Privacy and control

Company memory.
Not team surveillance.

Here is the full table of which data lives where, on every plan. It is the question your DPO asks, and the one that decides whether your works council approves the tool.

What data goes where, by plan

What data goes where, by plan
DataFreeProEnterprise / Pro Cloud
Full email contentLocalLocalLocal
Chat question + context snippetsOpt-inLocalLocal
Your history, for indexingLocalLocalLocal
Semantic memoryLocalLocalLocal
Account metadataZenntroZenntroZenntro
Local
Your machine or your server, end-to-end encrypted
Opt-in
Explicit opt-in · European provider with zero retention
Zenntro
Managed by Zenntro (metadata only, never content)

Privacy 2.0 · three layers

Who controls what, and where.

  1. Layer 0 · Platform

    Zenntro defaults

    Infrastructure domains (Stripe, OAuth, notifications) are never indexed. Read-only for the organisation and the user. Enforced on every sync.

  2. Layer 1 · Organisation

    Org-wide policy

    The admin or owner sets filters, domain blacklists and GDPR categories from the Dashboard, with no access to any individual employee's content.

  3. Layer 2 · User

    Employee control

    Pause indexing, set personal exclusions and choose granular redaction, mirrored between the app and the web. The owner cannot override an employee's private settings.

  • Three layers of privacy

    Platform (Zenntro, not overridable), organisation (admin) and user (employee). The most restrictive rule always wins. Domain blacklists at every layer, including infrastructure such as Stripe or OAuth.

  • Separation of powers, owner and employee

    Every employee can pause their own indexing, exclude domains and choose a redaction level (full, metadata only, or PII redacted) without going through the admin. The owner sees aggregates, never individual detail.

  • DSAR audit and dry-run in the app

    “What does Zenntro know about me”: a list of indexed events and attributes, selective deletion, a pre-ingest simulation and a log of what was blocked. In the app only; the Dashboard mirrors the toggles, never the content.

  • You choose where the AI runs

    Indexing and AI search always run on your machine, on every plan. If you enable chat on Free, your question and its context snippets go to a European provider with zero retention — and only if you turn it on. On Pro, chat AI runs on your own server: not even your questions leave.

  • Ledger and works-council dossier

    An append-only record of privacy decisions, plus one-click export of your aggregate posture and a dossier for a DPO or works council. Available on Enterprise.

  • Zenntro never sees your operational data

    On no plan does your clients' data pass through Zenntro's servers. We only handle account metadata: plan, billing and devices. The cloud Dashboard never reads emails or the relationship map.

Your company's memory
should stay in your company.

Install the app, connect your email and ask whatever you need. Five minutes, no card, and nothing to migrate.

GDPR · Curated master on Free · Action Engine on Pro · Free plan available