ZenoFuse legal
Privacy Policy
Last updated: 19 September 2026
This policy explains what ZenoFuse collects, why, how long we keep it, and what you can ask us to do with it. It is written to be read, not to be survived.
1. Who we are
ZenoFuse is an AI-powered bookmark manager. For anything in this policy, the contact point is contact@zenofuse.com.
2. What we collect
- Account data - your name, email address and a bcrypt hash of your password. We never store your password itself.
- Your content - the bookmarks, collections, tags and workspaces you create, including page titles, descriptions and favicons fetched from the URLs you save.
- Billing data - your plan, billing period and subscription status. Card details are handled entirely by Razorpay and never reach our servers.
- Technical data - IP address and request metadata, used for rate limiting and abuse prevention.
- Analytics - if enabled, Google Analytics 4 and Google Tag Manager collect usage statistics. These are configured by the site operator and may be absent.
3. What we do not do
- We do not sell your data, to anyone, ever.
- We do not share your bookmarks with third parties.
- We do not read your bookmarks except to provide the features you ask for.
- We do not use your content to train our own models.
4. AI processing
When you use AI categorization, the title and URL of the bookmarks being sorted are sent to the AI provider you have selected (OpenAI, Google Gemini or Anthropic) so it can suggest a collection and tags. If you supply your own API key it is encrypted at rest with AES-256-GCM and is only ever used server-side - it is never sent to your browser.
AI categorization is optional. If you never use it, nothing leaves our infrastructure for an AI provider.
5. Public sharing
Collections are private by default. If you generate a share link, that collection and the bookmarks inside it become readable by anyone who has the link, along with your display name. Revoking the link stops that immediately. Nothing else in your account is ever exposed.
6. Cookies
- Session cookies that keep you signed in. These are essential and cannot be turned off while you use an account.
- Analytics cookies, only if the operator has configured GA4 or GTM.
7. How long we keep things
- Account and content data: for as long as your account exists.
- Trashed bookmarks: permanently deleted after the retention window configured by the operator (30 days by default).
- Password reset tokens: one hour, single use, stored only as a hash.
- Backups: deleted data may persist in routine backups for a short period before being overwritten.
8. Your rights
You can access and correct your data from your account settings, export every bookmark as HTML or JSON, and delete your account at any time. Deleting your account removes your workspaces, collections, tags and bookmarks by cascade. To ask for anything else - a copy of your data, or erasure - email contact@zenofuse.com and we will respond within 30 days.
9. Security
Passwords are hashed with bcrypt. Stored provider secrets are encrypted with AES-256-GCM. Sessions are signed tokens. Traffic is served over HTTPS with HSTS. No system is perfectly secure, and we do not claim otherwise - if we ever discover a breach affecting your data, we will tell you.
10. Changes
If this policy changes materially, we will update the date at the top and, where the change affects how your data is used, notify account holders by email.
Questions?
Write to contact@zenofuse.com and a human will answer.