Zoo Code
DocsGitHub

Privacy Policy

Effective Date: May 21, 2026•Version 1.0
Zoo Code is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your personal information in compliance with applicable privacy laws including PIPEDA (Canada) and GDPR (European Union).

1. Information We Collect

Account Information

  • Email address (used for account identification and communications)
  • Name (if provided)
  • Account preferences and settings
  • Authentication data (passwords are securely hashed)

Payment Information

  • Payment processing is handled entirely by Stripe. We do not store credit card numbers, CVVs, or full payment card details.
  • We retain: transaction IDs, purchase amounts, and timestamps
  • Billing address (for tax calculation purposes)

Usage Information

We only log AI request metadata when you route requests through the Zoo Gateway (zoocode.dev). If you configure the VS Code extension with your own provider API keys (OpenAI, Anthropic, OpenRouter, etc.), those requests go directly to that provider and we never see or log them.

For each Zoo Gateway request we record:

  • Model identifier (e.g. anthropic/claude-sonnet-4.5)
  • Token counts (input, output, cache reads, cache writes) and total tokens
  • Cost in USD (provider cost and the cost we charged your account)
  • Timing (request timestamp, time-to-first-byte, total stream duration)
  • HTTP status code and, on errors, an error code/message
  • Request context: task ID, session ID, mode (e.g. code, ask, debug), tool name, request type
  • Editor and extension version (e.g. "VS Code", "3.55.0")

We do not log the content of your prompts, your code, the model's response text, or your IP address against these request records.

We also retain:

  • Credit transaction history
  • Device information (for authorized device management)
  • IP addresses (collected for authentication and fraud prevention; stored separately from request logs)

Code and Prompts

We do not permanently store the content of your code or prompts. Request content is processed in real-time and not retained after the response is delivered. Only metadata (timestamps, token counts, model used) is logged for billing and service improvement purposes.

2. How We Use Your Information

We use collected information for the following purposes:

  • Service Delivery: Processing your AI requests, managing your account, and providing customer support
  • Billing: Processing payments, calculating taxes, and maintaining financial records as required by law
  • Communications: Sending transaction receipts, service updates, and account notifications (you may opt out of marketing communications)
  • Security: Detecting and preventing fraud, unauthorized access, and abuse of our services
  • Improvement: Analyzing aggregate usage patterns to improve our service (never using individual code content)
  • Legal Compliance: Meeting our obligations under applicable laws and regulations

3. Data Retention

We retain your personal information for the following periods:

Data TypeRetention Period
Financial records & transaction history7 years (tax compliance requirement)
Account informationDuration of account + 2 years
API request logs (metadata only)180 days (automatically deleted after this period)
Dashboard visibility for request logsFree: last 7 days · Pro/Team: last 180 days
Request content (code/prompts)Not stored (processed in real-time only)

4. Your Rights

Under PIPEDA, GDPR, and other applicable privacy laws, you have the following rights regarding your personal information:

Right to Access

You can request a copy of all personal data we hold about you. We will provide this information in a commonly used, machine-readable format (JSON or CSV) within 30 days of your request.

Right to Data Portability

You can export your data at any time from Account settings in your dashboard. This includes your transaction records, dispute records, and account information.

Right to Rectification

You can update your display name anytime in Account settings. For email corrections, contact privacy@zoocode.dev.

Right to Deletion

You can delete your account from Account settings in the dashboard, or request deletion by emailing privacy@zoocode.dev. Please note:

  • Financial records must be retained for 7 years due to legal requirements
  • Self-serve deletions take effect after confirmation. Email requests are processed within 30 days
  • Account deletion is irreversible and any remaining credit balance will be forfeited

Right to Object

You can opt out of product announcement emails anytime in Account settings. Transaction receipts and security notices are still sent when required to operate your account.

To exercise your rights:

Use Account settings in your dashboard for export, email preferences, and account deletion. You can also email privacy@zoocode.dev with your account email and the right you wish to exercise. We will respond within 30 days.

5. Data Security

We implement appropriate technical and organizational measures to protect your personal information:

  • All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Payment processing is PCI-DSS compliant through our partner Stripe
  • Regular security audits and penetration testing
  • Access controls and authentication for all systems
  • Employee training on data protection practices

6. Third-Party Services

We use the following third-party services that may process your data:

  • Stripe — Payment processing (Privacy Policy)
  • Resend — Email delivery (Privacy Policy)
  • AI Model Providers — Your prompts are sent to AI providers (OpenAI, Anthropic, Google, etc.) for processing. These providers have their own privacy policies regarding data handling.

We use industry-standard cloud infrastructure providers for hosting and data storage. All providers are bound by data processing agreements and contractual obligations to protect your data.

We do not sell your personal information to third parties.

7. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act:

  • Right to Know: You can request information about the categories and specific pieces of personal information we have collected.
  • Right to Delete: You can request deletion of your personal information (subject to legal retention requirements).
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
  • Do Not Sell: We do not sell personal information. If this ever changes, we will provide an opt-out mechanism.

8. International Data Transfers

Zoo Code is operated from Canada. If you are accessing our services from outside Canada:

  • Your data may be transferred to and processed in Canada or the United States
  • We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses where required
  • Canada has been recognized by the European Commission as providing adequate data protection

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the updated policy on this page
  • Sending an email notification for significant changes
  • Updating the "Effective Date" at the top of this policy

We encourage you to review this policy periodically for any updates.

10. Contact Us

For questions or concerns about this Privacy Policy or our data practices:

  • Privacy inquiries: privacy@zoocode.dev
  • General support: support@zoocode.dev
  • Response time: Within 30 days for privacy-related requests

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority:

  • Canada: Office of the Privacy Commissioner of Canada
  • EU: Your local supervisory authority
  • UK: Information Commissioner's Office (ICO)
Zoo Code

A community-maintained VS Code AI coding extension. Open source.

  • Docs
  • Contact us
  • Discord
  • Terms of Service
  • Privacy Policy
  • Acceptable Use
  • Privacy Rights

Built on the foundation of Roo Code. Apache 2.0 licensed.

© 2026 Zoo Code

Sign inGet startedSign up