Privacy Policy
Effective Date: January 01, 2025
I. INTRODUCTION & OVERVIEW
CPMX Tech LLC (“we,” “our,” “us”) operates Zayah AI, a digital mental wellness and conversational AI platform available through our mobile application and website www.zayah.ai. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our products and services.
By accessing, downloading, installing, or using our Products, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. Given the sensitive nature of emotional wellness data and the artificial intelligence (AI) component of Zayah AI, we want to ensure you are fully informed about our data practices.
Who We Are (Data Controller): CPMX Tech LLC. is a company incorporated under the laws of the United States. We are responsible for deciding how your personal information is processed.
If you are located in the EU, UK, Brazil, or other regions with data protection laws, you may have additional rights described in Section 9 below.
II. INFORMATION WE COLLECT
We use your information to:
-
Provide and improve our Services – including personalization, conversation continuity, and emotional insights.
-
Authenticate users and manage accounts.
-
Process payments and subscriptions.
-
Analyze product performance and improve features.
-
Ensure safety, prevent fraud, and comply with legal obligations.
-
Communicate with you – service notices, updates, or optional marketing (with opt-out).
-
Conduct research and aggregate analytics in anonymized form to enhance mental wellness outcomes.
We do not sell your personal information to third parties.
III. HOW WE USE YOUR INFORMATION
Where required by law, our processing is based on one or more of the following legal grounds:
-
Your consent (e.g., optional wellbeing questionnaires or marketing emails).
-
Performance of a contract (e.g., providing the Zayah AI service).
-
Legitimate interests (e.g., product improvement and fraud prevention).
-
Legal obligations (e.g., record-keeping, tax compliance).
You may withdraw consent at any time by contacting us at privacy@zayah.ai.
IV. LEGAL BASIS FOR PROCESSING (GDPR/LGPD)
You agree that all Personal Information collected via or by CPMX Tech LLC. may be transferred, processed, and stored anywhere in the world, including but not limited to, Singapore, the United States, and the European Union. This transfer may occur on our servers, on the servers of our affiliates, or the servers of our service providers.
Your Personal Information may be accessible to law enforcement or other authorities pursuant to a lawful request in the jurisdictions where the data is processed or stored. By providing information to CPMX Tech LLC, you explicitly consent to the storage and processing of your Personal Information in these locations and acknowledge the potential for access by local authorities as described.
When transferring data outside of your country of residence, we implement appropriate safeguards to ensure that your personal data receives a level of protection consistent with applicable laws. These safeguards may include reliance on adequacy decisions, standard contractual clauses, or other legally recognized transfer mechanisms.
V. DATA RETENTION
We retain your personal data for as long as necessary to fulfill the purposes for which it was collected, as outlined in this Privacy Policy, and to comply with our legal obligations.
-
Account Data: Your account data will be retained until you choose to delete your account. If you delete your account, all associated data is permanently removed from our servers, except for aggregated and anonymized data used for AI improvement.
-
Conversational Data (User Content): Your conversational data is retained until you choose to delete it. We do not automatically erase this data unless you take action (e.g., clearing chat history or deleting your account).
-
Transactional Data: Data relating to your purchases and financial transactions is kept for the entire period of the contractual relationship and then in accordance with legal obligations and applicable statute of limitation periods. Please note that this data does not include Payment Card information, which is not stored by CPMX Tech LLC.
-
Marketing Communication Data: Data collected based on your consent to receive marketing communications will be used until you withdraw consent or applicable law requires that such data is no longer used.
-
Requests/Queries Data: Data collected in the context of requests or queries is kept for the period necessary to process and reply to such requests or queries.
-
Cookies and Tracking Data: When cookies or other trackers are placed on your terminal, they are kept for a period of up to 12 months, or as otherwise specified in our Cookie Policy.
-
Other Data: Other data will be kept as long as necessary for the purposes pursued and in compliance with our legal obligations, including the applicable statute of limitations.
VI. DATA SECURITY
We prioritize the security of your information and follow generally accepted industry standards to protect the personal data submitted to us, both during transmission and after we receive it.
-
Encryption: All user conversations are encrypted, including End-to-End Encryption where technically feasible, for maximum privacy. Payment transactions are encrypted using SSL technology.
-
De-identification and Anonymization: We implement de-identification and anonymization techniques to ensure that your data, especially conversational data, remains anonymous where used for AI model enhancement, ensuring it cannot be reconstructed to identify you as an individual.
-
Secure Storage: Conversational data is stored using unique User IDs (randomly generated identifiers) instead of personal details. All data is stored on our secure servers located in Singapore.
-
Limited Access: We employ strict access controls, ensuring that only authorized employees and third-party vendors with a legitimate business need have access to user data. Any analysis of sensitive data is primarily conducted on aggregated and anonymized data.
-
Transcription on User Device: For voice interactions, transcription typically occurs on your device, meaning the raw audio is generally never stored on our servers.
Acknowledgement of Inherent Risks: While we implement commercially reasonable security measures to protect your data, you acknowledge that no data transmission over the Internet or any wireless network can be guaranteed to be 100% secure. Therefore, we cannot guarantee the absolute security of any information you transmit to or receive from Zayah AI, and you do so at your own risk. Once we have received your data, we will use strict procedures and security features to try to prevent unauthorized access.
VII. YOUR DATA PROTECTION RIGHTS
As required under applicable data protection laws, including the Singapore PDPA, EU GDPR, and other relevant global regulations, you have certain rights concerning your personal data. We are committed to helping you exercise these rights:
-
Right to Access: You have the right to obtain confirmation as to whether personal data concerning you are processed and, if processed, to obtain access to such data and a copy thereof.
