The short version. You can use Zymura without an account, in which case nothing leaves your device. If you sign in, we store your email address and a copy of your flows so they follow you between devices — and nothing else. No tracking, no advertising, no data sold or shared.
Who is responsible
Zymura is operated by TEJ Workspace, Bengaluru, India. For any question about this policy or your data, write to support@tejworkspace.com.
What is stored, and where
| What | Where it lives | How long |
|---|---|---|
| Your email address (only if you create an account) | Our database, hosted by Supabase | Until you ask us to delete your account |
| Saved connections (a named credential, e.g. "Team Slack") | Your device, and our database if signed in | Until you delete the connection or your account |
| Flows you build, including any API keys or webhook URLs you enter into a step | Your browser's local storage. If you are signed in, also our database, so they appear on your other devices | Until you delete the flow, or clear the app's data on a device where you are signed out |
| Run history — each step's status, duration, inputs and outputs | Your browser's local storage, on your device | Last 300 runs, then oldest are dropped |
| Rows added by the Tables feature | Your browser's local storage, on your device | Until you delete them |
| Payloads sent to a flow's webhook URL | Cloudflare Workers KV, on our infrastructure | Deleted as soon as the app collects them, and automatically after 3 days |
Uninstalling the app or clearing site data erases everything held on the device. That is permanent — export your flows first if you want to keep them.
Accounts, and what signing in changes
An account is optional. Without one, Zymura works exactly as described above and no data reaches us.
If you sign in, we ask for one thing: your email address. We do not ask for your name, phone number, address, date of birth, employer or payment details, and there is no field in which to give them. Your email is used to send you the sign-in link, to identify your account, and to contact you about the service. We do not send marketing email.
Signing in also uploads your flows and your saved connections to our database so they are available on your other devices. That upload includes any API keys, tokens or webhook URLs you have entered, whether typed directly into a step or stored as a named connection. If you would rather those never leave your device, use Zymura signed out, or keep credential-bearing flows on a single device.
Authentication and database hosting are provided by Supabase, acting as our processor. Access is enforced by row-level security, meaning the database itself refuses to return one account's rows to another account.
Credentials you enter
When a step needs an API key, bot token or webhook URL, it is saved with that flow and sent only to the service that step names — Slack to Slack, Telegram to Telegram, and so on. We never transmit your credentials to any other destination and we do not read them. Anyone with access to your unlocked device can see them, so treat the device accordingly and prefer keys scoped to the narrowest permission the task needs.
The request proxy
Browsers block many direct calls to third-party APIs. When the proxy setting is on, a step's request is sent to /api/proxy on our server, forwarded to the destination you configured, and the response is returned to your device. The proxy does not write request or response bodies to storage and does not log them. Cloudflare, our hosting provider, processes the request in transit and retains standard technical metadata such as IP address and timestamps under its own privacy policy. You can switch the proxy off in Settings, in which case requests go directly from your browser and never reach our servers.
Third parties
Zymura contains no analytics, no advertising and no trackers. Two service providers are involved in running it: Cloudflare hosts the application and the request proxy, and Supabase provides authentication and the database if you create an account. Beyond those, the only external services contacted are the ones you name in your own flows. Each of those has its own privacy policy and terms, and your use of them is between you and that provider.
Notifications
If you allow device notifications, they are generated locally by flows you built. There is no push server and no notification is sent from us.
Your rights
Access and portability: Settings → Export everything gives you a complete JSON copy of your flows at any time, signed in or out.
Correction: edit or delete any flow in the app; the change propagates to your account immediately.
Erasure: deleting a flow removes it from our database as well as your device. To delete your entire account and every row attached to it, use Settings → Delete your account in the app, which erases everything immediately. You can also email the address above from your registered address and we will erase it within 30 days. Full detail is on the account deletion page. You do not have to give a reason.
These rights are available to you under India's Digital Personal Data Protection Act, 2023, and to users in other jurisdictions under their local law. Our grievance contact is the email address at the top of this policy.
Paying for Zymura
Paid plans are sold through a merchant of record, which is the legal seller of the subscription. They collect payment, apply the correct tax for your country, and issue your invoice. We never see or store your card details — the payment provider handles them, and we receive only your plan, its status and your billing country. Customers in India are billed through Razorpay; customers elsewhere through our international merchant of record. Each provider's own privacy policy governs the payment data they hold.
Where you are, and what law applies
Zymura is operated from India and available worldwide. The data controller is TEJ Workspace, Bengaluru, contactable at support@tejworkspace.com.
Where your data is processed. Accounts and synced flows are stored by Supabase; the application and request proxy run on Cloudflare's global network. This means your data may be processed outside your own country. Both providers operate under standard contractual clauses and equivalent safeguards for international transfers.
If you are in the UK, the EEA or Switzerland, we process your data on two lawful bases: performance of a contract, for the account and flows you asked us to store and run, and legitimate interests, for keeping the service secure and working. You have the right to access, correct, delete and port your data, to object to or restrict processing, and to lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office. We do not use your data for automated decision-making or profiling, and we do not sell it.
If you are in India, the Digital Personal Data Protection Act, 2023 applies, and the grievance contact is the address above.
If you are in Japan, the Act on the Protection of Personal Information applies and the same rights of disclosure, correction and deletion are available through that address.
Retention. Flows and connections are kept until you delete them or close your account. Run history is kept per plan — 7 days on Free, 90 days on Pro, one year on Team — and then deleted automatically. Webhook payloads expire after 3 days. Deleted accounts are erased, not archived.
What we deliberately do not collect
Many automation tools gather telemetry by default. We gather none. Specifically, Zymura does not collect:
- Analytics, session recordings, heatmaps or product-usage events
- The contents of your flows' inputs and outputs — the data that actually passes through a run
- Credential values, at any point, for any purpose
- Error payloads or step data from failed runs
- Anything at all from people using Zymura without an account
There is no opt-out setting for telemetry because there is no telemetry to opt out of.
Who else processes your data
Two providers are involved in running the service, and no others:
| Provider | What they handle | Where |
|---|---|---|
| Cloudflare | Hosting, the request proxy, and the webhook queue | Global edge network |
| Supabase | Authentication and the database, if you have an account | Mumbai, India |
| Our payment provider | Checkout, invoicing and tax, as merchant of record | Only if you buy a paid plan |
If this list changes, the date at the top of this page changes with it. We will not add an analytics provider without saying so here first.
Log retention
Operational logs — the technical records of requests reaching our servers — are kept for 30 days and then deleted, except where a specific security investigation requires keeping a subset for longer. Run history follows your plan: 7 days on Free, 90 days on Pro, one year on Team, after which entries are removed automatically. Backups held by our database provider are cycled within 90 days, so deleted data disappears from backups within that window.
AI steps
If a flow uses the AI model action, your prompt is sent to the provider you configured, using your API key, and their terms govern what happens to it. We do not add prompts to any model, we do not train anything on your data, and Zymura itself sends nothing to an AI service on your behalf.
For business customers
If you use Zymura to process other people's personal data, you are the controller and we are your processor. A data processing agreement including standard contractual clauses is available on request from support@tejworkspace.com.
Children
Zymura is a business productivity tool and is not directed at children under 13. We do not knowingly collect information from children.
Security
The app is served over HTTPS. The proxy refuses cross-origin callers and requests to private network addresses. Because credentials live on the device rather than a central server, there is no user credential database to breach — but equally, we cannot recover anything for you if a device is lost. Keep exports of any flow you would not want to rebuild.
Changes to this policy
If this policy changes materially, the date at the top changes and the new version appears at this URL. The Play Store listing links here, so the current version is always the one that applies.