ZERODESK PRIVACY POLICY
Effective Date: 25 July 2026 Last Updated: 30 July 2026
1. INTRODUCTION
IFUTURIX AI LABS PRIVATE LIMITED, operating under the brand name "ZeroDesk" ("ZeroDesk," "we," "our," or "us"), provides an AI-powered workspace platform for individuals, teams, and organisations.
This Privacy Policy explains how ZeroDesk collects, accesses, uses, stores, processes, shares, and protects information when you use:
- The ZeroDesk website;
- The ZeroDesk mobile or desktop applications;
- ZeroBrain and other artificial-intelligence features;
- ZeroDesk workspaces;
- Connected services such as Gmail and Microsoft Outlook;
- Any other products or services that link to this Privacy Policy.
By using ZeroDesk, you acknowledge the practices described in this Privacy Policy.
ZeroDesk is operated by:
IFUTURIX AI LABS PRIVATE LIMITED A-131, Sector 136, Noida, Uttar Pradesh, India
Email: connect@futurixai.com Website: ZeroDesk.io
2. SCOPE OF THIS PRIVACY POLICY
This Privacy Policy applies to personal information and other information processed through ZeroDesk.
For individual users, IFUTURIX AI LABS PRIVATE LIMITED generally acts as the entity responsible for determining how personal information is processed.
Where ZeroDesk is provided through an employer, educational institution, enterprise customer, or other organisation, that organisation may control the workspace and may determine how information within the workspace is processed. In such circumstances, the organisation may act as the data controller and ZeroDesk may act as its service provider or data processor.
Users should contact their organisation's workspace administrator regarding organisation-specific privacy practices.
3. INFORMATION WE COLLECT
3.1 Account Information
When you create or use a ZeroDesk account, we may collect:
- Your name;
- Email address;
- Login and authentication information;
- Profile information;
- Organisation or workspace membership;
- Workspace role and permissions;
- Subscription and account status;
- Preferences and settings.
ZeroDesk does not share your password with external artificial-intelligence providers.
3.2 User Content
ZeroDesk may process content that you create, upload, import, store, generate, send, receive, or manage through the Service, including:
- Prompts and instructions;
- Chat messages and conversation history;
- Workspace conversations;
- Tasks, projects, comments, and approvals;
- PDF documents;
- Text documents;
- Images;
- Email messages and attachments selected through connected services;
- Generated responses;
- Generated documents, images, and other files;
- Information included in files or content submitted by the user;
- Content submitted to customer support.
Users retain ownership of their User Content, subject to the limited permissions required for ZeroDesk to provide the Service.
3.3 AI Request Content
When you use an artificial-intelligence feature, ZeroDesk may process information necessary to complete your request, including:
- The prompt or instruction you submit;
- Relevant messages from the selected conversation;
- System instructions required to operate the selected feature;
- PDF files, text documents, images, or attachments that you select;
- Extracted text or relevant portions of selected documents;
- Selected email messages or attachments from a connected Gmail or Outlook account;
- Relevant workspace content that you intentionally select or authorise;
- Previous AI-generated responses where required to maintain conversation context;
- The selected AI model;
- Technical request information necessary to process and deliver the response.
AI Request Content may contain personal, confidential, commercially sensitive, or other protected information depending on what the user chooses to submit.
Users should not include information in a prompt or attachment unless they are authorised to process and share that information for the selected purpose.
3.4 Connected Service Information
ZeroDesk allows users to connect third-party services, including:
- Gmail;
- Microsoft Outlook;
- Other supported applications or data sources made available through ZeroDesk.
ZeroDesk accesses information from a connected service only after:
- The user actively chooses to connect the service;
- The user grants the requested permissions through the service provider's authorisation process; and
- The user manually selects or invokes the connector within ZeroDesk.
ZeroBrain does not independently or automatically access Gmail, Outlook, or another connector unless the user has connected and manually selected the relevant connector.
Depending on the action requested by the user, connector information may include:
- Selected email messages;
- Email subject lines;
- Sender and recipient information contained in the email;
- Email body content;
- Selected attachments;
- Other information required to complete the user-requested action.
ZeroDesk does not use connected email information for advertising or to build advertising profiles.
3.5 Payment and Subscription Information
Payments may be processed through third-party payment providers.
ZeroDesk may receive limited information relating to a transaction, including:
- Subscription plan;
- Payment status;
- Billing period;
- Transaction identifier;
- Limited billing information.
ZeroDesk does not store complete payment-card information where that information is submitted directly to a payment provider.
