Privacy Policy

Effective: October 1, 2026

TxnLab Inc. (“TxnLab,” “we,” “us,” “our”) provides ZeroSignal, a privacy-preserving AI inference service that lets you chat with AI models served by independent third-party operators, with usage settled on the Algorand blockchain (the “Service”). This Privacy Policy (“Policy”) describes how we collect, use, and disclose personal information when you use the Service, visit our website located at https://zerosignal.ai (the “Site”), or communicate with us in connection with the Service. It should be read alongside our Terms of Service. By using the Service and providing us with personal information, you are agreeing to the terms of this Policy.

ZeroSignal is designed to minimize the personal information we collect. Much of this Policy therefore describes information we intentionally do not collect, information that stays on your device, or information handled by independent third parties rather than by us. The sections below identify the limited cases in which we do receive information about you.

Information We Collect

Information we intentionally do not collect. The Service is designed so that we do not collect:

  • Your name, email address, or phone number. Registration is passkey-only and requests none of them.
  • The content of your conversations, including your prompts, your attachments, content from apps you connect to the Service, and the responses you receive.
  • Server-side logs of your activity in the Service.
  • Advertising identifiers or behavioral profiles. We do not assemble data for sale to, or sharing with, data brokers.

We do not use third-party analytics, telemetry, advertising pixels, web beacons, session-recording tools, or social media plugins in the application, and we do not intentionally include third-party tracking code.

Passkey authentication. You register and sign in with a passkey, unlocked by your device’s face, fingerprint, or PIN, rather than with a username and password. Your passkey credential is created and stored by your device or platform authenticator; we do not receive it. We will not ask you to share your private keys or your 24-word recovery phrase.

Information that stays on your device. Your private keys, your recovery phrase, the content of your conversations, and any display name you set are held in your browser’s storage on your device, encrypted with keys derived from your passkey. The Service is designed so that this data is not transmitted to us, and we do not maintain server-side copies of it. The Service may also keep a local diagnostics journal to help debug problems; it is stored encrypted on your device, omits message content by default, and reaches us only if you choose to export it and send it to us. If you turn on sync, the Service also copies your conversations, encrypted with keys derived from your passkey, to a folder or storage bucket you choose; the provider of that storage holds only the encrypted copy, under its own terms.

Connected apps. The Service includes connectors: optional features of the ZeroSignal web app that link it to a third-party app you choose, such as Google Drive. TxnLab writes and publishes the connectors, and they run in your browser, which communicates with the third-party app directly. The access credentials for that app, and the list of what you have made available through it, are stored on your device, encrypted with keys derived from your passkey, and neither they nor the data you access through a connector are transmitted to us. Connectors are available only in the ZeroSignal web app, not through the ZeroSignal proxy or other clients. How the Google Drive connector handles data is described under “Google User Data” below.

Free-trial anti-abuse check. The Service can give a brand-new account a small one-time credit. Because we fund it, we run a check when it is claimed to prevent repeat claims. For that check, our server records one-way hashes of your Algorand account address, your passkey’s credential identifier, and the IP address the request came from, not the values themselves. The hashes exist simply to recognize a repeat claim. We also use Cloudflare Turnstile to confirm a person rather than a script is making the request; Cloudflare receives your IP address for that purpose under its own privacy policy. This data is not linked to your conversations.

Contact information. If you email us at support@txnlab.dev or join our community channels, we receive the information you choose to send, such as your email address and the contents of your message, and we use it to respond to you.

Your information on the blockchain. The Service settles usage on the Algorand blockchain, a distributed ledger that is fully transparent. The payments you make and the settlement records they create, including the account addresses involved and the amounts, are written to a public ledger, are permanently visible to anyone, and can be deleted neither by you nor by us. Your account address is not inherently linked to your real-world identity, but anything recorded on a public blockchain should be treated as public.

Server logs. Unlike most online services, the Service is designed so that our servers do not log your activity or the content of your conversations. The free-trial check described above is the case in which our own server records information about you.

Cookies and local storage. The application sets a single functional cookie of its own, which remembers whether you left the sidebar open or closed. We do not set tracking, advertising, or analytics cookies, and we do not set third-party cookies. The application makes extensive use of your browser’s local storage, because that is where your account and your conversations live; the Service is designed not to transmit that storage to us. Note that clearing the Service’s local data removes your conversations from your device.

How We Use and Process Your Information

The primary purpose for which we process information is to provide you with the Service. Our legal bases for processing your personal information are: 1) our legitimate interest in running and protecting our business, including preventing abuse of the free trial; 2) performance and fulfillment of our contracts; 3) your consent; and 4) compliance with our legal obligations. We use the limited information described above to:

  • Operate the Service, including routing your funding transactions to the correct account;
  • Prevent repeated claims of the free-trial credit;
  • Respond to your inquiries and provide you with support;
  • Comply with legal and/or regulatory requirements; and
  • Manage our business.

