Privacy Policy
Last updated: June 2026
Zenlify Inc. ("Zenlify", "we", "us", or "our") operates an AI-powered phone answering service for home service professionals. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data. By using Zenlify, you agree to the practices described in this policy.
1. Information We Collect
- Account information: Your full name, email address, phone number, and business name provided during registration.
- Call data: Inbound call recordings, AI-generated summaries, caller name and phone number, call duration, and reason for call.
- Usage data: Dashboard activity, analytics events, and session cookies used to keep you logged in.
- Payment information: Subscription billing is handled entirely by Razorpay. We do not store your card number or CVV on our servers.
2. How We Use Your Information
- Provide and operate the AI receptionist service on your behalf
- Deliver SMS call summaries and job notifications to your phone
- Process subscription payments and manage your billing account
- Improve call handling quality based on aggregated, anonymized call interactions only — we never use Google Calendar data, identifiable customer recordings, or any sensitive personal information to train AI models
- Respond to support requests and account inquiries
- Send service-related communications (never marketing without consent)
3. Third-Party Services
Zenlify relies on the following trusted third-party providers to deliver its service. Each has its own privacy policy.
- Telnyx — Powers all phone calls, SMS messaging, and AI voice processing.
- Firebase (Google) — Secure cloud storage for your account data and call records.
- Razorpay — Subscription billing and payment processing.
- Google Calendar — Optional integration for job scheduling. Only activated if you choose to connect your account.
4. AI Model & Processing
Zenlify uses self-hosted AI models to power its phone answering and call-handling features. AI processing is limited strictly to what is necessary to operate the service and does not include using your data to train AI models.
5. Google User Data and Limited Use Disclosure
When you choose to connect your Google Calendar, Zenlify requests a single sensitive OAuth scope: https://www.googleapis.com/auth/calendar.events. This scope grants Zenlify access only to calendar events on your primary Google Calendar. It does not grant access to Gmail, Google Drive, Contacts, your profile photo, or any other Google service or account information.
We use this access for two purposes only, both directly required to deliver the calendar booking feature:
- Read your upcoming events to check availability before our AI offers a time slot to a caller.
- Create new events on your calendar when our AI books a job on your behalf.
We do not use Google user data to train AI or machine-learning models, sell or rent it to anyone, share it with advertisers or analytics partners, or transfer it to any third party except as strictly required to operate the calendar feature itself. We do not retain Google user data beyond what is necessary to provide the feature.
You can disconnect Google Calendar at any time from the Settings page in your Zenlify dashboard, or by revoking access from your Google Account permissions. When you disconnect, we permanently delete all stored Google OAuth tokens associated with your account from our database.
Zenlify's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Data Retention
Your account data is retained while your subscription is active and for 90 days after cancellation, after which it is permanently deleted upon request. Call recordings and AI summaries are retained for up to 24 months to support your analytics and call history review.
7. Data Security & Protection
We protect sensitive data with the following technical and organizational safeguards:
- In transit: all traffic is served over HTTPS with TLS 1.2 or higher, with HSTS enforced at our edge.
- At rest — Google OAuth tokens: refresh tokens are encrypted with AES-256-GCM (12-byte random IV, authenticated) before being written to our database. Encryption keys are held outside the database.
- Passwords: never stored in plaintext or reversibly encrypted. Each password is hashed with scrypt using a unique random salt per user.
- Sessions: authenticated via httpOnly, secure cookies carrying a 32-byte cryptographically-random token. Cookies are not accessible to client-side JavaScript and are transmitted only over HTTPS in production.
- Database access: our database is restricted to our backend via a private service-account credential and is not directly exposed to the public internet.
- Network controls: security headers via Helmet, per-IP rate limiting on all endpoints, and Cloudflare edge protection against abuse and DDoS.
- Access controls: internal access to production systems is limited to authorized engineering personnel under the principle of least privilege.
The only cookie we set is the session cookie described above; we do not use advertising, analytics, or third-party tracking cookies.
8. Your Rights
You have the right to access, correct, export, or delete your personal data at any time. To exercise these rights, email us at [email protected]. We will respond within 30 days.
9. Contact
For privacy-related questions or requests, contact us at [email protected].
