Privacy Policy for Zahan

Effective Date: February 6, 2026

1. Our Commitment to You

Welcome to Zahan! Our mission is to unlock the collective intelligence of your team by making corporate learning effortless for experts and engaging for everyone. We call this our "Confidence Engine."

This Privacy Policy explains what information we collect, how we use and share it, and your rights regarding your data when you use our services. We are committed to being transparent and protecting your privacy. We've written this policy in plain language to be as clear and easy to understand as possible.

This policy applies to all users of the Zahan platform and services (collectively, the "Services"), including individuals who create and host quizzes ("Hosts") and individuals who participate in them ("Participants").

Groqify, Inc. ("Groqify," "we," "us," "our") is the company responsible for your information under this Privacy Policy (the "data controller").

2. What Information We Collect and Why

We collect information in a few different ways to provide and improve our Services. We have broken this down into categories to make it clear.

2.1 Information You Provide to Us

  • Account Information: When you or your organization creates an account, we collect information like your name, email address, optional organization name and Phone number. We use this to set up and manage your account, provide customer support, and communicate with you about the Services.
  • Quiz Content and Prompts: When a Host uses our AI-powered tools to create a quiz, we collect the text prompts, questions, and conversational instructions they provide. We use this information solely to generate and refine the quiz content as requested.
  • Communications and Feedback: If you contact us for support, provide feedback, or participate in a survey, we collect the information you include in your communications. For feedback submissions, we also collect minimal technical metadata (browser name, operating system, and screen resolution) to help diagnose issues. We use this to respond to you and to improve our Services.

2.2 Information We Collect Automatically

  • Game and Participation Data: When Participants engage with a quiz, we automatically collect data about their interactions. This includes the answers submitted, scores achieved, time taken to answer, and overall completion status. This data is used to provide real-time leaderboards and to generate analytics reports for the Host and their organization.
  • Usage and Device Information: Like most online services, we automatically collect technical information when you use our Services. This includes your IP address, browser type, device information (like its operating system), and information about your activity on our platform (like pages visited and features used). We use this information to operate, secure, and improve our Services.

2.3 Information from Other Sources

Third-Party Sign-In: If you choose to create an account or log in using a third-party service (like Google or Microsoft), we will receive basic profile information from that service, such as your name and email address, to authenticate your account.

2.4 Cookies and Tracking Technologies

We use cookies and similar technologies to operate our Services, remember your preferences, and understand how you use our platform.

Strictly Necessary Cookies: These cookies are essential for the Service to function and cannot be disabled. They include:

  • Supabase Auth (sb-*): Used to keep you logged in and authenticate your requests.
  • session_token: Used when you join a game as a participant to identify your session.

Functional Cookies: These cookies enable enhanced functionality and personalization:

  • zahan_consent_preferences: Stores your cookie consent choices so we remember your preferences.

Analytics Cookies: These help us understand how our Services are used:

  • Vercel Analytics: Provides anonymized usage metrics. This cookie is only set if you consent to analytics cookies.

You can manage your cookie preferences at any time by visiting our Privacy Preferences page, where you can enable or disable analytics and functional cookies. Strictly necessary cookies cannot be disabled as they are required for the Service to work.

3. How We Use Your Information

We use the information we collect for several purposes, which are directly related to providing and improving the Zahan experience:

  • To Provide and Maintain the Services: We use your information to deliver the core functionality of Zahan, such as creating and hosting quizzes, enabling participation, calculating scores, making analytics reports and displaying results.
  • To Provide Analytics to Our Customers: A key feature of our Services is providing our customers (your employer) with insights into their team's engagement and learning progress. We process Participation Data to calculate a "Zahan Engagement Score" and generate reports that are shared with the customer organization.
  • To Improve and Personalize the Services: We analyze how our users interact with our Services to understand what's working, what's not, and how we can make Zahan better.
  • To Communicate With You: We use your contact information to send you service-related announcements, updates, security alerts, and support messages.
  • For Safety and Security: We use information to protect against fraud, abuse, and security incidents, and to enforce our terms of service.
  • To Comply with Legal Obligations: We may use your information where required by law, such as for tax and accounting purposes or in response to a valid legal request.

4. Our Use of Artificial Intelligence (AI)

A core part of our "Confidence Engine" is the use of advanced Artificial Intelligence (AI) models from third-party providers like Google (Gemini) to help you create engaging quiz content.

How it Works:

When a Host provides a prompt to create a quiz, that prompt is sent to our AI partners for processing. The AI model then generates the quiz content based on the instruction.

