Privacy Policy

Last updated: 24 September 2026

1. Introduction

ZenMode Ltd ("ZenMode", "we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website (zen-mode.io) and desktop application.

2. Information We Collect

Account Information: When you create an account, we collect your name, email address, and payment information (processed securely via Stripe).

LinkedIn Data: When you use ZenMode, the desktop application interacts with your LinkedIn account locally on your computer. We store campaign data, connection names, job titles, companies, and profile URLs that you import into campaigns.

Usage Data: We record how the website and the product are used, and most of that record is linked to you rather than anonymous. Our own page-view record stores the page path, the referring URL, any utm_* parameters, your browser's user agent, your screen width, the country and city your IP address resolves to, and your user id when you are signed in. PostHog product analytics keeps a profile per person, and once you sign in we attach your email address and first name to that profile. The marketing source of your first visit is written onto your account record, and our admin analytics page lists signed-in visitors by name. We also collect campaign performance metrics.

Two things here genuinely carry no identifier: the Sangha Intelligence statistics described in section 6, and the blueprint download count described just below. Treat the rest of "usage data" as data about you.

Chat messages: If you use the Peacock chat assistant on our website, we store what you typed, the reply, and the IP address it came from. Section 9 covers this in full.

Blueprint requests: When you ask for one of our free PDF blueprints at /blueprints, we store your email address, which blueprint you asked for, any utm_* parameters on the page, and when we sent the email and when its link was used. We use it to email you that PDF, which we do because you asked for it (UK GDPR Article 6(1)(b), steps taken at your request), and to stop the form being used to send email to someone else. We send you nothing else unless you tick the optional box to receive new blueprints and occasional ZenMode updates. That is marketing, so it is based on your consent: we record that you ticked it, which wording you saw, and when. Every email we send has an unsubscribe link, which withdraws that consent at once, or you can email hello@zen-mode.io. If you did not tick the box, or you later unsubscribe, we delete the request after 12 months. If you did tick it, we keep your address for those updates until you unsubscribe. The emails are sent through Resend, our email provider.

Blueprint download count: When a blueprint link is used, we also count the download: which blueprint, the utm_* parameters it came with, and the time. That count holds no IP address, no browser details and no identifier, sets and reads nothing on your device, and is used only to see which blueprints are useful and where readers come from.

3. How We Use Your Information

We use the information we collect to:

Provide, maintain, and improve our services; process transactions and send related information; send you technical notices, updates, and support messages; respond to your comments, questions, and customer service requests; monitor and analyse trends, usage, and activities; and detect, investigate, and prevent fraudulent transactions and other illegal activities.

4. Data Storage and Security

Your campaign data is stored securely in our cloud database. LinkedIn automation runs locally on your computer through our desktop application — we never store your LinkedIn password or session credentials on our servers. Payment information is processed and stored by Stripe and never touches our servers.

5. Data Sharing

We do not sell, trade, or rent your personal information to third parties. We share information with the service providers that run parts of our platform, and only as far as they need it to do their job. Those are Stripe for payments, Clerk for authentication, Cloudflare for the bot filtering in front of Clerk, Resend for the email we send you, Anthropic for the AI features and the chat assistant, ElevenLabs for voice notes, Neon and Vercel for hosting, Sentry for error reports, and PostHog for product analytics. We also send ourselves internal alerts over Telegram, and some of those name you. The full list, with where each one is based and what it is for, is in section 7.

6. Sangha Intelligence

Sangha Intelligence helps every ZenMode customer write better outreach by learning from de-identified statistics across our customer community, such as acceptance and reply rates by target role, industry, sequence step and message length, and from the de-identified wording of customers' messages.

Aggregate statistics are on by default, and you can opt out at any time. We count how your campaigns perform (requests sent, accepted and replied to) together with simple facts about your messages, such as their length and position in the sequence, and combine these counts with those of other customers. Our message writer learns from the combined statistics of all participating customers, with no minimum group size, but it never shows anyone's figures or text and it writes every message fresh. Any combined figure we show you includes at least three other customers, grouped broadly (for example founders and C-level, sales leaders or managers, in software, agencies or recruiting), with no single customer making up more than half of it, and we round what we show. Nobody, including other customers, can see your individual numbers. You can opt out in your application settings, under Data Preferences, or with the link in our notice email. An opt-out takes effect immediately: from then on your statistics are not used, and you no longer receive pooled suggestions.

Existing customers. If you had a ZenMode account before 25 September 2026, we will not include your statistics until 14 days after we have emailed you about this change, and never if you opt out. Accounts created from 25 September 2026 are covered from the start.

Message wording is also used by default, with identifying details removed. Unless you opt out, we also learn from the wording of the messages and templates you send, to find which kinds of messages get replies and to improve suggestions for all customers. Before we use any text, we remove names, company names, brands, product names and anything else that could identify you, your company or the people you write to. We never show, copy or reproduce your messages for anyone else: every suggestion is checked against the messages we learn from, and anything too close to one of them is discarded. We never use your prospects' replies. You can switch off the message wording on its own in Data Preferences. If you opt out of the statistics, your message wording is not used either, and the opt-out link in our notice email switches off both. The notice period for existing customers above applies to the message wording too.