3.6 Device, Usage, and Technical Information
When you access ZeroDesk, we may process limited technical information necessary to operate, secure, and improve the Service, including:
- Device type;
- Operating system;
- Browser type;
- Application version;
- IP address;
- Login and access times;
- Features used;
- Actions performed;
- Performance and diagnostic information;
- Crash reports;
- Security events;
- Cookie or session information;
- Authentication and fraud-prevention information.
Technical information is not used to reconstruct deleted User Content.
3.7 Communications
When you communicate with ZeroDesk, we may process:
- Your contact details;
- The contents of your message;
- Support requests;
- Feedback;
- Bug reports;
- Other information you choose to provide.
4. HOW WE USE INFORMATION
ZeroDesk may use information to:
- Create and manage user accounts;
- Authenticate users and protect accounts;
- Provide workspaces, files, projects, tasks, conversations, and collaboration features;
- Store and display User Content;
- Process prompts and generate AI responses;
- Analyse documents, text, and images selected by users;
- Process selected email messages or attachments;
- Operate user-authorised connectors;
- Generate documents, images, videos, and other requested outputs;
- Maintain relevant conversation context;
- Process subscriptions and transactions;
- Provide technical and customer support;
- Detect unauthorised access, fraud, abuse, or security threats;
- Maintain access controls and workspace permissions;
- Monitor performance and reliability;
- Improve the functionality and usability of the Service;
- Enforce our Terms of Service;
- Comply with legal obligations;
- Protect the rights, safety, and security of users, ZeroDesk, and others.
ZeroDesk does not sell personal information.
ZeroDesk does not use User Content or AI Request Content for targeted advertising.
5. ZEROBRAIN
ZeroBrain is ZeroDesk's native artificial-intelligence system.
Requests made using ZeroBrain are processed through ZeroDesk's backend infrastructure and may be routed to one or more external AI processors or routing intermediaries identified in Section 6. ZeroDesk requests the user's explicit permission before this routing occurs.
Information from Gmail, Outlook, or another connected service is not made available to ZeroBrain unless:
- The user has connected the relevant service;
- The user has granted the required permissions; and
- The user manually selects or invokes the connector for a specific request.
ZeroDesk does not use customer prompts, emails, documents, images, files, conversations, generated responses, or connector data to train or improve ZeroBrain or any other ZeroDesk AI model.
6. THIRD-PARTY AI SERVICES
ZeroDesk and ZeroBrain may use AI models operated by external providers. The provider used may depend on the model, requested capability, availability, safety controls, and routing configuration.
ZeroDesk currently uses or may route requests through the following AI processors, hosting infrastructure, and routing intermediaries:
- OpenAI;
- Anthropic;
- Google AI.
The in-app disclosure presents the current list before consent is collected. If the list changes materially, ZeroDesk updates the disclosure version and requires renewed consent before further external AI processing.
6.1 GPT Models Through OpenAI
When a user selects a GPT model within ZeroDesk, the request is processed through OpenAI services using a business/API account maintained by IFUTURIX AI LABS PRIVATE LIMITED.
The external recipient and processor for this request is OpenAI.
Depending on the user's request, ZeroDesk may send:
- The user's prompt;
- Relevant conversation context;
- Selected PDF or text-document content;
- Selected images;
- Selected email messages or attachments;
- Relevant content manually selected from a connected service;
- Technical request information necessary to generate the response.
This information is sent only for the purpose of generating the user-requested result.
6.2 Claude Models Through the Anthropic API
When a user selects a Claude model within ZeroDesk, the request is processed through the Anthropic API using a business/API account maintained by IFUTURIX AI LABS PRIVATE LIMITED.
The external recipient and processor for this request is Anthropic PBC.
Depending on the user's request, ZeroDesk may send:
- The user's prompt;
- Relevant conversation context;
- Selected PDF or text-document content;
- Selected images;
- Selected email messages or attachments;
- Relevant content manually selected from a connected service;
- Technical request information necessary to generate the response.
This information is sent only for the purpose of generating the user-requested result.
6.3 Google AI Models
When a user selects Gemini, Nano Banana, Veo, or another supported Google AI model within ZeroDesk, the request is processed through Google AI services using a business/API account maintained by IFUTURIX AI LABS PRIVATE LIMITED.
The external recipient and processor for this request is Google LLC or the applicable Google contracting entity.
Depending on the selected feature, ZeroDesk may send:
- The user's prompt;
- Relevant conversation context;
- Selected PDF or text-document content;
- Selected images;
- Selected email messages or attachments;
- Relevant content manually selected from a connected service;
- Media or instructions required to generate an image or video;
- Technical request information necessary to generate the response.
