Zymura — privacy policy

Open the app

The short version. You can use Zymura without an account, in which case nothing leaves your device. If you sign in, we store your email address and a copy of your flows so they follow you between devices. If you switch a flow to run on our servers, we also store a record of each run so you can see what happened. Nothing else. No tracking, no advertising, no data sold or shared.

Last updated: 22 August 2026 · Applies to Zymura at zymura.app, worldwide.

Who is responsible

Zymura is operated by Zymura, a sole proprietorship based in Bengaluru, India, registered as a micro enterprise with the Ministry of Micro, Small and Medium Enterprises under Udyam registration number UDYAM-KR-03-0744649. For any question about this policy or your data, write to support@zymura.app.

What is stored, and where

WhatWhere it livesHow long
Your email address (only if you create an account)Our database, hosted by SupabaseUntil you ask us to delete your account
Saved connections (a named credential, e.g. "Team Slack")Your device, and our database if signed inUntil you delete the connection or your account
Flows you build, including any API keys or webhook URLs you enter into a stepYour browser's local storage. If you are signed in, also our database, so they appear on your other devicesUntil you delete the flow, or clear the app's data on a device where you are signed out
Run history for flows you run in the app — each step's status, duration, inputs and outputsYour browser's local storage, on your deviceLast 300 runs, then oldest are dropped
Run history for flows that run on our servers — each step's status, duration, and its inputs and outputs with credentials maskedOur database, hosted by Supabase7 days on Free, 90 days on Pro, one year on Team
Rows added by the Tables featureYour browser's local storage, on your deviceUntil you delete them
Payloads sent to a flow's webhook URLCloudflare Workers KV, on our infrastructureDeleted as soon as the app collects them, and automatically after 3 days

Uninstalling the app or clearing site data erases everything held on the device. That is permanent — export your flows first if you want to keep them.

Accounts, and what signing in changes

An account is optional. Without one, Zymura works exactly as described above and no data reaches us.

If you sign in, we ask for one thing: your email address. We do not ask for your name, phone number, address, date of birth, employer or payment details, and there is no field in which to give them. Your email is used to send you the sign-in link, to identify your account, and to contact you about the service. We do not send marketing email.

Signing in also uploads your flows and your saved connections to our database so they are available on your other devices. That upload includes any API keys, tokens or webhook URLs you have entered, whether typed directly into a step or stored as a named connection. If you would rather those never leave your device, use Zymura signed out, or keep credential-bearing flows on a single device.

Authentication and database hosting are provided by Supabase, acting as our processor. Access is enforced by row-level security, meaning the database itself refuses to return one account's rows to another account.

What running on our servers means for your data

A flow switched to Runs on the server is executed by us on the schedule you set, without your browser open. To do that we necessarily hold more than we would otherwise:

Before a run is written, two things happen to it. Fields a connector has declared secret are replaced with a mask. Values that match the shape of a known credential — an API key or token belonging to a common service — are also masked, wherever they appear. Masking happens at the moment of writing, not when the screen is drawn, so the unmasked value never reaches storage. Large values are truncated and marked as truncated rather than stored whole.

This is best-effort, not a guarantee: a credential in an unusual format inside a response body may not be recognised. If a flow handles something you would not want recorded, run it in the app rather than on the server.

Flows you run in the app behave as they always have — that data stays on your device and never reaches us.

Failure alerts

If you switch on failure alerts for a server-side flow, then when it fails we send a message through the connection you chose — your Slack webhook, your Discord webhook, your Telegram bot or your email provider. That message contains the flow name, the step that failed, the error text and the time. We do not operate a sending service of our own; the message travels through your credentials to your destination.

Credentials you enter

When a step needs an API key, bot token or webhook URL, it is saved with that flow and sent only to the service that step names — Slack to Slack, Telegram to Telegram, and so on. We never transmit your credentials to any other destination and we do not read them. Anyone with access to your unlocked device can see them, so treat the device accordingly and prefer keys scoped to the narrowest permission the task needs.

The request proxy

Browsers block many direct calls to third-party APIs. When the proxy setting is on, a step's request is sent to /api/proxy on our server, forwarded to the destination you configured, and the response is returned to your device. The proxy does not write request or response bodies to storage and does not log them. Cloudflare, our hosting provider, processes the request in transit and retains standard technical metadata such as IP address and timestamps under its own privacy policy. You can switch the proxy off in Settings, in which case requests go directly from your browser and never reach our servers.

Third parties

Zymura contains no analytics, no advertising and no trackers. Three service providers are involved in running it: Cloudflare hosts the application and the request proxy, Supabase provides authentication and the database if you create an account, and Google's Gemini API answers questions asked in the support chat on our website. Beyond those, the only external services contacted are the ones you name in your own flows. Each of those has its own privacy policy and terms, and your use of them is between you and that provider.

Notifications

If you allow device notifications, they are generated locally by flows you built. There is no push server and no notification is sent from us.

Your rights

Access and portability: Settings → Export everything gives you a complete JSON copy of your flows at any time, signed in or out.

Correction: edit or delete any flow in the app; the change propagates to your account immediately.

Erasure: deleting a flow removes it from our database as well as your device. To delete your entire account and every row attached to it, use Settings → Delete your account in the app, which erases everything immediately. You can also email the address above from your registered address and we will erase it within 30 days. Full detail is on the account deletion page. You do not have to give a reason.

