1. The short version
A plain-English summary. It is a summary only, and the rest of this policy governs.
| Question | Answer |
|---|---|
| Who runs Zicy | Growth Pro Sdn. Bhd., a company registered in Malaysia. |
| What we mainly hold | Your account details, your billing details, the brands and prompts you choose to track, and the data you connect from Google, Bing and your own website. |
| Do we sell your data | No. We do not sell personal data and we do not share it for cross-context behavioural advertising. |
| How long we keep it | While your account is active, then for the periods set out in section 12. |
2. Who this policy covers
This policy applies to:
- The Zicy web application at app.zicy.com
- The Zicy marketing website at zicy.com and the help centre at docs.zicy.com
- The Zicy Chrome extension
- The public AEO and GEO consultant tool at zicy.com/consultant
- The Zicy WordPress plugin
- Email, support and sales conversations with us
It does not cover third-party websites we link to, or what an AI platform does with a question you type into it directly.
3. When we are the controller and when we are the processor
This distinction matters if you are buying Zicy on behalf of a client or an employer.
We are the data controller for:
- Your account and profile details
- Your organisation, team and invitation records
- Billing, subscription and quota records
- Product usage, device and log data
- Marketing and support communications
We are the data processor for:
- Brand profiles, tracked prompts and competitor lists you enter
- Analytics and Search Console data you connect
- Content crawled from a website you nominate
- AI engine responses captured for your tracked prompts
- Content drafts generated or optimised in the product
For that second group you, or the client you act for, are the controller. Our processing terms for that data are available on request from privacy@zicy.com.
4. What we collect and why
Everything below is either given to us by you, generated by your use of Zicy, or fetched from a service you connected.
4.1 Account and identity
- What: full name, email address, password (stored hashed, never in readable form), organisation name, organisation ID, sign-in method, role, profile access scope
- Why: to create and secure your account, apply permissions, and provide the service
- Legal basis, where the GDPR applies: performance of a contract
4.2 Team and invitations
- What: the email address, role and status of anyone you invite, and the expiry of their invitation
- Why: to run team access and quota allocation
- Note: if you invite a colleague, you are asking us to email them on your behalf. Only invite people who expect to hear from you
- Legal basis: performance of a contract, and our legitimate interest in operating team features
4.3 Billing and subscription
- What: plan, quota and credit usage, add-on purchases, voucher redemptions, invoices, billing contact details
- Why: to take payment, issue invoices, meet tax and accounting obligations
- Legal basis: performance of a contract, and legal obligation
4.4 Brand and prompt data
- What: brand names and variations, website URLs, industry, products and services, mission, unique selling proposition, tone and writing style, competitor names and URLs, brand facts such as founding year and headquarters, the prompts you track, and the tags you apply
- Why: every Zicy module is calibrated against this. Without it we cannot measure anything
- Personal data warning: these fields are free text. Do not enter personal data about individuals unless you need to, and never enter special category data such as health or biometric information
- Legal basis: performance of a contract. Where the data belongs to your client, we process it on your instructions
4.5 AI engine responses
- What: the answers ChatGPT, Gemini, Perplexity, Google AI Overviews and Google AI Mode return for your tracked prompts, plus the brands, positions, sentiment and citations we extract from them
- How: we send your tracked prompt to each engine on a daily cycle and record the response
- Incidental personal data: an AI answer can name a person, for example a founder or an author. We store the answer as returned so you have the evidence
- Legal basis: performance of a contract, and our legitimate interest in providing a measurement record you can rely on
4.6 Connected Google accounts
Covered separately in section 5, because Google imposes specific rules on us.
4.7 Connected Bing Webmaster Tools
- What: impressions, clicks, click-through rate, average position, top pages and top queries for the property you connect
- Why: Bing's index also feeds Microsoft Copilot and other answer engines, so it is part of your visibility picture
- Legal basis: performance of a contract
4.8 WordPress plugin and AI bot logs
- What: access-log records showing which AI crawlers visited your site and which pages they read. Depending on your server configuration these logs can contain IP addresses and user-agent strings
- Why: to show you which AI assistants are actually reading your site and where they take answers from
- Your responsibility: you are the controller of your own server logs. Only sync them if you are entitled to
- Legal basis: performance of a contract, on your instructions
4.9 Website crawl data
- What: page URLs, titles, meta descriptions, headings, body content, structured data, robots.txt, sitemap and llms.txt for the domain you nominate
- Why: to run site audits, page summaries, duplicate detection and content scoring
- Limit: we crawl only domains you nominate on a brand profile, and we never publish or change anything on your website. Every asset Zicy produces is handed to you to publish yourself
- Legal basis: performance of a contract
4.10 Ask Zicy and the AI consultant
- What: the messages you type into Ask Zicy, the chat tab titles you set, and the responses returned
- Why: to answer your question and to meter chat usage against your plan
- Legal basis: performance of a contract
4.11 Generated and optimised content
- What: article drafts, optimised page copy, schema markup and llms.txt files produced in the product, and the inputs you gave to produce them
- Why: so your content library persists and you can return to a draft
- Legal basis: performance of a contract
4.12 Product usage, device and log data
- What: IP address, browser and device type, pages and features used, timestamps, referring URL, error and diagnostic records
- Why: to keep the service secure, diagnose faults, prevent abuse, and understand which features are used
- Legal basis: legitimate interests in securing and improving the service
4.13 Communications and marketing
- What: contact form and demo request details, support conversations, and email preferences
- Why: to reply to you and to send product and marketing email you have asked for
- Control: the notification centre in Settings has a master switch to pause all optional emails. Emails about payments, invoices and invitations are operational and are always sent
- Legal basis: consent for marketing, legitimate interests for operational messages
5. Google user data, and Google's Limited Use requirements
If you connect Google Analytics or Google Search Console, Zicy accesses Google user data through Google APIs, with your explicit permission at the consent screen.
