Privacy and data

Privacy Policy

Last updated: September 2026

Your business information stays yours

Zeni uses the information you provide to deliver and personalize your business support. We do not sell your personal information, provide it to data brokers, or use it for third-party advertising.

Because Zeni works through WhatsApp and uses artificial intelligence, relevant messages, documents, images, and voice notes may be processed by our service providers, including Meta, OpenAI, Supabase, Netlify, Railway, Stripe, and Sentry. Some processing occurs outside Canada, including in the United States.

Not sold Your personal and business information is not sold to advertisers or data brokers.
No third-party advertising Your Zeni conversations are not used to target third-party advertisements.
AI processing is disclosed Relevant content is sent to OpenAI only when needed to provide AI-powered features.
You remain in control You may request access, correction, export, or deletion of your information.

Administrative access is restricted to authorized personnel and the service providers needed to operate Zeni, subject to the limits described below.

Please do not send: passwords, one-time security codes, banking login credentials, full payment-card numbers, private encryption keys, or government-issued identification images. Zeni does not need those items to provide its normal service.

Section 1Who we are and who is accountable

Zeni is operated by Every Ingredient Gourmet Spices LLC, doing business as Aneurin Advisory, under the Zeni brand. Every Ingredient Gourmet Spices LLC is a single Wyoming company that also operates other ventures; Zeni and Aneurin Advisory are one line of business under it, and this policy applies only to that line of business.

Privacy Lead: Aneurin Advisory / Zeni
Email: support@aneurinadvisory.com
Website: ca.aneurinadvisory.com

The Privacy Lead is responsible for Zeni's privacy practices, responding to privacy questions and requests, and reviewing how personal information is handled.

Zeni is currently offered to business operators in Ontario, British Columbia, and Alberta. We aim to comply with applicable Canadian private-sector privacy law, including the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, British Columbia's and Alberta's private-sector privacy legislation.

Section 2Information we collect

We collect information that is reasonably needed to create your account, provide Zeni's features, remember your business context, protect the service, and meet legal obligations.

Account and subscription information

  • Your name and WhatsApp phone number
  • Your email address, when provided
  • Your business name, business type, province, and setup status
  • Your account status, subscription tier, and billing status
  • Preferences you choose for briefings, reminders, and service delivery
  • If you join our waitlist, the email address and province you provide

Business information you provide

  • Income, expense, invoice, transaction, and cash-flow information
  • Client, supplier, contractor, and business-contact details
  • Business registration, tax, entity, and compliance details
  • Banking and payment-platform preferences, but not banking passwords
  • Business goals, plans, strategies, priorities, and decisions
  • Tasks, reminders, deadlines, renewal dates, and open items
  • Shipment, inventory, fulfilment, and marketplace information
  • Documents and content you ask Zeni to review, store, or generate

Conversation and uploaded content

  • The content of messages you send to Zeni through WhatsApp
  • Voice notes and their transcriptions
  • Images, receipts, PDFs, and other documents you submit
  • Button taps, menu selections, and other interactive responses
  • Timestamps, message identifiers, and delivery metadata

Technical and security information

  • API usage records used for rate limiting and service reliability
  • Error logs, diagnostic records, and security events
  • Application error, diagnostic, and performance information, such as technical stack traces, affected pages or routes, browser or operating-system type, release version, event identifiers, and timing or tracing information
  • Basic device, browser, IP-address, and request information collected by hosting providers

Payment information

Stripe processes payments. Zeni does not store full payment-card numbers, CVV codes, or complete card credentials. We receive limited billing information such as payment status, subscription tier, customer identifiers, and billing dates.

Voice and biometric information

A voice note is personal information. Zeni may process a voice note to create a transcription, but we do not use it to identify you through biometric analysis or create a voiceprint.

Section 3How we use information

We use information for the following purposes:

  • Providing Zeni: processing messages, producing responses, storing business context, managing records, generating documents, and delivering reminders, summaries, and briefings
  • Personalizing the service: remembering relevant details so Zeni can give business-specific rather than generic support
  • Managing your account: activating service, managing subscriptions, processing billing events, and communicating about your account
  • Providing requested human-assisted services: completing support or Premium services you specifically ask us to provide
  • Protecting the service: preventing fraud, abuse, unauthorized access, duplicate processing, and technical failures
  • Improving Zeni: reviewing aggregated or de-identified usage patterns, reliability signals, and feature performance
  • Meeting legal obligations: responding to valid legal requests, keeping required business records, and enforcing our agreements

We do not sell personal information. We do not use identifiable customer information for third-party advertising, and we do not provide customer lists to data brokers.

