The data we use should have a clear job.

This notice explains the information handled by Zelikore's company site, shared account plane, and connected products. Product-specific data remains with the product that owns it.

Last updated July 26, 2026

Information we handle

  • Account and organization data: name, email address, verified identity, memberships, roles, and product access.
  • Commercial data: subscription state, billing customer references, purchases, and universal AI-token ledger activity.
  • Product data: the business, live-session, or execution information a customer places in Zelio, Protheos, or Autokore.
  • Support and security data: messages, diagnostics, and information supplied to investigate a request or protect the service.
  • Technical records: request, authentication, error, and operational logs needed to run and secure the service.

Google sign-in data

Google sign-in is a standard way to authenticate a Zelikore account. The shared Google sign-in client requests only the basic OpenID Connect scopes openid, email, and profile. When a person chooses this option, Google provides the stable account subject identifier, verified email address, given and family name, display name, profile photo, and managed Workspace domain when Google supplies them.

Zelikore uses those basic identity attributes to authenticate the account, safely connect a verified Google identity to an existing Zelikore identity, populate the account profile, protect sign-in, and administer organization and product access. This shared sign-in client does not request or read Gmail, Drive, Calendar, YouTube, Ads, Merchant, Search Console, or other Google API content.

Basic identity attributes are stored in the Zelikore identity plane and its Cognito service provider. Authorized product workspace directory records may contain the minimum name and email context needed to serve a Zelikore organization, but products do not receive Google access or refresh tokens through this shared client. Zelikore does not sell Google user data or use it for third-party behavioral advertising. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

A person can revoke Zelikore's Google authorization from their Google Account security controls or ask privacy@zelikore.com about access, export, or deletion. Revoking Google authorization stops future Google sign-in authorization; it does not by itself delete the Zelikore account.

How information is used

We use information to create and protect accounts, authorize product access, deliver the requested product workflows, administer subscriptions and AI-token balances, answer support requests, prevent misuse, diagnose failures, and improve service reliability.

Google sign-in is used only for the basic identity and account purposes described in the Google sign-in data section. Choosing Google sign-in does not by itself authorize Zelikore to read a person's Google product data.

Essential cookies and bounded first-party acquisition events

Signed-in surfaces use essential security and session cookies so an account can remain authenticated and requests can be protected. The public company site does not load advertising pixels or cross-site behavioral analytics.

When the ordinary Zelio public-source integration is configured, public pages can send only seven allowlisted first-party events: page view, call-to-action selection, form start and submission, account start, content view, and preference update. Those events use a normalized page or content identifier, locale, consent state, and an opaque short-lived context rather than a Zelikore contact or campaign record. Global Privacy Control and Do Not Track are carried as an essential-only consent state. The hosted diagnostic collects submitted business information in Zelio, which owns its permission, attribution, lifecycle, and retention. Zelikore records only aggregate accepted, replayed, rejected, or unavailable launch and submission counts; those metrics contain no form fields, URL, secret, token, or destination response.

Service providers and connected services

We use infrastructure and specialist providers to deliver the service, including AWS for hosting, Google when a person chooses Google identity, and Stripe when paid billing is used. A product may also connect to a third-party service at a customer's direction. We share only the information needed for that provider or connection to perform its role.

Information may also be disclosed when required by law, to protect users or the service, or as part of a company transaction subject to appropriate handling of the information. We do not sell personal information or use it for third-party behavioral advertising.

Access, correction, and deletion

Account and organization administrators can manage memberships and access from the Zelikore account surface. Zelikore coordinates verified export, organization-closure, and account-deletion requests, while Zelio, Protheos, and Autokore export or delete the product-domain records they own. Access is disabled before destructive deletion proceeds.

To ask about access, correction, export, or deletion, email privacy@zelikore.com. We may need to verify identity and organization authority before fulfilling a request. A legal hold, active dispute, security investigation, or recordkeeping duty can delay deletion; we will identify that exception and the next review step in the response.

Retention and protected backups

OAuth login transactions expire within minutes. Browser sessions have an eight-hour idle limit and a 30-day absolute limit, and server-held refresh credentials are erased through the revocation workflow. Customer webhook delivery metadata is retained for 90 days. Webhook receipts, integration audit records, and mutation-id records are retained for up to 400 days so retries cannot duplicate charges, access grants, identity correlations, or token movements. Destination response bodies are not retained.

Active account, subscription, entitlement, token-ledger, audit, and product records are retained while needed to provide the service and resolve customer or security issues. Billing and audit records may be retained longer when required for accounting, fraud prevention, a legal hold, or another legal duty. Deletion removes records from active systems first; encrypted backups then age out under their bounded backup lifecycle and are not restored to ordinary service after a verified deletion.