This information is sent only for the purpose of generating the user-requested text, analysis, image, video, or other output.
7. INFORMATION NOT INTENTIONALLY SENT TO EXTERNAL AI PROVIDERS
ZeroDesk does not intentionally include the following account information in requests sent to external AI processors unless it is necessary for, or expressly included in, the user's request:
- The user's ZeroDesk account name;
- The user's registered email address;
- The user's phone number;
- The user's ZeroDesk account identifier;
- Passwords or authentication credentials;
- Complete payment-card information.
However, an external AI provider may receive personal information if the user includes that information within:
- A prompt;
- A selected email;
- A document;
- An image;
- An attachment;
- Conversation context;
- Other content intentionally submitted for processing.
Users are responsible for reviewing the content they select before submitting it to an external AI provider.
8. ZERODESK BACKEND PROCESSING
AI requests are not sent directly from the user's device to an external AI provider.
The request first passes through ZeroDesk's own backend infrastructure, where it is processed and routed to the AI provider selected by the user.
ZeroDesk's backend may:
- Authenticate the request;
- Apply the user's selected model and settings;
- Retrieve content manually selected by the user;
- Prepare relevant prompt context;
- Transmit the request to the selected provider;
- Receive the generated response;
- Deliver and, where selected, save the response within ZeroDesk.
9. EXPLICIT PERMISSION BEFORE THIRD-PARTY AI SHARING
Before ZeroDesk sends personal information or User Content to an external AI processor for the first time, ZeroDesk presents a versioned in-app disclosure that:
- Identifies the external AI processors and routing intermediaries that may receive the information;
- Explains what categories of information may be transmitted;
- Explains why the information is being transmitted;
- Provides access to this Privacy Policy; and
- Requests the user's explicit permission.
New users creating an account in the iOS app must affirmatively accept the current disclosure during account creation. Other users who have not previously made a choice are shown the disclosure immediately before their first AI action. No AI request is sent to an external processor before a current grant is recorded.
If the user declines permission:
- The request will not be sent to an external AI processor;
- AI features will remain unavailable; and
- Existing users may continue using non-AI ZeroDesk features.
For new users in the iOS app, account creation requires acceptance of the current AI processing disclosure. ZeroDesk records the disclosure version, decision, source, timestamp, and disclosure snapshot for audit purposes.
Users may withdraw permission for future sharing through the privacy controls provided within ZeroDesk. Withdrawal of permission does not affect processing that occurred before consent was withdrawn.
ZeroDesk may request consent again if:
- A new external AI provider is added;
- The categories of information shared materially change;
- The purpose of processing materially changes; or
- Applicable law or platform requirements require renewed consent.
10. CONNECTOR DATA AND EXTERNAL AI MODELS
Connecting Gmail, Outlook, or another service does not by itself authorise ZeroDesk to send connector content to an external AI provider.
Connector content may be sent to an external AI processor listed in Section 6 only where:
- The user has connected the relevant service;
- The user has granted the necessary connector permissions;
- The user manually selects or invokes the relevant connector;
- The user initiates an AI action;
- The user has granted the current version of the AI processing disclosure; and
- The content is necessary to complete the user-requested action.
For example, if a user selects an email and asks Claude to summarise it, the selected email content may be sent to Anthropic for that specific purpose.
ZeroBrain requests are also subject to the same consent requirement when they are routed to an external processor.
11. AI TRAINING AND MODEL IMPROVEMENT
ZeroDesk does not use the following information to train or improve ZeroBrain or another ZeroDesk AI model:
- User prompts;
- Email content;
- Documents;
- Images;
- Files;
- Workspace content;
- Connector information;
- Generated responses;
- Generated files.
ZeroDesk does not authorise the external AI processors listed in Section 6 to use ZeroDesk customer content to train general-purpose AI models.
ZeroDesk uses paid business/API accounts and configures available zero-data-retention, modified-monitoring, reduced-retention, and data-control options where supported.
ZeroDesk disables optional provider logging, dataset contribution, feedback sharing, or model-improvement features where such controls are available.
External AI providers necessarily process request content transiently to generate the requested output. Limited technical, safety, or operational processing may also occur in accordance with the provider's business terms, applicable configuration, and legal obligations.
12. STORAGE OF PROMPTS, RESPONSES, AND GENERATED FILES
ZeroDesk may save:
- User prompts;
- Conversation history;
- Generated responses;
- Generated documents;
- Generated images;
- Other generated files;
- Selected workspace content.
