Privacy and Data Policy
Last updated: August 27, 2026
The short version
Zero is a wearable ring and an AI concierge that works on your behalf. To be useful it has to hold real things about your life: what you said, who you met, what you asked it to do, and the accounts you let it act on. That is a lot of trust, so here is exactly how we handle it.
We do not sell your data. We do not use your data to train AI models. Every customer runs in their own isolated instance, not a shared pool. Traffic is encrypted end to end across our systems. Your passwords live in a vault that only you can unlock, so nobody at Zero can read them. And we actively screen the content your concierge reads for hidden instructions that try to hijack it.
Who this covers
This policy applies to the Zero Ring, the Zero app, Zero Concierge, and meetzero.ai.
Zero is operated by Get Zerohrs Inc., 2803 Philadelphia Pike, Suite B #1459, Claymont, DE 19703, United States. Get Zerohrs Inc. is the data controller responsible for the personal data described in this policy, and you can reach us at contact@meetzero.ai.
Because Get Zerohrs Inc. is established in the United States and offers Zero to people in the European Union, we have appointed a representative in the EU under Article 27 of the GDPR. Our EU representative is Matthieu Brown, based in Luxembourg, reachable at matt@meetzero.ai. If you are in the EU or the EEA you can raise anything covered by this policy with him, instead of or as well as contacting us directly.
What we collect
- Account and order information. Your email address, and if you have ordered a ring, your name, shipping address and order amount. Order details come to us from our payment processor.
- What the ring captures. Audio of the in-person conversations around you, recorded when you activate the ring, and the transcripts, summaries, notes and follow-ups generated from it.
- What the concierge captures on calls. When you send Zero into an online call, the conversation on that call, and the transcript, summary, notes and follow-ups generated from it.
- What you tell the concierge. Your messages, requests, uploads and anything you ask it to remember, across whichever surface you use to reach it.
- Accounts you connect. When you connect a service, we store the authorisation needed to act on your behalf. Where a service offers a proper API, that means an access token scoped to the permissions you granted, and never your password. Where a service has no API and the concierge has to use a browser the way you would, your credentials are held in your vault, described below.
- What the concierge reads to do its job. To act for you, the concierge reads the content of the accounts you connect, for example your email, calendar and messages. It reads only what is in the accounts you have connected, and only to carry out what you have asked of it.
- Usage data. Metadata about how Zero runs for you: request volumes, token usage, feature usage, error and performance data. This is operational telemetry, not the content of your conversations.
- Site analytics. Anonymous page views and performance metrics on meetzero.ai. Our analytics run without cookies and without fingerprinting.
What we use it for
We use your data to run the concierge for you, to carry out the tasks you ask it to carry out, to fulfil and support your order, to keep the service secure and reliable, and to tell you about things that affect your account.
That is the whole list. We do not use your data to build advertising profiles, we do not share it with data brokers, and we do not sell it.
Why we are allowed to use your data
European law requires us to have a lawful basis for everything we do with your data. Here is ours, in plain terms.
To give you what you asked for. When you onboard you accept our terms, and that agreement is the contract between us. Under it we run the concierge, carry out the tasks you set it, connect the accounts you choose to connect, fulfil and support your ring order, and administer your account. This is processing necessary to perform that contract, and without it there is no service.
Because you agreed to something specific. A few things rest on your consent rather than on the terms, because each deserves its own decision: recording with the ring or on a call, storing a credential in your vault, and promotional email. Each one is something you switch on yourself, and you can withdraw at any time by turning the feature off, removing the credential, or unsubscribing. Withdrawing does not make anything we did beforehand unlawful.
Because we have a legitimate interest. Keeping the service secure and reliable, preventing fraud and abuse, screening incoming content for hidden instructions, fixing faults, and understanding in aggregate how Zero is used so we can improve it. We have weighed these against your rights and kept the processing to what is needed for the purpose. You can object to any of it and we will stop, unless we have compelling grounds not to.
Because the law requires it. Keeping order and payment records for tax and accounting, and responding to valid legal orders as described above.
