Privacy Policy
Last updated: April 19, 2026
Data Controller
Zikit (zikit.ai), operated from Israel. Contact: support@zikit.ai. For the purposes of the EU/UK GDPR, Zikit is the data controller of personal data you submit.
What we collect
When you create an account, we collect your email address and name. When you add monitors, we store the URLs you choose to track and snapshots of their text content.
Lawful Basis for Processing (GDPR)
We process your personal data under the following legal bases:
- Contract performance: Processing necessary to deliver the monitoring service you signed up for.
- Legitimate interest: Processing for security, fraud prevention, and service improvement.
- Consent: For optional marketing communications. You can withdraw consent at any time.
How we use your data
We use your data solely to provide the monitoring service: checking pages, detecting changes, generating AI summaries, and sending you alerts.
Cookies & Similar Technologies
We distinguish between essential and optional technologies:
- Essential cookies - required for authentication, session management, and CSRF protection. Set by Supabase Auth. These cannot be disabled without breaking the Service.
- Performance analytics (cookieless) - Vercel Analytics and Vercel Speed Insights run on every page. They measure page-load performance and aggregate traffic without storing persistent identifiers on your device.
- Product analytics (opt-in) - PostHog is loaded only after you click "Accept" on the cookie banner. PostHog helps us understand which features are used. It sets a first-party cookie to identify returning visits. Session replay is disabled. You can decline at the banner or clear the
zikit-analytics-consentkey in your browser storage to revoke consent.
Data Storage
Your data is stored on Supabase (PostgreSQL) hosted in the EU. Page content snapshots are retained according to your plan (7-365 days) and then automatically deleted.
Data Retention
We retain your data according to the following schedule:
- Account data (email, name, settings): Retained until you delete your account.
- Page snapshots: Retained per your plan — Free: 7 days, Pro: 90 days, Business: 365 days.
- System logs: 30 days, then automatically deleted.
Third-Party Processors
We use the following processors to deliver the Service. Each is bound by a Data Processing Agreement (DPA) and processes personal data only under our instructions:
- Supabase - PostgreSQL database hosting (EU region).
- Vercel - web application hosting (US, global CDN).
- OpenAI - AI summarization of detected page changes (US). OpenAI does not use API data for model training.
- Paddle - payments merchant of record (UK/US).
- Resend - transactional email delivery (US).
International Data Transfers
Some of our processors are located outside the European Economic Area, United Kingdom, or Israel (notably the United States). When we transfer personal data to these processors, we rely on one or more of the following safeguards required by GDPR Chapter V:
- The European Commission's Standard Contractual Clauses (SCCs) (2021/914/EU), incorporated into our agreements with US-based processors.
- Participation by the processor in the EU-US Data Privacy Framework (where applicable).
- A Transfer Impact Assessment (TIA) confirming supplementary measures (encryption in transit and at rest, access controls) where required.
To request a copy of the relevant SCCs or TIA summary, email support@zikit.ai.
Your Rights (GDPR)
Under the General Data Protection Regulation, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate personal data.
- Right to Erasure: Request deletion of your personal data (“right to be forgotten”).
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Restriction: Request limitation of processing in certain circumstances.
- Right to Object: Object to processing based on legitimate interest or direct marketing.
To exercise any of these rights, email support@zikit.ai. We will respond within 30 days. You can also export or delete your data at any time from your dashboard settings.
Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with data-protection law, you have the right to lodge a complaint with your local supervisory authority. EU residents can find the list at edpb.europa.eu. UK residents can contact the ICO at ico.org.uk. Israeli residents can contact the Privacy Protection Authority at gov.il/en/departments/the_privacy_protection_authority.
California Residents (CCPA/CPRA)
If you are a California resident, you have the rights described above plus the right to (a) know what personal information we collect and how we use it, (b) request deletion, (c) opt out of the "sale" or "sharing" of personal information, and (d) non-discrimination for exercising your rights. We do not sell or share personal information for cross-context behavioral advertising. To exercise these rights, email support@zikit.ai.
Israeli Privacy Protection Law
For Israeli residents, we process personal data in accordance with the Privacy Protection Law, 5741-1981 (as amended by Amendment 13, effective 14 August 2025), and its regulations. You have the right to access, correct, and request deletion of personal data we hold about you.
Our database does not meet the thresholds for mandatory registration with the Privacy Protection Authority under Amendment 13 (fewer than 10,000 subjects, no sensitive data, no data-transfer or direct-marketing purpose), so it is not registered. We remain bound by the law’s substantive obligations (lawful processing, security, data-subject rights, breach notification).
Children's Privacy
The Service is not directed at children under 13 (or under 16 for EEA/UK residents), and we do not knowingly collect their personal data. If we learn that we have collected personal data from a child below the applicable age without verifiable parental consent, we will delete it promptly.
Security & Breach Notification
We protect personal data using encryption in transit (TLS) and at rest, access controls, and audit logging. In the event of a personal data breach likely to result in a risk to your rights, we will notify you and the relevant supervisory authority within 72 hours, as required by GDPR Article 33-34.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or dashboard notice at least 14 days before taking effect. The "Last updated" date at the top reflects the current version.
Contact
Email: support@zikit.ai