1. Who is responsible
Arbiter Technologies Ltd., UIC 207164164, Prof. Krastyo Mirski Str., Bl. 10, Ent. A, Apt. 8, Sofia 1407, Bulgaria, provides Zymorph. Contact support@arbt.tech for privacy questions or requests.
We are the controller of personal information we process to operate our website and hosted services, manage billing and business relationships, respond to support requests, and meet our own legal obligations. This notice describes those activities and explains the separate data flows you initiate from the desktop app.
When your organisation determines why and how personal information is used in its generated apps or shared workspaces, it may be the controller of that information. Its own notices and responsibilities apply. Where we process information solely on an organisation’s behalf, the applicable data-processing agreement governs that processing. This notice does not replace such an agreement.
2. Information on your device
Zymorph normally keeps app source, working app data, conversations, settings, local recovery materials, and saved credentials on your device. Keeping information locally does not make every use offline. AI requests, network-enabled apps, connected services, and Team collaboration can transmit information as described below.
Your operating system, device administrators, backup services, and people with access to your device may also have access to local information. Credentials are kept outside generated app source, but their protection varies by credential type and operating-system support. Do not assume that every local file or saved credential is encrypted by Zymorph.
We do not receive the contents of a local workspace merely because you created it. Information can reach us when you use our hosted features or send it to support. Information can reach other providers through the features you use.
3. AI requests and generated apps
When you ask Zymorph to create or change an app, your selected model provider receives the request and relevant working context. Depending on the task, that can include conversation history, app source, sample or working data, tool results, and screenshots or files you provide or authorise the app to read. Context may include personal information contained in those materials.
Your device communicates with the selected model service using your configured access. The provider receives connection and account information as well as the submitted content. Its own terms, retention rules, international-transfer arrangements, and training settings apply. Zymorph does not promise that every provider excludes submitted information from training. Review the settings and terms for the account you actually use.
A generated app can make network requests or send information to services as part of its behaviour. Review its behaviour and permissions before using personal or confidential information. Giving an app folder access can make information in that folder available for its authorised work; read-and-write access also permits changes.
4. Connections and private app values
When you connect an external account, the provider supplies the account details, permissions, and access credentials needed for that connection. Account labels and permissions help you recognise and manage it. Credentials are stored separately from generated source, and a generated app receives the results of permitted operations rather than the connected-account credential itself.
Some sign-in flows use an Arbiter-operated service to complete authentication and return credentials to your device. That service processes device and request identifiers and handles authorisation codes and credentials during the exchange. It is not a central store of your connected-account documents. When you use a Connection, the relevant service receives the approved operation and associated information.
For Google Connections, access is limited to the permissions you approve and the features you request. Zymorph’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Those requirements restrict use of Google account data, including use to develop or train general-purpose AI models. If you request work that sends relevant connected-service information to your selected AI provider, that transfer must remain within the permissions and restrictions applicable to that data.
Private values you enter for an app, such as service API keys, are used for that app’s authorised work. Do not put secrets in prompts, screenshots, or ordinary app fields. You can disconnect accounts and revoke grants in Settings, and revoke access with the external provider. Disconnection does not delete information the provider or another recipient already received.
5. Team collaboration and hosted coordination
Team makes shared workspace information available to authorised participating devices. Those devices receive the app information needed for collaboration. Workspace content is encrypted during transfer between devices; our coordination services can carry encrypted deliveries without holding the workspace keys needed to read their contents.
Operating collaboration still requires metadata. We process device and workspace identifiers, public keys, Team ownership and membership, invitations and approvals, subscription and access status, routing information, delivery timing and acknowledgements, and service-request information such as IP addresses. Identifiers and encrypted information may still be personal data; encryption does not make all processing anonymous.
Participating devices and administrators can see the identity and membership information exposed by the sharing features. Direct connections can also reveal network information to peers. Transport and relay providers process connection information necessary to deliver traffic. Only share with recipients you trust: access removal cannot erase files or copies already downloaded, and offline devices may not learn about a change immediately.
6. Website, payments, and support
Website and service access. Requests to our website and hosted services involve information such as IP address, request time, requested resource, browser or app information, and security-related events. We use this information to deliver content, prevent abuse, and diagnose faults. The website stores your documentation theme preference locally in your browser. Third-party sites you open, including checkout, apply their own storage and cookie practices.
Payments. Stripe collects payment and billing details when you purchase Team or use its billing portal. We receive or can access the customer and subscription identifiers, billing contact and invoice information, payment status, amounts, and other records needed to manage the purchase, refunds, disputes, and accounting. We also record the Terms version accepted at checkout and its association with the purchasing installation and checkout session. We do not receive your full card number or card security code. See Stripe’s Privacy Policy.
Support and diagnostics. If you contact us, we receive your contact details, correspondence, and any attachments or diagnostic material you choose to send. Diagnostic records are kept locally and can be exported for troubleshooting. Redaction reduces sensitive details but cannot guarantee that a report contains no personal information. Review exports before sharing them. Do not send passwords, API keys, or unrelated private data to support.