What we access:
- Google Analytics: traffic, source and engagement metrics for the property you select, including the AI referral sources we report on
- Google Search Console: query, impression, click, click-through rate and position data for the property you select
- The email address of the connected Google account, so you can see which account is linked and disconnect it
How we use it: only to produce the reports and features you can see in Zicy. Nothing else.
The Limited Use commitment. Zicy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In practice that means:
- We use Google user data only to provide or improve features that are visible and prominent in Zicy
- We do not transfer Google user data except to provide those features with your consent, for security purposes, to comply with the law, or in a merger, acquisition or sale of assets
- We do not allow humans to read Google user data, except where you have specifically agreed, where it is necessary for security or to comply with the law, or where the data is aggregated for internal operations
- We do not use Google user data for advertising, and we do not sell it
How to disconnect: open Site Traffic in the app and choose Disconnect on the Analytics or Search Console tab, or revoke Zicy's access at myaccount.google.com/permissions. Revoking access stops future syncing. To delete data already imported, contact privacy@zicy.com.
6. The Chrome extension
The Zicy Chrome extension audits a page for AI readiness when you ask it to.
- It analyses a page only when you trigger an audit. It does not run in the background
- It does not track or transmit your browsing history
- It does not sell or share your data with third parties for their own purposes
- Uninstalling the extension stops all collection
7. The public AEO and GEO consultant
The consultant tool at zicy.com/consultant is open to visitors without an account.
- We process the questions and URLs you submit in order to answer them
- Do not paste confidential or personal information into a public tool
8. How we use AI, and whether your data trains models
This is the question buyers ask most, so we answer it directly. We use AI in two different ways, and we keep them separate rather than blur them together.
OpenAI: Ask Zicy, embeddings, content and analysis
Ask Zicy, our embeddings, and our content and analysis tools run on OpenAI's API.
- OpenAI does not use API data to train its models unless the customer opts in to that. Zicy has not opted in
- OpenAI may retain API inputs and outputs for up to 30 days for abuse monitoring, then deletes them
- OpenAI has completed a SOC 2 Type 2 audit covering the API platform
Tracked prompts sent to the AI engines we measure
Separately from how we use OpenAI, Zicy sends your tracked prompts to ChatGPT, Gemini, Perplexity, Google AI Overviews and Google AI Mode, in order to record what those engines answer. That is the product itself.
- We do use aggregated and de-identified statistics, which cannot identify you or your clients, to improve Zicy's benchmarks and features
- We do not make decisions about you that have a legal or similarly significant effect using automated processing alone
9. Cookies and similar technologies
We use cookies and similar technologies for sign-in and security, for remembering preferences such as the theme toggle, and for measuring how the site and product are used.
Non-essential cookies are set only with your consent, and you can change your choice at any time using in the footer. The full list is in the cookie policy.
10. Who we share data with
We share personal data only with the categories below, and only as far as needed.
- Service providers, sometimes called sub-processors. Hosting, database, email delivery, payments, error monitoring, product analytics and AI providers. Each is engaged under its published terms, and where a data processing agreement is in place, it requires that provider to protect the data and process it only on our instructions
- The AI engines we measure. We send your tracked prompt text
- Your own organisation. Anyone you invite can see the profiles they are assigned to. An owner can see the organisation's usage and billing
- Professional advisers, auditors and insurers, under confidentiality
- Authorities, where we are legally required to disclose, and where lawful we will tell you first
- A buyer, if the business is merged, acquired or sold, with notice to you
We do not sell personal data. We do not share personal data for cross-context behavioural advertising.
Sub-processor list. A current list of our sub-processors is available on request from privacy@zicy.com.