These rights are available to you under India's Digital Personal Data Protection Act, 2023, and to users in other jurisdictions under their local law. Our grievance contact is the email address at the top of this policy.

Paying for Zymura

Paid plans are sold through a merchant of record, which is the legal seller of the subscription. They collect payment, apply the correct tax for your country, and issue your invoice. We never see or store your card details — the payment provider handles them, and we receive only your plan, its status and your billing country. The same merchant of record handles customers in India and elsewhere. Their own privacy policy governs the payment data they hold.

Where you are, and what law applies

Zymura is operated from India and available worldwide. The data controller is Zymura (Udyam registration UDYAM-KR-03-0744649), Bengaluru, Karnataka, India, contactable at support@zymura.app.

Where your data is processed. Accounts and synced flows are stored by Supabase; the application and request proxy run on Cloudflare's global network. This means your data may be processed outside your own country. Both providers operate under standard contractual clauses and equivalent safeguards for international transfers.

If you are in the UK, the EEA or Switzerland, we process your data on two lawful bases: performance of a contract, for the account and flows you asked us to store and run, and legitimate interests, for keeping the service secure and working. You have the right to access, correct, delete and port your data, to object to or restrict processing, and to lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office. We do not use your data for automated decision-making or profiling, and we do not sell it.

If you are in India, the Digital Personal Data Protection Act, 2023 applies, and the grievance contact is the address above.

If you are in Japan, the Act on the Protection of Personal Information applies and the same rights of disclosure, correction and deletion are available through that address.

Retention. Flows and connections are kept until you delete them or close your account. Run history is kept per plan — 7 days on Free, 90 days on Pro, one year on Team — and then deleted automatically. Webhook payloads expire after 3 days. Deleted accounts are erased, not archived.

What we deliberately do not collect

Many automation tools gather telemetry by default. We gather none. Specifically, Zymura does not collect:

There is no opt-out setting for telemetry because there is no telemetry to opt out of.

Who else processes your data

Three providers are involved in running the service, and no others:

ProviderWhat they handleWhere
CloudflareHosting, the request proxy, and the webhook queueGlobal edge network
SupabaseAuthentication and the database, if you have an accountMumbai, India
GoogleThe Gemini API, which answers questions asked in the website support chatGoogle infrastructure
Our payment providerCheckout, invoicing and tax, as merchant of recordOnly if you buy a paid plan

The authoritative list, with 30 days' advance notice of any change, is Annex III of our data processing agreement. If this list changes, the date at the top of this page changes with it. We will not add an analytics provider without saying so here first.

Log retention

Operational logs — the technical records of requests reaching our servers — are kept for 30 days and then deleted, except where a specific security investigation requires keeping a subset for longer. Run history follows your plan: 7 days on Free, 90 days on Pro, one year on Team, after which entries are removed automatically. Backups held by our database provider are cycled within 90 days, so deleted data disappears from backups within that window.

AI steps

If a flow uses the AI model action, your prompt is sent to the provider you configured, using your API key, and their terms govern what happens to it. We do not add prompts to any model and we do not train anything on your data.

There is one place where Zymura contacts an AI service itself rather than on your instruction: the support chat on our website. It is described in the next section.

The support chat

The chat bubble on our marketing pages sends your question to Google's Gemini API so it can be answered from our documentation. Your question, and the few preceding messages in that conversation, are sent. Nothing else is: the chat does not know who you are, does not require an account, and is not connected to your flows, your run history or your credentials.

We do not store the conversation. It exists in your browser tab until you close it, and our server keeps no copy. We do count requests per IP address for one hour at a time so the endpoint cannot be abused; that counter holds a number, not message content.

Where the chat is not available. We use Gemini's free tier, and Google's terms require a paid plan before an application using it is offered to people in the European Economic Area, Switzerland or the United Kingdom. Rather than offer it to you anyway, we switch it off there. If you are visiting from any of those countries the chat will tell you so and point you at support@zymura.app, and no request is sent to Google at all — not the question, and not your IP address.

Everywhere else, what Google's free tier means. Under Google's terms for its non-paid services, content submitted to them and the responses generated may be used to provide, improve and develop Google's products and machine-learning technologies, and human reviewers may see it. Google's own guidance is not to submit sensitive, confidential or personal information to those services.

So please do not type anything into the support chat that you would not put in a public forum post — no API keys, no customer data, no personal details. If you need to discuss something specific to your account, email support@zymura.app instead. That reaches a person and does not pass through an AI service.

For business customers

If you use Zymura to process other people's personal data, you are the controller and we are your processor. Our data processing agreement sets out that relationship in full, including the security measures in place, the ones that are not, the subprocessor list, breach notification and the standard contractual clauses for international transfers. It applies automatically; if your procurement process needs a countersigned copy, write to support@zymura.app.

Children

Zymura is a business productivity tool and is not directed at children under 13. We do not knowingly collect information from children.

Security

The app is served over HTTPS. The proxy refuses cross-origin callers and requests to private network addresses.

If you use Zymura without an account, nothing reaches us and there is nothing of yours for us to lose. If you sign in, your flows and connections are stored in our database, and access is enforced by row-level security — the database itself refuses to return one account's rows to another account. Credentials needed for server-side execution are held there because the server cannot authenticate without them.

We cannot recover data for you from a device we never had a copy of, so keep exports of any flow you would not want to rebuild.

Changes to this policy

If this policy changes materially, the date at the top changes and the new version appears at this URL. The version published here is always the one that applies.