Privacy Policy — Pazi

Who Controls Your Information?

Pythagora is generally the controller of account, product, security, billing, and service-operations information. When a customer uses Pazi to process personal information in its own content or workflows, that customer may be the controller and Pythagora may act as its service provider or processor.

1. Information We Collect

Account and Profile Information

We collect information such as your name, email address, username, profile image, authentication provider, provider account identifier, account role, preferences, and consent choices.

Business, Agent, and Workspace Data

We process the information you and your organization provide to operate Pazi, including business profiles and goals, websites, prompts, conversations, messages, agent instructions and memory, files and uploads, generated content and images, schedules, opportunities, activity records, and communications sent or received through connected channels. Agent runtime transcripts and provider storage may contain the context needed to continue a conversation or complete a task.

Saved Credentials and Connected Services

When you intentionally save a credential or connect a service, we process the service name, credential field names, encrypted credential values, OAuth tokens, scopes, provider identifiers, connection status, and related metadata. Saved credential values are encrypted at rest and made available to authorized agent runs only when needed to perform your instructions.

Billing and Funding Information

We process plan, subscription, Stripe customer and subscription identifiers, invoices and payment status, cash balances, payout balances, and usage, transaction history, and related billing records. Payment-card details are collected and processed by Stripe; Pazi does not store complete card numbers.

Meta Advertising Data

If you use Pazi-Funded Advertising, we process your advertising authorization, accepted terms version, business and website information, creative text and images, destination, audience and placement selections, budget and schedule, moderation state, campaign status, daily funding charges, and performance metrics such as impressions, clicks, spend, CPM, CTR, and CPC. We also retain internal and Meta identifiers needed to create, manage, reconcile, pause, and report on the campaign.

Device, Usage, and Support Information

We collect device and browser type, IP address, timestamps, page and feature interactions, cookie or device identifiers, referral information, performance data, diagnostic events, error details, support messages, and security signals. We minimize or redact sensitive values in logs where practical.

Web and Third-Party Information

At your direction, Pazi may process content from webpages, public sources, connected applications, email, Slack, advertising platforms, or other services. Browser or webpage content is not retained merely because an agent viewed it, but information included in an agent result, message, file, memory, integration event, or workspace may be stored as part of the Service.

2. Sources of Information

We receive information:

3. How and Why We Use Information

Where EEA or UK data-protection law applies, our legal bases may include performance of a contract, legitimate interests in operating and securing the Service, consent (including where required for advertising cookies), and compliance with legal obligations.

4. AI Processing

Pazi sends the instructions, context, tools, and content needed for a task to AI model and infrastructure providers acting for us or, when you choose a user-owned provider connection, acting under your account. Pazi does not use Business DNA, project files, conversation content, or agent outputs to train or fine-tune our own general-purpose models. We use commercial and API services whose business-data terms restrict provider training by default, subject to the provider and connection you select.

5. Meta Advertising and Platform Data

Pazi uses a Pazi-owned Meta system credential, business portfolio, ad account, Facebook Page, Instagram account, and payment method. Customers do not connect their own Meta account for this feature. When an eligible owner starts or continues a campaign, Pazi sends Meta the approved creative, destination, audience and placement settings, campaign budget and schedule, and advertiser or beneficiary disclosures required for delivery.

Meta returns provider object identifiers, approval and delivery status, diagnostic codes, and normalized campaign insights. Pazi uses this Platform Data only to create, manage, secure, reconcile, and report on the advertising service, meet Meta requirements, resolve disputes, and comply with law. Raw provider identifiers and credentials are not exposed through customer-facing Pazi responses.

Ads and associated business identities are public, may be re-shared, and may appear in Meta's Ad Library and transparency tools. Meta processes information under its own terms and policies, including the Meta Commercial Terms and Meta Privacy Policy.

6. How We Disclose Information

We may disclose information to:

We do not sell personal information for money. Our marketing website uses advertising pixels that may be considered "sharing," "targeted advertising," or cross-context behavioral advertising under some laws, as explained below.

7. Cookies, Analytics, and Advertising Pixels

We use session and preference technologies needed to operate the Service, PostHog for product analytics, and Sentry and logging providers for reliability and security. On production marketing pages, we may use Meta, Google Ads, X, and LinkedIn pixels to measure campaigns and build remarketing audiences.

Where consent is required, advertising pixels do not load until you accept them. You can reject them through the cookie banner. We also honor a recognized Global Privacy Control signal by keeping those pixels disabled. Browser settings may provide additional cookie controls, but blocking essential technologies can affect the Service.

Pazi-hosted customer websites may also use PostHog analytics and sampled session recordings. We mask form inputs and marked private content, remove URL query strings, and give the business owner and authorized members access to the resulting reports.

8. Data Retention and Deletion

Deletion cannot recall copies another person already downloaded or content retained by a third-party service under its own terms. We retain information no longer than reasonably necessary for the purposes described here, unless a longer period is required or permitted by law.

9. Security

We use reasonable administrative, technical, and organizational safeguards, including access controls, tenant scoping, encryption for saved credentials, short-lived runtime authorization, secret redaction, and monitored provider boundaries. No service is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.

10. Government and Legal Requests

When a public authority requests user information, our policy is to:

We may notify the affected customer before disclosure unless prohibited by law, the request, or a reasonable safety or integrity concern.

11. International Data Transfers

Pythagora is based in the United States, and our providers may process information in the United States and other countries. Those countries may have different data-protection laws. Where required, we rely on appropriate transfer mechanisms and safeguards, such as contractual protections.

12. Your Privacy Rights

Depending on where you live and subject to applicable exceptions, you may have rights to access, know, correct, delete, or receive a copy of personal information; restrict or object to processing; withdraw consent; opt out of sale, sharing, or targeted advertising; limit certain uses of sensitive information; and receive equal service without unlawful discrimination.

Submit a request to hi@pythagora.ai. We may need to verify your identity and authority. Authorized agents may also submit requests where permitted. If we deny a request, you may appeal by replying to our decision and may complain to your local regulator. We honor recognized Global Privacy Control signals for marketing pixels as described above.

13. Children's Privacy

Pazi is not intended for anyone under 18, and we do not knowingly collect personal information from a person under 18. If you believe a person under 18 provided information to Pazi, contact us so we can investigate and remove it where appropriate.

14. Changes to This Policy

We may update this Privacy Policy. If a change is material, we will provide reasonable notice through the Service, by email, or by updating the effective date. Your use of the Service is also governed by our Terms of Service.

15. Contact Us

Pythagora Technologies Incorporated

548 Market St.

San Francisco, CA 94104

United States

Email: hi@pythagora.ai