Zolt AI
Privacy Policy
Effective October 1, 2026
Zolt AI (“the Service”) is operated by RED Media Network LLC (“we”, “us”). This policy explains what information we collect, how we use it, and the choices you have. Questions any time: info@redmedianetwork.com.
Information we collect
- Account information. Your name, email address, and a hashed password — or, if you sign in with Google, the name and email Google shares with us. We never see or store your Google password.
- Workspace content. The businesses, boards, zones, and tiles you create; files you upload; links you import; notes; chat messages; and voice recordings you choose to transcribe.
- Content you import. When you paste a link (a website, video, or article), we fetch and process that content — including extracting text and transcripts — so your workspace chat and generations can use it. You are responsible for having the right to import the content you import (see our Terms of Service).
- Visitor and lead data collected on your behalf. If you publish a landing page or embed a chatbot, we store the form submissions and chat messages your visitors send. For that data, you (our customer) are the data controller and we act as your processor — you are responsible for your own privacy notices to your visitors.
- Billing information. If you buy a plan or a credit pack, our payment processor (Stripe) collects and processes your payment details. We never see or store your full card number— it goes directly to Stripe. We keep the identifiers and records we need to run billing: a Stripe customer and subscription id, your plan, invoice and receipt history, and your credit balance and the ledger of credits granted and spent. Stripe processes this as an independent controller under its own privacy policy.
- Usage information. Sign-ins and product activity (for example, that a board was created), used to operate features like your activity feed and to keep the Service secure.
- Cookies. We use a session cookie to keep you signed in. We do not use advertising cookies or third-party trackers.
- Website analytics. On getzolt.ai we count page views and a few actions (such as starting the free audit or choosing a plan) with Umami, which we host ourselves on the same infrastructure as the Service. It sets no cookies and does not identify you; it records aggregate visits, the page and site that referred you, and your browser, device type and country.
- Email link clicks. Links in our introduction and follow-up emails to creators pass through getzolt.ai so we can see whether a link was clicked and when. We record that click against the email we sent, nothing about your browsing beyond it, and the link takes you straight to the page it shows.
- Waitlist and referrals. If you join the waitlist or use a referral link, we store the email and name you provide and the referral relationship.
How we use information
- To provide and operate the Service — including grounding AI chat and generations in your content.
- To send transactional email (account and access messages) and, with your consent, occasional product updates. Every marketing email includes an unsubscribe link.
- To secure the Service, prevent abuse, and debug problems.
- To improve the product, using aggregate usage patterns — not the contents of your workspace.
AI processing
Core features send relevant parts of your workspace content to third-party AI model providers — currently Anthropic, OpenAI, Google, xAI, and Perplexity — to generate responses, content, and images. We send only what a feature needs, under each provider’s API terms. We do not use your content to train our own models, and we do not permit these providers to use API data for training where they offer that control.
Connected social accounts
If you connect a social account — a Facebook Page, Instagram professional account, Threads profile, LinkedIn profile or page, X, Pinterest, TikTok, YouTube, or Bluesky — you authorize us to act on that account on your behalf, and we receive data from that platform (“Platform Data”). We ask each platform only for the permissions the features you use actually require.
What we receive and store: the access credential for the account, the account’s id, name or handle and profile picture, the identifier of the post we publish, and performance readings for posts published through Zolt (such as views, reach, likes, comments, shares, and watch time where the platform provides them).
What we use it for: publishing the content you approve, showing you how those posts performed, and improving the content we generate for you — your own results are fed back into generation so future content reflects what works for your audience. We do not use Platform Data for advertising, we do not sell it, we do not combine it with data from other customers, and we do not use it to train AI models.
How long we keep it: credentials for as long as the account is connected, and performance readings for as long as your account is open, because a deleted reading cannot be recovered later — platforms do not keep this history indefinitely — except where a platform’s own rules require less (see YouTube and LinkedIn below).
How to delete it: disconnect the account in Zolt (Settings → Social accounts), or remove Zolt AI in the platform’s own app settings — the platform notifies us and we delete the connection and its stored readings automatically. Full instructions are on our data deletion page. Posts already published remain on the platform; they belong to your account there.
Our use of information received from Meta APIs follows Meta’s Platform Terms and Developer Policies, including their limited-use requirements.
