Privacy Policy for Pazi
Effective Date: August 14, 2026
Pazi is a product operated by Pythagora Technologies Incorporated ("Pythagora," "Pazi," "we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use our websites, applications, AI agents, business workspaces, integrations, and advertising services (collectively, the "Service").
We do not sell personal information for money. We do not use Business DNA, project files, conversation content, or agent outputs to train or fine-tune our own general-purpose AI models.
Who Controls Your Information?
Pythagora is generally the controller of account, product, security, billing, and service-operations information. When a customer uses Pazi to process personal information in its own content or workflows, that customer may be the controller and Pythagora may act as its service provider or processor.
1. Information We Collect
Account and Profile Information
We collect information such as your name, email address, username, profile image, authentication provider, provider account identifier, account role, preferences, and consent choices.
Business, Agent, and Workspace Data
We process the information you and your organization provide to operate Pazi, including business profiles and goals, websites, prompts, conversations, messages, agent instructions and memory, files and uploads, generated content and images, schedules, opportunities, activity records, and communications sent or received through connected channels. Agent runtime transcripts and provider storage may contain the context needed to continue a conversation or complete a task.
Saved Credentials and Connected Services
When you intentionally save a credential or connect a service, we process the service name, credential field names, encrypted credential values, OAuth tokens, scopes, provider identifiers, connection status, and related metadata. Saved credential values are encrypted at rest and made available to authorized agent runs only when needed to perform your instructions.
Billing and Funding Information
We process plan, subscription, Stripe customer and subscription identifiers, invoices and payment status, cash balances, payout balances, and usage, transaction history, and related billing records. Payment-card details are collected and processed by Stripe; Pazi does not store complete card numbers.
Meta Advertising Data
If you use Pazi-Funded Advertising, we process your advertising authorization, accepted terms version, business and website information, creative text and images, destination, audience and placement selections, budget and schedule, moderation state, campaign status, daily funding charges, and performance metrics such as impressions, clicks, spend, CPM, CTR, and CPC. We also retain internal and Meta identifiers needed to create, manage, reconcile, pause, and report on the campaign.
Device, Usage, and Support Information
We collect device and browser type, IP address, timestamps, page and feature interactions, cookie or device identifiers, referral information, performance data, diagnostic events, error details, support messages, and security signals. We minimize or redact sensitive values in logs where practical.
Web and Third-Party Information
At your direction, Pazi may process content from webpages, public sources, connected applications, email, Slack, advertising platforms, or other services. Browser or webpage content is not retained merely because an agent viewed it, but information included in an agent result, message, file, memory, integration event, or workspace may be stored as part of the Service.
2. Sources of Information
We receive information:
- directly from you and other authorized members of your organization;
- automatically from your browser, device, and use of the Service;
- from authentication, payment, AI, sandbox, analytics, communication, and integration providers;
- from Meta when Pazi creates or manages advertising through Pazi-controlled Meta assets; and
- from public sources and third-party services you direct Pazi to use.
3. How and Why We Use Information
- provide, personalize, maintain, and support the Service;
- authenticate users and enforce business, agent, and resource permissions;
- run AI agents and carry out your authorized workflows and connected-service actions;
- process subscriptions, funding, usage, and Pazi-funded advertising;
- secure the Service, prevent abuse, debug failures, and enforce our Terms;
- measure and improve reliability, performance, features, and user experience;
- communicate about service, security, billing, support, and material policy updates; and
- comply with law, valid legal process, and our legal obligations.
Where EEA or UK data-protection law applies, our legal bases may include performance of a contract, legitimate interests in operating and securing the Service, consent (including where required for advertising cookies), and compliance with legal obligations.
4. AI Processing
Pazi sends the instructions, context, tools, and content needed for a task to AI model and infrastructure providers acting for us or, when you choose a user-owned provider connection, acting under your account. Pazi does not use Business DNA, project files, conversation content, or agent outputs to train or fine-tune our own general-purpose models. We use commercial and API services whose business-data terms restrict provider training by default, subject to the provider and connection you select.
5. Meta Advertising and Platform Data
Pazi uses a Pazi-owned Meta system credential, business portfolio, ad account, Facebook Page, Instagram account, and payment method. Customers do not connect their own Meta account for this feature. When an eligible owner starts or continues a campaign, Pazi sends Meta the approved creative, destination, audience and placement settings, campaign budget and schedule, and advertiser or beneficiary disclosures required for delivery.
Meta returns provider object identifiers, approval and delivery status, diagnostic codes, and normalized campaign insights. Pazi uses this Platform Data only to create, manage, secure, reconcile, and report on the advertising service, meet Meta requirements, resolve disputes, and comply with law. Raw provider identifiers and credentials are not exposed through customer-facing Pazi responses.
