Privacy Policy

Last updated: September 24, 2026

The short version

Who we are

Zelos, Inc. ("Zelos," "we," "us") makes the Zelos desktop app, the cloud console, our SDKs and command-line tools, and the website at zeloscloud.io. We are based in the United States. Contact us at info@zeloscloud.io or at Zelos, Inc., 340 Pine St, Suite 100, San Francisco, CA 94104, USA.

This policy covers zeloscloud.io, docs.zeloscloud.io, console2.zeloscloud.io, our older console at console.zeloscloud.io, the desktop app, and our SDKs and command-line tools.

Zelos decides how account, billing, support, security, marketing, and product-analytics information is used. This includes personal information from your content that appears in analytics, session replays, or diagnostic reports used for those purposes. When we host or otherwise process your organization's content solely to provide services under its instructions, we act on that organization's behalf. Contact the organization about that processing, and contact us about processing for which Zelos decides the purposes.

What we collect

When you visit our websites. Our hosting provider receives your IP address, browser and device details, the page you asked for, and the time. If you have not made a cookie choice on zeloscloud.io, PostHog records page views, page leaves, and selected clicks, such as downloads and demo requests, without cookies. We use these events only to measure visits, traffic sources, and clicks in aggregate. Events include the page URL and path, referrer and referring domain, UTM campaign parameters, device, browser and operating system details, and click details, including the link address. PostHog uses your IP address, browser user agent, site host, and a salt that changes daily to compute a visitor ID for that day on its servers. It then drops the IP address and raw user agent. This counting does not store your location or create a person profile, and we do not link these visits across days or to a later signup. It stops as soon as you make any cookie choice. This counting does not start if your browser sends GPC on page load, or if Cloudflare, which serves our website, places your connection in the European Economic Area, the United Kingdom, or Switzerland, or cannot place it. If you allow Analytics, we also record the pages you visit, what you click, where you came from, campaign details, your approximate location based on your IP address, and your device type. We may also record a session replay. Replays mask what you type into form fields, but they can show other text on the page. Ad click IDs in page URLs are masked before they are sent to PostHog, whether or not you allow Analytics.

When you create an account. You sign in with Google, Microsoft, or GitHub. We receive your name, email address, profile picture, and an account identifier from that provider. We also keep your organizations, roles, invitations, sign-in sessions, and security records.

Account identifiers and contact information are required to create and manage your account. Billing information is required for paid purchases. Providing this information is a contractual requirement for those features; without it, we cannot provide the account or process the purchase. You choose whether to provide content or contact support.

When you pay. Stripe collects your payment details. We receive and keep billing contacts, subscription and seat details, invoices, payment status, credit balances, and your AI and storage usage. We do not receive or store full card numbers.

When you use the cloud console. We use PostHog to record page views and what you click. We link this to your account, including your name and email address. The console can also record session replays, which mask what you type into form fields but can show other content on the screen.

When you use the desktop app.

The desktop app stores your recordings, notebooks, and settings on your computer. Information from them can leave your computer when you upload or share them, use Zelos AI, send feedback, or use an extension or integration that sends data. Usage events and session replays described above can also include details such as file paths, trace names, and what is shown on screen.

Your content in the cloud. When you upload or share traces, layouts, notebooks and their outputs, or other files, we store and process them to provide the features you use.

Our older Python tools. Versions of our zeloscloud Python package and its command-line tool send usage telemetry to console.zeloscloud.io by default. It includes a random installation identifier, your computer's hostname, your operating system and Python version, the commands and functions you run with their arguments, and error details. To turn it off, set telemetry: false in ~/.zelos/telemetry/config.yaml. Setting traceback: false only removes error tracebacks.

We do not ask for sensitive personal information, such as health data, and the Services are not meant for children.

