zeno

Privacy.

updated 2026-07-06

Short version: zeno measures your cognition from derived numbers, never from your content. We do not store your prompts, your agent output, or your code. We collect the minimum needed to run the product, and when you ask us to delete it we hard-delete your data within 30 days.

Who we are

zeno is a beta research pre-release operated by Zeno Center (United States). Questions and requests: privacy@zeno.center.

What we collect

Account identity. When you sign in, our authentication provider (Clerk) gives us your email address, your name, and an opaque user id. That id is how your data is tagged.

Cognition capture. The zeno CLI computes derived numerics on your machine: attention, effort, and drive scores, token counts, the model name, and opaque device and session ids. On the free tier nothing syncs; every number stays on your machine. On Pro and Team the CLI pushes those numerics to our cloud automatically at the end of each turn while you are signed in, so your dashboard works anywhere. Log out or set ZENO_SYNC_DISABLE=1 to stop syncing at any time. Your synced numerics are visible to you alone: real-time streams and dashboard reads are scoped to your account, and no other zeno user can see your samples, your device id, or your session ids. Raw content never leaves your machine: no prompts, no agent output, no code, no free text.

Session aggregates and research responses. Supervision events that build your curve, and survey responses if you take part in a study. Studies are optional and carry their own consent.

Usage and billing. Metered-usage counters, funnel events, and your Stripe customer and subscription ids with tier status.

We do not store, in our database: raw prompts, raw outputs, code being supervised, free-form text from supervision events, IP addresses, or browser fingerprints. Like every hosted service, our infrastructure providers (Vercel and Google Cloud) keep standard, short-lived access logs that include IP addresses; we do not use them to identify you.

Where it lives

On your machine: a local SQLite database (in ~/.zeno) under your control. We never touch it and nothing expires it; it is yours until you delete it.

In our cloud: a Postgres database, retained while your account is active.

Waitlist and contact forms

When you join the waitlist we receive your email address, your role if you share it, and which offer you clicked (trial, research updates, or design partner). Joining also subscribes you to the zeno newsletter: occasional product and research updates, sent from our own mail server. We record that you subscribed and the time you did, as our record of consent. Every newsletter carries a one-click unsubscribe link, and you can unsubscribe any time by emailing unsubscribe@zeno.center; unsubscribing stops the newsletter and does not remove you from the waitlist. The talk-to-sales form sends us your email, your team size, and whatever you write in the message box; that message is emailed to us and is not stored in our database. We may add a private note to a waitlist entry, for example that we invited you to an interview. Forms run through our own serverless functions on our hosting provider (Vercel); there is no third-party form product and no advertising pixel. We use what you send for launch updates, the newsletter, and follow-up, nothing else.

Analytics

We use Plausible Analytics: EU-hosted, cookieless, no personal data, no linkage to your account. This site sets no tracking cookies.

Deletion

When you ask us to delete your account, two things happen. Within 30 seconds: any active subscription is cancelled immediately and your account stops working. Within 30 days: your data is hard-deleted from our database. The window absorbs in-flight billing webhooks and gives you a recovery clock in case the request was a mistake. Email privacy@zeno.center from your account address to start it.

Hard-deleted means the rows that describe you and your work: sessions, capture samples and events, survey responses, and usage and funnel event logs. Two records survive: an anonymized billing row, with the Stripe ids kept for financial record-keeping but detached from your user id, and a dated log of the deletion request itself, kept as proof we honored it. Waitlist entries are separate from accounts; email us and we remove yours. Stripe also keeps its own record of past payments under financial record-keeping law; use the Stripe customer portal or contact Stripe to manage that.

Your rights

Access, rectification, erasure, portability, and objection, wherever you are. Write to privacy@zeno.center. Requests are answered within 30 days; most within 7.

Sub-processors

Clerk (authentication), Cloudflare (bot protection at sign-in, loaded by Clerk), Stripe (billing), Vercel (site and dashboard hosting, and the serverless functions behind our forms), Google Cloud (API hosting and Postgres database, US), Plausible (analytics, EU-hosted and cookieless), and the host of our own mail server (mail.zeno.center), which delivers our email and keeps a log of sent messages. A data processing agreement is signed with each; copies on request.

Updates

We revise this page when our practices change and date the revision. Last revised: 2026-07-06. For questions, write to privacy@zeno.center.