This information is saved so that users can access their work, continue conversations, and manage generated files within ZeroDesk.
Content remains under the user's control and may be deleted by the user.
13. DATA RETENTION AND DELETION
ZeroDesk retains account information and User Content while the user's account remains active and for as long as the information is required to provide the Service.
When a user deletes a prompt, conversation, response, document, image, or generated file:
- The corresponding content is deleted from ZeroDesk's active backend systems;
- The associated stored file is deleted from the backend;
- The content is not retained in backup copies, content archives, or content trails maintained by ZeroDesk.
When a user deletes their ZeroDesk account, account-associated User Content is deleted from ZeroDesk's backend systems.
ZeroDesk does not retain deleted User Content for AI training, product training, advertising, or profiling.
Limited non-content information may be retained only where strictly required to:
- Comply with applicable law;
- Satisfy tax, accounting, or payment obligations;
- Resolve disputes;
- Enforce contractual rights;
- Prevent fraud or security abuse.
Any such legally required information will be limited to what is necessary and will not include deleted document, email, image, or conversation content unless retention is specifically required by law.
Information already transmitted to an external AI provider is subject to the provider configuration and applicable business/API terms. ZeroDesk uses zero-data-retention or the lowest available retention settings where supported.
14. INFORMATION SHARING
ZeroDesk may share information only in the circumstances described below.
14.1 External AI Providers
Information may be shared with the external AI processors and routing intermediaries listed in Section 6 when the user:
- Initiates an AI feature or selects a model;
- Submits a request requiring external processing; and
- Has granted the current version of the AI processing disclosure.
14.2 Operational Service Providers
ZeroDesk may use service providers that assist with:
- Cloud hosting;
- Data storage;
- Authentication;
- Payment processing;
- Email delivery;
- Application monitoring;
- Security;
- Customer support;
- Infrastructure operations.
These service providers may process information only to provide services to ZeroDesk and are subject to applicable contractual, confidentiality, and security obligations.
14.3 Connected Services
Information may be exchanged with Gmail, Outlook, or another connected service when required to complete an action initiated by the user.
The use of connected services is also subject to the privacy terms and permissions of the relevant service provider.
14.4 Legal Requirements
ZeroDesk may disclose information where reasonably necessary to:
- Comply with applicable law, regulation, legal process, or enforceable government request;
- Protect the rights, property, or safety of ZeroDesk, its users, or others;
- Investigate fraud, abuse, or security incidents;
- Enforce agreements or legal rights.
14.5 Corporate Transactions
Information may be transferred as part of a merger, acquisition, restructuring, financing, insolvency proceeding, or sale of all or part of the business.
Where applicable, users will be notified of material changes affecting the handling of their personal information.
14.6 At the User's Direction
ZeroDesk may share information where the user expressly directs or authorises ZeroDesk to do so.
15. NO SALE OF PERSONAL INFORMATION
ZeroDesk does not sell or rent personal information.
ZeroDesk does not share User Content with data brokers.
ZeroDesk does not use prompts, documents, emails, images, generated responses, or connector data for behavioural advertising or targeted advertising.
16. SECURITY AND COMPLIANCE
ZeroDesk implements administrative, organisational, and technical safeguards designed to protect information, including:
- Encryption in transit and at rest where applicable;
- Authentication and access controls;
- Role-based access control;
- Restricted access to production systems;
- Security monitoring;
- Application and infrastructure security controls;
- Vulnerability management;
- Employee confidentiality and security practices;
- Incident-response procedures;
- Vendor and processor assessments.
IFUTURIX AI LABS PRIVATE LIMITED maintains:
- ISO/IEC 27001 certification;
- ISO 9001 certification; and
- A Cloud Application Security Assessment, or CASA assessment, for applicable Google-connected integrations.
CASA and other security assessments relate to the assessed systems and integration scope and do not eliminate all security risks.
Although ZeroDesk uses safeguards designed to protect information, no online service or transmission method can guarantee absolute security.
17. GOOGLE AND MICROSOFT CONNECTOR SECURITY
Access to Gmail and Outlook is based on authorisation granted by the user through the relevant provider.
ZeroDesk:
- Does not request connector access before the user initiates the connection;
- Uses connector access only to provide user-requested functionality;
- Does not allow ZeroBrain to independently browse a connected account;
- Does not sell connector data;
- Does not use connector data for advertising;
- Does not use connector data for model training;
- Does not transfer connector data to an external AI provider without user selection and required consent;
- Allows users to disconnect a connected service and prevent future access.
