Privacy Policy
Last updated 10 August 2026
ZYLX operates Zylx Studio at zylx.studio, together with zylx.ai and companion applications. This policy explains what Zylx Studio collects, how connected business systems are used, and the control you keep over them.
This is the same policy that governs ZYLX generally, stated here for the zylx.studio application.
Information we collect
We collect only what is needed to run the product and to build the model of your business that Zylx calls your Business Brain.
- Account information — your name, email address and authentication details.
- Business data from the systems you connect — for example Shopify, Google Search Console, Google Analytics, Google Ads, Stripe, Klaviyo, Microsoft Clarity, Ahrefs, Semrush and GitHub.
- Public content from a website you ask us to analyze.
- Usage records — audits you run, recommendations produced, and actions you approve or reject.
Connecting your business systems
Every connection is optional and is started by you. Nothing is connected on your behalf.
When you connect a provider, you are shown what Zylx will read and at what access level before the authorization begins. Zylx requests the narrowest access the provider offers for the feature — Search Console and Analytics are requested read-only.
After you authorize a provider, you choose which specific resource Zylx may use — a Search Console property, an Analytics property, an Ads account, or a set of repositories. Zylx reads only the resource you select.
How connected data is used
Data from connected systems is used to provide the features you see in Zylx Studio: understanding your business, producing audits and findings, generating recommendations, and — only where you approve it — carrying out a change on a connected system.
To produce that analysis, business data may be processed by the AI providers Zylx uses as service providers, solely to generate results for your own workspace.
We do not sell your data. We do not use it for advertising or ad targeting. We do not use it to train, develop or improve general-purpose AI or machine-learning models.
Google user data
Zylx Studio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Search Console and Google Analytics are connected with read-only permissions. Zylx cannot change anything in either.
Google Ads is different, and we want to be exact about it: Google does not publish a read-only permission for the Google Ads API, so the standard Google Ads permission is the only one available and Google describes it as allowing changes. Zylx uses it to read your campaign, keyword, search-term, budget and conversion data. Zylx does not change your campaigns on its own — any change to a connected system is proposed for your review and is only carried out after you approve it.
Google data is used only to provide the reporting, findings and recommendations visible to you inside Zylx Studio. It is not used for advertising targeting, is not sold, and is not used to train general-purpose AI or machine-learning models.
You can withdraw Google access at any time from inside Zylx Studio, or from your Google Account permissions page at myaccount.google.com/permissions.
How credentials are protected
Access tokens and API keys are held on our servers only. They are encrypted at rest and are reachable only by the server code that calls the provider on your behalf.
Credentials are never sent to your browser, never included in the data given to the AI layer, and never exposed through the Zylx MCP interface. The AI receives business data — never the credential that fetched it.
Disconnecting a provider
You can disconnect any provider at any time from Connections inside Zylx Studio.
When you disconnect, Zylx stops reading new data from that provider and deletes the stored credential. Where the provider supports revocation — Google and Shopify do — Zylx also revokes the authorization at the provider. For providers connected with a key you pasted, delete the key in that provider's own dashboard to be certain it can no longer be used.
If several Google services share one authorization, disconnecting one service stops that service only; the authorization is released when the last Google service is disconnected.
Information already imported before you disconnected remains in your Business Brain so your history stays intact, and is clearly marked with when it was last updated. It is not deleted automatically. To have it removed, ask us.
Retention and deletion
We retain your data while your account is active.
You can ask us to delete your account and its data at any time through our contact page. We remove it within a reasonable period, except where we are required to keep records by law.
Payments
Payments are processed by Stripe. Stripe stores your card details; ZYLX never receives or stores a full card number.
Contact
For privacy questions, access requests or deletion requests, reach us through our contact page.