What is never shared. We never show another customer your message content, your contact lists, your prospects' names, profiles or replies, or your company name.

7. Your Data Rights and GDPR Compliance

ZenMode Ltd is registered in the United Kingdom and is subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. If you are located in the EU, the EU GDPR also applies to our processing of your data.

Legal Basis for Processing

We process your personal data under the following legal bases:

  • Contract performance: Processing your account information, campaign data, and LinkedIn data is necessary to provide the ZenMode service you have signed up for.
  • Legitimate interest: We process usage data and anonymized analytics to improve our product, monitor for security issues, and ensure service reliability. We have assessed that these interests do not override your fundamental rights and freedoms.
  • Sangha Intelligence statistics and message wording: We compute and use de-identified aggregate statistics and de-identified message wording (section 6) to provide the service you signed up for and on the basis of our legitimate interest in improving suggestions for all customers. We protect your interests with de-identification, minimum group sizes and rounding, and you have the right to object: opting out in Data Preferences stops it immediately.
  • Consent: Analytics and advertising cookies on zen-mode.io are based on your consent, which you can withdraw at any time from the Cookie settings link in the footer (see section 8).

Your Rights

Under UK GDPR and EU GDPR, you have the following rights:

  • Right of access: You can request a copy of the personal data we hold about you.
  • Right to rectification: You can request that we correct any inaccurate or incomplete personal data.
  • Right to erasure: You can request that we delete your personal data. Upon account deletion, we will remove your data from our systems within 30 days, except where we are legally required to retain it.
  • Right to restrict processing: You can request that we limit how we use your data in certain circumstances.
  • Right to data portability: You can request your campaign data in a structured, commonly used, machine-readable format.
  • Right to object: You can object to processing based on legitimate interest at any time, including Sangha Intelligence statistics and message wording, which you can switch off yourself in Data Preferences.
  • Right to withdraw consent: Where processing is based on consent (such as analytics cookies), you can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, contact us at hello@zen-mode.io. We will respond to your request within 30 days.

Data Retention

We keep your account and campaign data for as long as your account is active, and if you delete your account we remove it within 30 days. Several other things are deleted much sooner than that, on their own clocks, and a few have no clock yet. Section 10 lists all of them in one place, says which ones an automatic job enforces, and is the version to rely on.

International Data Transfers

ZenMode uses third-party service providers who may process data outside the United Kingdom and European Economic Area, including:

  • Vercel (United States) — website and application hosting
  • Neon (United States) — database hosting
  • Stripe (United States) — payment processing
  • Clerk (United States) — authentication
  • Anthropic (United States) — AI message generation, and the Peacock chat assistant on our website
  • ElevenLabs (United States) — AI voice note generation
  • Resend (United States) — sending our email, including sign-up, billing, team, affiliate and support messages, and the blueprint PDFs you request
  • Cloudflare (United States) — bot filtering in front of Clerk, our authentication provider
  • Telegram (outside the UK and EEA) — internal alerts to Jonathan. Some of these name you: the sign-up, waitlist, affiliate application, guide request, new campaign and payment alerts all carry your email address, and the sign-up alert also carries the marketing source you arrived from. Routine dashboard activity is not sent this way. It is recorded in our own database, with your email address, which page of the dashboard you are on and the country your IP address resolves to, and only a daily count with no names in it reaches Telegram
  • Sentry (United States) — error monitoring only; Sentry records no sessions at all
  • Google (United States) — advertising measurement, with your consent only
  • PostHog (Germany, EU region) — product analytics, plus session recording and heatmaps on our public marketing pages with every input masked, with your consent only
  • Vercel Web Analytics (United States) — traffic counts, with your consent only

Where data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place, including reliance on the service provider's Standard Contractual Clauses (SCCs), UK International Data Transfer Agreement (IDTA), or adequacy decisions where applicable.

Data Protection Contact

For any questions or concerns about how we handle your data, or to exercise your rights, please contact us at hello@zen-mode.io. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk if you believe your data protection rights have been infringed.

8. Cookies and Similar Technologies

We use a small number of strictly necessary cookies to run zen-mode.io — keeping you signed in, remembering your theme, and recording your cookie choice itself. Under regulation 6 of the Privacy and Electronic Communications Regulations 2003 (PECR) these do not require consent.

Sentry error monitoring also runs on every page, without consent, because it stores nothing at all on your device — no cookie, no local or session storage — so regulation 6 does not reach it. It reports the page address, your browser's user agent and the stack trace when a fault occurs, so that a broken page is noticed. Sentry Session Replay is switched off entirely. It would have recorded a reconstruction of what happened on screen, everywhere, including the dashboard — and those screens show information about other people, the prospects in a customer's account. We removed it rather than ask for permission to record them.

We do record sessions on our public marketing pages, and only there, and only if you accept. PostHog session recording and heatmaps run on pages such as the home page, pricing, the blog, the comparison pages and these policies. They are switched off in code on /dashboard, /admin and the affiliate portal, and on the sign-in and sign-up pages, so a recording of your account — or of anybody's prospects — is not something we are in a position to make. On the pages where recording does run, every field is masked: we record that a field was filled in, never what you typed, and passwords are never recorded. If you withdraw consent, recording stops immediately, not on your next page load.

