Privacy at a glance
Boards are account-protected and are not shared unless the owner grants access. Zen Whiteboard does not use board content for advertising and does not sell personal information. Optional client-side encryption can prevent stored board content from being readable without the user's separate passphrase. Using Zen Assistant intentionally sends the information needed for the request to the AI provider selected by the user.
1. Scope and service provider
This Privacy Notice applies to the Zen Whiteboard website, web application, account services, collaboration features, and related support interactions (collectively, the “Service”). In this notice, “Zen Whiteboard,” “we,” “us,” and “our” refer to the operator of the Service.
This notice does not govern the independent practices of third-party services that a user chooses to connect or use, including Google, OpenAI, Anthropic, an app store, or a device operating-system provider. Their own terms and privacy notices apply to their processing.
2. Information we process
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, display name, email address, WordPress account identifier, and authentication status. | From you or your selected sign-in provider. |
| Board and productivity content | Cards, notes, projects, routines, tags, images, drawings, calendar entries, reminders, activity history, completion records, and board preferences. | From you and users authorized to edit your board. |
| Collaboration data | Board owner, invited account, view or edit permission, and sharing history. | From board owners and collaborators. |
| Zen Messages | In-app messages, encrypted images and files, delivery and read timestamps, and short-lived typing status shared between accounts connected through board permissions. | From message participants and their use of Zen Messages. |
| AI request data | Prompts, selected board context, uploaded images, provider choice, model selection, and the provider's response. | From you when you invoke Zen Assistant. |
| Security and technical data | IP address, browser and device information, session identifiers, request timestamps, sign-in events, security actions, and error or abuse signals. | Collected automatically when the Service is used. |
| Support communications | Messages, requests, and information supplied when contacting support or exercising a privacy right. | From you. |
Board content may contain personal or sensitive information at the user's discretion. Users should only place information in the Service that they are authorized to process and share.
3. How information is used
We process information as reasonably necessary to:
- create and authenticate accounts and maintain signed-in sessions;
- store, synchronize, display, search, export, restore, and secure board content;
- operate projects, routines, calendars, reminders, notifications, collaboration, and Zen Messages;
- fulfill AI requests initiated by the user and return provider responses;
- prevent fraud, abuse, unauthorized access, and technical disruption;
- diagnose errors, maintain availability, and improve reliability;
- respond to support, privacy, legal, and security requests; and
- comply with applicable law and enforce service terms.
We do not use the contents of private boards to serve targeted advertising.
5. Zen Assistant and third-party AI
Zen Assistant is an optional, user-initiated feature. The user selects an AI provider and supplies a personal provider API key. When a request is submitted, Zen Whiteboard sends the prompt, recent conversation context, relevant board data, and any selected image to the chosen provider through the application service. Do not submit information to an AI provider unless you are authorized to do so.
AI requests are outside the client-side encryption boundary because requested content must be decrypted in the browser before it can be processed. OpenAI or Anthropic may process submitted information under the terms governing the user's API account. Provider behavior, retention, and model training policies are controlled by the selected provider, not Zen Whiteboard.
Saved AI credentials are stored with encrypted account data or on the native device, depending on the client. Credentials are not included in Zen Whiteboard account data exports. Users can remove saved credentials from the Privacy & Security Center.
6. Security and encryption
Zen Whiteboard applies administrative and technical safeguards designed to protect account and board information. Current controls include HTTPS, authenticated sessions, server-enforced owner/view/edit permissions, request validation, restricted private API caching, sign-in throttling, security headers, assistant rate limits, attachment type and size checks, and security-event logging that excludes card and message content and API keys. Zen Messages text and attachments are encrypted at rest and attachment access is limited to the sender and recipient.
Optional client-side encryption
Client-side encryption is not enabled automatically. Enabling it is permanent and cannot be undone. Supported board content and images are encrypted in the browser before upload. The board passphrase and derived key are not sent to WordPress and remain only in the active browser session, so the user must enter the encryption key/passphrase again after reloading, leaving and returning, or opening Zen Whiteboard in another browser. Zen Whiteboard cannot recover a lost passphrase.
Before this feature is enabled, data is protected by authentication, access controls, HTTPS, and server-side protections, but authorized hosting or application administrators may be able to access stored content when necessary to operate, restore, or secure the Service. After client-side encryption is enabled, stored ciphertext is not readable without the passphrase. No web application can promise absolute security: a party capable of changing code delivered to the browser could attempt to capture information after it is unlocked.
Two-factor authentication
Two-factor authentication and content encryption address different risks. Two-factor authentication can reduce account-takeover risk; a separate encryption passphrase protects supported stored content. If a two-factor option is made available through the account's authentication system, users should consider enabling both controls.
No transmission or storage system is guaranteed to be completely secure. Users are responsible for protecting account credentials, encryption passphrases, API keys, devices, and recovery methods, and should report suspected unauthorized access promptly.
7. Retention and deletion
Account and board information is generally retained while the account remains active and as needed to provide the Service. Security records may be retained for a limited operational period to investigate abuse and protect the Service. Records may be retained longer where required for security, dispute resolution, legal compliance, or establishment of legal claims.
Deleting an eligible non-administrator account removes its board storage, routines, project templates, Zen Messages and attachments, sharing records, saved AI settings, and security activity from the live WordPress database. Copies may remain in encrypted or access-controlled infrastructure backups until those backups rotate under the hosting provider's retention process. Deletion does not remove information another user independently exported or lawfully retained.
8. Your rights and choices
Subject to location, applicable law, identity verification, and lawful exceptions, users may have rights to request access, correction, deletion, portability, restriction, objection, or information about processing. Zen Whiteboard provides direct product controls to:
- download account and board information;
- correct board content and account profile information;
- revoke all board-sharing permissions;
- remove saved OpenAI and Anthropic API credentials;
- sign out other active devices or sessions; and
- delete an eligible non-administrator account.
These controls are available from the Privacy & Security Center inside the signed-in application. A request may also be submitted using the contact information below. We may ask for information necessary to verify identity and authority before completing a request. We will not discriminate against a user for exercising an applicable privacy right.
If you believe a request was not handled appropriately, contact us so it can be reviewed. Depending on your jurisdiction, you may also have the right to complain to your local data-protection or consumer-protection authority.
10. International processing
Zen Whiteboard and its service providers may process information in countries other than the country where a user lives. Privacy laws and government-access rules may differ across jurisdictions. Where applicable law requires a transfer mechanism or additional safeguard, the responsible party will use an appropriate mechanism for the relevant transfer.
11. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from a child under 13 without legally sufficient authorization. If you believe a child has provided personal information improperly, contact us so the matter can be investigated and appropriate action taken. Users responsible for organizational or school deployments must obtain any permissions required by applicable law.
12. Changes to this notice
We may update this notice when the Service, vendors, or legal requirements change. The “Last updated” date and version identify the current notice. Material changes will be communicated through the Service or another appropriate channel when required. Previous conduct remains governed by the notice in effect when that conduct occurred, subject to applicable law.
13. Contact and privacy requests
Zen Whiteboard Privacy
Email: jesjaxon@gmail.com
For faster handling, use the email address associated with your Zen Whiteboard account and identify the request as a privacy or security matter. Do not send an encryption passphrase, account password, or API key.