ZenBriefr logo ZenBriefr
Pricing Zendesk Start Free Trial
โ† Back to Home

Privacy Policy

Effective Date: January 2025 ยท Last updated: August 2026 (added Stored Summaries disclosure; added Render and Sentry to third-party services)

Overview

ZenBriefr LLC is committed to protecting your privacy. This policy explains how we handle data when you use our Zendesk app for file viewing, OCR text extraction, reply enhancement, and link detection.

Privacy by Design: ZenBriefr processes ticket content in real time and does not store raw ticket conversations or attachments. AI processing runs under OpenAI's zero-retention API terms, and contact and financial identifiers are replaced with placeholders before ticket content is sent for processing. We retain the account metadata needed to run the app, the generated summaries described under "Stored Summaries" below, and the knowledge data described under "Knowledge Features" (your published help articles and short, redacted resolution snippets). All of it is deleted when your account is deleted.

Data Collection & Processing

What We Process

  • File Content: PDFs, images, and documents for instant viewing and OCR text extraction
  • Reply Text: Ticket replies for AI draft generation and translation
  • Ticket Content: Text content for automatic link detection and extraction
  • Account Information: Zendesk subdomain, admin email, user ID for authentication

What We DON'T Store

  • No File Storage: Attachments are viewed in real-time, never stored on our servers
  • No Raw Ticket Storage: Full ticket conversations are processed temporarily and discarded after the request (generated summaries are stored for up to 90 days, and Knowledge Features store short redacted resolution snippets; both are described below)
  • No Requester Profiles: Contact and financial identifiers are replaced with placeholders before content is sent for AI processing, and resolution snippets are stored redacted; full requester profiles are never stored
  • No Reply History: Enhanced replies are not stored after processing
  • No Link Data: Extracted links are not retained after display

How We Protect Your Data

Selective PII Redaction (Summaries)

  • Contact & Financial Identifiers: When generating ticket summaries, email addresses, phone numbers, Social Security numbers, and payment card numbers are detected and replaced with placeholder tokens before the content is sent to our AI provider.
  • Local Restoration: Any placeholder tokens returned by the AI are restored to their original values in your result. The mapping is held in memory only for the duration of the request and then discarded.
  • Scope: This redaction is applied to the summarization feature. Other features (such as reply drafting and translation) require the original wording to function and rely on the AI-provider safeguards described below.

AI Provider Safeguards

  • Zero-Retention API: We use OpenAI's API (not consumer ChatGPT). Content sent for processing is not used to train models and is deleted within 30 days under OpenAI's data-handling terms.
  • Encryption in Transit: All data transmission uses TLS.
  • Data Minimization: Only the content needed to perform the requested feature is sent.

Data Handling

What We Store

  • No File Storage: Attachments are viewed in real time and are never stored on our servers.
  • No Raw Ticket Storage: Raw ticket content is processed in memory and discarded after the request completes.
  • Generated Summaries: The summaries ZenBriefr produces are stored for up to 90 days so a ticket you reopen shows its summary instantly instead of being generated again. Raw ticket content is not stored. See "Stored Summaries" below.
  • Account Metadata: Zendesk subdomain, admin email, and user ID for authentication, plus OAuth tokens stored encrypted at rest.
  • Knowledge Data: Help Center article content and short redacted resolution snippets, as described under "Knowledge Features" below.

Stored Summaries

When ZenBriefr summarizes a ticket, it keeps the result so that reopening the same ticket does not require a second AI call. Here is exactly what that record contains:

  • The Generated Summary: The summary text and its expanded detail, along with the ticket ID, the summary type used, the model and prompt version, and processing statistics such as timing and token counts. The raw ticket conversation is not stored.
  • Identifiers in Summaries: Contact and financial identifiers are replaced with placeholders before ticket content is sent to the AI provider, and those placeholders are restored before the summary is shown to your agents. Because the stored summary is the restored version, it can contain names, order references, or similar details that appeared in the ticket.
  • Retention: Stored summaries are deleted automatically once they are 90 days old, by a job that runs daily.
  • Why We Keep Them: To serve a summary instantly on reopen, to avoid charging repeat AI processing for the same ticket, and to review summary quality across prompt versions.
  • Deletion: All stored summaries for your account are deleted when your account is deleted, and can be removed sooner on request at support@zenbriefr.com.

Knowledge Features (Past Solutions & Brand Knowledge)

Two features keep a per-account knowledge index so agents can find answers faster. Here is exactly what that index contains:

  • Your Published Help Center Articles: To suggest relevant articles and ground reply drafts in your own documentation, ZenBriefr indexes the text of your published Help Center articles (content you have already made public) together with mathematical representations (embeddings) used for matching. Unpublished drafts are excluded.
  • Redacted Resolution Snippets: To surface how your team resolved similar past tickets, ZenBriefr stores short snippets of solved tickets (the subject and the final agent reply, capped in length). Contact and financial identifiers are redacted before these snippets are stored.
  • Matching Diagnostics: Short, redacted previews of what was searched and which articles matched are retained for up to 90 days to tune matching quality, then deleted automatically.
  • Zero-Retention Embeddings: Embeddings are computed via OpenAI's API under the same zero-retention terms as all other AI processing.
  • Deletion: All knowledge data for your account (articles, snippets, embeddings, and diagnostics) is deleted when your account is deleted, and can be removed sooner on request at support@zenbriefr.com.

