Privacy Policy
🛡️ Our Core Promise: Zero Node does not log request or response content. Reversible token mappings are stored only for a short, configured session and are deleted on first rehydration or expiry.
1. Introduction
Zero Node ("we," "our," or "us") operates the Privacy Firewall PII Redaction API and related services. This Privacy Policy explains how we handle information when you use our services.
By using our services, you agree to the collection and use of information in accordance with this policy.
2. Our Data-Minimizing Architecture
Privacy Firewall is designed to minimize processing storage. This means:
- No Content Logs: Application code does not write submitted text or returned content to logs, posts, metrics, or the API-key repository.
- Short-Lived Token Sessions: Token mode stores only the token-to-original mapping in application memory or non-persistent Redis for the configured TTL (five minutes by default). It is deleted on first successful rehydration or expiry. Redis AOF and snapshots are disabled in the release configuration.
- Non-Token Modes: Mask, remove, hash, pseudonym, partial, and the public demo do not create a reversible mapping.
- Local Model Processing: Contextual detection runs in a private local sidecar, not an external AI API.
- Transport Providers: The public service uses Cloudflare for encrypted ingress; Cloudflare may process connection metadata under its own terms. It is not used as the redaction engine.
3. Information We Collect
3.1 Early-Access and API-Key Information
The MVP has manual provisioning rather than self-service accounts. We may store:
- The owner/contact label supplied when an API key is provisioned
- API-key ID, one-way SHA-256 hash, short preview, tier, creation time, and revocation status
- Commercial correspondence and payment records agreed during manual activation, when applicable
3.2 Usage Metrics
We collect operational metadata without request content:
- Per-key daily request count and a last-used timestamp
- Aggregate daily counts for redact, rehydrate, demo, model success/failure, rate-limit rejection, and login lockout events
- Short-lived IP-based rate-limit and login-protection keys
3.3 Optional Website Analytics
Google Analytics 4, measurement ID G-8GWFWVS6MG, loads only after a visitor selects Allow analytics. When enabled, Google may process the page URL and title, referrer, approximate location, device and browser information, engagement measurements, and the product events listed below. A network request also makes the visitor's IP address available to Google for processing under Google's terms.
We use these bounded events: demo started, demo success or error, pricing viewed, documentation or Quick Start viewed, API example copied, and request-access or contact actions. Event payloads are designed not to include redaction input, redaction output, API keys, session IDs, contact content, or customer identifiers.
3.4 Content and Identifiers We Do Not Send to Analytics
- API or playground redaction input and output
- API keys, reversible mappings, session IDs, or finding previews
- Contact email content or manually provisioned account records
- Advertising-personalization signals or application-created cross-site profiles
4. How We Use Information
The limited information we collect is used to:
- Provide and maintain our services
- Administer manually agreed early-access plans
- Send important service updates
- Improve service performance and reliability
- Understand whether consented visitors find the demo, documentation, pricing, and access path useful
- Respond to support requests
5. Data Security
The current release configuration includes these security measures:
- Encryption in Transit: The public endpoint is served over HTTPS through Cloudflare
- Rate Limiting: Protection against abuse and attacks
- Authentication: Hashed API keys for firewall calls and short-lived JWTs for administration
- Isolation: Redis and local-model services are not directly published by the Compose stack
6. Your Rights
You have the right to:
- Access: Request a copy of your account information
- Correction: Update or correct your account details
- Deletion: Request deletion of your account
- Portability: Export your account data
Redaction content is unavailable after a token session is consumed or expires. Contact us regarding retained provisioning or operational metadata.
7. Browser Storage and Analytics Consent
The public site stores your analytics choice in browser localStorage under zero_node_analytics_consent. Selecting Essential only prevents the Google Analytics tag from being requested. Selecting Allow analytics permits Google Analytics to load and may allow Google to set first-party analytics cookies.
- No advertising storage, advertising personalization, or Google Signals is enabled by our tag configuration
- No redaction input or output is placed in browser storage by the public playground
- The admin dashboard stores its JWT in browser
sessionStoragefor that tab and removes it on logout - You can reopen the consent choice through Analytics settings in the site footer
8. International Data Transfers
If you access the service from outside its server region, connection metadata and submitted content may transit internationally through the hosting and encrypted-ingress path. If you consent to website analytics, Google may process analytics metadata internationally under its own terms and data-transfer mechanisms. Application code does not persist request or response content; token mode retains only the short-lived, non-persistent mapping described in Section 2.
9. Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or a prominent notice on our website. Your continued use of our services after changes constitutes acceptance.
📧 Contact Us
Questions about this Privacy Policy? Contact us at [email protected]