ZexirAI · Privacy Policy

Your work should not be a mystery to you.

This Privacy Policy explains what personal information ZexirAI processes, where it comes from, why it is needed, when it reaches service providers, how long it is kept, and how you can request access, export, correction, or deletion.

Important: Prompts, files, images, and audio may contain personal or confidential information. They are transmitted to the providers needed to complete your request. Private mode keeps a conversation out of your saved ZexirAI history; it does not prevent that live processing.

1. Scope and roles

This Privacy Policy applies to the ZexirAI website, applications, workspace, accounts, chat and project features, model-selection tools, voice and image features, subscriptions, support, and related services that link to it (the “Service”). It covers information processed by the operator of ZexirAI when deciding why and how that information is used. It does not replace a third party’s privacy policy when you leave the Service or independently use that party’s product.

In most individual-user contexts, ZexirAI acts as the business or controller responsible for personal information described here. A model, payment, hosting, authentication, email, search, or infrastructure provider may act as our processor or service provider for some activities and as an independent controller for others, depending on its service and contract. If an organization gives you access under a separate business agreement, that organization may control workspace data and its agreement may modify or supplement this policy.

“Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or can reasonably be linked to a person or household, where applicable law uses that concept. It does not include information that has been lawfully made public, deidentified so it cannot reasonably be linked back, or aggregated so individuals are not identifiable.

2. Information we collect

The information collected depends on the features you use. We try to collect what is reasonably necessary to operate the Service rather than requiring information for unrelated purposes. The principal categories are:

Account and profile information
Username, display name, email address, password verifier, age or age range supplied during onboarding, sign-in method, account identifiers, verification status, multi-factor authentication status, and security settings. Passwords are stored as protected verifiers rather than readable account text.
Workspace and content information
Prompts, chat messages, model selections, response feedback, generated output, uploaded images and files, project names and descriptions, project-file paths and contents, shared-memory selections, preferences, and associated timestamps or identifiers.
Subscription and transaction information
Plan, subscription status, billing-period end, cancellation status, payment-processor customer and subscription identifiers, purchase and upgrade events, billing contact or address supplied to the processor, and limited transaction metadata. ZexirAI does not need to store a full payment-card number in its application database when Stripe handles checkout.
Device, network, and usage information
IP address, browser or app type, user-agent information, request and session identifiers, authentication-cookie data, language or theme preferences, feature interactions, timestamps, model and quota usage, diagnostic events, error details, and security or rate-limit signals.
Communications
Messages sent to support, bug reports, verification emails, policy or privacy requests, survey responses, and any contact information or attachments you include.

We receive most account and content information directly from you. We may also receive authentication details from Google or another sign-in provider you choose; transaction status from Stripe; model output and usage metadata from AI providers; results from search providers; technical events from hosting or network providers; and fraud, abuse, or security information from service providers and authorized reporters.

3. Chats, files, images, voice, and projects

Signed-in standard chats are stored so they can appear in your history and retain context across sessions. Stored records may include the chat title, user and assistant messages, attachments represented within the conversation, created and updated times, and account ownership. Project workspaces may store folders, descriptions, file paths, file contents, language labels, generated artifacts, job activity, and usage amounts. You may delete supported items through the Service; deletions remove them from active account views and are processed according to the retention section below.

When you attach a file or image, the Service extracts or transmits content needed for the requested operation. An image may be encoded and sent to a model capable of viewing images. A document may be converted to text or another usable representation. Voice features may require microphone permission and may process audio to transcribe speech, generate speech, or support a live interaction. Your operating system or browser controls device permissions, and you may revoke them there.

Content can reveal highly sensitive facts even when no form asks for them. For example, a prompt may include health, financial, legal, employment, education, identity, biometric, location, political, religious, or relationship information. ZexirAI does not require those details for a general account. Submit them only when necessary, lawful, and appropriate, and avoid uploading another person’s sensitive information without authority. The Service is not designed as a system of record for protected health information, cardholder data, government identifiers, classified material, or similarly regulated secrets unless a separate written agreement expressly covers that use.