Zelos AI

When you use Zelos AI, we send your request through our cloud service and Vercel AI Gateway to AI model providers such as OpenAI. Today our default model comes from OpenAI and our backup model comes from DeepSeek. Vercel AI Gateway chooses which company runs each request. That can be the model's developer or a cloud provider that hosts the model. We also use AI to write chat titles and to summarize long conversations.

A request can include:

Our AI requests tell Vercel AI Gateway to use only providers that do not train models on the prompts they receive. That restriction relies on each provider's own terms and settings.

We store your AI chats, including tool results, in our database so you can return to them. We also record which model you used, token counts, and cost, so we can bill usage and prevent abuse.

Why we use information

We use information to:

If you are in the European Economic Area (EEA) or the United Kingdom, our legal bases are:

Cookies and similar technologies

NameSet by and purposeHow long
zelos_consentZelos, local storage. Remembers your cookie choices. Holds no identifier.Until cleared
zelos_themeZelos, local storage. Remembers whether you chose the light or dark theme.Until cleared
ph_* cookies and local storagePostHog. A pseudonymous identifier that recognizes repeat visits and links them to a later signup. On the website, set only if you allow Analytics. The console and the desktop app always use it.1 year
zelos_gclid, zelos_wbraid, zelos_gbraid, zelos_li_fat_id, zelos_twclid, zelos_rdt_cidZelos, set on zeloscloud.io and its subdomains only if you allow Advertising. Stores the ad click ID from the link you arrived on.30 days
Google, LinkedIn, X, and Reddit tagsThose platforms. Measure ad conversions and build audiences. Loaded only if you allow Advertising.Set by each platform
Console sign-in cookiesZelos. Keep you signed in to the console and protect sign-in and account linking.Up to 90 days
Desktop app storageZelos, on your computer. Stores app settings, sign-in state, and analytics settings.Until you remove it

Your choices on the website. Use to turn Analytics or Advertising on or off. Any choice, including Reject all, also ends the counting without cookies described in "When you visit our websites." When you withdraw a previously enabled category in Cookie settings, we clear Zelos's click-ID cookies and PostHog cookies and storage. Storage for a category you leave enabled can be created again. Turning off Analytics stops website PostHog capture and replay; turning off Advertising does not unload advertising tags already running. We cannot delete cookies that the Google, LinkedIn, X, or Reddit tags set. Clear those in your browser. An ad tag that already loaded stays active until you reload the page. If your browser starts sending GPC after you allowed Advertising, we stop loading ad tags, but we do not delete click-ID cookies already stored. To delete them, turn Advertising off in before you turn on GPC, or clear your cookies.

Advertising and signup reporting

If you allow Advertising on our website, we load ad tags from Google, LinkedIn, X, and Reddit. These tags measure visits and conversions, such as download clicks, and help those platforms build audiences. We also store the ad click ID from the link you arrived on.

When you create an account:

These reports use the click-ID cookies that are in your browser when you sign up. If you allowed Advertising earlier and later withdrew it in a way that did not delete those cookies, such as by turning on GPC, the click IDs can still be sent.

A hashed email address can still be matched to you by a platform that already knows your email address.

Under some US state laws, this reporting may count as "sharing" personal information, "targeted advertising," or a "sale," even though no one pays us for it. To opt out, email info@zeloscloud.io with the subject "Do not share." Turning off Advertising in Cookie settings before enabling GPC clears Zelos's stored ad click IDs; reload the page to stop previously loaded advertising tags. If you have already enabled GPC, clear those cookies in your browser. GPC alone does not currently stop signup reporting based on previously stored click IDs.

Emails

We send service emails, such as invitations, email verification, account-linking codes, and renewal notices, from no-reply@mail.zeloscloud.io through Resend.

After you sign up, we may send you up to two onboarding emails from our CEO, Michael Jaradah (michael@zeloscloud.io), through PostHog. They help you install the app and try the demo. They stop once you open the app or finish the demo. Each has an unsubscribe link, and we do not track whether you open them or click their links.

