Legal
Privacy Policy
Last updated: September 3, 2026
1. Overview
Zetrr (“we,” “us,” or “our”) operates the website zetrr.com and the Zetrr creator platform, together with our native applications for iOS, iPadOS, macOS, and Android (collectively, the “Platform”). We are committed to protecting your privacy and handling your personal data with care.
The Zetrr platform is modular. Our native apps include Zetrr Planner (content planning, boards, scripts, tasks, notes, saved ideas, and team collaboration) and Zetrr Control (local control of a Mac from an iPhone or iPad). Additional modules are available on the web at zetrr.com. This Privacy Policy applies to all of them.
This Privacy Policy explains what personal data we collect, how we use it, who we share it with, your rights regarding your data, and how to contact us. It applies to all users of the Platform, including visitors, free-tier users, and paid subscribers.
In brief
2. Our Native Apps
This section summarizes exactly what our native apps do with your data and mirrors the “App Privacy” / Data Safety disclosures shown on our App Store and Google Play listings.
Zetrr Planner for iOS, iPadOS, macOS, and Android collects the following data, all linked to your account and used only to operate the app:
- Account email address — to sign you in and sync your planner across your devices.
- The planner content you create — to-dos, boards, cards, scripts, script versions, notes, saved ideas, tags, and chat messages you exchange with your team.
- Optional voice notes — recorded only when you choose to record one and attach it to a saved idea. The microphone is accessed only at that moment, and only if you grant permission.
- A device notification token — created only if you enable notifications, so we can deliver reminders and updates to your device.
What the apps do not do:
- No advertising and no advertising SDKs.
- No advertising identifier (such as Apple’s IDFA) and no cross-app or cross-website tracking.
- No third-party analytics SDKs are embedded in the apps.
Device permissions are optional and requested only at the point of use: Microphone (for voice notes) and Notifications (for reminders). You can use the core planner without granting either, and you can change these at any time in your device settings.
Consistent with the App Store label
Zetrr Control for iOS, iPadOS, and macOS does not collect data. It does not require an account, include advertising or analytics SDKs, or send usage or personal data to Zetrr or any third party. The iPhone or iPad connects directly to the paired Mac over the same local network using an authenticated, encrypted session; there is no cloud relay.
Zetrr Control requests device permissions only when needed. Camera access is used only to scan the one-time pairing QR code. Microphone and speech-recognition access are used only when you start Dictation; speech is transcribed on the device and only the resulting text is sent to the paired Mac in real time. Local Network access finds and communicates with the paired Mac. macOS Accessibility permission lets the Mac app perform only the pointer, click, typing, and shortcut actions you request. Pairing and trusted-device information stays on your devices.
Zetrr Control data collection
Zetrr Capture browser extensions (Chrome and Safari) save what you are looking at into your Planner. Only when you click the extension does it read the current tab’s address, title, selected text, and page preview details, and — if you choose — take a screenshot of that tab; it then sends those to your Planner account. It keeps a capture-only sign-in token in the browser’s extension storage and does not read your browsing history.
3. Information We Collect
Account information you provide directly: name, email address, profile picture, and any other information you add to your account profile.
Content you create: planner content (to-dos, boards, cards, scripts, notes, saved ideas, tags, team chat), and — when you use other Zetrr modules on the web — form submissions, content pipeline data, invoices, automation rules, giveaway configurations, and any other content you generate using the Platform (“User Content”). Content you put in a shared workspace is visible to the other members of that workspace according to the roles you assign.
People who visit your public pages: when someone opens your biolink page, submits one of your forms, or taps a link we shortened for you, we record what they submit and limited technical data — approximate location inferred from their IP address, device and browser type, the referring page, campaign tags, and a visitor identifier — so we can show you analytics and stop abuse. We process this on your behalf; you are responsible for telling your audience how you use it.
