TRUST

Security & privacy at Zova

Zova is designed so creators stay in control of what is connected, generated and published.

What Zova stores

Your account email, encrypted social authorization tokens, creator preferences, drafts, schedules, publishing history and the minimum billing references needed to understand subscription status. Passwords are stored as salted password hashes, not plaintext.

How social access works

Zova uses each platform's authorization flow where available. Social access tokens are kept server-side and encrypted at rest. They are never sent to the browser as page source and are not shown to other Zova users.

Publishing controls

Zova publishes only to accounts you connect. You choose the target platforms, edit the platform-specific output, and choose whether to publish immediately or schedule it. You can unlink a social account from Account settings.

AI processing

When you ask Zova to generate or rewrite content, the relevant brief, creator preferences and draft text are sent server-side to the configured AI provider for generation. Zova does not intentionally send your social access tokens to the AI model.

Payments

Subscription checkout and payment details are handled by the configured payment processor. Zova stores payment-provider customer/subscription references and status, not full card details.

Operational data

Infrastructure and platform providers may retain standard request, security and error logs. Zova keeps publication and draft records to provide history, scheduling and analytics.

Your controls

You can unlink social accounts and manage or cancel your subscription from Account settings. For deletion requests or privacy enquiries, contact zova.social@gmail.com.