11. Where your data goes
Growth Pro Sdn. Bhd. is in Malaysia, and the providers we use operate in several countries, so your data may be processed outside the country you are in.
The Personal Data Protection (Amendment) Act 2024 replaced the old transfer whitelist with a risk-based test: a transfer is permitted where the destination has law substantially similar to the PDPA or provides an adequate level of protection, or under one of the Act's other permitted grounds. The Personal Data Protection Commissioner's 2025 Cross-Border Personal Data Transfer Guidelines accept contractual protections, including the European Commission's standard contractual clauses, as one valid way to meet that test.
| Provider | Purpose |
|---|---|
| Firebase Authentication for sign-in, and Google Analytics 4 and Tag Manager for site and product analytics | |
| Stripe | Payment processing |
| Sentry | Error and crash monitoring. Sentry's ingest region for Zicy is the United States |
| Vercel | Marketing site hosting and cookieless site analytics |
| OpenAI | Ask Zicy, embeddings, content and analysis features |
| MongoDB Atlas | Primary database and vector search |
You can ask us for more detail on the safeguards at privacy@zicy.com.
12. How long we keep things
| Data | Kept for | Why |
|---|---|---|
| Account and profile records | Life of the account, then deleted 90 days after closure | Industry-standard grace period for accidental closure and reactivation |
| Brand profiles, tracked prompts and analysis history | Life of the account, then deleted 90 days after closure | One rule across product data is easier to honour than five |
| AI engine responses | Life of the account, then deleted 90 days after closure | This is the historical trend record the product exists to build |
| Connected Google and Bing data, after disconnect | 30 days | Deliberately short. Google's Limited Use terms push toward prompt deletion, and a short window is a selling point |
| Ask Zicy chat history, after account closure | 90 days | Matches the account rule |
| Generated content drafts | Life of the account, then deleted 90 days after closure | Matches the account rule |
| Billing and invoice records | 7 years | Not discretionary. Malaysian tax law requires business records to be kept for 7 years |
| Security and access logs | 12 months | Long enough for incident forensics, proportionate under storage limitation |
| Data sent to OpenAI | Up to 30 days, held by OpenAI | OpenAI's published API retention for abuse monitoring, then deleted. Not used for training |
| Marketing contacts | Until you unsubscribe, then suppression-list only |
Data deleted from live systems remains in encrypted backups until the backup cycle overwrites it.
13. How we protect it
- Encryption in transit using TLS, and encryption at rest
- Role-based access control, with staff access limited to those who need it
- Password hashing, and support for the sign-in methods shown in your account settings
- Logging and monitoring of access to production systems
- Contractual security obligations on providers where a data processing agreement is in place
- Regular review of access rights
No system is perfectly secure. If a breach occurs that is likely to cause you significant harm, we will notify the Personal Data Protection Commissioner of Malaysia as soon as practicable and in any event within 72 hours of becoming aware of it, and we will notify affected individuals without undue delay and no later than seven days after that report, as required by the Personal Data Protection Act 2010 as amended. Where the GDPR applies, we will meet its equivalent obligations.
14. Your rights
If you are in Malaysia
Under the Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024, you can:
- Ask for access to the personal data we hold about you
- Ask us to correct data that is inaccurate, incomplete or out of date
- Withdraw consent where we rely on it
- Ask us to stop processing that is causing or likely to cause damage or distress
- Ask us to stop processing for direct marketing
- Ask us to transmit your personal data to another data controller, where that is technically feasible and the formats are compatible
- Complain to the Personal Data Protection Commissioner
If you are in the European Economic Area or the United Kingdom
You can also ask for erasure, restriction of processing, and a copy of your data in a portable format, and you can object to processing based on legitimate interests. You can complain to your local supervisory authority.
If you are in California
You can ask what we collect, ask for a copy, ask for deletion, ask for correction, and you have the right not to be discriminated against for exercising these rights. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out for you to exercise on those points.
How to make a request
Email privacy@zicy.com. We will verify your identity before acting, and we will respond within the period the law allows, which is 21 days in Malaysia and one month under the GDPR unless we tell you we need longer.
If your data sits inside a Zicy account run by someone else, for example an agency that added you, please contact them first. We will help them respond.
15. Children
Zicy is a business tool and is not intended for children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us data, email privacy@zicy.com and we will delete it.
16. Changes to this policy
We will post any change on this page and update the date at the top. If a change materially affects your rights, we will tell you by email or in the product before it takes effect.
17. Contact us
- Privacy questions and rights requests: privacy@zicy.com
- Postal address: Growth Pro Sdn. Bhd., 60 Persiaran Midlands, 10250 Penang, Malaysia
- Regulator in Malaysia: Personal Data Protection Department (Jabatan Perlindungan Data Peribadi), pdp.gov.my