Privacy Policy
Effective Date: August 6, 2026
1. Information We Collect
1.1 Account Information
When you create a Zimmer account, we collect your name, email address, organization name, and billing information. If you sign up through a third-party authentication provider (such as Google or Microsoft), we receive basic profile information from that provider.
1.2 Agent and Content Data
We store the AI agents you create, including agent configurations, conversation flows, knowledge base content, themes, design settings, and any files or media you upload to the platform. This data belongs to you and is used solely to provide and improve the Service.
1.3 Conversation Data
When end users interact with your published agents, we collect conversation transcripts, intent classifications, sentiment analysis data, session metadata (browser type, device, approximate location), and any files attached during a conversation. Conversation data is processed to deliver AI responses, generate audience segments, and provide conversation insights to you.
1.4 Usage and Analytics Data
We automatically collect information about how you and your end users interact with the Service, including page views, feature usage, agent performance metrics, API call logs, and error reports.
1.5 Integration Data
If you connect third-party services (including Google Ads, Google Merchant Center, Display & Video 360, Google Drive, Shopify, or custom APIs), we access and store data necessary to maintain those integrations, such as product catalogs, calendar events, or document contents, in accordance with the permissions you grant. Where you have authorized it, we also write data to connected platforms on your behalf — for example, publishing your product catalog to Google Merchant Center. See Section 9 for details of data received from and sent to Google APIs.
1.6 Cookies and Tracking Technologies
We use cookies and similar technologies to maintain sessions, remember preferences, and analyze usage patterns. You can manage cookie preferences through your browser settings.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Zimmer platform and its features
- Process AI agent interactions using our AI backend or your connected custom AI backend
- Generate conversation insights, intent classifications, and audience segments as part of our core analytics features
- Improve our AI models and platform functionality (only using aggregated and anonymized data, and excluding data received from Google APIs, which is never used for model training — see Section 9.3)
- Process payments and manage your subscription
- Send you service-related communications, updates, and security alerts
- Respond to your support requests
- Detect and prevent fraud, abuse, or security incidents
- Comply with legal obligations
3. AI Processing and Data Handling
Zimmer processes conversation data through AI language models to deliver intelligent agent responses. When you use Zimmer's AI backend, conversation content is sent to our AI infrastructure (built upon third-party large language models) for processing. We do not use your specific conversation data to train or fine-tune foundational AI models.
When you connect your own custom AI backend (BYOM/RAG), conversation data is routed directly to your designated endpoint, and Zimmer does not retain copies of the AI-processed content beyond what is needed for conversation logging and analytics.
Audience segmentation and intent tagging are derived from conversation data and stored within your account. You control the export and use of these audience segments.
Data received from Google APIs is sent to language models only for in-session processing of requests you initiate, and is never used to train or fine-tune models. See Section 9.3.
4. How We Share Your Information
We do not sell your personal information. We may share information with:
- Cloud infrastructure and hosting providers who store and process data on our behalf
- AI model providers (such as Anthropic, OpenAI, or others) to process agent conversations when using Zimmer's AI backend
- Additional restrictions apply to data received from Google APIs — see Section 9.5.
- Payment processors to handle billing transactions
- Third-party integrations you have explicitly connected and authorized
- Analytics providers who help us understand platform usage (using aggregated data)
- Law enforcement or regulatory authorities when required by law or to protect rights and safety
All third-party service providers are bound by data processing agreements and are prohibited from using your data for their own purposes.
5. Data Retention
- Account data is retained for as long as your account is active.
- Conversation data is retained according to your plan settings and agent configuration (default: rolling retention based on your subscription tier).
- Files attached during conversations are automatically deleted 24 hours after upload.
- Generated documents (DOCX, PDF, CSV, XLSX exports) are retained for 7 days after creation.
- When you delete your account, we will remove your data within 30 days, except where retention is required by law.
- Google API data and OAuth tokens are deleted within 30 days of disconnecting the integration or deleting your account. Product data already published to your Merchant Center account remains under your control in Merchant Center.
6. Data Security
We implement industry-standard security measures to protect your data, including:
- Encryption in transit (TLS 1.2+) and at rest
- Regular security audits
- Access controls and authentication mechanisms
- Infrastructure monitoring
While we take reasonable steps to protect your information, no method of transmission or storage is completely secure.
7. Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
- Access, correct, or delete your personal data
- Export your data in a portable format
- Restrict or object to certain processing activities
- Withdraw consent where processing is based on consent
- Lodge a complaint with a data protection authority
- Revoke a connected platform's access at any time (see Section 9.7)
To exercise these rights, contact us at privacy@zimmer.app.