If you select content from other chats as shared memory, that selected material is included as context for the current request. If prompt suggestions are saved, they remain associated with the account; only suggestions separately classified as suitable for anonymous sharing may be offered as generic suggestions to others, without exposing the source account. You should still avoid placing secrets in suggestion-sized prompts.

4. Cookies, local storage, and technical data

ZexirAI uses an HTTP-only authentication cookie to maintain a signed-in session. The cookie is configured with protections appropriate to the connection, a same-site setting, and a limited lifetime. The browser application may also use local or session storage for interface preferences and state such as theme, selected model, composer layout, cached subscription display, guest-session identifiers, or in-progress user-interface choices. Clearing browser data may reset these preferences or sign you out.

Servers receive ordinary connection data such as IP address, time, requested route, request identifiers, user-agent, response status, and security signals. We use this data to route traffic, operate rate limits, diagnose failures, prevent abuse, enforce access controls, and measure aggregate service capacity. We may derive approximate region from network information when necessary for security, routing, tax, or legal compliance, but this policy does not state that ZexirAI collects precise device location.

Some embedded services, such as authentication or secure checkout, may set their own cookies or receive technical information when their components load. Their handling is governed by their privacy notices and our agreements with them. At the effective date, ZexirAI does not state that it sells browser activity or uses it for cross-context behavioral advertising. If that practice changes, we will update this policy and provide legally required choices before the change applies.

5. Why and how we use information

We process information to perform the Service you request: create and authenticate accounts; preserve standard chat history; send prompts and attachments to the selected or routed model; return output; run search when current information is needed; generate or edit images; support files and projects; save settings; calculate usage; provide exports; and administer subscriptions. This processing is necessary to provide the contract or requested pre-contract service.

We also use information for legitimate operational purposes: secure accounts and infrastructure; detect fraud, abuse, malware, and attempts to bypass controls; debug errors; maintain availability; balance traffic; understand aggregate feature performance; improve usability and reliability; respond to support; enforce policies; protect legal rights; and plan capacity. When law requires consent for a particular activity, we seek it and allow withdrawal as required. Withdrawing consent does not make earlier lawful processing unlawful.

We process information to comply with legal obligations, valid legal process, tax and accounting rules, sanctions, consumer requests, safety duties, and regulatory requirements. We may also use information to establish, exercise, or defend legal claims and to protect users, ZexirAI, providers, or the public from credible harm.

We may create deidentified or aggregate statistics, such as total model usage or broad feature adoption, to operate and improve the Service. We maintain safeguards intended to prevent those statistics from reasonably identifying a person and do not attempt to reidentify lawfully deidentified information except to test whether deidentification works.

6. AI providers, search, and Private mode

ZexirAI connects to multiple model families and may use providers such as OpenAI, Google Gemini, xAI, Anthropic, or another provider made available in the product. A request normally includes the current prompt and the conversation or memory context needed for a coherent response. It may include images, extracted file content, personality instructions, age-appropriate response guidance, model settings, and technical limits. A live-search request may send a search query derived from your prompt to a search provider and then provide relevant results to the model as context.

Providers receive information as service providers or independent recipients according to the feature and contract. Their retention, review, location, and model-improvement practices may differ. We seek configurations and contractual terms suitable for the Service, but you should not assume every provider has identical data controls. The selected provider may be replaced with a fallback when needed for availability, safety, format compatibility, or plan access. Avoid submitting information you cannot permit the applicable provider to process.

For a signed-in user, Private mode sends the current conversation to the server for live inference without creating or updating a saved ZexirAI chat thread. The browser holds the conversation context needed for that session and resends relevant context with later turns. Private-mode content is still temporarily present in network traffic and provider processing; limited operational, security, rate-limit, or error records may still be produced. Private mode does not make you anonymous to the network, erase content you separately copied or downloaded, control screenshots, or override a provider’s legally required retention.