Ads and associated business identities are public, may be re-shared, and may appear in Meta's Ad Library and transparency tools. Meta processes information under its own terms and policies, including the Meta Commercial Terms and Meta Privacy Policy.
6. How We Disclose Information
We may disclose information to:
- Service providers that help with cloud hosting, databases, storage, AI models, sandbox execution, security, logging, error monitoring, analytics, payments, email, authentication, and customer support. Examples include Amazon Web Services, MongoDB, Sentry, PostHog, and Stripe.
- Connected services and platforms when you direct Pazi to use them, including Meta, Slack, email providers, authentication providers, and applications for which you save credentials.
- Your organization, including owners, members, and agents authorized to access the same business or workspace.
- Authorities and other parties when required by law or reasonably necessary to protect rights, safety, security, users, Pazi, or the public.
- Transaction participants in a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to appropriate safeguards.
We do not sell personal information for money. Our marketing website uses advertising pixels that may be considered "sharing," "targeted advertising," or cross-context behavioral advertising under some laws, as explained below.
7. Cookies, Analytics, and Advertising Pixels
We use session and preference technologies needed to operate the Service, PostHog for product analytics, and Sentry and logging providers for reliability and security. On production marketing pages, we may use Meta, Google Ads, X, and LinkedIn pixels to measure campaigns and build remarketing audiences.
Where consent is required, advertising pixels do not load until you accept them. You can reject them through the cookie banner. We also honor a recognized Global Privacy Control signal by keeping those pixels disabled. Browser settings may provide additional cookie controls, but blocking essential technologies can affect the Service.
Pazi-hosted customer websites may also use PostHog analytics and sampled session recordings. We mask form inputs and marked private content, remove URL query strings, and give the business owner and authorized members access to the resulting reports.
8. Data Retention and Deletion
- We generally retain account and product information while your account or business remains active and as needed to provide the Service.
- You can delete ordinary files and saved credentials, delete an owned business, or request full account deletion through the available controls.
- Business and account deletion remove active product records and durable runtime storage through an asynchronous, retryable cleanup process.
- Website session recordings are retained for up to 30 days. Taking down a Pazi-hosted website queues deletion of its analytics events and recordings.
- For advertising, customer creative, targeting, generated images, detailed insights, and operational request state are removed after provider pause and cleanup. Minimum provider mappings, terms acceptance, moderation evidence, charges, reversals, and financial records may be retained for accounting, dispute, provider-reconciliation, enforcement, and legal periods.
- Security logs, backups, fraud-prevention records, and legal records may remain for a limited period consistent with their purpose and deletion cycle.
Deletion cannot recall copies another person already downloaded or content retained by a third-party service under its own terms. We retain information no longer than reasonably necessary for the purposes described here, unless a longer period is required or permitted by law.
9. Security
We use reasonable administrative, technical, and organizational safeguards, including access controls, tenant scoping, encryption for saved credentials, short-lived runtime authorization, secret redaction, and monitored provider boundaries. No service is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.
10. Government and Legal Requests
When a public authority requests user information, our policy is to:
- require review of the request's legal basis, validity, scope, and jurisdiction;
- challenge requests we reasonably believe are unlawful, invalid, or overbroad when appropriate and legally permitted;
- disclose only the minimum information reasonably necessary to comply with a valid request; and
- document the request, our response, the legal reasoning, and the people involved in the review.
We may notify the affected customer before disclosure unless prohibited by law, the request, or a reasonable safety or integrity concern.
11. International Data Transfers
Pythagora is based in the United States, and our providers may process information in the United States and other countries. Those countries may have different data-protection laws. Where required, we rely on appropriate transfer mechanisms and safeguards, such as contractual protections.
12. Your Privacy Rights
Depending on where you live and subject to applicable exceptions, you may have rights to access, know, correct, delete, or receive a copy of personal information; restrict or object to processing; withdraw consent; opt out of sale, sharing, or targeted advertising; limit certain uses of sensitive information; and receive equal service without unlawful discrimination.
Submit a request to hi@pythagora.ai. We may need to verify your identity and authority. Authorized agents may also submit requests where permitted. If we deny a request, you may appeal by replying to our decision and may complain to your local regulator. We honor recognized Global Privacy Control signals for marketing pixels as described above.
13. Children's Privacy
Pazi is not intended for anyone under 18, and we do not knowingly collect personal information from a person under 18. If you believe a person under 18 provided information to Pazi, contact us so we can investigate and remove it where appropriate.
14. Changes to This Policy
We may update this Privacy Policy. If a change is material, we will provide reasonable notice through the Service, by email, or by updating the effective date. Your use of the Service is also governed by our Terms of Service.
15. Contact Us
Pythagora Technologies Incorporated548 Market St.
San Francisco, CA 94104
United States
Email: hi@pythagora.ai