With Whom and Why We Share Your Information

Model operators. When you send a message to an AI model, the content of that message is transmitted to the applicable third-party model operator solely to generate your response. Operators are independent of us and handle that content under their own terms. When you select a frontier model that an operator serves by relaying to the lab that publishes it, your message reaches that lab as well, under its terms. If you connect an app such as Google Drive and turn it on in a conversation, the content the model reads from that app becomes part of your request and reaches the operator, and any lab it relays to, in the same way. By default, your request is routed through a second independent operator acting as a relay: the relay can see your IP address, and your request is encrypted for the answering operator and is designed to be unreadable by the relay. The Service is designed so that no single party holds both your identity and the content of your request. If you enable web search or use the document tools, those run on the operator’s side rather than ours, so the resulting queries reach the search or retrieval provider that operator uses.

Service providers. We use third-party service providers that perform services on our behalf, including web hosting, IT infrastructure, and Cloudflare, whose Turnstile service supports the free-trial check described above. Our service providers are not permitted to use information about our users for their own purposes and are contractually obligated to maintain confidentiality.

Payment partners. Buying with a card takes place on our payment partner’s own surface, under that partner’s privacy policy rather than this one. ZeroSignal does not receive or store your card details. To begin a purchase, our server passes your Algorand account address to the partner so the funds reach the right account; we pass it through for that purpose and do not retain it. Our current partners are Coinbase, for card purchases, which include that partner’s own identity verification; Exodus’s XO Swap, for transfers from another blockchain; and the Haystack Router, for exchanging one Algorand asset for another. Each handles what it receives under its own privacy policy.

Services your device connects to directly. The application runs in your browser and communicates with several independent services directly, rather than routing everything through our servers. Each of these services sees your device’s IP address and handles it under its own privacy policy: model operators and relays, to generate your responses; Algorand network infrastructure, which sees your account address alongside your IP address in order to read balances and submit transactions; payment partners, when you add funds; a public model repository, the first time on-device search downloads the small model it runs (like any web request, the download includes your IP address, but no account information is sent); Google, when you connect Google Drive, select files in Google’s file picker, or the Google Drive connector reads a file you selected (Google’s sign-in and file-picker code is loaded from Google into the application when you use these features); and Cloudflare, when the free-trial check runs.

Legal purposes. We also may use or share your information with third parties, including government agencies or other regulatory bodies and law enforcement officials, when we believe, in our sole discretion, that doing so is necessary:

  • To comply with applicable law, including a court order, subpoena, or other legal process, or otherwise cooperate with appropriate law enforcement or regulatory investigations;
  • To investigate, prevent, or take action regarding illegal activities, suspected fraud, violations of our terms and conditions, or situations involving threats to our property or the property or physical safety of any person or third party;
  • To establish, protect, or exercise our legal rights or defend against legal claims; or
  • To facilitate the financing, securitization, insuring, sale, assignment, bankruptcy, or other disposal of all or part of our business or assets.

As this Policy describes, the information we hold is limited, and we are able to produce only what we actually possess.

Google User Data

This section applies if you turn on the Google Drive connector. TxnLab publishes the connector and is the developer of the app you authorize when you sign in with Google, which Google shows as “ZeroSignal.” This section describes how the connector accesses, uses, stores, and shares information received from Google APIs (“Google user data”), and it supplements the rest of this Policy.

Who handles your Google user data. The Google Drive connector runs entirely in the ZeroSignal web app in your browser. When this section says the connector accesses, stores, or sends data, that happens on your device. TxnLab is responsible for how the connector behaves, but Google user data is never transmitted to TxnLab’s servers, and TxnLab personnel cannot access it.

Data the connector accesses. When you turn on the connector, you sign in with Google and grant it Google’s “drive.file” permission. This permission covers only the specific files you select in Google’s file picker, not the rest of your Google Drive. For each selected file, the connector accesses the file’s identifier, name, type, size, and last-modified time and, when the file is read, its contents. The connector also receives a temporary Google access token and an opaque identifier for your Google account, which it uses to tell apart files selected under different Google accounts. It does not request your name, email address, or profile photo.

How it is used. Google user data is used only to provide the Google Drive connector: to show you the files you have selected and, in a conversation where you have turned the connector on, to let the AI model answer using those files. The model does not access Google Drive itself. When the model asks for a file, the connector on your device checks that it is one you selected, fetches it from Google, and includes it in your request to the model. Unless you turn this off, the app asks you to approve each lookup first. We do not use Google user data for advertising, we do not sell it, and we do not use it to build profiles of you.