Usage and diagnostic data: on our website, we automatically collect limited technical data such as browser type, device information, pages visited, timestamps, referring URLs, and general geographic location inferred from IP address — collected in part through Google Analytics — to operate the site, improve it, and diagnose issues. To understand how the website and the signed-in dashboard are actually used — and to spot errors and points of friction — we also use heatmaps and session-replay analytics (Microsoft Clarity), which record on-page interactions such as clicks, scrolling, and mouse movement. This is used only to improve your experience; sensitive input is masked by default. As noted in Section 2, our native apps do not embed third-party analytics or tracking SDKs; any diagnostic information from the apps is limited to what is necessary to operate and secure the service.
Authentication & abuse-prevention data: when you sign in or sign up, we process your credentials securely and use a bot/abuse challenge (Cloudflare Turnstile) to protect accounts. This may involve your IP address and challenge token being processed by our security provider (see Section 5).
Payment data: if you subscribe to a paid plan on the web, our payment processor (Razorpay) handles your payment information. We store only transaction and subscription identifiers and your billing history on our systems — never your full credit or debit card number. Your billing currency is chosen from your location. Free trials do not require a card. Web subscriptions renew automatically until you cancel them in Settings. Purchases made through an app store are handled by that store (see Section 5 and our Terms of Service).
Third-party connections: if you connect third-party accounts (e.g., Instagram via OAuth, Google) when using web modules, we may receive certain profile information from those services, subject to your privacy settings with those providers. In particular, when you use the Automation or Giveaways modules and connect your Instagram Business or Creator account through Meta’s official Instagram API, we access your Instagram profile, media, comments, and messages — and process limited information about the Instagram users who interact with you — as needed to run those features. See Section 14 for full details.
4. How We Use Your Information
We use your data to:
- Provide, maintain, and improve the Platform and its features.
- Create and manage your account; authenticate you on each visit and keep your data in sync across your devices.
- Deliver reminders and notifications you have enabled.
- Process transactions and send related service communications (e.g., receipts, renewal reminders).
- Send you service-related notices (e.g., password resets, security alerts, policy changes).
- Send you occasional product announcements and updates by email, push, or in-app notice. You can ask us to stop these at any time by writing to privacy@zetrr.com.
- Respond to your support requests and provide customer service.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Analyze usage patterns (primarily on the website) to improve user experience and develop new features.
- Enforce our Terms of Service and other agreements.
We do not use your personal data for advertising, and we do not sell your personal data to third parties.
7. Data Retention
We retain your personal data for as long as your account is active and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce agreements.
- Account data and planner content: retained until you delete your account (see Section 10). After deletion, limited records may be kept for up to 90 days for legal, tax, security, and fraud-prevention purposes, unless a longer period is required by law.
- Voice notes: stored as part of your account content and deleted when you delete the note or your account.
- Instagram giveaway data: entrant comments collected for a run are automatically deleted 7 days after the run. The winning username and winning comment are kept in your run history until you delete your Zetrr account.
- Usage logs: anonymized and aggregated where possible, retained for up to 12 months.
- Payment records: retained for a minimum of 7 years as required by financial regulations.
8. Data Security
We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include:
- Encryption in transit (TLS/HTTPS) for all data transmitted to and from the Platform.
- Encryption at rest for data stored in our databases.
- Row-level security so that you can only access your own data, enforced at the database layer.
- On-device secure storage of your session credentials (e.g., the iOS/macOS Keychain) so you stay signed in safely.
- Access controls: our team follows the principle of least privilege — only personnel who need access to your data to maintain the Platform have it.
- Support access: to resolve a request you raise, or to investigate abuse or a security incident, an authorised member of our team may temporarily view your account through a dedicated review environment, and only for that purpose.
- Support chat: the messages, files, and screen captures you choose to send us through Support chat are stored with your conversation so we can help you.
- Regular security reviews and vulnerability scanning.
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. If you suspect a security breach, contact us immediately at security@zetrr.com.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Correction: request that we correct inaccurate or incomplete data.
- Erasure: request deletion of your personal data (the “right to be forgotten”).
- Restriction: request that we limit how we process your data in certain circumstances.
- Portability: request your data in a structured, commonly used, machine-readable format.
- Objection: object to our processing of your data for certain purposes.
- Withdraw consent: where our processing is based on your consent, withdraw that consent at any time.