Section 4Consent and essential processing

Some processing is necessary to provide Zeni. For example, Zeni cannot respond to a WhatsApp message without processing that message, and it cannot remember your business context without storing relevant information.

By subscribing to and using Zeni, you consent to processing that is reasonably necessary to provide the service, as described in this policy. Where an optional feature requires a materially different use of information, we will provide additional notice and request consent where required.

You may withdraw consent for optional processing at any time. You may also stop using Zeni and request deletion. Withdrawing consent for processing that is essential to the service may mean we can no longer provide some or all Zeni features.

Zeni also sends you service-related messages through WhatsApp, such as setup steps, reminders, deadline alerts, and briefings. By subscribing, you consent to receive these as part of the Service. They are operational messages, not marketing, and where Canada's Anti-Spam Legislation (CASL) applies to a message, we identify ourselves as the sender and provide a way to withdraw consent.

We may process or disclose information without consent where permitted or required by applicable law, including for fraud prevention, security investigations, legal claims, emergencies, or valid legal process.

Section 5AI and automated processing

Zeni uses OpenAI's API to provide AI-generated responses and may use OpenAI services to transcribe voice notes and analyze images or documents. Relevant content is transmitted to OpenAI when needed to provide those features.

OpenAI states that data submitted through its API is not used to train or improve its models by default unless the API customer explicitly opts in. Depending on the endpoint and account settings, OpenAI may temporarily retain certain API data for abuse monitoring, safety, or service operation.

Zeni does not use your identifiable personal information to build an advertising profile or to make binding legal, tax, employment, lending, insurance, or credit decisions about you.

AI outputs can be incomplete or inaccurate. You remain responsible for reviewing important information and obtaining qualified legal, tax, accounting, banking, or other professional advice where needed.

OpenAI information: OpenAI Privacy Policy and API data controls .

Section 6Human access to information

Authorized personnel may access account information, conversation content, documents, and technical records only when reasonably necessary to:

  • provide customer support you requested;
  • investigate an error, failed action, or security concern;
  • manage your account or subscription;
  • provide a human-assisted service you requested;
  • prevent fraud, abuse, or unauthorized access; or
  • comply with law or protect legal rights.

If Zeni later adds employees, contractors, or professional specialists who require access, their access will be limited to what they need for their role and subject to confidentiality and privacy obligations.

Service providers may process information for their stated technical function, but they are not authorized by Zeni to use it for their own advertising purposes.

Section 7Information about other people

You may provide information about clients, customers, suppliers, contractors, employees, business partners, or other contacts. This may happen when you upload an invoice, receipt, contract, contact record, email, shipment document, or other business material.

You are responsible for ensuring that you have the authority to provide that information to Zeni and that your use of Zeni complies with your own privacy, confidentiality, and legal obligations.

Please provide only the information reasonably needed for the task. Do not use Zeni to store highly sensitive information about another person unless it is necessary, lawful, and appropriate.

Section 8Service providers and disclosures

We use service providers to operate Zeni. They receive information only as needed to provide their services, maintain security, process transactions, or comply with law.

View the main service-provider list
Provider Purpose Processing location
OpenAI AI responses, voice transcription, and image or document analysis Primarily United States and provider-supported regions
Supabase Database, authentication-related infrastructure, and file storage Current Zeni project region is in the United States
Meta / WhatsApp WhatsApp message delivery and related messaging infrastructure Global infrastructure, including the United States
Stripe Checkout, subscription management, billing, and payment processing Global infrastructure, including the United States
Netlify Public Zeni website hosting and delivery Global infrastructure, including the United States
Railway Zeni backend/application runtime, hosting, logs, and performance Global infrastructure, including the United States
Sentry Application error monitoring, performance tracing, release diagnostics, and readable technical stack traces United States — Sentry US region

Sentry privacy controls. Zeni uses Sentry to identify and diagnose application errors and performance problems. The current configuration is designed to minimize the personal information included in Sentry events. Automatic collection of user information, cookies, request and response headers, HTTP request and response bodies, query parameters, generative-AI inputs and outputs, and stack-frame local variables is disabled. Additional filtering removes sensitive authentication and webhook information. Session Replay and Sentry Logs are not enabled.

We may also disclose information to professional advisers or specialists under confidentiality obligations when you request a service that requires their involvement.

We may disclose information where required by law, court order, valid legal process, or to investigate fraud, abuse, security incidents, or threats to rights and safety.

If Zeni or its operating business is involved in a merger, reorganization, financing, sale, or transfer of assets, information may be disclosed as part of that transaction subject to appropriate confidentiality and privacy protections.