Disconnecting a connector stops future access by ZeroDesk but does not automatically delete content that the user previously chose to save separately within ZeroDesk. Users may delete such saved content through the applicable ZeroDesk controls.
18. INTERNATIONAL DATA PROCESSING
ZeroDesk, its infrastructure providers, and external AI providers may process information in countries other than the user's country of residence.
The processing location may depend on:
- ZeroDesk's hosting infrastructure;
- The selected external AI provider;
- OpenAI's API infrastructure;
- Anthropic's API infrastructure;
- Google AI or Google API infrastructure;
- The location of service providers involved in operating the Service.
Where required by applicable law, ZeroDesk uses appropriate contractual, organisational, and technical safeguards for international data transfers.
19. LEGAL BASES FOR PROCESSING
Where applicable data-protection law requires a legal basis, ZeroDesk may process information on the following bases:
- Performance of a contract, where processing is required to provide the Service;
- Consent, including consent to share selected content with an external AI provider;
- Legitimate interests, including securing, maintaining, and improving the Service;
- Compliance with legal obligations;
- Protection of users, ZeroDesk, or others from fraud, abuse, or security threats.
Users may withdraw consent where processing is based on consent. Withdrawal applies to future processing and does not affect lawful processing completed before withdrawal.
20. USER RIGHTS AND CHOICES
Depending on applicable law, users may have the right to:
- Access personal information;
- Request a copy of personal information;
- Correct inaccurate or incomplete information;
- Delete personal information;
- Delete individual files, messages, conversations, and generated outputs;
- Request account deletion;
- Export eligible information;
- Withdraw consent;
- Withdraw permission for external AI providers;
- Disconnect Gmail, Outlook, or another connected service;
- Object to or restrict certain processing;
- Lodge a complaint with an applicable data-protection authority.
Requests may be submitted by contacting:
ZeroDesk may need to verify the identity of the requester before completing a privacy request.
21. WORKSPACE AND ORGANISATION CONTROLS
Where a user accesses ZeroDesk through an organisation-managed workspace, authorised workspace administrators may be able to:
- Add or remove workspace members;
- Assign roles and permissions;
- Access content according to workspace permissions;
- Configure available connectors;
- Configure available AI models;
- Apply workspace policies;
- Delete or manage workspace content;
- Control access to organisation-managed accounts.
Users should direct questions concerning organisation-controlled processing to their workspace administrator.
22. COOKIES AND SIMILAR TECHNOLOGIES
ZeroDesk may use cookies, session tokens, local storage, or similar technologies to:
- Keep users signed in;
- Maintain secure sessions;
- Remember preferences;
- Prevent fraud and unauthorised access;
- Measure performance;
- Diagnose technical issues;
- Provide essential functionality.
Where required by applicable law, ZeroDesk will request consent before using non-essential cookies or similar technologies.
23. CHILDREN'S PRIVACY
ZeroDesk is not intended for children under 13 years of age or any higher minimum age required under applicable local law.
ZeroDesk does not knowingly collect personal information from a child below the applicable minimum age without legally valid authorisation.
If a parent, guardian, or other person believes that a child has provided personal information without appropriate permission, they may contact:
ZeroDesk will take appropriate steps to investigate and delete the information where required.
24. THIRD-PARTY WEBSITES AND SERVICES
ZeroDesk may contain links to or integrations with third-party websites and services.
This Privacy Policy does not govern the independent privacy practices of those third parties. Users should review the privacy policies and terms of the relevant third-party services before using them.
25. CHANGES TO THIS PRIVACY POLICY
ZeroDesk may update this Privacy Policy to reflect:
- Changes to the Service;
- New integrations or AI providers;
- Changes to data-processing practices;
- Security or operational changes;
- Legal or regulatory requirements.
The "Last Updated" date will be revised when this Privacy Policy changes.
Where a change materially affects how personal information is collected, used, or shared, ZeroDesk will provide appropriate notice through the Service, by email, or through another reasonable method.
If ZeroDesk adds a new external AI provider or materially changes the information shared with an existing provider, ZeroDesk will update the relevant disclosure and request consent where required.
26. CONTACT US
For questions, complaints, requests, or concerns regarding this Privacy Policy or ZeroDesk's handling of information, contact:
IFUTURIX AI LABS PRIVATE LIMITED
Email: connect@futurixai.com
Address: A-131, Sector 136, Noida, Uttar Pradesh, India
Website: ZeroDesk.io