People who are not our customers. Where the concierge handles information about someone who never signed up, our basis is legitimate interest: producing the result our customer asked for. We keep that to the minimum needed, we never use it for marketing or profiling, and anyone can object by contacting us.
Sensitive information. An concierge that reads your inbox and records real conversations will sometimes encounter information the law treats as sensitive, such as health, religion or political opinions. We do not seek it out, we do not use it to categorise you, and we do not use it to make decisions about you. Where we process it, we do so on the basis of your explicit consent, given when you switch on the feature that captures it, and you can withdraw that consent at any time.
We do not train AI models on your data
We never use your conversations, recordings, transcripts, notes or connected account content to train or fine-tune AI models.
Zero uses third-party AI model providers to generate responses. Your content is sent to them only to produce your result.
We may look at aggregated, de-identified patterns in how Zero is used, for example which kinds of requests are most common, so we can improve the product. That analysis is only ever done in aggregate and is never used to train models.
Your own isolated instance
Every customer runs on a dedicated, isolated instance rather than in a shared multi-tenant pool. Your concierge, your data and your connected accounts live inside your own instance. There is no path by which one customer's concierge can be routed into another customer's instance, and no shared conversation store between customers.
Access to production systems is limited to the engineers who operate them, under least-privilege controls.
Encryption in transit
Passwords and the vault
Some services you will want the concierge to use, for example LinkedIn or a travel booking site, offer no API. The only way for the concierge to act there is to sign in through a browser, the same way you would.
For these, Zero uses a credential vault:
- Your credentials are stored encrypted in a vault that is unlocked by you, using a method only you hold, such as a passcode, biometric confirmation or two-factor approval.
- You choose which individual credentials the concierge may use. Granting access to one does not grant access to the rest of your vault.
- When the concierge needs a credential it asks you to approve, in the moment. You approve, it signs in, the vault relocks.
- The concierge can use a credential to sign in without the plaintext password being exposed to it.
- Nobody at Zero can read your stored passwords. We do not hold the key that unlocks your vault, so this is a structural limit rather than a policy promise. If someone obtained access to your instance, your vault contents would still be encrypted.
We never store your card details. Where a task requires payment, the concierge sends you a payment link and you pay directly through the merchant.
Protection against prompt injection
Because your concierge reads real content from the outside world, that content can be used to attack it. A malicious email, message or document can carry hidden instructions designed to make the concierge do something you never asked for, such as leaking your data or taking an action on your accounts.
This is a genuine and industry-wide risk, and we treat it as one:
- Content the concierge ingests is screened for hidden or malicious instructions before it is acted on. This applies across the sources it reads, including email, messaging and your connected integrations.
- The concierge is built to treat content it reads as information, not as commands. Instructions come from you.
- When we detect something suspicious, we tell you rather than quietly proceeding. You will get a message along the lines of “this email looked like it was trying to give me instructions, I did not act on it, take a look.” You decide what happens next.
- Suspicious activity also raises an internal alert so our team can respond if a customer is being targeted.
- We test these defences continuously against known attack patterns, and update them as new ones emerge.
We will not claim this is solved. No one in the industry has solved it. What we can commit to is that we screen for it, that when something looks wrong we stop and ask you rather than going ahead, and that we tell you when we catch something.
Automated decisions
Zero acts on your instruction. It does not make decisions about you.
The concierge drafts, schedules, books and replies on your behalf, and it does all of that because you asked it to. Where an action would commit you to something, it asks you to approve it first. We do not make automated decisions about you without your prior agreement.
We do not use automated processing to make decisions that produce legal effects for you, or that affect you significantly in a similar way, such as decisions about credit, employment, insurance, or whether you can use a service. If we ever build something that decides rather than acts, we will tell you before it applies to you.
Google account access
If you connect a Google account, Google shows you exactly what access is being requested before you agree to anything. You can withdraw that access at any time from your Google account permissions page, and doing so stops all future access immediately.
Zero's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Google user data only to provide and improve the features you are using.
- We do not transfer it to anyone except as needed to provide those features, to comply with the law, or in a business transfer with notice to you.
- We never use it for advertising, and we never use it to market to the people who appear in your mail or your calendar.
- We do not use it to train or improve AI models.