Guest use similarly does not create ordinary signed-in chat history, although a guest-session identifier, quota information, request content, and operational data may be processed to provide and protect the service. Signing in may allow eligible guest chats to be associated with the new account when that adoption feature is used.

7. When information is disclosed

We disclose information only for purposes described in this policy or with your direction. Recipient categories include:

  • Infrastructure and operations providers that host applications or databases, deliver traffic, cache temporary state, store files, monitor availability, send email, or support development and security.
  • AI, image, audio, and search providers that process the content and settings needed to complete a request or determine appropriate routing.
  • Authentication providers when you choose a federated sign-in option, and payment providers such as Stripe for checkout, recurring billing, tax or address collection, fraud prevention, and the customer billing portal.
  • Professional advisers and authorities when reasonably necessary for audits, insurance, legal advice, compliance, valid legal process, security incidents, or protection against fraud and harm.
  • Transaction participants in a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate confidentiality and applicable notice requirements.

We may disclose information to another person when you share output, authorize an integration, collaborate through a feature, or ask support to communicate with them. Public disclosure is not the default for private workspace content. We do not sell personal information for money, and we do not share it for cross-context behavioral advertising as those terms are commonly defined in U.S. state privacy laws. We do not knowingly sell or share personal information of users under 16 for such advertising.

8. Retention and deletion

We retain each category only as long as reasonably necessary for the purpose collected, including to provide the Service, maintain an account, preserve user-selected history, meet legal and accounting duties, resolve disputes, enforce agreements, prevent fraud or abuse, and protect system integrity. The period depends on the data and context rather than one rule for every record.

Account profile and authentication information generally remain while the account is open. Standard chats and project files remain until you delete them or close the account, subject to storage limits and operational changes. Subscription and transaction records may be retained for tax, accounting, chargeback, and legal periods after a subscription or account ends. Security, rate-limit, and diagnostic records are kept for shorter operational periods unless an incident, legal hold, or abuse investigation requires longer preservation.

Deleting an item or account begins a process rather than guaranteeing instantaneous removal from every system. Active copies are removed or de-associated within a reasonable period, while encrypted backups may persist until rotated and provider copies may be governed by provider retention. We may retain limited information when necessary to document consent, honor an opt-out, prevent a banned user from immediately recreating abusive access, complete billing, respond to a legal demand, or establish or defend claims. When retention is no longer justified, information is deleted, anonymized, or securely disposed of.

9. Security

We use administrative, technical, and organizational safeguards designed for the nature of the Service and information involved. Examples may include encrypted transport, protected password verification, HTTP-only session cookies, access controls, rate limits, multi-factor authentication options, logging, provider access restrictions, software updates, backups, incident handling, and separation of user-owned records. Payment-card entry is handled through Stripe’s secure checkout components rather than ordinary ZexirAI form storage.

No service can promise absolute security. Internet transmission, user devices, third-party providers, software dependencies, and human actions all create risk. You can reduce risk by using a unique password, enabling multi-factor authentication, securing your email account, keeping devices updated, reviewing URLs before signing in, signing out on shared devices, and never sending passwords or authentication codes to support.

If we confirm a security incident affecting personal information, we will investigate, contain and remediate as appropriate, preserve necessary evidence, and notify affected people or authorities when law requires. If you believe your account or ZexirAI data is at risk, contact us promptly with the time, device, and activity involved, but do not include passwords, one-time codes, or exploit details that would expose other users.

10. Your controls and choices

You can choose what to submit, which model or routing option to use, whether to save an ordinary chat or start Private mode, which memories to attach, and whether to use files, images, voice, search, Google sign-in, or a paid plan. Browser and operating-system settings control camera, microphone, cookies, local storage, and some network permissions. Restricting essential storage or authentication may prevent parts of the Service from working.

