Zymura — privacy policy

Open the app

The short version. You can use Zymura without an account, in which case nothing leaves your device. If you sign in, we store your email address and a copy of your flows so they follow you between devices — and nothing else. No tracking, no advertising, no data sold or shared.

Last updated: 9 August 2026 · Applies to the Zymura web app and the Zymura Android app, worldwide.

Who is responsible

Zymura is operated by TEJ Workspace, Bengaluru, India. For any question about this policy or your data, write to support@tejworkspace.com.

What is stored, and where

WhatWhere it livesHow long
Your email address (only if you create an account)Our database, hosted by SupabaseUntil you ask us to delete your account
Saved connections (a named credential, e.g. "Team Slack")Your device, and our database if signed inUntil you delete the connection or your account
Flows you build, including any API keys or webhook URLs you enter into a stepYour browser's local storage. If you are signed in, also our database, so they appear on your other devicesUntil you delete the flow, or clear the app's data on a device where you are signed out
Run history — each step's status, duration, inputs and outputsYour browser's local storage, on your deviceLast 300 runs, then oldest are dropped
Rows added by the Tables featureYour browser's local storage, on your deviceUntil you delete them
Payloads sent to a flow's webhook URLCloudflare Workers KV, on our infrastructureDeleted as soon as the app collects them, and automatically after 3 days

Uninstalling the app or clearing site data erases everything held on the device. That is permanent — export your flows first if you want to keep them.

Accounts, and what signing in changes

An account is optional. Without one, Zymura works exactly as described above and no data reaches us.

If you sign in, we ask for one thing: your email address. We do not ask for your name, phone number, address, date of birth, employer or payment details, and there is no field in which to give them. Your email is used to send you the sign-in link, to identify your account, and to contact you about the service. We do not send marketing email.

Signing in also uploads your flows and your saved connections to our database so they are available on your other devices. That upload includes any API keys, tokens or webhook URLs you have entered, whether typed directly into a step or stored as a named connection. If you would rather those never leave your device, use Zymura signed out, or keep credential-bearing flows on a single device.

Authentication and database hosting are provided by Supabase, acting as our processor. Access is enforced by row-level security, meaning the database itself refuses to return one account's rows to another account.

Credentials you enter

When a step needs an API key, bot token or webhook URL, it is saved with that flow and sent only to the service that step names — Slack to Slack, Telegram to Telegram, and so on. We never transmit your credentials to any other destination and we do not read them. Anyone with access to your unlocked device can see them, so treat the device accordingly and prefer keys scoped to the narrowest permission the task needs.

The request proxy

Browsers block many direct calls to third-party APIs. When the proxy setting is on, a step's request is sent to /api/proxy on our server, forwarded to the destination you configured, and the response is returned to your device. The proxy does not write request or response bodies to storage and does not log them. Cloudflare, our hosting provider, processes the request in transit and retains standard technical metadata such as IP address and timestamps under its own privacy policy. You can switch the proxy off in Settings, in which case requests go directly from your browser and never reach our servers.

Third parties

Zymura contains no analytics, no advertising and no trackers. Two service providers are involved in running it: Cloudflare hosts the application and the request proxy, and Supabase provides authentication and the database if you create an account. Beyond those, the only external services contacted are the ones you name in your own flows. Each of those has its own privacy policy and terms, and your use of them is between you and that provider.

Notifications

If you allow device notifications, they are generated locally by flows you built. There is no push server and no notification is sent from us.

Your rights

Access and portability: Settings → Export everything gives you a complete JSON copy of your flows at any time, signed in or out.

Correction: edit or delete any flow in the app; the change propagates to your account immediately.

Erasure: deleting a flow removes it from our database as well as your device. To delete your entire account and every row attached to it, use Settings → Delete your account in the app, which erases everything immediately. You can also email the address above from your registered address and we will erase it within 30 days. Full detail is on the account deletion page. You do not have to give a reason.

These rights are available to you under India's Digital Personal Data Protection Act, 2023, and to users in other jurisdictions under their local law. Our grievance contact is the email address at the top of this policy.

Paying for Zymura

Paid plans are sold through a merchant of record, which is the legal seller of the subscription. They collect payment, apply the correct tax for your country, and issue your invoice. We never see or store your card details — the payment provider handles them, and we receive only your plan, its status and your billing country. Customers in India are billed through Razorpay; customers elsewhere through our international merchant of record. Each provider's own privacy policy governs the payment data they hold.

Where you are, and what law applies

Zymura is operated from India and available worldwide. The data controller is TEJ Workspace, Bengaluru, contactable at support@tejworkspace.com.

Where your data is processed. Accounts and synced flows are stored by Supabase; the application and request proxy run on Cloudflare's global network. This means your data may be processed outside your own country. Both providers operate under standard contractual clauses and equivalent safeguards for international transfers.

If you are in the UK, the EEA or Switzerland, we process your data on two lawful bases: performance of a contract, for the account and flows you asked us to store and run, and legitimate interests, for keeping the service secure and working. You have the right to access, correct, delete and port your data, to object to or restrict processing, and to lodge a complaint with your national supervisory authority — in the UK, the Information Commissioner's Office. We do not use your data for automated decision-making or profiling, and we do not sell it.

If you are in India, the Digital Personal Data Protection Act, 2023 applies, and the grievance contact is the address above.

If you are in Japan, the Act on the Protection of Personal Information applies and the same rights of disclosure, correction and deletion are available through that address.

Retention. Flows and connections are kept until you delete them or close your account. Run history is kept per plan — 7 days on Free, 90 days on Pro, one year on Team — and then deleted automatically. Webhook payloads expire after 3 days. Deleted accounts are erased, not archived.

What we deliberately do not collect

Many automation tools gather telemetry by default. We gather none. Specifically, Zymura does not collect:

There is no opt-out setting for telemetry because there is no telemetry to opt out of.

Who else processes your data

Two providers are involved in running the service, and no others:

ProviderWhat they handleWhere
CloudflareHosting, the request proxy, and the webhook queueGlobal edge network
SupabaseAuthentication and the database, if you have an accountMumbai, India
Our payment providerCheckout, invoicing and tax, as merchant of recordOnly if you buy a paid plan

If this list changes, the date at the top of this page changes with it. We will not add an analytics provider without saying so here first.

Log retention

Operational logs — the technical records of requests reaching our servers — are kept for 30 days and then deleted, except where a specific security investigation requires keeping a subset for longer. Run history follows your plan: 7 days on Free, 90 days on Pro, one year on Team, after which entries are removed automatically. Backups held by our database provider are cycled within 90 days, so deleted data disappears from backups within that window.

AI steps

If a flow uses the AI model action, your prompt is sent to the provider you configured, using your API key, and their terms govern what happens to it. We do not add prompts to any model, we do not train anything on your data, and Zymura itself sends nothing to an AI service on your behalf.

For business customers

If you use Zymura to process other people's personal data, you are the controller and we are your processor. A data processing agreement including standard contractual clauses is available on request from support@tejworkspace.com.

Children

Zymura is a business productivity tool and is not directed at children under 13. We do not knowingly collect information from children.

Security

The app is served over HTTPS. The proxy refuses cross-origin callers and requests to private network addresses. Because credentials live on the device rather than a central server, there is no user credential database to breach — but equally, we cannot recover anything for you if a device is lost. Keep exports of any flow you would not want to rebuild.

Changes to this policy

If this policy changes materially, the date at the top changes and the new version appears at this URL. The Play Store listing links here, so the current version is always the one that applies.