- No one at Zero reads your Google data, except with your specific permission, where it is necessary for security or to comply with the law, or where the data has been aggregated and anonymised first.
The connection to Google is brokered by an integration provider working on our behalf, under contract and bound by the same restrictions.
Recording, calls and consent
Zero captures conversations in two ways. The Zero Ring records the conversations you have in person, when you activate it. Zero Concierge joins your calls online as a participant. In both cases Zero produces a summary of the conversation, along with notes and follow-ups.
Consent is your responsibility. Laws on recording conversations differ by country and, in some places, by state. Some require the consent of everyone present, not only yours. You are responsible for using the ring and the concierge lawfully wherever you are, and for telling the people you are with. The ring indicates when it is recording, and the concierge appears as a visible participant in your call.
Raw audio, and where you are. If you are in the EU, the EEA, the UK or Switzerland, we do not store raw audio. The audio is processed to produce the transcript and is then discarded. What we retain is text: the transcript, the summary, and anything you asked the concierge to remember. Everywhere else, we retain the audio recording alongside the transcript unless you delete it.
How we tell speakers apart. A transcript shows you who said what. We work that out by separating the voices within that one recording, and nothing about anyone's voice is kept once it is done. The names come from context rather than from sound: the calendar invitation, the participant list on the call, the email thread, or you telling the concierge who was there. We do not create voiceprints. We do not store voice signatures. We cannot recognise someone by their voice in a later recording. When the same person turns up in two meetings, we know that from the invitations, the same way you would.
You can stop a recording, remove the concierge from a call, or delete a recording, transcript or summary afterwards.
People who are not Zero customers
Zero necessarily handles information about people who never signed up for it. Your inbox contains other people's names and messages. Your calendar lists other attendees. A conversation the ring records, or a call the concierge joins, includes whoever else was there.
We treat that information as part of the conversation it came from, never as a lead:
- We use it only to produce the result our customer asked for: the summary, the reply, the scheduled meeting, the follow-up.
- We do not build profiles of people who are not customers, we do not add them to any marketing list, and we do not sell or share their information.
- We do not use it to train AI models. That commitment covers everyone who appears in the data, not only our customers.
- It lives inside our customer's isolated instance and is deleted along with the conversation or recording it belongs to.
If you are not a Zero customer and believe we hold information about you, email contact@meetzero.ai and we will tell you what we have and delete it where we can. In most cases that information sits inside a customer's private instance, which means we may need to involve them before we can act, and we will tell you if that is the case.
Where your data lives
Your data is hosted in the European Union. That is true wherever you are. If you are in the United States, in Asia, or anywhere else, your data still sits on EU infrastructure.
This is deliberate. The EU sets the strictest data protection standard in the world, and hosting everything there means one standard across our infrastructure rather than a patchwork that varies by where you happen to live. The access, correction, export and deletion rights described below are available to every Zero customer, not only to those the GDPR covers.
Application infrastructure runs with our cloud and platform providers. The site is fronted by Cloudflare DNS. Payment data lives with Stripe and their handling is covered by Stripe's privacy policy.
We use a limited set of sub-processors to run the service, covering hosting, infrastructure, payments, AI model providers and integration connectivity. All are bound by agreements covering confidentiality and data protection. A current list is available on request from contact@meetzero.ai.
We do not mirror your data to providers outside this set.
International transfers. If you are outside the European Union, your data is transferred to and stored in the EU. Members of our team and some of our sub-processors are located outside the EU and access it from there, under the safeguards required by law.
When we are legally required to disclose
We may have to disclose information when the law requires it. We would rather set out how we handle that now than surprise you later.
We disclose in response to a valid legal order we are obliged to comply with, such as a court order, subpoena, warrant or binding regulator request. We may also disclose where we reasonably need to in order to investigate suspected fraud or abuse of Zero, to enforce our terms, or to protect someone from imminent harm.
How we handle those requests:
- We review every one. Where a request is broader than the law requires we ask for it to be narrowed, and we push back on requests that look invalid or overbroad.
- We tell you before we disclose anything, so you have a chance to respond, unless we are legally prohibited from telling you or someone's safety is at immediate risk. If a gag order later expires, we will tell you then.