YouTube: Zolt’s YouTube features use YouTube API Services. When you connect a YouTube channel we receive your channel’s id and name, permission to upload the videos you approve, and read-only access to those videos’ public statistics (views, likes, and comments), which we use only to publish your approved videos and show you how they performed. By connecting YouTube you also agree to YouTube’s Terms of Service, and Google’s handling of your data is described in the Google Privacy Policy. You can revoke Zolt’s access at any time by disconnecting YouTube in Zolt or from your Google account’s security settings; when you disconnect we revoke our access with Google immediately, and if access to a channel lapses we delete the YouTube data we stored for it within 30 days. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
LinkedIn: When you connect LinkedIn we receive your LinkedIn member id and name, the name and logo of any LinkedIn Page you administer and choose to connect, permission to publish the posts you approve to your profile or Page, and aggregate statistics for those posts (such as impressions, reactions, comment counts, and reshares). We use this only to publish your approved posts and to show you, and the people in your Zolt workspace for that business, how they performed. We do not display LinkedIn comments or information about the people who comment, we do not use LinkedIn data for advertising, sales, lead generation, or recruiting, and we do not export LinkedIn data or combine it with other data. For LinkedIn accounts connected through Zolt’s own LinkedIn integration, we keep LinkedIn data only as long as LinkedIn’s data storage requirements allow — Page statistics for up to one year, and data about other LinkedIn members for no longer than 48 hours — and we delete a business’s stored LinkedIn data within 10 days of a request or of the business leaving Zolt. You can revoke Zolt’s access at any time by disconnecting LinkedIn in Zolt or in your LinkedIn settings (Settings → Data privacy → Permitted services). LinkedIn’s handling of your data is described in the LinkedIn Privacy Policy.
Where your data lives and who can access it
The Service is hosted in the United States: the application and PostgreSQL database run on Railway infrastructure, and the images and files the product generates or you upload are stored on Tigris Data object storage. We do not sell your data, and we share it only with the service providers needed to run the product — hosting (Railway), object storage (Tigris Data), email delivery, payment processing (Stripe), the AI providers listed above, and the services that publish to the social accounts you connect and that analyse the public web and social content you ask us to look at. We can provide the current list of these providers on request, for example under a data processing agreement. If you use the Service from outside the United States, your data is processed in the United States.
Legal requests and government demands
We may disclose your information when we are required to do so by law — for example in response to a subpoena, court order, search warrant, or other lawful request from a public authority — or where disclosure is necessary to protect our rights, your safety or the safety of others, or to investigate fraud or a violation of our Terms of Service.
When we receive a request from a public authority for your information, we:
- Review it for legal validity before responding, including whether the request is properly issued and covers the data it claims to.
- Disclose only the minimum necessary. We produce the narrowest set of data that answers the request, rather than an entire account or workspace.
- Document the request and our response, including who asked, what was produced, and the reasoning — so our handling of these requests can be audited.
- Notify you where we are lawfully able to, so that you have the opportunity to object, unless we are legally prohibited from telling you.
Retention and deletion
Your content stays in your workspace until you delete it (boards you delete go to Trash first, then can be permanently removed). To delete your account and its data entirely, email info@redmedianetwork.com and we will complete the deletion within 30 days. Waitlist entries are deleted on request. Data from connected social accounts can be deleted separately and immediately — see our data deletion page.
Billing records are an exception: we retain invoices, payment records, and the credit ledger for as long as tax, accounting, and anti-fraud obligations require, even after an account is deleted. Deleting your account does not reverse a completed purchase — see “Paid plans and Zolt Credits” in our Terms of Service.
The free Brand Voice Audit
If you run the free Brand Voice Audit on our website, we collect the website address you paste, the email address you ask us to send the result to, and a hashed (not raw) form of your IP address, used only to limit abuse. The public text of that website is sent to the AI providers listed above to produce the audit, under their API terms; it is not used to train AI models, ours or theirs, and it is not sold. We keep each audit and its result for 12 months, then delete it automatically. Your email is added to our newsletter only if you tick the box on the form; every newsletter email carries a one-click unsubscribe, and you can ask us to delete an audit sooner at any time.
Your rights
You can access, correct, export, or delete your information by emailing us. If you are in a jurisdiction with specific privacy rights (such as the EEA, UK, or California), we honor access, correction, deletion, and portability requests under those laws. We do not sell or share personal information as those terms are defined under the CCPA.
Security
Data is encrypted in transit, passwords are stored hashed, sessions are signed, and access to production systems is limited. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you promptly.
Children
The Service is not directed to children under 16, and we do not knowingly collect their data.
Changes
We will post any changes to this policy here and update the effective date. Material changes will be announced by email to account holders.