-
Right to Rectification/Correction: You have the right to obtain the rectification of any inaccurate personal data concerning you. You also have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
-
Right to Erasure ("Right to be Forgotten"): In some cases, you have the right to obtain the erasure of personal data concerning you. Upon request, CPMX TECH LLC. will permanently and irrevocably anonymize your data such that it can never be reconstructed to identify you as an individual. However, this is not an absolute right and CPMX TECH LLC. may have legal or legitimate grounds for keeping certain data.
-
Right to Restriction of Processing: In some cases, you have the right to obtain restriction of the processing of your personal data.
-
Right to Data Portability: You have the right to receive the personal data concerning you which you have provided to CPMX TECH LLC. in a structured, commonly used and machine-readable format, and you have the right to transmit those data to another controller without hindrance from CPMX TECH LLC. This right only applies when the processing of your personal data is based on your consent or on a contract and such processing is carried out by automated means.
-
Right to Object to Processing: You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you when such processing is based on the legitimate interest of CPMX TECH LLC. may, however, invoke compelling legitimate grounds for continued processing. When your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of such data. You may exercise that right by clicking on the “unsubscribe” link provided at the bottom of any messages received, or by emailing us at privacy@zayah.ai.
-
Right to Lodge a Complaint: You have the right to contact the competent supervisory authority (e.g., the Personal Data Protection Commission (PDPC) in Singapore, or the relevant Data Protection Authority in your jurisdiction) to complain about CPMX TECH LLC.'s personal data protection practices.
-
Right to Give Instructions Concerning the Use of Your Data After Your Death: As required by applicable law, you may have the right to give CPMX TECH LLC. instructions concerning the use of your personal data after your death.
How to Exercise Your Rights: To exercise one or more of these rights, you can email privacy@cpmxtech.com. You may also access your data to modify or update it at any time by emailing privacy@zayah.ai. We will respond to your request in a reasonable timeframe by applicable law and subject to identity verification.
VIII. INTERNATIONAL DATA TRANSFERS
We collect the following categories of information:
A) Information You Provide
-
Account Information: email, phone number, nickname.
-
Profile Data: optional details like age range, emotional areas, or preferences.
-
Conversations & Inputs: messages, reflections, or voice transcriptions exchanged with the AI assistant.
-
Questionnaire Responses: emotional wellbeing or self-assessment data (e.g., PHQ-9, GAD-7) for personalization.
-
Payment Details: transaction confirmation data from Apple Store, Google Play, or Stripe (we do not store card numbers).
B) Information Automatically Collected
-
Device identifiers, IP address, browser type, operating system, time zone, and usage logs.
-
App performance metrics, interactions, and feature usage.
-
Approximate geolocation (country or region) inferred from your IP or device settings.
C) Information from Third Parties
-
App Store / Play Store transaction data.
-
Authentication or analytics data from Firebase.
-
Service usage data from Supabase and OpenAI used to enable AI interactions.
IX. CHILDREN'S PRIVACY
Zayah AI is generally intended for individuals who are at least twenty-one (21) years of age or the age of legal majority in their jurisdiction of residence. Individuals under the age of twenty-one (21), or the applicable age of majority, may utilize the Products only with the involvement and consent of a parent or legal guardian, under such a person's account, as explicitly stated in our Terms and Conditions.
If we become aware that we have collected personal data from a child under the age of 21 without verifiable parental consent, we will take reasonable steps to delete it as quickly as possible. If you believe that we might have any information from or about a child under this age, please contact us at privacy@zayah.ai.
X. COOKIES AND OTHER TRACKING TECHNOLOGIES
CPMX Tech LLC. and our analytics partners use technologies such as cookies, beacons, tags, and scripts to enable service functionality and improve user experience.
-
What are Cookies: Cookies are small data files placed on your device. We also use local storage, such as HTML5, to store content data and preferences.
-
-
How We Use Them:
-
Functionality: To recognize your device so you don't have to provide the same data multiple times, to recognize that you may have already given a username and password, and to store your preferences.
-
Analytics: To measure how people are using the Products, gather statistical data (e.g., number of visitors, usage volumes), and understand user behavior to optimize content and services. We use Google Analytics for these purposes.
-
Advertising: We partner with third parties, such as Facebook and Google, to manage our advertising of the Products on other sites or platforms and across your other devices based on your past visits to our Website. Our third-party partners may use technologies such as cookies to gather data about your activities within the Products to deliver such advertising to you, such as retargeting ads.
-
Log Files: We gather certain data and store it in log files, including IP addresses, browser type, ISP, referring/exit pages, OS, and clickstream data, which helps us understand user popularity and make decisions about content.
-
-
Your Choices: We will acquire consent from you in order to use such trackers to the extent required by applicable law. Various browsers and devices offer management tools for removing cookies and local storage. Please note that opting out of interest-based advertising does not opt you out of being served generic ads. You may adjust your ad preferences in your Google or Facebook account.
XI. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or service offerings. If we make any material changes, we will notify you by an in-Product message, email (sent to the email address specified in your account), or by means of a notice on the Website or App prior to the change becoming effective.
We encourage you to periodically review this page for the latest information on our privacy practices. It is your responsibility to maintain a valid email address as a registered user. If you opt out of communications from us, you may not receive these notifications; however, the updated Privacy Policy will still govern your use of the Service, and you are responsible for checking for any changes. Your continued use of the Site or the Service after changes become effective indicates your agreement to abide by and be bound by the modified Privacy Policy.
XII. CONTACT US
If you have any questions or concerns regarding this Privacy Policy, please contact:
CPMX Tech LLC
1711 North University Drive, Plantation, Florida 33322, USA
Email: privacy@zayah.ai
Website: www.zayah.ai