To exercise any of these rights, contact us at privacy@zetrr.com. We will respond to all verified requests within 30 days.
GDPR (EEA users)
CCPA/CPRA (California residents)
10. Account Deletion & Data Erasure
You can delete your account and its associated data at any time, directly inside any Zetrr app or on the web — you do not need to contact us or wait for a manual process.
In the apps (iOS, iPadOS, macOS, Android):
- Open Settings.
- In the account section, tap “Delete account”.
- Confirm. Your account and associated planner content are permanently deleted.
On the web: go to Account Settings, choose “Delete account,” and confirm.
What happens when you delete your account:
- Deletion is permanent and cannot be undone.
- If you are the only owner of a workspace that still has other members, transfer ownership to another member first (on the web); deletion is declined until then so your team’s content is not destroyed by accident.
- Your account and your planner content — to-dos, boards, cards, scripts, notes, saved ideas, tags, chat, and any voice notes — are removed from our active systems.
- We may retain limited records required for legal, tax, security, or fraud-prevention purposes for up to 90 days (or longer where required by law), after which they are deleted.
- Any subscription purchased through Apple or Google must be canceled through that store’s account settings; deleting your Zetrr account does not automatically cancel an app-store subscription.
- Content you previously shared publicly (e.g., via a share link) may remain accessible through cached copies or third-party archives outside our control.
Available now, in-app
11. Children’s Privacy
The Platform is not directed to, and we do not knowingly collect personal data from, anyone under the age of 16 (or the applicable minimum age in your jurisdiction). If we learn that we have collected personal data from a child under the minimum age without parental or guardian consent, we will take steps to delete that data as quickly as possible.
If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us at privacy@zetrr.com.
12. International Data Transfers
Our databases and application servers are hosted in Mumbai, India (Supabase and Vercel), and the files you upload are stored on Cloudflare’s storage network. If you are accessing the Platform from outside India, your data will be transferred to and processed in India, which may have different data protection laws than your country.
When we transfer personal data from the European Economic Area, United Kingdom, or Switzerland, we rely on standard contractual clauses (SCCs) and other approved transfer mechanisms to ensure an adequate level of data protection.
13. Third-Party Services & Integrations
The Platform may contain links to or integrations with third-party websites, services, or applications. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you use, including the app store from which you obtained our app:
- Apple: apps obtained from the App Store are subject to Apple’s Privacy Policy and the App Store terms.
- Google: apps obtained from Google Play are subject to Google’s Privacy Policy and the Google Play terms.
- Razorpay: payment data on the web is handled by Razorpay under its Privacy Policy.
- Instagram / Meta (Automation & Giveaways, and social sign-in): when you connect Instagram or use Meta or Google sign-in, your data is also subject to Meta’s, Instagram’s, and Google’s policies (see Section 14).
- Microsoft: heatmaps and session-replay analytics on the website are provided by Microsoft Clarity and are subject to Microsoft’s Privacy Statement.
- Google Analytics: website traffic and usage analytics are provided by Google Analytics and are subject to Google’s Privacy Policy.
14. Meta / Instagram Integrations (Automation & Giveaways)
Two optional web modules — Zetrr Automation (comment and keyword auto-replies, direct messages, and the Collabs inbox that surfaces collaboration inquiries from your DMs) and Zetrr Giveaways (comment-based entry and winner selection) — connect to your Instagram Business or Creator account through Meta’s official Instagram API (“Instagram API with Instagram Login”). Zetrr is a verified Meta Tech Provider. These features are available on the zetrr.com website and, for Automation, in the Zetrr Automation app for iOS and Android; they are not part of the Planner apps.
The Zetrr Automation app collects the same account information as the website (your email and profile), your Instagram connection, a push-notification token if you turn notifications on, and the voice notes you record for follow-up messages. The microphone is used only while you are recording. It does not embed advertising or third-party analytics SDKs.