8. User Data Deletion
8.1 How to Request Deletion of Your Data
You can request deletion of your data at any time through any of the following methods:
In-App Deletion: Log in to your Zimmer account, navigate to Settings → Account → Delete Account. This will initiate deletion of your account and all associated data, including agent configurations, conversation history, knowledge base content, audience segments, and any uploaded files.
Email Request: Send a deletion request to privacy@zimmer.app from the email address associated with your account. Include your account email and organization name. We will verify your identity and process the request within 15 business days.
Data Deletion Instructions Page: We maintain a dedicated Data Deletion Instructions page that provides clear, step-by-step guidance on how to request deletion of your data.
8.2 Scope of Deletion
Upon receiving a valid deletion request, Zimmer will delete:
- Your account profile and credentials
- All AI agents, themes, and configurations you created
- Knowledge base content and uploaded files
- Conversation transcripts and analytics data
- Audience segments and intent tags
- Integration credentials and cached third-party data
- Any other personal data associated with your account
8.3 Deletion Timeline
We will process deletion requests within 30 days of receipt. Some data may be retained beyond this period only where required by law, necessary for fraud prevention, or needed to resolve ongoing disputes. We will notify you if any data must be retained and the reason for retention.
8.4 End-User Data Deletion
If you are an end user who interacted with an AI agent built on Zimmer (not a Zimmer account holder), you may request deletion of your conversation data by contacting the brand or organization that operates the agent. Alternatively, you may submit a request directly to privacy@zimmer.app with details of the agent you interacted with and any identifying information (such as email or session identifier), and we will process the deletion on your behalf.
8.5 Confirmation
After your data has been deleted, we will send a confirmation to your registered email address (or the email provided in your request).
9. Google API Services and User Data
Zimmer uses Google API Services to operate its agent kits, integrations, and authentication. Zimmer's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
9.1 Google APIs We Use and Data Accessed
The Google APIs listed below are those Zimmer requests OAuth scopes for; which ones apply to you depends on the integrations you enable from your dashboard. We access data only through the integrations you connect.
| API / Service | Data Accessed | Purpose |
|---|---|---|
| Google OAuth 2.0 / Google Sign-In | Name, email address, profile image, authentication and refresh tokens | Account creation and sign-in; authorizing Zimmer to access the Google accounts you connect |
| Google Ads API | Campaign, ad group and asset structure; performance metrics; search term reports; change history; Google recommendations; budget and bid settings | Reading performance data for monitoring, health-check and optimizer agents, and executing the write actions you approve — budget and bid changes, pause and resume, targeting adjustments |
| Merchant API (Google Merchant Center) | Product listing data — titles, descriptions, images, links, prices and sale prices, availability, GTIN/MPN/brand identifiers, product categories and custom labels; data source configuration; product status and item-level feed issues; Merchant Center account and sub-account structure | Publishing and maintaining your product catalog in Google Merchant Center so items can appear in Shopping ads and free listings; keeping price and availability current; surfacing feed disapprovals and item issues; supplying product data to Shopping, Performance Max and Demand Gen optimizer agents |
| Display & Video 360 API | Insertion orders, line items, creatives, audience lists, supply and exchange settings, performance metrics | DV360 programmatic optimization across display, video, CTV and audio, and performance analytics |
| DoubleClick Bid Manager API | DV360 performance reports — impressions, clicks, spend, conversions, viewability and reach metrics | Reporting only. Used solely to retrieve performance data from DV360 for analytics and reporting agents. No write access |
| Google Drive API (drive.readonly) | File metadata and the contents of the documents you select via the file picker | Importing selected documents into brand knowledge bases for AI agent retrieval (RAG) |
| Google Sheets API (spreadsheets) | Spreadsheet contents of the sheets you select | Syncing spreadsheet data into knowledge bases and connected data catalogs |
| Google Calendar API (calendar, calendar.events) | Calendar list, event times and availability; events created or modified on your behalf | Checking availability and booking appointments through scheduling agents |
| YouTube Data API (youtube.readonly) | Video titles, descriptions, transcripts and channel metadata | Syncing channel content into brand knowledge bases for AI agent retrieval |
| Google Ad Manager API (admanager) | Ad units, line items and orders; delivery and revenue reporting | Ad operations automation, yield optimization and revenue reporting |
| Campaign Manager 360 API (dfareporting, dfatrafficking) | Advertisers, campaigns, sites and placements; impression, click and conversion reports | Attribution mapping and cross-channel performance reporting. Zimmer performs no writes; the dfatrafficking scope is used read-only, only to list trafficking resources (advertisers, campaigns, sites and placements) |
9.2 How We Use Google User Data
We use data accessed through Google APIs solely to deliver the features you have asked us to run on your behalf. This includes reading campaign and performance data, generating analysis and action proposals, and executing approved changes across Google Ads, Merchant Center and DV360 under the guardrails, approval workflows and audit logging you configure. Every action taken through a Google API is recorded in your audit trail.
