Zenonify
Privacy Policy ← Back to Sign In
🔒 Privacy Policy

Your privacy matters

We built Zenonify to be a private, personal workspace. This policy explains exactly what data we collect, how we use it, and what we never do with it.

Effective: September 15, 2026 App: www.zenonify.com Contact: uiuxpert@ishtiaqshaheer.in
1

Information We Collect

When you create an account, we collect:

  • Your name and email address
  • A hashed (never plain-text) version of your password - we cannot read it
  • Your optional Gemini or Anthropic API key, encrypted at rest when configured, to enable AI features

When you use Zenonify, we also store:

  • Notes, tasks and steps you create, including their content and completion state
  • Folders and workspaces you create and their settings
  • Timestamps of when notes were created and last modified
  • Campaign attribution such as UTM parameters, referring site and common advertising click IDs when they are present in the URL
We do not store IP addresses or create device/browser fingerprints for campaign attribution. Payment card details are handled by the configured payment processor and are not stored in Zenonify.
2

How We Use Your Information

Your data is used solely to provide the Zenonify service:

  • To authenticate you and maintain your session securely
  • To store and retrieve your notes and folders
  • To send password reset emails when you request them
  • To send a one-time welcome email when you sign up
  • When you use an AI action, the relevant note text is sent to the configured Gemini or Anthropic API. Writing improvement sends text segments only, preserving rich formatting locally.
  • To connect campaign landings and lead clicks with completed registrations and checkout starts

We do not sell attribution or account data. Optional third-party analytics and advertising pixels load only after you choose Allow in the analytics preference notice.

3

Data Storage & Security

Your data is stored in a MySQL database on Hostinger shared hosting. We take reasonable steps to protect it:

  • HTTPS encryption for all data in transit
  • Passwords are bcrypt-hashed (cost 12) - we cannot recover them
  • Session cookies are HttpOnly, Secure, and SameSite=Lax
  • All forms are CSRF-protected
  • Login attempts are rate-limited to prevent brute force
  • Each user's data is isolated - you can only access your own notes

While we take security seriously, no internet service is 100% immune. We recommend not storing highly sensitive secrets (bank passwords, private keys, etc.) in any cloud note app.

4

Third-Party Services

  • Hostinger - hosting provider. Your data physically resides on their servers.
  • Google Gemini or Anthropic Claude API - used only for an AI feature when a user or instance API key is configured. The relevant note text is sent for that request.
  • Google Analytics, Google Tag Manager and Meta Pixel - optional measurement tools configured by the administrator. They load only after analytics consent is granted.
  • Google Fonts - we load the Inter typeface from Google's CDN. Google may log this request per their own policy.
  • Chart.js CDN (Cloudflare) - used only in the admin panel.

We do not sell, rent, or share your personal data with any other third parties.

5

Your Rights & Data Deletion

You have the right to:

  • View all your notes and folders directly in the app at any time
  • Delete any note or folder from within the app
  • Delete your entire account and all associated data via Settings → Danger Zone
  • Remove your Anthropic API key at any time from Settings

Account deletion is immediate and permanent. To request deletion if you cannot access your account, email uiuxpert@ishtiaqshaheer.in - we will process it within 7 business days.

6

Cookies & Sessions

Zenonify uses a session cookie (zenonify_sess) for authentication and a pseudonymous first-party visitor cookie (zn_vid) for campaign attribution. These cookies:

  • Contain only random identifiers - note content and contact details are not stored in the cookies
  • Are HttpOnly and SameSite=Lax; Secure is enabled over HTTPS
  • Can be removed by clearing browser cookies
  • Support sign-in security and first-party source/medium/campaign reporting

Your analytics consent choice is stored in local browser storage. Optional Google and Meta scripts are not loaded when you decline.

7

Changes to This Policy

If we make material changes to this Privacy Policy, we will update the effective date shown above. Continued use of Zenonify after changes are posted constitutes acceptance of the updated policy.

✉️

Questions about your privacy?

Email us at uiuxpert@ishtiaqshaheer.in and we'll respond within 48 hours.

© 2026 Zenonify ·Privacy Policy ·Terms of Service ·Sign In