Universal Form AIzenmysoul.com

Privacy Policy

Last updated: 2025-09-29

This Privacy Policy explains how we collect, use, disclose, and protect information when you use Universal Form AI on zenmysoul.com (the “Service”). The Service helps users digitize and fill complex forms using OCR and AI assistance.

1. Information We Collect

CategoryExamplesSource
Account & ContactName, email, organization, roleYou
AuthenticationHashed passwords or OAuth/SSO identifiersYou / SSO
Content You UploadForms, PDFs, images, passports/IDs, immigration/employment/financial details in your documentsYou
Processing OutputsOCR text, extracted fields, AI suggestions, field coordinates, version historyDerived
Usage & DeviceIP, device/browser metadata, pages/actions, timestamps, approximate geolocationAutomatic
PaymentsBilling name, email, last4, transaction IDs (processed by third parties)Payment provider
SupportTickets, messages, attachments, diagnosticsYou

2. Sensitive Personal Information

Your documents may include sensitive data (e.g., government IDs, financial/health data if present in scans). We process such data only as necessary to provide the Service, with enhanced safeguards (encryption in transit/at rest, strict access controls, limited retention). Do not upload data you are not authorized to share.

3. How We Use Information

4. Legal Bases (EEA/UK)

Where GDPR/UK GDPR applies, our legal bases include: performance of a contract, legitimate interests (e.g., security, improvement), consent (for optional analytics/marketing or processing you explicitly request), and legal obligations.

5. Automated Processing & AI

6. Sharing of Information

We do not sell personal information. We share data only with:

7. Processors We Commonly Use

ProcessorPurposeData TypesMain Location
Cloudflare (Pages/Workers)Hosting, DNS, securityIP/usage, site contentGlobal
SupabaseAuth, database, storageAccount data, documents, outputsRegion you select
AWS (Textract)OCRUploaded documents & imagesSelected AWS region
OpenAI / AnthropicLLM inferencePrompts and extracted text needed for outputAs per regional endpoints
Payment provider (Stripe/Paddle/Razorpay)BillingCustomer & transaction dataAs per provider
Email provider (SendGrid/Postmark)Transactional emailAccount & email metadataAs per provider
Analytics (optional)Product analyticsUsage/telemetryAs configured

Note: Exact processors/regions depend on configuration and may change; we will update this list as needed.

8. International Transfers

Data may be processed in countries other than your own. Where required, we use safeguards such as Standard Contractual Clauses and regional hosting choices (e.g., Supabase/AWS region selection).

9. Retention

10. Your Rights

Depending on your location (EEA/UK, California, Canada, etc.), you may have rights to access, correct, delete, or port your data; to object to or restrict processing; and to withdraw consent. To exercise rights, contact privacy@zenmysoul.com. We may need to verify your identity.

11. Cookies

We use essential cookies for sign-in and security. With your consent, we may use analytics cookies. You can manage cookies in your browser settings; blocking essential cookies may affect functionality.

12. Security

13. Organization-Controlled Data

For multi-tenant or enterprise accounts, your organization is the controller for workspace content (documents and outputs). We act as processor on their instructions.

14. Children’s Privacy

The Service is not directed to children under 13 (or the applicable age in your region). We do not knowingly collect data from children. If you believe a child provided data, contact us to delete it.

15. Region-Specific Disclosures

16. Contact

Privacy questions or requests: privacy@zenmysoul.com

17. Changes to This Policy

We may update this Policy from time to time. The “Last updated” date reflects the latest version. If material changes occur, we’ll provide reasonable notice.