What we collect, why we collect it, how long we keep it, and the choices you have. Last updated: August 31, 2026.
This policy covers ziplogger.ai (the marketing website) and app.ziplogger.ai (the ZipLogger service). "ZipLogger", "we", and "us" refer to the operator of the ZipLogger service. Questions about anything on this page: [email protected].
ZipLogger handles two very different categories of data, and treats them differently:
Account data — information about you and your organization: name, email address, organization name, billing status, and the settings you configure. We are the data controller for this.
Customer telemetry — the logs, traces, metrics, and product events your applications send to your workspace. You control what is in this data; we store and process it on your behalf and on your instructions (we act as a processor for it). Do not send us data you are not allowed to share — telemetry payloads are defined entirely by your integration.
When you create an account: your name, email address, organization name, and a password (stored only as a salted PBKDF2 hash — we cannot read it). Signup requires a card check; card details go directly to our payment processor, Stripe, and never touch our servers. We store only Stripe's customer and subscription references.
When you use the service: the telemetry your applications send (logs, traces, metrics, product events), the configuration you create (dashboards, alerts, saved filters, health-check URLs, browser monitors), API keys (stored hashed), and operational records such as sign-in timestamps and audit logs of administrative actions.
When you connect integrations: if you connect a git provider (GitHub or GitLab), we store the access credential encrypted and fetch commit metadata and blame information over the provider's API — we never clone your repository. If you configure AI analysis, you supply your own AI provider key (BYOK); it is stored encrypted and used only to send analysis requests to the provider you chose.
When you visit the website: standard analytics as described in section 6.
To provide the service: storing and searching your telemetry, evaluating your alert rules, running the health checks and browser monitors you configure, attributing regressions to commits, and sending you transactional email (invoices, password resets, alert and usage notifications). To bill you, via Stripe. To secure and operate the platform: rate limiting, abuse prevention, and debugging. We do not sell your data, and we do not use your telemetry for advertising or to train AI models.
AI analysis is opt-in and bring-your-own-key: when you ask for a root-cause analysis, the relevant log excerpts and stack traces are sent to the AI provider you configured (Anthropic, OpenAI, or Google), under your own account with that provider and subject to their terms. If you never configure a key, no telemetry is sent to any AI provider.
If you connect an AI assistant to your workspace over MCP (for example Claude or Cursor), the assistant gets read-only access to your workspace's logs, error patterns, traces, service status, and regression analyses — authorized either by OAuth with your explicit consent, or by a workspace API key you create. Whatever the assistant reads is then handled by the assistant under its own provider's terms. You can revoke access at any time by revoking the API key or contacting support.
Telemetry retention follows your plan: 5 days (Free), 7 days (Starter), 30 days (Pro), or 90 days (Team). Traces that contain an error are kept for the plan's full retention window; error-free traces are cleaned up after 48 hours. Expired telemetry is deleted automatically by our retention workers.
Account data is kept while your account is active. When you close your account (or ask us to delete it), we delete your account data and remaining telemetry within 30 days, except for records we are legally required to keep, such as invoices.
The marketing website uses Google Analytics 4 and Microsoft Clarity to understand how the site is used. The application uses Microsoft Clarity for product-usage insight. The application also sets cookies and browser storage strictly needed for signing you in. We run no advertising pixels and no cross-site tracking of our own.
We share data with subprocessors only as needed to run the service: Stripe (payments and card verification), Brevo (transactional email), Cloudflare (DNS, CDN, and network security in front of our infrastructure), Google and Microsoft (website/product analytics, section 6), and our hosting provider (servers on which the service runs). Each receives only what its function requires.
All traffic is encrypted in transit (TLS). Passwords are salted and hashed (PBKDF2), API keys and session tokens are stored only as SHA-256 hashes, and integration credentials (git tokens, AI provider keys) are stored encrypted. Access to production systems is restricted and audited. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you without undue delay.
You can access and update your account information in the app. You can export or delete telemetry through the product's search and retention controls. Depending on where you live (for example under the GDPR or CCPA), you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing. To exercise any of these, email [email protected] — we respond to verified requests within 30 days.
ZipLogger is a developer tool for businesses and is not directed at children under 16. We do not knowingly collect personal data from children.
When this policy changes materially, we will update the date at the top and, for significant changes, notify account owners by email. Continued use of the service after a change takes effect constitutes acceptance.
See also our Terms of Service.