Where you connect a Google Merchant Center account, we read your existing product data and write product, inventory and promotion data on your behalf so your catalog stays synchronized with the source you have designated, such as Shopify or a connected data catalog. We write only to the Merchant Center accounts and data sources you have authorized. You remain the merchant of record for your listings and are responsible for compliance with the Shopping ads and free listings policies; Zimmer does not review or approve product content on Google's behalf.
We do not use Google user data to serve advertising to you, to build advertising profiles, for credit assessment or lending purposes, or for any purpose unrelated to the features described above. We do not sell Google user data.
9.3 Limited Use and AI Model Training
Google user data receives specific protections that go beyond our general practices:
- We do not use Google user data to develop, train, fine-tune or improve generalized or foundational artificial intelligence or machine learning models, whether our own or those of any third party.
- Where Google user data is processed by a large language model to produce output you have requested, it is transmitted only for that specific in-session request, under contractual terms that prohibit the provider from retaining it or training on it.
- Where our general policy permits us to improve our platform using aggregated and anonymized data, that permission does not extend to Google user data.
- Humans do not read your Google user data except: with your explicit consent for a specific purpose, such as support you have requested; where necessary for security, abuse investigation or to comply with applicable law; or where the data has been aggregated and anonymized so that it no longer identifies any individual or account.
9.4 How We Store and Protect Google User Data
Google user data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. OAuth access and refresh tokens are stored encrypted, held server-side only, never exposed to client-side code, and scoped to the minimum permissions required for the agents you have enabled. Access by our personnel is restricted through role-based access controls and logged. We do not retain raw Google user data beyond what is necessary for the purposes described in this section.
9.5 Sharing of Google User Data
We do not sell, rent or transfer Google user data to third parties, except:
- To sub-processors — such as cloud hosting and infrastructure providers — who process it on our behalf under binding data processing agreements
- To AI model providers, strictly for in-session processing of a request you have initiated, with no rights to retain or train on the data
- To Google, where you have instructed us to publish product, inventory or promotion data to your Merchant Center account
- Where you have explicitly directed or consented to a transfer
- Where required by law or valid legal process
9.6 Retention and Deletion of Google User Data
Google API data is retained only for as long as necessary to fulfill the purposes described above, or as required by law. When you disconnect a Google integration, we delete the associated tokens and all Google API data within 30 days, except where retention is required by law. You can additionally revoke Zimmer's access from your Google Account directly, as described in Section 9.7. Deleting your Zimmer account removes all Google user data in accordance with Section 8 of this policy. You may also request deletion at any time by writing to privacy@zimmer.app.
Disconnecting a Merchant Center integration stops further synchronization and revokes our access, but does not remove product data already published to your Merchant Center account. That data remains under your control in Merchant Center and can be removed there, or by re-enabling the integration and issuing a deletion.
9.7 Revoking Access
You can disconnect any Google integration from the Integrations page in your Zimmer dashboard. You can also revoke Zimmer's access to your Google account at any time from your Google Account Permissions page. Revoking access stops all future data collection; agents depending on that integration will stop running.
9.8 Compliance with Google Terms
Our use of Google APIs is governed by the Google API Services User Data Policy, the Google Privacy Policy, the Google Terms of Service, and the Google Ads API Terms and Conditions.
Our use of the Merchant API is additionally governed by the Merchant API Terms of Service and by Google's Shopping ads policies and free listings policies.
Our use of the Display & Video 360 and DoubleClick Bid Manager APIs is additionally governed by the applicable Google Marketing Platform terms for those services.
10. International Data Transfers
Zimmer operates globally and may transfer your data to servers located outside your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place, such as standard contractual clauses or other legally recognized transfer mechanisms.
11. Children's Privacy
Zimmer is not directed at children under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us at privacy@zimmer.app and we will take steps to delete such information.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and, where appropriate, by email. Your continued use of the Service after changes become effective constitutes acceptance of the revised policy.
13. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at:
Email: privacy@zimmer.app