Privacy Policy
Last updated: September 26, 2026
This Privacy Policy explains what data Zenuro collects, how we use it, and your rights.
1. Data we collect
Account: email and a securely hashed password (never plain text). Content: the audio/video you upload and the transcripts/clips generated. Usage: processing history, minutes, plan. Payments: the plan, amount, date, status, the email given at payment and the payment and subscription numbers that the payment service sends us; for a crypto payment also the sending wallet address and the transaction hash. You enter card details on the page of the payment service (Gumroad or lava.top); Zenuro does not receive or store your card number. Support: messages you send through the support chat on the site and the contact you leave there. Technical & analytics: the cookies described in section 6, and basic visit data (IP address, browser/device (user-agent), page visited and referrer) used for security, rate-limiting and our own first-party visit analytics (legitimate interest). These visit logs are kept about 60 days and never sold.
2. How we use it
Only to run the Service: authenticate you, process uploads, enforce quotas, take payments and manage subscriptions, send transactional emails, answer support requests, and prevent abuse (including limiting how many accounts are created from one device).
3. Third-party processors
We share with each service only what it needs for its task. We do not sell your data.
- Replicate: speech transcription and cover images
- OpenAI: speech transcription
- Anthropic: analysis of the transcript (choosing moments, writing titles and descriptions)
- Gumroad: card payments in US dollars
- lava.top: Russian bank card payments in rubles
- Cryptomus: cryptocurrency payments
- Resend: sending emails
- Telegram: messages from the support chat and our service notifications reach us through Telegram; notifications can include your account email, IP address and approximate location
- ipwho.is: finding the approximate country and city by IP address for these notifications
- Cloudflare: the domain name service and forwarding of emails sent to our support address
- Google: sign-in with Google and the YouTube connection, only if you use them (see section 10)
- Contabo (Germany): hosting of our server, where files, transcripts and the database are stored
4. Retention
Uploaded files and generated clips are deleted automatically 7 days after processing. Transcripts (the text of the speech with word timings) and the moments selected from them are kept in a cache on our server with no fixed deletion date, so that cutting the same recording again does not need a new transcription. Account and billing records are kept while the account is active and as legally required. Deletion, including of transcripts, is available on request.
5. Security
HTTPS, hashed passwords, server-side sessions, access controls. No method is 100% secure.
6. Cookies
Our site sets only its own cookies, and none of them are for advertising or tracking. The Gumroad checkout that opens over our site and the payment pages of lava.top and Cryptomus belong to those services and follow their own cookie rules.
- sid: keeps you signed in. Essential, http-only, 30 days.
- zdev: device mark, about 2 years. It holds a random device number and a short hash of basic browser properties (browser, language, screen size, time zone, number of processor cores, memory and touch support). We use it only against abuse through several accounts of one person, for example to limit how many accounts are created from one device: when you register or sign in, we store this mark with your account together with the IP address. The same number is also kept in the local storage of your browser.
- zenuro_lang: the site language you chose, 1 year.
- zref: the invitation or partner code, if you came through such a link, 90 days.
- g_state, g_lang, g_ref, g_claim and other cookies whose names start with g_: temporary, 10 minutes, only while you sign in with Google.
7. Your rights
Access, correct, export or delete your data — contact support@zenuro.ai.
8. Children
Not directed to anyone under 18; we do not knowingly collect minors' data.
9. Changes
We may update this policy; changes shown by the date above.
10. Google and YouTube data
Zenuro uses YouTube API Services. If you choose to connect your YouTube channel, we ask Google for two permissions: to upload videos to your channel, and to read your channel’s name and ID so we can show which channel is connected. We store an access token and your channel’s name and ID on our servers in the EU and use them only to upload the clips you choose to publish, with the title, description and visibility you set. We do not read your other videos, comments or statistics, do not use this data for advertising, and do not share or sell it to anyone. When you disconnect YouTube in Zenuro, we delete the token and revoke our access at Google; the same happens if you ask us to delete your account. You can also revoke access at any time in your Google account settings: security.google.com/settings/security/permissions. How Google handles your data is described in the Google Privacy Policy: policies.google.com/privacy. Zenuro’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Questions? Contact us at support@zenuro.ai.