ZANCTA

/privacy

Your privacy is our product.

We believe privacy isn't just a policy — it is the way we build. This page describes current product behavior and requires review by the responsible legal owner before a commercial launch.

Local file processing

For implemented local PDF and image tools, selected file bytes are read and processed in the browser. ZANCTA does not receive those bytes for processing. Background removal is deferred rather than sending an image to an undisclosed cloud fallback.

This boundary does not control browser extensions, malware, operating-system backups, device sharing, or future features that are explicitly offered as optional cloud services.

Account information

If you create an account, the application stores information needed for authentication and entitlements, such as email address, optional name, password hash, sessions, verification tokens, and password-reset tokens. Passwords are not stored in plain text.

Cookies and browser storage

Authentication uses session mechanisms needed to keep an account signed in. Local tool results are held in the browser session for preview, copy, or download. Closing or clearing the workspace releases the active local result state.

Payments and email

When enabled and configured, a payment provider handles checkout and billing, and an email provider delivers verification or password-reset messages. Those providers receive only the information needed for their service. Live provider configuration and delivery verification are not claimed here unless they have been completed.

Analytics and advertising

No live advertising provider is enabled in the current application. If an analytics function is explicitly configured, the product may send a coarse completion event without filenames or file contents. Any future analytics or advertising provider must be disclosed, must not receive file content, and must stay outside the active tool workflow.

Retention and deletion

ZANCTA does not retain selected file bytes for implemented local processing. Authenticated account deletion removes associated application account records through the account flow. Provider retention, user-rights requests, and jurisdiction-specific retention language require legal review before launch.

Legal review

Before public commercial use, a legal owner must confirm the operating entity, applicable jurisdictions, provider disclosures, cookie and consent requirements, retention periods, user rights, and a real contact method.