Legal
Privacy Policy
Last updated: 18 March 2026 · Zenedge Consulting, Netherlands
This policy applies to pip0 (pip0.ai and next.pip0.ai), operated by Zenedge Consulting, registered in the Netherlands. We are subject to the EU General Data Protection Regulation (GDPR).
1. Who we are
pip0 is operated by Zenedge Consulting ("we", "us", "our"), a company registered in the Netherlands. We are the data controller for personal data collected through pip0.ai and next.pip0.ai.
Contact: [email protected]
2. Data we collect
Account data
- Email address — required to create an account and log in
- Name — provided during signup, used to personalise your experience
Usage data
- Workflow runs, flow configurations, and automation activity within your account
- Template interactions (views, installs, activations) — used to improve our template library
- Feature usage patterns — used to improve the platform
Payment data
- Payment information is processed by our payment provider. We do not store raw card details.
- We retain transaction records (amount, date, plan) for accounting purposes.
Technical data
- IP address, browser type, and device information collected automatically when you use the service
- Session cookies required for authentication (see our Cookie Policy)
3. How we use your data
- To provide and operate the pip0 service
- To authenticate your account and maintain your session
- To process payments and manage your subscription
- To improve the platform based on usage patterns
- To send transactional emails (password resets, account notifications)
- To comply with legal obligations
- To run the automations you build. If you connect a third-party account such as Google, data from that account passes through pip0 solely to execute the flows you have configured — see Section 10.
4. Legal basis (GDPR)
- Contract performance — processing your account data to provide the service you signed up for
- Legitimate interests — usage analytics to improve the platform
- Legal obligation — retaining transaction records for accounting
- Consent — where we ask for your permission (e.g. marketing emails)
5. Data storage and transfers
Your data is stored on servers located in the EU (Frankfurt, Germany via Supabase). We do not transfer personal data outside the EEA without appropriate safeguards.
6. Data retention
- Account data is retained while your account is active
- After account deletion, personal data is deleted within 30 days
- Transaction records are retained for 7 years for legal/accounting purposes
7. Your rights (GDPR)
As an EU resident, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data ("right to be forgotten")
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interests
- Restriction — request we limit how we process your data
To exercise any of these rights, email [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
8. Self-hosted installations
If you self-host pip0 on your own infrastructure, Zenedge Consulting does not have access to your users' data. You become the data controller for your installation and are responsible for your own GDPR compliance.
9. Third-party services
- Supabase — database hosting (EU, Frankfurt)
- Payment processor — payment processing (data subject to their privacy policy)
- Resend — transactional email delivery
- Google — where you choose to connect a Google account, so your flows can act on it. See Section 10.
10. Google user data
pip0 lets you connect your own Google account so your automations can act on it. Connecting is always your choice, it is never required to use pip0, and you grant access through Google's own consent screen. This section describes exactly what we access, why, and what we will never do with it.
What we access, and why
- Gmail — read messages and attachments (
gmail.readonly): so a flow can trigger on an incoming email and use its contents in later steps. - Gmail — create and manage drafts (
gmail.compose): so a flow can prepare a reply or a new message for you. - Gmail — send mail (
gmail.send): so a flow can send a message on your behalf when you have configured it to. - Drive — read and write files and folders (
drive): so a flow can trigger when a file appears, read a file into a step, and create or update files you have asked it to produce. - Drive — list your files so you can choose one (
drive.readonly): so a step can show you your own spreadsheets or forms to pick from when you are setting a flow up. This is what populates those choosers; it is not used to read file contents. - Sheets — read and write spreadsheet content (
spreadsheets): so a flow can read rows as input and append or update rows as output. - Forms — read form responses (
forms.responses.readonly): so a flow can trigger when someone submits one of your forms. It does not give us access to the questions on your forms, or to change them. - Calendar — create and manage events (
calendar.events): so a flow can add, update or remove events on a calendar you have chosen — for example booking a meeting when somebody submits a form. - Calendar — see your calendars and availability (
calendar.readonly): so a step can list the calendars you have access to when you choose which one to write to, offer the event colours that calendar supports, and look up free and busy times. - Your email address (
email): to identify which Google account is connected and show it in your integrations list.
How it is stored and processed
- Authorisation tokens are held encrypted by pip0 and are used only to make the API calls your flows require. You can revoke them at any time (see below).
- We do not keep a standing copy of your mailbox or Drive. Content is fetched when a flow runs and is retained only as part of that run's execution record, subject to the retention periods in Section 6.
- If you self-host pip0, your Google data is processed on your own infrastructure and Zenedge Consulting has no access to it. See Section 8.
What we will never do
- We do not sell Google user data, and we do not use it for advertising.
- We do not retain or use Google user data to develop, improve, or train generalised or non-personalised artificial intelligence or machine learning models, including foundational models.
- We do not allow humans to read your Google user data, except where you have given us affirmative permission for specific items (for example, when you ask us to debug a failing flow), where it is necessary for security purposes such as investigating abuse, where it is required by law, or where the data is aggregated and anonymised for internal operations.
- We do not transfer Google user data to anyone else, except as needed to provide the features you have configured and with your consent, for security purposes, to comply with law, or in connection with a merger, acquisition, or sale of assets.
Limited Use commitment
Revoking access
You can disconnect your Google account at any time from your pip0 connections page, or directly from Google at myaccount.google.com/permissions. Revoking access stops all future API calls immediately. Any Google data already stored in past flow-run records is deleted in line with Section 6, or sooner on request under Section 7.
11. Changes to this policy
We may update this policy from time to time. Material changes will be notified via email. Continued use of the service after changes constitutes acceptance.
12. Contact
Questions about this policy: [email protected]