Last updated: July 2026
This Policy explains how Zephex collects, uses, and shares personal information when you use our dashboard and MCP proxy.
Account data (email, profile, API key hashes, usage logs, billing links) is stored in Supabase Postgres with row-level security isolating each customer. Dashboard sign-in uses Supabase Auth — email/password, GitHub/Google OAuth, magic links, and passkeys. MCP tool calls authenticate with Bearer API keys validated against hashed keys in the same database. MCP connector OAuth (Claude.ai, ChatGPT, and similar clients) uses Auth0 as the authorization server with PKCE; dashboard accounts remain on Supabase Auth. We never store plaintext API keys.
Service health for the database and auth layers is monitored at zephex.dev/status. Technical detail: Authentication docs.
If you roll Zephex out to a team, the account owner remains responsible for every API key created under that account. Each developer should use named keys per environment; shared keys in chat or public repos violate our acceptable-use rules.
Usage metadata (tool name, timestamp, success/error, latency) is stored per API key so account owners can attribute quota in the dashboard. We do not store tool arguments or outputs. Rollout guide: Team MCP rollout.
Zephex does not use prompts, tool inputs, tool outputs, or repository content accessed through tools to train, fine-tune, or evaluate AI models. This applies to all plans without exception.
| Data | Stored? | Duration |
|---|---|---|
| Source code in tool calls | No | — |
| Tool input arguments | No | — |
| Tool output / response body | No | — |
| AI chat / prompts | No | — |
| Tool name per call | Yes | 90 days |
| Timestamp + success/error + latency | Yes | 90 days |
| API key hash (HMAC-SHA256 + salt) | Yes | Until revoked |
| Hashed IP address | Yes | 90 days |
We use cookies and similar storage to keep you signed in, protect your account, and operate the dashboard. We use PostHog for product analytics (page views, feature events, session replay with masked inputs). PostHog may set cookies (e.g. ph_*). Essential cookies (session, CSRF) are always required. EU users can decline optional analytics via the cookie banner.
We share personal information only with the service providers listed above, as needed to run the Service. No processor receives plaintext API keys or full tool call content.
We retain personal information only as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Some records (for example: billing) may be retained longer where required.
If you are a California resident, you have the following rights:
We do not sell your personal information.
Zephex is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has created an account, contact support@zephex.dev and we will delete it promptly.
In the event of a data breach that affects your personal information, we will notify you without undue delay and as required by applicable law (method and timing depend on jurisdiction and severity).
Privacy questions: support@zephex.dev
Last updated: July 2026
This Policy explains how Zephex collects, uses, and shares personal information when you use our dashboard and MCP proxy.
Account data (email, profile, API key hashes, usage logs, billing links) is stored in Supabase Postgres with row-level security isolating each customer. Dashboard sign-in uses Supabase Auth — email/password, GitHub/Google OAuth, magic links, and passkeys. MCP tool calls authenticate with Bearer API keys validated against hashed keys in the same database. MCP connector OAuth (Claude.ai, ChatGPT, and similar clients) uses Auth0 as the authorization server with PKCE; dashboard accounts remain on Supabase Auth. We never store plaintext API keys.
Service health for the database and auth layers is monitored at zephex.dev/status. Technical detail: Authentication docs.
If you roll Zephex out to a team, the account owner remains responsible for every API key created under that account. Each developer should use named keys per environment; shared keys in chat or public repos violate our acceptable-use rules.
Usage metadata (tool name, timestamp, success/error, latency) is stored per API key so account owners can attribute quota in the dashboard. We do not store tool arguments or outputs. Rollout guide: Team MCP rollout.
Zephex does not use prompts, tool inputs, tool outputs, or repository content accessed through tools to train, fine-tune, or evaluate AI models. This applies to all plans without exception.
| Data | Stored? | Duration |
|---|---|---|
| Source code in tool calls | No | — |
| Tool input arguments | No | — |
| Tool output / response body | No | — |
| AI chat / prompts | No | — |
| Tool name per call | Yes | 90 days |
| Timestamp + success/error + latency | Yes | 90 days |
| API key hash (HMAC-SHA256 + salt) | Yes | Until revoked |
| Hashed IP address | Yes | 90 days |
We use cookies and similar storage to keep you signed in, protect your account, and operate the dashboard. We use PostHog for product analytics (page views, feature events, session replay with masked inputs). PostHog may set cookies (e.g. ph_*). Essential cookies (session, CSRF) are always required. EU users can decline optional analytics via the cookie banner.
We share personal information only with the service providers listed above, as needed to run the Service. No processor receives plaintext API keys or full tool call content.
We retain personal information only as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Some records (for example: billing) may be retained longer where required.
If you are a California resident, you have the following rights:
We do not sell your personal information.
Zephex is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has created an account, contact support@zephex.dev and we will delete it promptly.
In the event of a data breach that affects your personal information, we will notify you without undue delay and as required by applicable law (method and timing depend on jurisdiction and severity).
Privacy questions: support@zephex.dev