Legal

Privacy Policy

Last updated: August 1, 2026

AskZeron is operated by Drazlon, a technology company specializing in AI-powered business solutions. This Privacy Policy explains what information we collect, why we collect it, and how we protect it. We are committed to handling your data responsibly, securely, and transparently.

What we collect

Account information

When you sign up, we collect your name, email address, and a hashed password. If you provide it, we also store your website URL and company name. This is the minimum we need to create and secure your account.

Business configuration

You provide details about your business — product info, shipping policy, return policy, FAQs, business hours — so our AI can answer your visitors accurately. This data is stored in Cloudflare KV and used exclusively to power your chatbot.

Visitor conversations

When a visitor chats with your AskZeron widget, we store the conversation text, their approximate country (from Cloudflare's geo headers), their device type, and any contact details they voluntarily share (name, email). Conversations are retained for 30 days, then automatically deleted.

Lead data

When a visitor shares their email through the chatbot, we store it as a lead on your dashboard — including their name, email, deal score, and a conversation snippet. This data belongs to you; we store it on your behalf.

Payment information

Payments are processed by Paddle, our merchant of record. Paddle handles all card details, billing information and tax — we never see, store, or handle your payment credentials. We store only the Paddle subscription or transaction ID, the plan or top-up purchased, the amount, and the payment status for our records, along with your remaining top-up conversation balance.

Technical data

We collect standard technical data: IP address (for rate limiting and security, not stored long-term), browser user agent (for error diagnostics), and Cloudflare analytics (page views, country). We do not use tracking pixels, third-party analytics, or advertising cookies.

How we use your data

We do not sell, rent, or share your data with advertisers. Ever.

AI processing

Visitor conversations are processed by Anthropic's Claude API to generate responses. Each conversation is sent to Claude with your business context (the information you configured in your dashboard) as a system prompt. Anthropic does not use API inputs to train their models. No visitor data is retained by Anthropic after processing.

Where data is stored

All data is stored on Cloudflare Workers KV, distributed across Cloudflare's global edge network. Cloudflare is SOC 2 Type II certified and GDPR compliant. Data is encrypted in transit (TLS) and at rest.

Data retention

Cookies

AskZeron's dashboard uses localStorage to store your session token — this is not a cookie and is not shared with any third party. The embeddable widget uses localStorage on your visitor's browser to save chat threads locally. We do not set any tracking cookies or use cookie-based advertising.

When you open the checkout to subscribe, Paddle may set its own cookies for fraud prevention and to complete your transaction. These are set by Paddle and governed by Paddle's privacy policy, not ours.

Third-party services

Each provider has its own privacy policy. We only share the minimum data each service needs to function.

Your rights

You can request at any time:

To exercise any of these rights, email us at help@askzeron.com. We respond within 48 hours.

Children

AskZeron is a business tool sold to businesses, and accounts may only be created by adults. We do not knowingly collect personal information from children. Visitor conversations happen on our customers' websites — the website operator, not AskZeron, controls who their site is aimed at and is responsible for compliance with children's privacy law in their jurisdiction. If you believe a child has provided personal information through a chatbot, contact us and we will delete it, and we will notify the relevant website operator.

Security

Passwords are hashed using PBKDF2 with SHA-256 (100,000 iterations) and unique salts — we never store plaintext passwords. All API communication uses TLS encryption. Customer sessions expire after 7 days and are invalidated everywhere when you change your password; administrative sessions expire after 12 hours. Password reset requests are rate-limited, reset links are single-use and expire after one hour, and failed administrative login attempts are logged. We review our codebase for security issues, though no independent third-party security audit has been carried out.

Changes to this policy

If we make material changes, we'll update the "Last updated" date at the top and, for significant changes, notify you via email. Continued use of AskZeron after changes constitutes acceptance.

Questions about your data?

Email us at help@askzeron.com — we respond within 48 hours.

Drazlon · Lahore, Pakistan