Section 9Storage and international processing

Zeni is offered to Canadian customers but uses service providers that may store or process information in the United States and other jurisdictions. Information processed outside Canada may be subject to the laws of the jurisdiction where it is processed, including lawful access requests by courts, law-enforcement agencies, or government authorities.

We remain responsible for personal information under our control and use contractual, technical, and organizational measures appropriate to our size, the service, and the sensitivity of the information.

Once a WhatsApp message reaches Zeni, it may be processed and stored by Zeni and the providers described in this policy. It is then governed by this policy in addition to the applicable terms and privacy practices of WhatsApp and our other providers.

Section 10How we protect information

We use administrative, technical, and organizational safeguards intended to protect information against unauthorized access, use, disclosure, alteration, loss, or destruction. These safeguards include, as appropriate:

  • encrypted network connections;
  • restricted administrative access;
  • protected credentials and service secrets;
  • authenticated and validated service requests;
  • rate limiting, error monitoring, and security logging;
  • service-provider security controls; and
  • access limited to the information needed for a legitimate operational purpose.

No internet-connected service can guarantee absolute security. You are also responsible for protecting your phone, WhatsApp account, email account, passwords, and devices from unauthorized access.

If we discover a breach of security safeguards, we will investigate, document, contain, and assess it. We will notify affected individuals and privacy regulators when required by applicable law.

Section 11Retention and deletion

We retain personal information only for as long as reasonably necessary for the purposes described in this policy, to operate your account, resolve disputes, protect the service, meet legal obligations, and enforce agreements.

  • Active account data: generally retained while your account is active.
  • Conversation and business records: retained while needed to provide Zeni's memory, records, summaries, and operator features.
  • Uploaded files: retained while needed for the requested feature or your ongoing account, unless deleted sooner.
  • Billing and legal records: may be retained longer where required for tax, accounting, fraud-prevention, dispute, or legal purposes.
  • Security and diagnostic records: retained for a limited operational period appropriate to their purpose.
  • Backups: deleted through the normal backup overwrite or expiry cycle.

After a verified deletion request or account closure, we will delete or de-identify information that is no longer reasonably required, subject to legal obligations, security records, unresolved disputes, backup cycles, and provider limitations.

Deleting essential account and business context may make it impossible to continue providing Zeni.

Section 12Your rights and choices

Subject to applicable law and reasonable identity verification, you may request:

Access

A description or copy of the personal information we hold about you, together with information about how it has been used or disclosed.

Correction

Correction of personal information that is inaccurate or incomplete.

Deletion

Deletion of information that is no longer required, subject to legal retention obligations and other permitted exceptions.

Export

An export of available business records in a commonly used format where technically feasible.

Withdrawal of optional consent

Withdrawal of consent for optional uses. Withdrawal does not affect processing that lawfully occurred before withdrawal.

Challenge or complaint

You may ask questions or challenge our privacy practices without retaliation or loss of service, except where the requested change makes it impossible to provide the service.

Send requests to support@aneurinadvisory.com with the subject line Privacy Request. We will generally respond within 30 days, unless applicable law permits an extension. We may ask for information needed to verify your identity before providing access, export, correction, or deletion.

Section 13Website, cookies, and payments

The Zeni marketing website does not use third-party behavioural advertising trackers. Hosting providers may collect basic request information, such as IP address, browser type, referrer, and timestamps, for security, reliability, and performance.

Stripe and other necessary service providers may use cookies or similar technologies when you open or interact with checkout, subscription-management, or payment features. Their handling of that information is also governed by their own privacy policies.

We do not receive or store your complete card number or CVV. Stripe handles that information directly.

Section 14Children's privacy

Zeni is intended for business use by adults aged 18 and older. We do not knowingly offer Zeni to children or knowingly collect personal information from anyone under 18.

Contact us if you believe a child has provided personal information to Zeni so we can investigate and delete it where appropriate.

Section 15Changes to this policy

We may update this Privacy Policy from time to time. The revised version will be posted with an updated “Last updated” date. Where applicable law requires additional notice or consent for a change in how we collect, use, or disclose personal information, we will provide that notice or obtain that consent before the change applies.

Section 16Contact and complaints

Send privacy questions, concerns, or requests to:

Privacy Lead — Aneurin Advisory / Zeni
Operated by Every Ingredient Gourmet Spices LLC
Email: support@aneurinadvisory.com
Website: ca.aneurinadvisory.com

We encourage you to contact us first so we can understand and address the concern.

If the matter remains unresolved, you may contact:

  • Office of the Privacy Commissioner of Canada: priv.gc.ca
  • Office of the Information and Privacy Commissioner for British Columbia: oipc.bc.ca
  • Office of the Information and Privacy Commissioner of Alberta: oipc.ab.ca