We access this data only after you explicitly connect your account and grant permission, only for the account you connect, and only to operate the features you turn on. The permissions we request are:
- Automation — instagram_business_basic (your Instagram profile and media, used to target which posts a rule applies to), instagram_business_manage_comments (read comments on your posts and post public or private replies), and instagram_business_manage_messages (send direct messages and private replies on your behalf, and read the direct messages sent to your account so the Collabs inbox can show you the ones that look like collaboration or brand inquiries).
- Giveaways — instagram_business_basic and instagram_business_manage_comments (read your profile and the comments on the post you choose, so we can list entrants and select winners).
Information about people who interact with you. To perform the actions you configure, these features necessarily process limited information about the Instagram users who comment on your posts or message your account. For Giveaways this is limited to the commenter’s username, the text of their comment, and the comment’s own Instagram ID — no profile pictures, follower counts, or other profile data. For Automation we additionally store the sender’s Instagram-scoped user ID, which Meta requires to address a reply, and, for people who message your account, the username, display name and a small copy of the profile picture that Instagram provides for that conversation, so your Top Fans and Leads views can show who they are. That copy is refreshed periodically and deleted when Instagram stops providing it, when you disconnect the account or remove Zetrr on Instagram, and in any case after 12 months. We use this information solely to carry out what you set up (for example, matching a keyword, sending the reply or direct message you configured, entering a commenter into your giveaway, or selecting a winner). We do not use it to build advertising profiles, and we do not sell it.
What Automation keeps, and for how long. We keep the comments left on the posts you connect (the commenter’s username, Instagram-scoped ID, and the comment text) so your Priority Comments inbox and Top Fans view can work, and we count how often each person’s comments and messages triggered your automations in order to rank them for you. If you turn on “Collect email or phone”, the contact details a person sends you are stored against their profile. When a follow-gated automation runs, we ask Instagram whether the person follows you and record that answer. If someone shares one of your posts into your DMs, we read the share only to identify which post it is. Your sent-message history is kept for 90 days and raw event logs for 30 days; comments, contact details, and engagement counts are kept until you delete them, use Disconnect & Delete, or delete your account. Anyone can stop receiving your automated messages by replying STOP.
Collabs. If you use the Collabs inbox, each direct message sent to your connected account is checked as it arrives — and your newest conversations are checked again when you open the tab — to see whether it reads like a collaboration, brand, or business inquiry. Only the messages that do are kept, together with the sender’s Instagram-scoped ID and the public profile details Instagram provides for that conversation (username, display name, profile picture, follower count, and whether the account is verified or follows you), so you can find them and reply on Instagram. Every other direct message is discarded immediately after the check and is never stored. Zetrr does not send any message from the Collabs inbox. Kept inquiries are deleted when you delete them, disconnect the account, remove Zetrr on Instagram, or delete your account, and in any case after 12 months.
Storage & security. Your Instagram access tokens are encrypted at rest. We store only the interaction data needed to run the feature and show you results — such as your message history, the comments on the posts you connect, and giveaway entrant and winner lists. For the Automation Collabs inbox, each direct message sent to your account is checked against a collaboration filter as it arrives; we keep only the messages the filter identifies as collaboration or brand inquiries — with the sender’s public profile details (username, name, profile picture, follower count) — for up to 12 months, or until you delete them or disconnect the account. Every other direct message is discarded immediately after the check and is never stored.
Your controls & deletion. Each Instagram module provides two separate controls. Disconnect deletes the stored access token and immediately stops all further access while preserving your run history; the Collabs inbox and any cached fan profile pictures are deleted at that point. Disconnect & Deletepermanently removes the Instagram connection and that module’s related runs, entrant comments, and winner history. Giveaway entrant comments are also deleted automatically 7 days after a run. You can erase all remaining Zetrr data by deleting your account (see Section 10), or contact privacy@zetrr.com for help.
Platform compliance
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the “Last updated” date at the top of this page.
- Post a prominent notice on the Platform for at least 30 days after the change.
- Send an email notification to the address associated with your account for significant changes.
Your continued use of the Platform after any changes constitutes acceptance of the revised Privacy Policy. If you do not agree with the changes, you must stop using the Platform and delete your account.
16. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact:
General Privacy Inquiries
Security Issues & Data Breaches
Legal & Formal Notices