7. Purposes and legal bases
Where the GDPR applies, we rely on the following bases for the processing for which we are controller:
- Contract: providing requested hosted features, administering an individual customer’s subscription, processing a purchase or refund, and responding to requests about that contract. Information necessary to provide these features is required for that purpose; you can use local features without purchasing Team.
- Legitimate interests: securing services, preventing fraud and misuse, resolving technical faults, handling business contacts and organisation-managed installations, and establishing or defending legal claims. Our interests are reliable services and responsible business administration; we consider your rights and reasonable expectations when relying on them.
- Legal obligations: accounting, tax, responding to valid legal demands, and handling statutory consumer and privacy rights.
- Consent, where required: optional activities that require it. We will explain the specific activity and request consent separately before it starts. You can withdraw consent without affecting the lawfulness of earlier processing.
Accepting the Terms is not blanket consent to personal-data processing. A permission allowing an app to access a folder or account is also not a substitute for any consent or other legal basis required for the information in it.
We do not use personal information to make decisions based solely on automated processing that have legal or similarly significant effects on you. Automated payment and access checks administer the service; contact support if you believe a restriction is incorrect. AI output in an app is not an Arbiter decision about the people whose information the app contains.
8. Recipients and international transfers
Information may be received by the model providers and connected services you choose, authorised workspace participants, and service providers supporting hosting, transport, payments, communications, support, and professional administration. We limit access to what is needed for the relevant purpose. Providers acting on our instructions are subject to appropriate contractual obligations; others, including payment providers for some activities, act under their own legal responsibilities.
We may disclose information when required by law, to protect legal rights or service security where lawful and necessary, or as part of a business transfer subject to applicable safeguards and notice requirements. We do not sell personal information.
Providers or recipients may be outside Bulgaria or the European Economic Area. For transfers we control that require a GDPR transfer mechanism, we use an applicable adequacy decision or appropriate safeguards such as European Commission standard contractual clauses, with additional measures where required. Contact us for information about the relevant recipients and a copy or description of applicable safeguards. Transfers you initiate through your chosen provider or to a Team participant are also affected by that recipient’s location and arrangements.
9. Retention and deletion
We retain information only for the purpose that justifies holding it, including applicable legal obligations. The relevant criteria differ:
- Local work and credentials: remain on your device until removed through the relevant controls or deleted with the app’s data. Uninstalling the application may leave its data directory or operating-system backups behind. Trashing a workspace is reversible; permanent deletion is a separate action. Removing a workspace does not automatically disconnect every saved external account.
- Local diagnostics: normally rotate after 14 days and are also limited by size. Exported copies remain wherever you save or send them.
- Hosted encrypted deliveries: are retained for delivery and removed on acknowledgement or expiry; the standard offline-delivery lifetime is seven days. Delivery storage is not a permanent backup.
- Device, membership, and security records: are retained while needed to operate access, prevent a removed identity from regaining access, resolve incidents, and establish or defend claims. Revocation records may need to outlast active membership.
- Billing and acceptance records: are retained for applicable accounting and tax periods and as necessary to evidence the contract, handle refunds or disputes, and establish or defend claims. Cancelling renewal does not immediately erase these records.
- Support correspondence and operational logs: are retained for the time needed to resolve the request or incident and any relevant follow-up or legal claim, with access restricted to that purpose.
Where deletion is required, we remove or anonymise the relevant information subject to lawful retention requirements. Backup copies may remain until their normal replacement cycle and are restricted from ordinary use. We cannot delete information held independently by another provider, a Team participant, or your own backup service. Ask those recipients directly where necessary.
10. Your rights and choices
Depending on applicable law, you can request access, correction, erasure, restriction, or portability of personal information, and object to processing based on legitimate interests. You may withdraw consent where we rely on it. Some rights are subject to legal conditions, including retention required by law.
Email support@arbt.tech. Describe the service and information concerned without sending credentials. We may request proportionate information to verify that the request relates to you or that you are authorised to act for someone else. We normally respond to GDPR requests within one month and will explain any lawful extension. You will not be penalised for exercising your rights.
For information controlled by your organisation or an external provider, contact it as well. Your practical controls include choosing a model provider, limiting folder and account permissions, disconnecting accounts, reviewing diagnostic exports, managing sharing, and deleting local information.
You may complain to the Bulgarian Commission for Personal Data Protection or your local supervisory authority, including where you live, work, or believe an infringement occurred. You do not have to contact us first.
11. Adults, changes, and contact
Zymorph is intended for adults aged 18 or older. If you believe a child has provided personal information to an Arbiter-operated service, contact us so we can assess and address it. This age rule does not itself authorise users to process children’s information in generated apps.
We will update this notice when relevant processing changes and provide additional notice where required. Each version shows its identifier and effective date. Material new purposes requiring consent will not begin merely because a notice has been updated.
For questions, contact support@arbt.tech. See also the Terms and Conditions.