TL;DR Summary
What we collect
Account info, team data, meeting notes, performance data, usage analytics
How we protect it
Encryption, access controls, SOC 2 compliant infrastructure, RLS
Who we share with
Only service providers necessary to operate (never advertisers or data brokers)
Your rights
Access, export, correct, delete your data anytime
Our promise: Your data is private, secure, and never sold. Private notes stay private.
Introduction
Welcome to Zebra. We're committed to protecting your privacy and handling your data with transparency and care. This Privacy Policy explains how we collect, use, store, and protect your information when you use our AI-powered employee performance management platform.
Our Privacy Philosophy
- Transparency First: We clearly explain what data we collect and why
- Minimal Collection: We only collect data necessary to provide our service
- User Control: You own your data and can export or delete it anytime
- Privacy by Design: Security and privacy are built into every feature
- No Data Selling: We never sell your personal or performance data to third parties
Information We Collect
1. Account Information
When you create an account, we collect:
- Full name
- Email address
- Company name (optional)
- Job title
- Password (encrypted and never stored in plain text)
- Profile photo (optional)
- Timezone and language preferences
2. Team & Relationship Data
To provide our service, we collect:
- Team member names and roles
- Manager-employee relationships
- Employment status (active, inactive, on leave)
- Team structure and hierarchy
3. Meeting & Conversation Data
Privacy Distinctions:
- Private Meeting Notes: Notes marked as "private" are visible ONLY to the creator. These are encrypted and never shared with team members, other managers, or administrators.
- Shared Action Items: Action items are visible to all meeting participants to enable collaboration and accountability.
What we collect:
- Meeting schedules and agendas
- Meeting notes
- Action items and commitments
- Meeting sentiment scores
- Conversation summaries generated by our AI
4. Performance Data
When you use our performance features, we collect:
- Performance metrics and ratings
- Goal progress and achievements
- Feedback from peers and managers
- Performance review content
- 360° feedback survey responses (anonymized)
5. Usage & Analytics Data
To improve our service, we collect:
- Pages visited and features used
- Time spent in the application
- Device and browser information
- IP address and location (city/country level)
- Error logs and diagnostic data
How We Use Your Information
1. Core Service Delivery
We use your data to:
- Provide and maintain the Zebra platform
- Generate AI-powered meeting agendas and insights
- Track action items and commitments
- Calculate risk scores and engagement metrics
- Personalize performance reviews
- Send notifications and reminders
2. AI-Powered Features
How Our AI Works:
- Meeting Agendas: AI analyzes previous meeting notes, action items, and team context to suggest discussion topics
- Risk Scoring: AI identifies patterns in meeting sentiment, communication frequency, and engagement to predict turnover risk
- Review Generation: AI creates draft reviews based on documented conversations and achievements
- Sentiment Analysis: AI analyzes conversation tone to track relationship health over time
What We DON'T Do:
- We don't use your data to train public AI models
- We don't share your data with third-party AI providers beyond processing
- We don't use employee data for marketing or advertising
- We don't build profiles for purposes outside our service
Data Storage & Security
How We Protect Data
Encryption
- All data encrypted in transit (TLS 1.3)
- All data encrypted at rest (AES-256)
- Private notes use additional end-to-end encryption
- Passwords hashed using bcrypt
Access Controls
- Role-based access control (RBAC)
- Row-level security (RLS) at database level
- Multi-factor authentication (MFA) available
- Regular access audits
Infrastructure Security
- SOC 2 Type II compliant infrastructure providers
- Regular security audits and penetration testing
- Intrusion detection and monitoring
- Automated threat detection
- Daily encrypted backups
Your Privacy Rights
Rights for All Users
- Access: Request a copy of your personal data
- Correction: Update inaccurate or incomplete data
- Deletion: Request deletion of your data ("right to be forgotten")
- Export: Download your data in portable format (JSON/CSV)
- Opt-Out: Unsubscribe from marketing emails
- Object: Object to certain data processing
How to Exercise Your Rights
Self-Service:
- Update profile in Account Settings
- Export data from Settings → Data Export
- Delete account from Settings → Account → Delete Account
Contact Us:
- Email: privacy@zebra.com
- Subject: "Privacy Rights Request - [Your Request]"
- We'll respond within 30 days (GDPR) or 45 days (CCPA)
Contact Us
This Privacy Policy is effective as of November 16, 2025. Thank you for trusting Zebra with your team's data. We take that responsibility seriously.