Privacy Policy | Viktor

Privacy Policy

Last Updated: May 21, 2026

This is a previous version, superseded on July 31, 2026. Read the current Privacy Policy.

1. Introduction

Welcome to Zeta AI, Inc. ("Zeta AI," "we," "us," or "our"). We operate the Viktor autonomous coworker service (the "Service"), which integrates with your Slack workspace to help improve business operations using artificial intelligence ("AI").

This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use the Service, and outlines your rights and choices. By using the Service, you agree to the practices described in this Privacy Policy.

We review this Privacy Policy at least annually to ensure it remains accurate, complete, and compliant with applicable laws and our internal data governance standards.

Key definitions

Customer Data means data submitted to or processed by the Service on your behalf, including: connection credentials (e.g., OAuth tokens), basic workspace/user identifiers, workspace settings, files stored in Viktor, conversations and outputs generated in Viktor, scheduled tasks, approval decisions, and service logs.

2. Information We Collect

We collect only the information necessary to provide, maintain, and secure the Service.

A. Slack workspace and user information

When you install or use Viktor, we may store:

B. Connection credentials

We store credentials necessary to maintain integrations, including:

C. Content and records inside Viktor

We store content needed to provide continuity and run the Service, including:

D. Slack message content

When you interact with Viktor in Slack, we access message content from channels where Viktor is invited, direct messages to Viktor, and thread replies. This data is used to process your requests, maintain conversation context, and provide the Service.

E. Service logs and usage data

We collect and store limited operational data, such as:

F. Communications with us

If you contact us (e.g., support tickets or email), we collect the information you provide in those communications.

G. Website/app analytics, advertising, and attribution data

When you visit our website, use product surfaces, or begin checkout flows, we may collect:

Sensitive data

We do not knowingly collect sensitive personal data (such as financial account numbers, health information, or children's data) unless necessary for the Service and provided by you.

3. How We Use Your Information

We use the information described above to:

A. Provide and operate the Service

B. AI processing to generate outputs

C. Maintain security, safety, and integrity

D. Service improvement (aggregated or de-identified)

We may use aggregated or de-identified data (that cannot reasonably identify you) to understand usage patterns and improve reliability and product experience.

E. Communications

F. Analytics, advertising, and attribution

G. Compliance and protection

Comply with legal obligations and enforce our Terms of Use, and protect the rights, safety, and property of our users and Zeta AI.

4. How We Disclose or Share Information

We do not sell your personal data for monetary consideration.

We may share certain identifiers and usage data with analytics, advertising measurement, and attribution partners to operate and improve the Service. Depending on your jurisdiction, this may be considered a "sale," "sharing," or "targeted advertising," and you may have rights to opt out.

We share information only as necessary to provide and support the Service, and subject to appropriate safeguards:

A. Service providers (subprocessors)

We use vendors to host and operate the Service and its infrastructure (for example, hosting, storage, monitoring, communications, support tooling, and billing). These providers may process Customer Data on our behalf solely to provide, secure, and support the Service.

Current subprocessors:

Subprocessor Service / Purpose Data Potentially Processed
Slack Core platform integration (OAuth, messaging, app functionality) Slack messages and metadata in channels/DMs where Viktor is used
AWS (Amazon Web Services) Hosting / storage / infrastructure Service data, logs, stored workspace context (as configured)
Cloudflare CDN, DDoS protection, edge security Network metadata, request logs, caching as applicable
Modal Compute / job execution (as applicable) Task inputs/outputs needed for compute workloads
Vercel Web hosting / frontend infrastructure Request metadata, logs, and content required to serve the app
Stripe Payments and billing Billing contact info, transaction metadata (payment details handled by Stripe)
Google (Gmail/Drive/Calendar/Sheets/Docs) Integrations (if enabled by customer) Data accessed via integration scopes authorized by customer
Microsoft (Outlook/OneDrive) Integrations (if enabled by customer) Data accessed via integration scopes authorized by customer
HubSpot CRM integration (if enabled by customer) CRM records and metadata authorized by customer
Meta Ads Ads integration (if enabled by customer) Ads account and reporting data authorized by customer
Google Ads Ads integration (if enabled by customer) Ads account and reporting data authorized by customer
QuickBooks Finance/accounting integration (if enabled by customer) Accounting records authorized by customer
Shopify E-commerce integration (if enabled by customer) Store, product, order, and customer data accessed via integration scopes authorized by customer
Intercom Customer support tools (if used) Support communications, identifiers, troubleshooting content
Notion Workspace/document integration (if enabled by customer) Notion content authorized by customer
Customer.io Customer messaging/notifications (if used) Contact details and messaging events (as configured)
Moz SEO tooling/integration (if enabled) SEO-related data authorized by customer
Baremetrics Metrics/analytics (business performance) Subscription/usage metrics (typically aggregated)
PostHog Product analytics (if enabled) Usage events and identifiers (as configured)
Axiom Logging/observability Logs and event data (may include identifiers and technical metadata)
Browserbase Browser automation Content accessed during automated browsing tasks (as configured)
BrightData Web data access/proxying (if used) Data involved in web research tasks (as configured)

B. AI technology partners

When you invoke AI features, relevant portions of data (e.g., the prompt/context needed to generate an output) may be sent to third-party AI providers to generate responses. We require these providers to use your data only to provide the requested service to you and not for advertising or training their general models.