Who receives information

We share information with the service providers below. They process it on our behalf. Some also act on their own account for some purposes, such as Stripe for payment compliance and the advertising platforms for their own ad services.

RecipientWhat and why
CloudflareHosts our website, the console, our release server, and cloud storage for traces and notebooks
NeonHosts the console database: accounts, organizations, content records, AI chats, and usage records
Amazon Web ServicesHosts our older console at console.zeloscloud.io
PostHog (US)Analytics, session replay, feature flags, onboarding emails, and forwarding signup reports to Google Ads and LinkedIn
SentryError reports, crash reports, and feedback reports
StripePayments, subscriptions, invoices, and usage billing
ResendService emails
Vercel AI Gateway and AI model providersAI requests and responses, with an account identifier, for Zelos AI
Google, Microsoft, GitHubSign-in, when you choose that provider
Google Ads, LinkedIn, X, RedditAdvertising and signup reporting, as described above
SlackInternal notices to our team about new signups, downloads, visits from ads, and desktop app launches
Google CalendarWhat you enter if you book a demo through our booking link
GitHubRequests from the app or marketplace for extension information hosted on GitHub

We also share information:

Where information is processed

We are based in the United States. We and our service providers process information in the United States and may process it in other countries. Those countries may have different data protection laws. Contact us if you want more information about transfers.

How long we keep information

Copies may remain in backups for a limited time after deletion.

Files the desktop app stores on your computer stay there until you delete them. See Uninstall Zelos.

Your choices in the console and the desktop app

In the desktop app, go to Settings → Diagnostics and turn off Share usage analytics. This stops the app's custom usage events and new analytics identification calls. It does not erase an analytics identity already stored, so automatic click capture and session replays may remain linked to your name and email. It does not stop automatic click capture, session replay, feature-flag requests, crash reports, or update checks. The console does not have an analytics setting. To object to analytics in the console or the desktop app, email info@zeloscloud.io.

To stop onboarding emails, use the unsubscribe link. We still send service emails you need, such as invitations and renewal notices.

Your rights

Wherever you live, you can ask us for a copy of your personal information, ask us to correct or delete it, or object to how we use it. Email info@zeloscloud.io. We will respond within the time the law allows. We will not treat you differently for asking.

Direct marketing: You have the right to object at any time to our use of your personal information for direct marketing, including related profiling. Email info@zeloscloud.io; for onboarding emails, you can also use the unsubscribe link. We must stop processing your information for those marketing purposes when you object.

If you are in the EEA or the UK, you also have the right to restrict processing, to receive your data in a portable form, to withdraw consent at any time without affecting earlier processing, and to complain to your data protection authority.

If you live in a US state with a privacy law, you may have the right to know what personal information we have about you, get a copy, correct it, delete it, and opt out of sale, sharing, and targeted advertising. The personal information we collect is described above. It includes identifiers such as your name, email address, and IP address; internet activity; billing records; your organization; approximate location; and personal information inside your content. We may ask for information to verify your request. You can use an authorized agent where the law allows. If we deny your request, you can appeal by replying to our decision or by emailing info@zeloscloud.io with the subject "Privacy appeal."

If you are in Canada, you have the right to access and correct your personal information, withdraw consent subject to legal or contract limits, and complain to the Office of the Privacy Commissioner of Canada or your provincial regulator.

If your organization controls content that contains your personal information, we may refer your request to that organization.

Security

We protect information with measures such as encryption in transit and access controls on organization data. No system is perfectly secure. Protect your sign-in, avoid putting secrets in your content, and report suspected unauthorized access to support@zeloscloud.io.

Children

The Services are not meant for children, and accounts are for adults. If you believe a child has given us personal information, contact us and we will delete it.

Changes

We will update this page and its date when our practices change. We will tell you about material changes by email or in the Services, and we will ask for your consent where the law requires it.

Contact

Zelos, Inc. 340 Pine St, Suite 100 San Francisco, CA 94104 USA info@zeloscloud.io