- We disclose the narrowest set of data that answers the request. We do not hand over an instance wholesale because it was easier.
- Get Zerohrs Inc. is a US company and your data is hosted in the EU, so we may receive legal process from either jurisdiction. We apply the same review to both.
There is one thing we cannot produce. We do not hold the key to your credential vault, so we cannot hand your stored passwords to anyone, including a government. That is a limit of how the system is built, not a promise about how we would behave.
If the business changes hands
Cookies
Most of Zero happens in WhatsApp and Telegram, where there are no cookies at all. The website is different, so here is exactly what meetzero.ai sets.
The website sets a small number of first-party cookies so that it works properly: remembering how you arrived, so a referral is credited to the right person, and keeping you signed in where you sign in. They expire on their own and they never leave our own site.
We use no third-party advertising or tracking cookies. We do not follow you around the internet. Our page analytics run without cookies and without fingerprinting.
How long we keep things
- Conversations, transcripts and summaries are kept while your account is active, so the concierge can remember context and stay useful to you.
- Audio recordings are kept while your account is active, except in the regions listed above where raw audio is never stored.
- You can delete individual recordings, transcripts, summaries and conversations at any time from the app.
- When you close your account we delete your data, including your instance, within 30 days. Backups age out on their normal cycle.
- Order and payment records are kept as long as tax and accounting law requires.
- Operational logs and usage metadata are kept on a short rolling window.
Marketing emails
If you join the waitlist or order a ring, we will email you about your order, your access, and anything that materially affects your account. Those are service messages, and you cannot unsubscribe from them while you have an account with us, because you need them.
Anything promotional is separate. Every promotional email has an unsubscribe link, unsubscribing takes effect immediately, and it has no effect on your account or your order. We do not sell or rent your email address, and we do not send you other companies' marketing.
Your controls
- Delete your data. Email contact@meetzero.ai and we will remove your record within 7 days. If you have an open pre-order we will refund and cancel it as part of the deletion.
- Export your data. Same email, same turnaround.
- Disconnect an account. You can revoke the concierge's access to any connected service at any time, from the app or from the service itself.
- Revoke a credential.You can remove any credential from your vault, or withdraw the concierge's permission to use it, at any time.
- Access, correction and objection. If you are in the EU, UK or another region with equivalent rights, you have the right to access, correct, port, restrict or object to our processing of your data, and to complain to your local data protection authority. Email us and we will handle it.
If you are in the United States
Some US states, California among them, give residents specific privacy rights: to know what is collected, to have it deleted or corrected, and to opt out of the sale or sharing of personal information.
That last one is simple in our case. We do not sell personal information and we do not share it for cross-context behavioural advertising. There is nothing to opt out of, because we do not do it.
Every control listed above is available to you wherever you live, not only where the law requires it. We will never treat you differently for exercising a privacy right, so using one will not cost you service, price or quality.
What we do not do
- We do not sell your data.
- We do not train AI models on your data.
- We do not use third-party advertising trackers.
- We do not store your card details.
- We do not read your vault passwords.
- We do not create voiceprints or identify anyone by the sound of their voice.
- We do not share your data with third parties for advertising.
Children
If there is a security breach
If data we hold about you is exposed in a way that is likely to put you at risk, we will tell you. We would rather deliver bad news ourselves than have you read it somewhere else.
- We notify the relevant supervisory authority within 72 hours of becoming aware of a breach, as the GDPR requires.
- We notify affected people without undue delay where the breach is likely to result in a high risk to them.
- The notice will say what happened, what data was involved, what we believe the consequences are, what we have done about it, and what you can do to protect yourself.
- We keep you updated as we learn more, rather than sending one notice and going quiet.
Security reporting
If you find a security issue, please tell us at security@meetzero.ai. We will acknowledge your report and keep you posted while we work on a fix. Depending on the severity of what you find, we may offer a bounty.
We treat good-faith research as a contribution rather than a threat. Please give us a reasonable window to fix the issue before sharing it publicly.
Changes
Contact
Our privacy contact is Matthieu Brown, who is responsible for how Zero handles personal data. You can reach him directly at matt@meetzero.ai.