Privacy Policy

Last updated: September 16, 2026

Introduction

Zivash Inc. ("we," "our," or "us") operates Ziva.sh and Ziva AI development agents for game engines. This Privacy Policy explains how we collect, use, and protect your information when you use our services or contact our team.

Information We Collect

Account Information

When you sign in using OAuth (GitHub, Discord, or Google), we collect:

  • Your name
  • Your email address
  • Your profile image
  • OAuth provider information
  • Last login method

Session Information

When you use our service, we collect:

  • Session tokens for authentication
  • IP addresses
  • User agent information (browser/device type)
  • A persistent, hashed device identifier used only to prevent abuse of free-tier limits

Usage Information

When you interact with Ziva, we store minimal usage data for billing and analytics purposes. We do not store your prompts, code, or project-specific data on our servers. The data we do store includes:

  • API usage statistics (request counts, timestamps)
  • Token usage and cost tracking per request

Sales and Project Inquiries

When you submit an enterprise or publishing inquiry, we collect:

  • Your name, work email, organization, and role
  • Your team size, engines, product interest, and project brief
  • Budget information when you choose to provide it
  • Links and publishing details when you submit a publishing inquiry
  • Referral information associated with the submission

Plugin Telemetry

The Ziva editor plugin sends product usage telemetry to help us understand which features are useful. Nothing is sent until you are signed in. Telemetry is on by default at the "Basic + usage statistics" level, and you can change or disable it at any time in the plugin under Settings → General, which offers four levels:

  • No telemetry - nothing is sent.
  • Basic system information - editor version, plugin version, and operating system.
  • Basic + usage statistics (the default) - the above plus product usage events and performance signals such as response time, project size, and conversation length.

At every level other than No telemetry, these events are sent with your user id and are therefore associated with your account, not anonymous. Your prompts, files, scenes, scripts, generated text, and project contents are never included in telemetry at any level.

Local Data Storage

Chat history and conversation data may be stored locally in SQLite on your device for offline access and faster loading. This data remains on your device and is not stored on our servers.

How We Use Your Information

To Provide AI Assistance

Your code and conversation data is sent to third-party LLM providers (such as but not limited to Google, Anthropic, and OpenAI) to generate AI responses. We may add additional providers in the future to improve service quality.

To Maintain Your Account

  • Authenticate and authorize access to your account
  • Track API usage for billing and rate limiting

Email Communications

We use your email address to send you:

  • Service communications (welcome, account, security, billing). These are required to use Ziva and cannot be opted out of while your account is active.
  • Marketing communications (product updates, newsletters, announcements). You can opt out of these at any time using the unsubscribe link at the bottom of any marketing email or via the newsletter setting in your account settings.

We honor opt-outs without undue delay. We do not share your email with third parties for their own marketing.

To Respond to Inquiries

We use enterprise and publishing inquiry data to review your brief, contact you about the requested project or program, qualify an engagement, and arrange a call when you choose to book one.

What We Never Do With Your Data

  • We never store your project data on our servers. Ziva does not store your prompts or code on its servers; we directly forward your requests to LLM providers.
  • We never use your code to train AI models. Your game projects and code are never used by Ziva to train AI models.
  • We never sell your data to advertisers or data brokers, and we do not share it for third-party advertising.

Cookies

We run no advertising or ad-network tracking on this site. There is no Google Ads, X, Quora or OpenAI tag, no third-party advertising pixel of any kind, and nothing on these pages is requested from an ad network. Because none of those exist here, there is no advertising-cookie choice to make and no cookie banner.

The cookies we do set are our own. Your sign-in session is one. The other two are ziva_attribution and ziva_ref, which remember which link brought you here so referrals are credited correctly. Both stay on our domain, expire after 30 days, and are never sent to an advertiser or data broker.

We also use product analytics to understand how the site and plugin are used, which is described under Analytics below. It is not used to target advertising.

Third-Party Services

LLM Providers

We use the following LLM providers to power Ziva's AI capabilities:

  • Google (Gemini)
  • Anthropic (Claude)
  • OpenAI (GPT)
  • OpenRouter (LLM routing)
  • Additional providers may be added in the future

These providers process your code and prompts according to their own privacy policies and API terms. While Ziva itself does not store your prompts or project data, these third-party providers may store data based on their own policies. You are encouraged to review the individual privacy policies of these providers. We never use your code or project data to train AI models.

Asset Generation Services

We use the following services for generating game assets:

  • Meshy API (3D model generation)
  • PixelLab API (pixel art generation)
  • Retro Diffusion API (pixel art generation)

When you use asset generation features, your prompts and parameters are sent to these services according to their respective privacy policies.

Cloud Storage

Generated assets (3D models, images, etc.) are stored in S3-compatible cloud storage. These files are associated with your account and may be retained until you delete your account or request removal.

Authentication

We use GitHub, Discord, and Google OAuth for authentication. When you sign in, these providers share basic profile information with us according to their privacy policies.

Payment Processing

We use Stripe to process payments for subscriptions and billing. When you subscribe or make a purchase, Stripe collects payment information directly according to their privacy policy. We do not store your full credit card details on our servers, we only store minimal subscription ID, status which are required to identify your subscription.

Analytics

We use the following analytics services to improve our product:

  • PostHog (product analytics, EU hosted)
  • Vercel Analytics (web analytics)

These services help us understand how users interact with Ziva and improve the experience. Vercel Analytics collects anonymous web analytics. PostHog product analytics, including plugin telemetry, is associated with your account rather than anonymized.

Discord Integration

In addition to Discord OAuth for authentication, we operate a Discord bot that may manage roles and permissions based on your subscription status. We also use private Discord webhooks to notify our team about enterprise and publishing inquiries; the notification contains the information submitted in the inquiry form.

Call Scheduling

If call booking is offered after an enterprise inquiry and you choose to schedule one, we share the contact and project details needed to prefill the booking with Cal.com. Cal.com processes that information according to its own privacy policy.

Data Retention

You can delete your account and account-associated product data through your account settings. We retain sales and project inquiry data for as long as reasonably needed to respond, evaluate an engagement, maintain business records, and meet legal obligations. To request access to or deletion of inquiry data, email privacy@ziva.sh.

Your Rights

You have the following rights regarding your personal data:

Right to Access

View all information we have about you through your account dashboard at any time.

Right to Delete (Right to Erasure)

You can permanently delete your account and all associated data at any time through the "Danger Zone" section in your account settings. This will immediately and permanently remove:

  • Your account and profile information
  • API keys and usage data
  • All settings and preferences

Note: Account deletion is irreversible. All data is purged from our servers within 24 hours. Some data may persist with third-party payment providers (if applicable), and third-party LLM providers. To request deletion from payment providers, contact us at privacy@ziva.sh after deleting your account.

Right to Control What You Share

You have control over what code and project context you share with Ziva. All AI requests are triggered by you.

GDPR Compliance

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to rectification: Correct inaccurate personal data through your account settings
  • Right to data portability: Contact us to receive a copy of your data in a portable format
  • Right to object: Object to processing of your personal data for specific purposes
  • Right to restrict processing: Request limitation of processing under certain circumstances

To exercise any of these rights, contact us at privacy@ziva.sh. We will respond to your request within 30 days.

Security

We implement reasonable security measures to protect your data from unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet is 100% secure.

Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the "Last updated" date at the top of this policy.

Contact Us

If you have questions about this Privacy Policy, please contact us:

Zivash Inc.
Federally registered in Canada
Email: privacy@ziva.sh