1.Who we are
This Privacy Policy describes how Ziroo (“Ziroo”, “we”, “us”) collects, uses, and shares information when you use the Ziroo for Chrome extension and related Ziroo products (ziroo.me, the Ziroo API, Ziroo Code, and the VS Code extension). The Chrome Web Store listing should link to this page: https://ziroo.me/privacy/en. A Persian version is at /privacy.
2.What the Chrome extension collects
The extension acts only when you use it. It does not read pages, clicks, or form fields in the background. Depending on the feature you request, it may process:
- Account and authentication data: your Ziroo sign-in (typically a phone number), display name, and a session or API key stored locally so you stay signed in.
- Personal communications: messages you send to the assistant, including chat text, attached files, and the assistant’s replies. Chats sync to your Ziroo account by default so they appear on the website; you can turn sync off in the extension settings.
- Website content you ask us to inspect: text and structure of the current page, text you select, and, when needed, a screenshot of the visible tab.
- Tab and browsing context for the same requested task: the current tab’s URL and title, and sometimes a list of open tabs or tab groups you ask the assistant to organize. This is not a full browsing-history log.
- User-initiated actions on a site: clicks, typing, and form filling happen only with your per-site approval, or the “full access” mode you turn on yourself. Password field values are never read. Banking sites are blocked by default.
- Local preferences: interface settings, allowed/blocked sites, and other extension state kept in Chrome storage so they survive browser restarts.
- Technical logs on our servers when the extension calls Ziroo: IP address, browser or device type, timestamps, and error reports, used for security and debugging.
3.What other Ziroo products collect
- Website and API accounts: phone number, name, optional profile photo, conversations, uploaded files, projects, documents, and items you save to Memory.
- Voice input: if you use voice-to-text, audio is processed on Ziroo servers to produce a transcript.
- Billing: plan, credit usage, and payment records. Card numbers and bank passwords are entered only on the payment gateway, not stored by Ziroo.
- Ziroo Code / VS Code: files from the open project that are needed to fulfill your request.
4.How we use this information
- To provide the extension’s single purpose: AI coding and browsing assistance in Chrome’s side panel (inspecting pages you choose, debugging you request, organizing tabs you ask us to organize, and answering your prompts).
- To send your prompt and the necessary page or file context to Ziroo (api.ziroo.me) and to the AI model providers that generate a response.
- To authenticate you, apply usage limits, prevent abuse, and keep your chats and settings available across sessions.
- To operate billing on the website, provide support, and improve reliability.
5.Chrome Web Store Limited Use
The use of information received from Google APIs and from the Chrome extension will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
- We do not sell user data to third parties.
- We do not use or transfer user data for purposes unrelated to the extension’s single purpose.
- We do not use or transfer user data to determine creditworthiness or for lending.
- We do not use chats, page content, screenshots, URLs, or files to train AI models, and we do not use them for advertising.
- We do not transfer user data to third parties except as needed to provide the disclosed features (for example AI model providers that generate the reply), or if we are legally required to do so.
6.Who processes the data
We do not sell your data. To run the product we send only what is needed to:
- AI model providers: the prompt, attached files, and relevant conversation or page context, so they can generate a response. Providers may be located outside Iran.
- Web search providers, when you turn search on: the search query.
- SMS providers: your phone number, to send a sign-in code.
- Payment gateways (website checkout only): order amount and identifier.
We may disclose information if required by a competent legal authority.
7.Storage, security, and retention
- In Chrome, the extension stores your sign-in key, account details, settings, and allowed/blocked sites. Signing out deletes and revokes the key.
- Synced chats and account data are stored on Ziroo servers until you delete them or ask us to delete the account.
- Connections use HTTPS. API keys are stored hashed. Access is limited to people who operate the service. No system is perfectly secure; do not send passwords or other highly sensitive secrets in chat.
- We keep financial records for as long as applicable law requires.
8.Your choices
- You can delete individual or bulk conversations; deletion is permanent.
- You can turn off chat sync in the extension settings.
- You can review, edit, or delete Memory items in Settings.
- You can revoke API keys and Ziroo Code sessions in Settings.
- To delete your account and associated data, contact us through Help. We will retain financial records where the law requires it.
- Uninstalling the extension removes locally stored extension data from that browser.
9.Children
Ziroo is not directed at children under 13, and we do not knowingly collect personal information from children under 13.
10.Changes and contact
We may update this policy. The date at the top of the page will change, and we will note material changes in the product when appropriate. For privacy questions, use Help. See also our Terms of Use (Persian).