How it is stored. Your Google access token and the list of files you have selected are stored on your device, encrypted with keys derived from your passkey. File contents are fetched from Google when a file is read and are sent to the model for that request only; they are not saved in your conversation history. The model’s answer, which may quote or summarize a file, is saved with that conversation on your device, encrypted like any other conversation. If you turn on sync, conversations are also copied, encrypted, to the folder or storage bucket you choose.

How it is shared. When the connector reads a file, the parts that are read, with the file’s name and details, are sent as part of your request to the independent model operator answering it and, where that operator relays to the lab that publishes the model, to that lab, as described under “Model operators” above. Google receives the connector’s requests for your files. Google user data is not otherwise transferred, and never to advertising platforms, data brokers, or information resellers.

Artificial intelligence and machine learning. TxnLab does not use Google user data to develop, improve, or train generalized or non-personalized artificial intelligence or machine learning models, and does not transfer it to anyone for that purpose. The model operator that receives file content commits, under the ZeroSignal network’s operator rules, not to log or store the content of requests. Where that operator relays to the lab that publishes the model, the lab’s own terms govern what it retains; each model’s details in the app show what is known about retention for each operator.

Retention and deletion. Your access token and file list stay on your device until you remove them. You can remove a selected file in settings at any time, after which the connector will no longer read it. Disconnecting the connector in settings deletes the stored token and file list from your device and, where the token is still valid, asks Google to revoke access. You can also revoke access at any time at https://myaccount.google.com/connections. Google access tokens expire after about one hour. The connector does not keep file contents after a request. Answers that quote or summarize a file are deleted when you delete the conversation or clear the app’s local data.

Limited Use. ZeroSignal’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Your Choices

Because your conversations and your account live on your device, you control them directly. Deleting a conversation, or clearing the Service’s local data, removes it from everywhere within our control; the Service is designed without server-side copies of your content, so there is no deletion request you need to send us for it. Your 24-word recovery phrase is held by you alone, and we are not able to produce or reset it for you. You can disconnect a connector at any time in the Service’s settings; for Google Drive, see “Google User Data” above.

By design, blockchain records are immutable and cannot be changed or deleted. This may affect your ability to exercise rights such as the right of deletion for information recorded on the Algorand blockchain.

Records from the free-trial check expire on the schedule described above. If you want to learn more about, update, change, or delete other information TxnLab holds about you, such as support correspondence, please contact us by email at support@txnlab.dev. We will respond to your request as soon as reasonably possible and no longer than what is permitted under applicable law.

External Links

The Site may contain links to third-party websites or services. If you use these links, you will leave the Site. We have not reviewed these third-party websites and do not control and are not responsible for any of these sites, their content, or their privacy policies. We do not endorse or make any representations about them, or any information, software, or other products or materials found there, or any results that may be obtained from using them. If you decide to access any third-party website linked from our Site, you do so at your own risk.

Data Security and Retention

We employ physical, technical, and administrative measures designed to safeguard the information the Service handles, including encryption of data stored on your device with keys derived from your passkey and encryption of messages in transit. However, no service is 100% secure, and we cannot ensure or warrant the security of any information you transmit to the Services or to us. You transmit such information at your own risk.

We retain the limited personal information we hold for as long as reasonably necessary to fulfill the purpose for which it was collected, as specifically limited by the retention periods described above, or as required or permitted by law.

International Transfers

The limited information that we process server-side is transferred to and processed in the United States for the purposes described above. The independent operators and relays that carry and answer your requests, and the other third-party services your device connects to, may be located in the United States or in countries other than your country of residence, and the data-protection laws in those countries may be different from, and less stringent than, those in your country of residence. By using the Service or by providing any personal or other information to us, you expressly consent to such transfer and processing.

Children

The Service is directed at individuals over the age of 18, or the age of majority in your jurisdiction, and is not directed at children. We do not knowingly collect personally identifiable information from children; as this Policy describes, we do not knowingly collect personal information from anyone beyond the limited categories above. If you believe a child has used the Service in a way that needs our attention, contact us at the address below.

Updates to this Policy

TxnLab reserves the right to modify this Policy at any time, for any reason. TxnLab will post all such changes on the Site, and material changes will be communicated through the Service where practicable. We encourage you to review this page periodically to review the current Policy in effect. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.

How to Contact Us

Should you have any questions or concerns about this Policy, you can contact us by sending an email to support@txnlab.dev or reach us in our Discord community.