Account settings provide controls that may include profile changes, password and multi-factor authentication management, individual chat and project deletion, and a structured export of account profile, chat, and project data. Export coverage reflects supported active records and may not include internal security data, provider-side data, derived fraud signals, or information we cannot lawfully disclose.

To request account deletion, correction that is not available in the interface, or another privacy action, email mail@zexiry.com from the account email when possible. Describe the request and jurisdiction. We may ask for reasonable information to verify identity and authority. An authorized agent may submit a request where law allows, but we may require proof of authorization and direct confirmation from the user.

11. Regional privacy rights

Depending on where you live and whether the relevant law applies to ZexirAI, you may have rights to know or access personal information, obtain a portable copy, correct inaccurate information, delete information, restrict or object to processing, withdraw consent, opt out of sale, sharing, targeted advertising, or certain profiling, and appeal a denied request. You may also have the right to complain to a privacy or data-protection authority. We will not unlawfully discriminate against you for exercising a privacy right.

For California residents, the categories described in “Information we collect” also serve as a notice of categories collected, sources, business purposes, and recipient categories. We may collect identifiers, customer records, commercial information, internet or electronic activity, approximate network location, audio or visual content you submit, professional or educational content you include, inferences used to route or personalize responses, and sensitive information you voluntarily put in content. We use sensitive information only for providing requested features, security, account access, legal compliance, and other purposes permitted without a right-to-limit request. We do not sell personal information or share it for cross-context behavioral advertising.

For people in the European Economic Area, United Kingdom, or similar jurisdictions, processing may rely on performance of a contract, legitimate interests described in this policy, compliance with legal obligations, protection of vital interests in an emergency, or consent where required. You may object to legitimate-interest processing based on your circumstances. You may lodge a complaint with the supervisory authority where you live or work. These rights are subject to exemptions and verification, and some information may be needed to continue providing the account.

We aim to respond within the period required by applicable law. If we need more time, cannot verify the request, or deny it in whole or part, we will explain when required. We may decline requests that are fraudulent, abusive, technically infeasible, disproportionate, or legally exempt, while still responding to valid portions.

12. Children and teen users

ZexirAI does not permit children under 13 to use the Service, including guest features, even with parental or guardian permission. Onboarding does not accept an age below 13. There is no upper age limit. We do not knowingly collect personal information online from children under 13. If we learn that such information was collected, we will take appropriate steps, which may include disabling the account and deleting information, subject to security and legal needs.

Users between 13 and the age of legal majority should use the Service with parent or guardian involvement when required. Parents and guardians should discuss AI limitations, supervise sensitive topics and purchases, and help minors avoid sharing addresses, school schedules, government identifiers, intimate images, or other information that could create safety risks. Age information may be used to adjust response language and detail and to apply age-appropriate safeguards; it is not a guarantee that all output will be suitable.

A parent or guardian who believes a minor used the Service contrary to this policy may contact us. We may request information reasonably necessary to confirm the adult’s identity, relationship, and authority before disclosing or deleting a minor’s account data.

13. International transfers

ZexirAI and its providers may process information in countries other than the one where you live. Those countries may have different privacy laws and government-access rules. When required, we use recognized transfer mechanisms and contractual, technical, or organizational safeguards intended to protect personal information across borders. Provider location can vary based on model availability, infrastructure, routing, and account configuration.

You should not use ZexirAI for data subject to localization, secrecy, professional, export-control, or sector-specific transfer restrictions unless you have confirmed that the applicable configuration and agreements satisfy those requirements. Consumer use of the Service does not create a business-associate agreement, data-processing addendum, or other regulated-data contract.

14. Changes and contact

We may update this policy when features, providers, laws, or practices change. The effective date identifies the current version. We will provide additional notice before a material change when required. A new policy applies prospectively from its effective date; it does not retroactively authorize a materially different use when consent or another legal basis is required.

