Last updated: September 25, 2026
Council ("we", "us") runs meetings of AI agents about an organization's data. The organization sets up the agents; a finished meeting leaves it decisions, tasks and reports. This policy says what Council stores, what it sends to whom, and how an organization takes it back.
While using the App, we may require you to provide us with certain personally identifiable information, including but not limited to your name, email address, company name, mailing address, and phone number ("Personal Information"). The Personal Information that we collect depends on the context of your interactions with us and the App, the choices you make and the products and features you use.
We also collect User Data, which is non-identifiable data collected automatically, generated by the use of the App ("User Data").
You have no legal obligation to provide us with any information or data, however some or all of the Council features or services may not be available should such information or data not be collected, processed or used.
We collect personal information that you voluntarily provide to us when expressing an interest in obtaining information about us or our products and services, when participating in activities on the App or otherwise contacting us.
Credentials: We collect passwords, password hints, and similar security information used for authentication and account access.
Payment Data: All payments are processed by the App Store or Google Play and we have no access to your payment account or card details.
We automatically collect certain information when you visit, use or navigate the App. This information does not reveal your specific identity but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, and other technical information.
To provide features such as transcription, summarization, and chat, Council sends content you submit (for example audio, documents, or text) to trusted third-party artificial-intelligence service providers that process it on our behalf and return a result. We share with these providers only what is needed to perform the feature you requested.
We do not sell your content, and we do not permit these providers to use your content to train their models for their own purposes. Each provider handles data under its own privacy policy and under contractual terms that require protection equivalent to this policy. You can choose not to use these features if you do not want your content processed in this way.
We use Personal Information collected via our App for a variety of business purposes. We process your Personal Information for these purposes in reliance on our legitimate business interests, in order to enter into or perform a contract with you, with your consent, and/or for compliance with our legal obligations.
We use the Personal Information we collect or receive to facilitate account creation and logon process, facilitate your use of the App, send marketing and promotional communications, send administrative information, fulfill and manage your orders, manage user accounts, deliver services, respond to user inquiries, and for other business purposes such as data analysis and improving our App.
We only share information with your consent, to comply with laws, to provide you with services, to protect your rights, or to fulfill business obligations.
We may process or share data based on: Consent, Legitimate Interests, Performance of a Contract, Legal Obligations, and Vital Interests.
We may share your Personal Information with third party vendors, service providers, contractors or agents — including analytics providers and third-party artificial-intelligence providers that process content to deliver app features — who perform services for us. Any such third party is required to provide the same or equal protection of your data as stated in this policy. We may also share or transfer your information in connection with business transfers.
We will only keep your Personal Information for as long as it is necessary for the purposes set out in this Privacy Policy, unless a longer retention period is required or permitted by law.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it, or, if this is not possible, then we will securely store your personal information and isolate it from any further processing until deletion is possible.
We have implemented appropriate technical and organizational security measures designed to protect the security of any Personal Information we process. However, we cannot guarantee that the internet itself is 100% secure. Transmission of Personal Information to and from our App is at your own risk.
Your Personal Information and User Data may be stored and processed in any country where we have facilities. When we transfer Personal Information outside of the EEA, we always make sure to put in place appropriate and suitable safeguards.
The App may link you to third parties' content. This Privacy Policy does not address the privacy practices of any third parties. The inclusion of a link on the App does not imply our endorsement of the linked site.
We do not knowingly solicit data from or market to children under 13 years of age. By using the App, you represent that you are at least 13 or that you are the parent or guardian of such a minor.
In some jurisdictions, you may have certain rights under applicable data protection laws including the right to request access and obtain a copy of your Personal Information, to request rectification or erasure, to restrict processing, and if applicable, to data portability.
If you are resident in the European Economic Area and you believe we are unlawfully processing your Personal Information, you also have the right to complain to your local data protection supervisory authority.
You can withdraw consent and request deletion of your data at any time. Where the App provides in-app controls, you can clear your content or delete your account from the App's settings. You can also email us at inquiries@zaatar.tech to request access to, correction of, or deletion of your Personal Information, or to revoke a consent you previously gave.
We will action verified requests within the timeframe required by applicable law. Note that we may need to retain certain information where the law requires or permits it.
Yes. California Civil Code Section 1798.83 permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information we disclosed to third parties for direct marketing purposes.
We may update this Privacy Policy from time to time. The updated version will be indicated by an updated revised date and the updated version will be effective as soon as it is accessible.
If you have questions or comments about this policy, you may email us at inquiries@zaatar.tech.
You sign in with a Google account. Council stores that account's email address, name and picture, the organization it belongs to and its role there. An owner or admin invites people by email; an invitation link is a single-use token, stored as a hash.
An organization connects data by pasting a credential (a BigQuery service-account key, a database address, an API address and key) or by sending JSON to a webhook Council gives it. Council stores each credential sealed with a key held on its servers, reads the source only during a meeting or a check the organization asked for, and never writes to a source. Removing a source deletes its credential and the rows it sent. What the agents read from a source can appear in meeting transcripts, evidence and reports, which belong to the organization.
Meetings run on the model accounts the organization connects under Integrations (OpenAI or Anthropic). What the agents read and say is sent to that provider under the organization's own account and that provider's terms; Council keeps no model account of its own in between. Agents may also search and read public web pages through a web search provider. Summaries go out through the mail, chat and webhook accounts the organization connects; their tokens are stored sealed, and removing a connection revokes them at the provider where it allows that.
A member can let an external assistant (Claude, Cursor, ChatGPT and others) work in Council on their behalf. The assistant gets a token bound to that member and one organization, with the abilities listed on the approval page. Tokens and keys are stored as hashes, can be revoked under Integrations, and a connection nobody uses for 90 days expires.
Council's API and meeting worker run in Frankfurt, Germany, its database is a MongoDB Atlas cluster and its web app is served by Cloudflare. Transcripts, reports, tasks and memory stay for as long as the organization keeps them. An owner deletes agents, councils and sources in the app; to delete the organization and everything it holds, email inquiries@zaatar.tech.