AI provider details:

C. Analytics

We may use analytics, advertising measurement, and attribution tools (for example, PostHog, Google services, Meta, TikTok, Reddit, X, LinkedIn, and referral/attribution partners such as Dub and Rewardful, where enabled) to understand usage, attribute signups/subscriptions, and improve the Service. These tools may receive online identifiers, event metadata, and referral/campaign data. We do not use Slack message content for advertising. You can manage cookies through your browser settings and can contact us regarding workspace-level controls where feasible.

D. Slack platform

The Service integrates with Slack via Slack OAuth 2.0 and Slack APIs. Your use of Slack is subject to Slack's terms and privacy policy. We access Slack data only after you grant permission through Slack's OAuth consent screen, and you can revoke access at any time in Slack App Management. We affirm that Slack APIs are not used to develop, improve, or train generalized AI and/or ML models.

E. Legal compliance and protection

We may disclose information if required by law or valid legal process, or when we believe disclosure is necessary to:

F. Business transfers

If Zeta AI is involved in a merger, acquisition, restructuring, financing due diligence, bankruptcy, or sale of assets, information may be disclosed to advisors and successor entities, subject to appropriate confidentiality protections.

G. Third-party links

The Service may link to third-party websites/services. We are not responsible for their privacy practices.

H. Shopify platform

The Service integrates with Shopify via Shopify OAuth 2.0 and Shopify's Admin GraphQL API. Your use of Shopify is subject to Shopify's terms and privacy policy. We access Shopify data only after you grant permission through Shopify's OAuth consent screen, and you can revoke access at any time by uninstalling the Viktor app from your Shopify admin. We affirm that Shopify APIs are not used to develop, improve, or train generalized AI and/or ML models, and we do not sell or share Shopify data for advertising.

5. Data Storage and Security

A. Data center location

United States.

B. Data storage and hosting

Customer Data is stored with reputable cloud service providers in U.S. regions, using encryption at rest and in transit, access controls, and service monitoring appropriate to the nature of the data.

C. Security measures

We maintain industry-standard safeguards, including:

You are responsible for maintaining appropriate security in your Slack workspace (e.g., limiting channel access, managing Slack admin permissions).

6. Data Retention

We retain Customer Data only as long as needed to provide the Service, meet contractual obligations, and comply with law.

A. Active production systems

When an account is closed or we receive a validated deletion request, we delete Customer Data from active production systems typically within ~30 days.

B. Backups

Encrypted backups are used only for business continuity. Remaining copies are removed as encrypted backups age out on their normal rotation (currently ~35 days), after which they are automatically overwritten or purged.

C. Exports

Where legally permitted, customers may request an export prior to deletion.

D. Derived data

Derived or transformed data (such as indexes, embeddings, or other internal representations) will be deleted or disassociated from Customer Data when the underlying Customer Data is deleted, subject to backup retention and legal obligations.

7. Your Rights and Choices

Depending on your location, you may have the following rights:

A. Access and correction

You can request access to personal data we hold about you and request correction of inaccurate or incomplete data.

B. Deletion

You may request deletion of your personal data (including workspace files, conversation threads, and related records). For workspace-level Customer Data, we may require the request to come from an authorized workspace administrator or account owner, or we may direct individual members to their workspace administrator where appropriate.

Upon receiving a verifiable deletion request, we will delete Customer Data from active production systems typically within ~30 days, and backups will age out on their normal rotation (currently ~35 days).

C. Withdrawal of consent / disconnecting Slack

You can revoke Viktor's access to Slack at any time via Slack App Management. After revocation, we stop collecting new Slack data immediately. Revoking access or uninstalling does not by itself delete previously stored data. If your account is deleted or closed, or we receive a verifiable deletion request, we delete previously stored data in accordance with Section 6 (Data Retention). You can also contact us to request deletion.

D. Marketing preferences

If you opt in to marketing communications, you can opt out at any time via unsubscribe links or by contacting us. You will still receive essential service communications.

