Legal

Privacy Policy

Draft of 24 September 2026, not yet reviewed by counsel

What we collect, why, who helps us process it, and how to have it deleted, written to match what the product actually does. The placeholders are the parts that wait on the company registration or on legal review.

01

Who we are

Zaqero ("we," "us") is software that plans, produces, publishes and measures short social videos for businesses. This policy explains what data we handle, why, who helps us process it, and what you can do about it. It is a draft written to match how the product works today; it has not yet been reviewed by a lawyer.

[Placeholder — the data controller is the company that operates Zaqero; its registered name, registry code and address go here once the company (an Estonian OÜ) is registered.]

02

What we collect

Your account: your name, email address and login details (handled by our authentication provider).

Your business: what you tell us at onboarding, what we read from your public website when you ask us to scan it (products, descriptions, prices, photos), and anything you upload (product photos, logo, footage).

Connected accounts: when you connect Instagram, we receive your account’s profile, your published media and its performance insights, and permission to publish on your behalf. We store the access token Instagram gives us so we can do that. Connections to TikTok and YouTube, when available, will work the same way and only with the permissions you grant on their consent screen.

Billing: payments are handled by Stripe. We never see or store your card number.

Operational records: what was generated for you, what it cost, what was published and when, so you can see it and we can bill and debug accurately.

We do not use advertising trackers or third-party analytics on this site. The only things your browser stores are what keeps you signed in and remembers your interface preferences; the Cookies link at the bottom of every page shows and changes your choice.

03

How we use it

To make your videos: your brief, products and brand details go to the AI services that write, generate and check them.

To publish and measure: we post to your connected accounts only at the autonomy level you choose, and read their performance back to learn what works for your business.

To run the service: billing, support, security, and keeping each business’s spending within its limits.

We do not sell your data, and we do not use your content or your connected-account data for advertising.

04

Who processes it for us

Supabase (database and file storage, hosted in the EU, Ireland) and Vercel (hosting the website and its servers).

OpenAI and Anthropic (writing the plan and checking the result), Kling AI (generating video and images), ElevenLabs (voice and sound). Under their API terms, what we send them is not used to train their models.

Stripe (payments). Meta, and when connected TikTok and Google/YouTube, receive what we publish to your accounts on your behalf.

Some of these providers process data outside the EU. [Placeholder — the transfer safeguards for each (standard contractual clauses or the EU–US Data Privacy Framework) need to be confirmed and listed here.]

05

AI-generated content

The videos we make are generated with AI. Where the platforms or the law require it — including the EU AI Act’s transparency rules — we disclose that when we publish, and we are adding machine-readable marking to the files themselves. People shown in our videos are generated and are never a real person’s likeness.

06

Google and YouTube data

Zaqero’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

When you connect YouTube, you agree to the YouTube Terms of Service (https://www.youtube.com/t/terms), and Google’s Privacy Policy applies to Google’s handling of your data (https://policies.google.com/privacy). You can revoke our access at any time at https://security.google.com/settings/security/permissions, as well as by disconnecting in Zaqero.

07

How long we keep it

While your account is active, we keep what the service needs to work and to show you your history.

When you disconnect a platform, we delete its access token straight away, so we can no longer act for that account; the record that it was once connected stays with your history.

When you delete your account, your assets, generated media, post records, platform metrics and business-specific learning are deleted. De-identified, aggregated statistics that cannot be traced back to you may be kept as part of a shared benchmark.

[Placeholder — retention periods for billing and tax records, which the law requires us to keep for a set time, go here.]

08

Deleting your data

To remove a connected account: disconnect it in Settings. To delete everything: email us at the address below and we will delete your account and its data and confirm when it is done (a self-serve button in Settings is coming). This is also how to request deletion of data we received from Meta (Instagram and Facebook), TikTok or Google.

09

Your rights

Under the GDPR you can ask to see the data we hold about you, correct it, delete it, receive it in a portable format, restrict or object to how we use it, and withdraw consent where we rely on it. You can also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or your local data protection authority.

[Placeholder — the privacy contact email, on our own domain, goes here once the domain is set up.]

10

Changes to this policy

We will tell you before a material change takes effect. The date of the current version is shown at the top of this page.