Everything else is off until you accept it. We ask on your first visit with an Accept and a Reject button of equal prominence, and nothing non-essential is loaded or stored before you choose. The analytics and advertising technologies covered by that choice are:

  • Google Ads (Google LLC) — conversion measurement and remarketing. Loading the Google tag sets _gcl_au (90 days) and _gcl_ls, and contacts google.com and google.co.uk.
  • PostHog (EU region) — product analytics. Sets a ph_…_posthog cookie lasting one year. Also session recording and heatmaps, on public marketing pages only and with every input masked, as described above.
  • Vercel Web Analytics — page-level traffic counts. Sets no cookie, but sends a request per page view.
  • Our own page-view record — stores nothing on your device, but records the page path, referrer, any utm_* parameters, your user agent, screen width, and the country and city your IP resolves to.
  • First-touch source — zm_ft (90 days, or until you sign up) remembers which marketing source first brought you here: the utm_* tags on your landing page, the referring site's name and the landing page. If you sign up it is copied to your account and deleted from your browser.
  • Affiliate attribution — zen_ref and zen_ref_at (90 days) credit a partner who referred you; recording the click also stores your IP address.

We apply Google Consent Mode v2, which is set to denied for advertising storage, advertising user data, advertising personalisation and analytics storage until you accept.

You can change or withdraw your choice at any time from the Cookie settings link in the footer of every page — withdrawing is one click, exactly like giving consent. The full named inventory, with each cookie's purpose, who sets it and how long it lasts, is in our Cookie Policy.

9. The Peacock chat assistant

The Peacock is the chat bubble on zen-mode.io. It does nothing until you open it and send a message, and opening it stores nothing on your device: no cookie, no local storage, no session storage. What it stores is on our servers instead, which is why it is here rather than only in the Cookie Policy.

What we store. Each time you send a message we save the message exactly as you typed it, the reply, and the IP address the message came from. The IP address is there so we can rate limit the chat and look into abuse. We read these conversations to find where the assistant gave a wrong or unhelpful answer and fix its instructions, which is the main reason the text is kept at all. They are readable by Jonathan through an admin page, including by search.

Where it goes. Your message, and the recent messages in the same conversation, are sent to Anthropic (United States) to generate the reply. Your IP address is not part of what we send them.

How long we keep it. Two clocks, because the identifier and the text are not the same question: we remove the IP address after 30 days, and we delete the whole conversation after 12 months. A job runs once a day and does both.

Please do not type anything into the chat that you would not want us to read. If you have already sent something and want it gone, email hello@zen-mode.io and we will delete it.

10. How long we keep things

One place to look. Where an automatic job enforces the period, we say so. Where there is no period yet, we say that too rather than invent one.

  • Account and campaign data: kept while your account is active. If you delete your account we remove it within 30 days.
  • Transaction records: about 6 years, because UK tax and accounting law requires it.
  • Website page-view records: 90 days, deleted by a daily job. Our Cookie Policy used to say these were kept while your account was active. That was wrong, and it was wrong in the direction of claiming we hold more than we do.
  • Peacock chat: the IP address is removed after 30 days, the conversation is deleted after 12 months. Both by a daily job. See section 9.
  • Desktop app diagnostic logs: 14 days, deleted by a daily job.
  • Page-structure snapshots (taken when the desktop app cannot find something it expected on a LinkedIn page): at most 14 days, deleted by a daily job, and only the most recent 1,000 are kept at all.
  • Blueprint requests: if you did not opt in to marketing, or you later unsubscribe, 12 months, deleted by a daily job. If you did opt in, we keep your email address until you unsubscribe. See section 2.
  • Desktop self-check alerts: 30 days. There is no daily job for these: each new one prunes anything older than 30 days as it is written.
  • Sangha Intelligence: opting out in Data Preferences stops your statistics and message wording being used immediately. See section 6, which also explains the 14-day notice period for accounts created before 25 September 2026.
  • Affiliate click records (which include the IP address of the click, your browser's user agent, the referring URL and the page you landed on): 24 months, deleted by a daily job. We keep them that long because an affiliate commission can still be queried a long time after the click that earned it.
  • Contact form messages: 24 months, deleted by a daily job.
  • Guide requests (the email address, your user id if you are signed in, any utm_* parameters and the screenshot you upload): 12 months, deleted by a daily job.
  • Waitlist entries: 12 months, deleted by a daily job.
  • Internal alert records described in section 7: 30 days, deleted by a daily job.

Until 24 September 2026 the five entries above had no period at all and nothing deleted them. They now do, and the daily jobs that enforce them run whether or not anyone is watching. If you would rather not wait for a period to run out, email hello@zen-mode.io and we will delete your record.

Copies can survive these periods for a short while in database backups, and our payment provider keeps its own records of payments independently of ours. Where the law requires us to keep something, that takes precedence, and we will tell you which if you ask.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

12. Contact Us

If you have any questions about this Privacy Policy, please contact us at hello@zen-mode.io.