of malicious extensions as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

14. Api Tokens: detailed guidance

This section explains how the policy applies to API tokens. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on API tokens, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to API tokens. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns API tokens, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of API tokens as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.