Important Notice:

The prompts you provide are processed by these third-party services. Please do not include any sensitive personal information (like health or financial data) or confidential company information in your prompts.

Accuracy:

While we strive for accuracy, AI-generated content may occasionally be incorrect or biased. We provide tools for you to review and edit all generated content before you use it.

5. How We Share and Disclose Your Information

We do not sell your personal information. We only share it in the limited circumstances described below:

  • With Your Organization: As Zahan is a B2B service, the quizzes, participant data, engagement scores, and analytics generated during your use of the Services are shared with the customer organization that provided you with access (i.e., your employer).
  • Service Providers (Sub-processors): We work with trusted third-party service providers to help us operate, secure, and improve our Services. These providers have access to your information only to perform tasks on our behalf and are obligated not to disclose or use it for any other purpose. This includes providers for cloud hosting, payment processing, and AI model hosting. View our Subprocessors page.
  • Legal Requirements: We may disclose your information if we believe it's required by law, subpoena, or other legal process, or to protect the rights, property, or safety of Groqify, our users, or the public.

6. Our Legal Basis for Processing Personal Information (For EEA/UK Users)

If you are in the European Economic Area (EEA) or the United Kingdom (UK), our legal basis for collecting and using the personal information described above will depend on the information concerned and the specific context in which we collect it.

We normally collect personal information from you only where:

  • We need the personal information to perform a contract with you or your organization (e.g., to provide the Zahan Services).
  • The processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms (e.g., for our security monitoring and product improvement).
  • We have your consent to do so (e.g., to send you marketing materials or to use certain optional features).
  • We have a legal obligation to collect personal information from you (e.g., for financial record-keeping).

If you have questions about the legal basis on which we collect and use your personal information, please contact us using the details provided below.

7. Data Retention and Deletion

Generally, we retain your account and user data for as long as your organization's account is active with us. When an account is terminated, we will permanently delete the associated personal data from our live systems within 90 days. Data may persist in our secure backup archives for up to an additional 180 days before being permanently erased.

We may retain aggregated and anonymized information indefinitely for research and service improvement purposes, as this information can no longer be used to identify you.

8. Data Security

We take the security of your data very seriously. We use a combination of technical, administrative, and physical controls to maintain the security of your data and protect it from unauthorized access, use, or disclosure. These measures include:

  • Encryption: We encrypt data in transit using industry-standard Transport Layer Security (TLS) and encrypt data at rest.
  • Access Controls: We limit access to personal data to authorized employees and contractors who have a business need to know.
  • Secure Infrastructure: We use secure cloud infrastructure from reputable providers to host our Services.
  • Regular Audits: We are working towards obtaining industry-standard security certifications, such as SOC 2, to independently verify our security practices.

While we take reasonable measures to protect your information, no security system is impenetrable. We cannot guarantee the absolute security of your data.

9. Your Data Protection Rights

Depending on your location, you may have the following rights regarding your personal information:

  • The right to access: You can request a copy of the personal information we hold about you.
  • The right to rectification: You can request that we correct any inaccurate or incomplete information.
  • The right to erasure (the "right to be forgotten"): You can request that we delete your personal information.
  • The right to restrict processing: You can request that we temporarily stop processing your information.
  • The right to data portability: You can request your data in a structured, machine-readable format.
  • The right to object: You can object to our processing of your data where we are relying on a legitimate interest.
  • The right to withdraw consent: If we are processing your data based on your consent, you can withdraw that consent at any time.

To exercise any of these rights, please contact us at [email protected]

Please note that since Zahan is a service provided to your employer, you should typically direct requests to your employer first, as they are the data controller of your information. We will work with them to fulfill your request.

10. International Data Transfers

Your information, including personal data, may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

If you are located in the EEA or UK, this means your personal data may be transferred outside of these regions. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy. For such transfers, we rely on legally-provided mechanisms to lawfully transfer data across borders, such as Standard Contractual Clauses.

11. Children's Privacy

Our Services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that a child under 16 has provided us with personal information, we will take steps to delete such information. If you become aware that a child has provided us with personal information, please contact us.

12. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top. For material changes, we will provide a more prominent notice, such as by sending you an email notification. We encourage you to review this Privacy Policy periodically for any changes.

13. How to Contact Us

If you have any questions, comments, or concerns about this Privacy Policy or our privacy practices, please contact us at:

Groqify Inc.

Email: [email protected]

Data Protection Officer (DPO): For data protection inquiries, privacy requests, or to exercise your data rights, contact our Data Protection Officer at [email protected].