Effective date: August 31, 2026
This Privacy Policy explains how Zoltra LLC (“Zoltra,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you visit https://zoltra.io or use the Zoltra service and dashboard (the “Service”).
1. The short version
Zoltra collects the information needed to authenticate you, run authorized security checks, show findings, operate your organization, process payments, send product messages, provide support, and keep the Service safe. We do not sell personal information. We share information with service providers that help us operate the Service, with integrations you choose, when you ask us to, or when law requires it.
2. Information we collect
Account and organization information
When you sign in or create an organization, we may receive your name, email address, WorkOS user and organization identifiers, organization name, member roles, authentication events, and account preferences.
Billing information
Stripe processes payments. We may receive Stripe customer, subscription, invoice, payment status, trial, cancellation, and limited payment-method information such as card brand and last four digits. We do not intentionally collect or store your full payment-card number.
Domains, targets, and security data
When you configure the Service, we may collect domain names, DNS challenge data, IP addresses, ports, URLs, scope rules, scan settings, credentials or tokens you intentionally connect, scan jobs, observations, evidence, findings, remediation guidance, retest history, timestamps, and related logs. Scan evidence can contain information that exists on or is returned by your systems. Do not include data you are not authorized to provide.
Connected repository data
If you connect a repository provider such as GitHub, we process the repository source you authorize us to read, file paths, branch names, commit metadata, proposed diffs, pull-request metadata, and review state needed to investigate code and prepare a fix pull request you request.
Messages and integrations
If you connect email, Slack, Discord, or another channel, we collect the channel identity, destination, installation or route metadata, delivery status, provider message identifiers, and messages or events needed to deliver the feature. If you use a Zoltra messaging or runtime feature, we process the requests, responses, and operational metadata needed to provide it.
Device and usage information
We may collect IP address, browser and device information, approximate location derived from IP, pages and features used, timestamps, referrer, diagnostic data, security events, and cookies or similar technologies.
Support and communications
If you contact support@zoltra.io or another Zoltra mailbox, we collect the message, contact details, attachments, and information needed to respond and keep an incident or support record.
3. How we collect information
We collect information directly from you, from your organization administrators, from WorkOS and Stripe, from connected providers you authorize, from your systems during authorized scans, and automatically from your browser or device when you use the Service.
4. How we use information
We use information to:
- authenticate users and administer organizations;
- provide domains, scans, findings, retests, guidance, dashboards, fix pull requests, messaging, and notifications;
- process subscriptions, trials, invoices, cancellations, and payment issues;
- send transactional and security-related emails;
- protect the Service, detect abuse, debug failures, and enforce access boundaries;
- provide support and respond to requests;
- measure reliability and improve the Service;
- comply with law, enforce our agreements, and protect rights, safety, and property; and
- carry out another purpose we explain at collection or that you authorize.
We do not use security findings or customer content to sell advertising. If a feature uses a model or other processing provider, we send only the information needed for that feature under the applicable provider and configuration.
5. Legal bases and roles
Where privacy law requires a legal basis, we may process information because it is necessary to perform a contract, to comply with law, to pursue legitimate interests such as security and service improvement, or because you gave consent. You may withdraw consent where consent is the basis, but withdrawal does not undo processing that already occurred or processing that has another lawful basis.
For account and service information, Zoltra is generally the business or controller. For Customer Content that an organization asks Zoltra to process on its behalf, the organization may be the controller and Zoltra may act as a service provider or processor. The exact role depends on the data and the service relationship. A data processing addendum may be needed for certain customers and regions; this Policy does not replace one.
6. When we share information
We may share information with:
- service providers that host, authenticate, bill, email, scan, provision runtimes, monitor, secure, or support the Service, such as WorkOS, Stripe, Railway, E2B, Resend, Zoho Mail, GitHub, and other providers used for a feature;
- integrations you choose, such as Slack or Discord, so the requested notification or message can be delivered;
- your organization administrators and members according to the permissions and controls in your organization;
- professional advisers, insurers, auditors, or financing partners who need it for their work and must protect it;
- law enforcement, regulators, courts, or other parties when required by law or needed to protect rights, safety, or the Service; and
- a successor entity if Zoltra is involved in a merger, acquisition, financing, reorganization, or sale of assets.
We do not sell personal information or share it for cross-context behavioral advertising. We do not disclose Customer Content to other customers.
7. Third-party services
Third-party services have their own privacy notices and may process information under their own terms. For example, WorkOS handles authentication, Stripe handles payments, Railway and E2B support hosting or runtime execution, Resend and Zoho support email, and connected channels deliver messages at your direction. GitHub is an optional connected provider: when you authorize a repository, it is used to read that repository and to create customer-requested branches, commits, and pull requests. We do not control the independent privacy practices of those providers.
8. Cookies and similar technologies
We use cookies and similar technologies needed for authentication, sessions, security, preferences, and basic operation. We may use limited analytics or measurement tools if we enable them. If we use optional advertising or analytics cookies that require consent, we will provide the applicable notice and controls. Your browser can block or delete cookies, but doing so may break sign-in or other Service features.
9. Retention and deletion
We keep information for as long as needed to provide the Service, maintain security and audit records, comply with law, resolve disputes, enforce agreements, and handle legitimate business needs. Retention periods depend on the type of information and the customer’s configuration.
When an organization or user requests deletion, we will process the request under the account, contract, and applicable legal requirements. Some information may remain in backups, security logs, financial records, or records we must keep; we will isolate or delete it when the applicable retention period ends. Final retention windows must be confirmed before publication.
10. Security
We use administrative, technical, and organizational safeguards appropriate to the information and the Service, including access controls, encryption or protected credential boundaries where supported, tenant isolation, logging, and provider controls. No method of storage or transmission is completely secure. If we confirm a breach that requires notice, we will follow applicable law and notify affected people or customers as required.
11. International processing
Zoltra and its providers may process information in countries other than where you live. Those countries may have different privacy laws. Where required, we use appropriate transfer safeguards and contractual protections. The final provider locations and transfer mechanism should be confirmed before publication.
12. Your privacy choices and rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, object to, or limit certain processing of your personal information, and to withdraw consent. You may also have the right to opt out of sale or sharing for cross-context behavioral advertising. Zoltra does not sell personal information or use it for that advertising, but you may still contact us to exercise applicable rights.
To make a request, email privacy@zoltra.io and include enough information for us to verify and handle the request. You may also use available account controls. We will not discriminate against you for exercising a privacy right. We may need to verify your identity and may use an authorized agent process where required by law.
If we process your information on behalf of an organization, send the request to that organization first; we will help the organization respond as required by our agreement and applicable law.
Residents of the European Economic Area, United Kingdom, and Switzerland may complain to their local data protection authority. California residents may have rights under the California Consumer Privacy Act, as amended. We do not knowingly sell or share personal information for cross-context behavioral advertising.
13. Children
The Service is not directed to children under 18, and we do not knowingly collect personal information from children under 18. If you believe a child provided information, contact privacy@zoltra.io.
14. Do-not-track and global privacy signals
Browser “Do Not Track” settings may not have a common technical meaning. If we enable a feature that must honor a recognized opt-out preference signal, we will process it as required by applicable law.
15. Changes to this Policy
We may update this Policy as the Service, providers, or law changes. We will post the updated version and change the effective date. If a change materially affects your rights, we will provide additional notice where required.
16. Contact
Privacy requests: privacy@zoltra.io.
General support: support@zoltra.io.
Privacy contact: Zoltra LLC, 30 N Gould St Ste 51063, Sheridan, WY 82801.