Send privacy questions or requests to mail@zexiry.com. Include the account email, the right or issue involved, and your jurisdiction. Do not include passwords, one-time codes, full payment-card information, or unnecessary sensitive content. We may route billing issues to Stripe or another relevant provider when needed to resolve the request.

1. Account Identifiers: detailed guidance

This section explains how the policy applies to account identifiers. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on account identifiers, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to account identifiers. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns account identifiers, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of account identifiers as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

2. Authentication Records: detailed guidance

This section explains how the policy applies to authentication records. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on authentication records, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to authentication records. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns authentication records, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of authentication records as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

3. Profile Information: detailed guidance

This section explains how the policy applies to profile information. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on profile information, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to profile information. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns profile information, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of profile information as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

4. Conversation Content: detailed guidance

This section explains how the policy applies to conversation content. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on conversation content, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to conversation content. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns conversation content, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of conversation content as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

5. File Uploads: detailed guidance

This section explains how the policy applies to file uploads. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on file uploads, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to file uploads. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns file uploads, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of file uploads as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

6. Image Content: detailed guidance

This section explains how the policy applies to image content. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on image content, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to image content. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns image content, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of image content as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

7. Voice Input: detailed guidance

This section explains how the policy applies to voice input. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on voice input, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to voice input. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns voice input, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of voice input as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

8. Usage Telemetry: detailed guidance

This section explains how the policy applies to usage telemetry. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on usage telemetry, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to usage telemetry. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns usage telemetry, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of usage telemetry as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

9. Device Data: detailed guidance

This section explains how the policy applies to device data. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on device data, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to device data. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns device data, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of device data as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

10. Network Data: detailed guidance

This section explains how the policy applies to network data. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on network data, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to network data. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns network data, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of network data as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

11. Cookies And Local Storage: detailed guidance

This section explains how the policy applies to cookies and local storage. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on cookies and local storage, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to cookies and local storage. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns cookies and local storage, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of cookies and local storage as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.

12. Payment Metadata: detailed guidance

This section explains how the policy applies to payment metadata. The governing principle is that a user should understand the feature, use only the access and information reasonably needed for the task, and keep qualified human judgment in control whenever an action may affect another person. Product labels, examples, interface text, and automated notices illustrate ordinary operation; they do not replace the specific facts, laws, contracts, professional duties, or provider terms that apply in a particular situation.

Before relying on payment metadata, review the requested purpose, the sensitivity of the information involved, the people who may be affected, and the consequences of an error. Use the least sensitive input that can complete the task. Confirm names, dates, amounts, permissions, sources, and destinations before sending, publishing, purchasing, deleting, or connecting anything. If a result appears incomplete, inconsistent, unusually confident, or outside the expected context, pause and verify it through an independent and authoritative source.

ZexirAI may apply technical limits, safety checks, rate controls, account verification, logging, provider routing, and human review to support this policy in relation to payment metadata. These measures reduce risk but cannot identify every mistake or misuse. A control that does not block an action is not approval, legal advice, a guarantee of accuracy, or a waiver. Users remain responsible for instructions they provide, content they choose to keep, actions they authorize, and the final use of any output.

When an exception, dispute, or unexpected result concerns payment metadata, preserve the minimum information needed to understand what happened: the approximate time, affected account, feature used, relevant settings, safe transaction or request identifiers, and a concise description of the expected and actual behavior. Remove passwords, one-time codes, full payment details, unrelated personal records, and confidential material. Contact support promptly when delay could increase harm, and use emergency or official reporting channels when the situation requires them.

We review the operation of payment metadata as the Service, models, providers, security threats, and legal requirements change. We may clarify instructions, adjust safeguards, restrict a capability, or request additional verification. Material policy changes receive notice when required. Existing non-waivable rights continue to apply. If this detailed guidance conflicts with a more specific section of this policy, the more specific section controls for that issue; the Terms and applicable law control the overall relationship.