Third-Party Services

  • OpenAI: Processes ticket content to generate summaries, drafts, and translations under zero-retention API terms (not used for training; deleted within 30 days). Contact and financial identifiers are redacted from summarization content beforehand.
  • Supabase: Stores account authentication data (subdomain, admin email, encrypted tokens, plan/usage metadata), the generated summaries described above, and the knowledge data described above (indexed article content, redacted resolution snippets, and matching diagnostics).
  • Render: Hosts the ZenBriefr backend service that processes requests from the app.
  • Sentry: Receives error diagnostics (exception type, stack trace, and the code path that failed) when a request fails, so faults can be detected and fixed. Request bodies, query strings, headers, cookies, and user identifiers are stripped before transmission, so ticket content is not sent.
  • Service Provider Compliance: Our third-party providers maintain industry-standard security practices.

Data Security

Security Measures

  • Encryption in Transit: All data transmission uses TLS 1.3
  • OAuth Authentication: Secure token-based Zendesk integration
  • Redaction Before Processing: Contact and financial identifiers are replaced with placeholders before ticket content is sent to the AI provider. Placeholders are restored in the result your agents see, so stored summaries can contain identifiers that appeared in the ticket; resolution snippets are stored redacted
  • Access Controls: Minimal access principles and role-based permissions
  • Security Monitoring: Continuous monitoring for unusual access patterns

Compliance

  • GDPR Aligned: Data minimization, zero-retention AI processing, and selective redaction support compliance with data protection regulations
  • CCPA Compliant: California privacy law requirements met through privacy-by-design approach
  • SOC 2 Principles: Security, availability, and confidentiality controls implemented
  • Enterprise Standards: Bank-level security practices and data handling procedures

Legal Basis for Processing (GDPR Article 6)

Our legal basis for processing personal data under GDPR is:

  • Legitimate Interests (6(1)(f)): Processing ticket content (with contact and financial identifiers redacted for summaries) to provide AI services that improve support team efficiency
  • Consent (6(1)(a)): When you install and use ZenBriefr, you consent to data processing as described
  • Contract Performance (6(1)(b)): Processing necessary to provide the services you've subscribed to

You can withdraw consent or object to processing at any time by uninstalling the app.

Your Rights

Data Subject Rights (GDPR Articles 15-22)

  • Right to Access (Article 15): Contact us for account information access
  • Right to Rectification (Article 16): Update account info through Zendesk admin
  • Right to Erasure (Article 17): Uninstall app to remove all account data
  • Right to Object (Article 21): Object to processing by uninstalling the app
  • Right to Data Portability (Article 20): Beyond account metadata, stored summaries, and the knowledge index described above (all of it derived from content that originates in your own Zendesk), no customer data is stored; contact us for a copy or deletion of your summaries or knowledge data
  • Right to Restrict Processing (Article 18): Temporarily disable app features

How to Exercise Rights: Email support@zenbriefr.com or uninstall the app through Zendesk admin.

Account Management

  • Uninstallation: Removes all stored account tokens and metadata
  • Trial Expiration: Account data automatically deleted after 30 days of inactivity
  • Data Retention: Account metadata retained only while app is installed; generated summaries and matching diagnostics deleted automatically after 90 days

Data Breach Notification (GDPR Articles 33-34)

In the unlikely event of a data breach affecting personal data:

  • Authority Notification: We will notify relevant supervisory authorities within 72 hours
  • User Notification: Affected users will be notified without undue delay if high risk to rights and freedoms
  • Mitigation: Immediate steps will be taken to contain and remedy the breach
  • Limited Impact: Our data-minimization and zero-retention approach minimizes potential breach impact

International Data Transfers

When we process data using third-party AI services:

  • Provider Safeguards: Content is processed by OpenAI under zero-retention API terms; contact and financial identifiers are redacted from summarization content beforehand
  • Adequate Safeguards: International transfers rely on the providers' contractual data-protection terms and applicable safeguards
  • Data Minimization: Only the data necessary for the requested feature is transferred

Updates to This Policy

We may update this privacy policy to reflect changes in our practices or legal requirements. Users will be notified of material changes through their Zendesk admin interface or email at least 30 days before implementation.

Governing Law

This privacy policy is governed by and complies with GDPR, CCPA, and other applicable privacy regulations. For EU users, this policy is subject to EU data protection law.

Contact Information

For privacy-related questions or to exercise your data protection rights:

support@zenbriefr.com
×

Connect to Zendesk

Enter your Zendesk subdomain to install ZenBriefr

.zendesk.com