E. Data portability (where applicable)

Where required by law (e.g., GDPR), you may request a copy of your data in a machine-readable format.

F. Authorized agents (where applicable)

If permitted by law (e.g., certain U.S. states), you may designate an authorized agent to submit requests on your behalf; we will verify identity and authority as required.

G. U.S. state privacy rights (where applicable)

Residents of certain U.S. states may have rights to know, access, delete, correct, and opt out of certain data uses, including "sale," "sharing," or targeted advertising as defined under applicable law. You may exercise these rights by contacting us at support@getviktor.com. We will not discriminate against you for exercising applicable privacy rights.

To help us process your request, please provide sufficient information for verification (and, if applicable, authorized agent authorization). After receiving a verifiable request, we will respond within the timeframe required by applicable law (typically within 45 days, or with a permitted extension where allowed by law and notice is provided).

If we deny your request in whole or in part, you may appeal by contacting support@getviktor.com with "Privacy Appeal" in the subject line within the period required by applicable law. We will review and respond to appeals within the timeframe required by applicable law.

H. Additional EEA/UK rights (where applicable)

If you are located in the EEA or UK, you may also have the right to object to certain processing, request restriction of processing, and lodge a complaint with your local supervisory authority.

To exercise rights, contact us at support@getviktor.com.

8. Children's Privacy

The Service is not intended for children and we do not knowingly collect personal data from anyone under the age of 18 (or the age of majority in their jurisdiction, if higher). If we learn we have collected such data, we will delete it promptly. Contact support@getviktor.com if you believe a child has provided personal data.

9. International Users and GDPR/UK GDPR

Zeta AI, Inc. is based in the United States and may process personal data in the U.S. If you are located in the EEA/UK, we process personal data under one or more legal bases, including:

Where required for cross-border transfers, we use appropriate safeguards (such as Standard Contractual Clauses).

If required by applicable law, we will appoint an EU/UK representative and update this Policy with representative details.

10. Slack Marketplace Compliance

Viktor accesses the following Slack data:

Data Type Purpose
Messages in channels where Viktor is invited Process requests and provide AI assistance
Direct messages to the bot Respond to direct interactions
Thread replies Maintain context for requested actions
User profile information Identify users and personalize responses
Channel information Understand context and permissions
File metadata and files (if you request) Process attachments and uploads/downloads

Our commitments

Revoking access

You can uninstall Viktor or revoke access at any time in Slack App Management. After revocation, we stop collecting new Slack data immediately. Uninstalling or revoking access does not by itself delete previously stored data. If your account is deleted or closed, or we receive a verifiable deletion request, we delete previously stored data in accordance with Section 6 (Data Retention).

11. Shopify Marketplace Compliance

Viktor accesses the following Shopify data on behalf of merchants who have explicitly connected their Shopify store:

Data Type Purpose
Products, variants, inventory, locations Answer merchant questions about catalog and stock; perform updates the merchant requests
Orders, draft orders, fulfillments, returns, refunds Order lookup, status questions, fulfillment and refund operations the merchant requests
Customer records (name, email, phone, addresses, marketing consent, order history) Customer service workflows the merchant requests (e.g., look up an order by email, update a shipping address, check consent status)
Store configuration (discounts, metaobjects, files, translations, markets, locales, themes) Merchandising and store-operations tasks the merchant requests
Aggregate analytics (ShopifyQL) Sales and operations questions from the merchant

Our commitments

Compliance webhooks

Viktor implements the three GDPR-mandated Shopify webhooks (customers/data_request, customers/redact, shop/redact). Each webhook is verified against Shopify's HMAC-SHA256 signature before processing; unsigned or forged webhooks are rejected. Because Viktor does not persist Shopify customer data, its response to customers/data_request is "no stored customer data" and customers/redact is processed as a no-op. On shop/redact (sent 48 hours after uninstall), Viktor invalidates its stored OAuth tokens for that shop.

Revoking access

A merchant may uninstall Viktor or revoke access at any time from their Shopify admin. After revocation, Viktor stops collecting new Shopify data immediately. Uninstalling or revoking access does not by itself delete previously stored data (which for the Shopify integration is only OAuth tokens). If the account is deleted or closed, or a verifiable deletion request is received, previously stored data is deleted in accordance with Section 6 (Data Retention).

12. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by appropriate means (e.g., notifying workspace administrators and/or emailing the address associated with the account). The "Last Updated" date reflects the most recent revision. Your continued use of the Service after changes become effective indicates acceptance of the revised policy.

13. Contact Us

If you have questions or requests regarding this Privacy Policy or our data practices, contact:

Email: support@getviktor.com

Address:

Zeta AI, Inc.

2810 N Church St, PMB 20589

Wilmington, Delaware 19802, USA