Effective date: September 16, 2026 · Applies to zivraglobal.com and all its subdomains
Zivra Global (“we”, “us”) operates zivraglobal.com and the services hosted on its subdomains: an AI marketing system (ai.), a social-media posting platform (app.), a multi-vendor marketplace (shop.) and a website search engine (index.). Contact: our contact page.
Account data — your name, email address and password (stored only as a salted hash) when you create an account.
Content you create — briefs, prompts, captions, images, videos and schedules you submit through our products.
Social connections — if you connect a social account (Facebook, Instagram, YouTube, LinkedIn, X, TikTok, Pinterest, Google Business), we store the OAuth tokens needed to post on your behalf, plus the page/profile identifiers and display name you authorize.
Usage data — job logs, delivery status, and basic analytics (page views, feature usage) used to run and improve the service.
Marketplace data — on the marketplace, seller-provided listings and the contact information you choose to publish. Payments for sponsored placements are processed by third-party processors (e.g. Stripe, PayPal); we never see or store your full card number.
We use your data to: operate the products (generate and publish the content you ask for, on the accounts you connect); show you results and status; send you service notifications (including through Telegram when you opt in); and debug failures. We do not sell your personal data, and we do not use your content to train third-party AI models.
Content generation uses third-party AI providers (for example Cloudflare Workers AI and the model APIs configured for your workspace) plus our own self-hosted models. Prompts and media are processed only to fulfil your request. You can configure your own provider keys; those calls then go directly to your chosen provider under its own privacy policy.
When you connect a social platform, we request only the permissions needed to publish and read basic delivery status for the accounts you select. Tokens are stored encrypted-at-rest in our database, are used solely to perform the actions you initiate, and are deleted when you disconnect the account or delete your workspace. You can revoke access at any time from the platform’s connected-apps settings or by removing the destination in our dashboard.
We share data only with: infrastructure providers (Cloudflare, Supabase), the AI providers configured for your workspace, and the social platforms you connect — each processing data to deliver the feature you asked for. We may disclose data if legally required.
Account and content data are kept while your account is active. Disconnected accounts stop token use immediately and stored tokens are deleted. On request, we delete your account and associated personal data within 30 days; marketplace listings you published are removed at the same time.
You can access, export, correct or delete your personal data at any time from your dashboard or by contacting us. Where GDPR or similar laws apply, you also have the right to object to processing and to lodge a complaint with your supervisory authority.
Passwords are hashed; OAuth tokens and API keys are stored with encryption at rest; traffic is served over HTTPS; access to production data is limited to the operator.
If we make material changes we will notify account holders by email or in-app notice before they take effect.