Privacy Policy
1. Overview
Zcope is operated by 2morrow.ai, LLC, a Colorado limited liability company ("Zcope," "we," "us," or "our"), and is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our platform at zcope.app ("Platform").
This policy applies to everyone who touches the Platform: Creators/Publishers (account holders who build and run a brand), Subscribers and audience members (people a Creator communicates with or collects data from), Consumers (people with a cross-brand /me account), Buyers (people who purchase a digital product), Community Members (people who participate in a Creator's community), and Visitors (anyone viewing a public page).
Because Zcope plays more than one legal role depending on whose data is involved, Section 4 ("Our Roles") is the most important section in this policy — read it first if you're trying to figure out who to contact about your data.
2. Definitions
To avoid ambiguity, this policy uses the following defined terms, consistent with our Terms of Service and Acceptable Use Policy:
- "Creator" or "Publisher" — an account holder who registers with Zcope, builds a Brand, and uses the Platform to reach an audience and/or sell products. (Our Terms of Service and AUP currently use "Creator"; product and business materials increasingly use "Publisher." The terms are interchangeable and refer to the same account type.)
- "Subscriber" — a person whose contact information (typically an email address) a Creator has collected through forms, scorecards/assessments, or signup flows, for the purpose of receiving that Creator's communications. Subscriber data belongs to the Creator's Brand.
- "Consumer Account" or "
/meaccount" — a lightweight, cross-brand account an audience member can create atzcope.app/me, using email-code login, that is not tied to any single Creator's Brand. - "Buyer" — a person who purchases a digital product from a Creator through the Platform.
- "Community Member" or "Member" — a person who joins a Creator-hosted community and can post, comment, or otherwise contribute content.
- "Visitor" — anyone who views a public-facing page (a Brand's site, a scorecard, a product page) without an account.
One real person may occupy several of these roles at once — for example, a Subscriber to one Creator's newsletter may also be a Buyer of another Creator's product and hold a single Consumer Account that ties those interactions together for them (but not for either Creator — see Section 4).
3. Data We Collect
Account Data (Creators/Publishers): Email address, name, profile information, and Brand configuration when you register and set up your account.
Subscriber & Audience Data (Publisher-owned): Email addresses and optional metadata collected through a Creator's forms, scorecards, and signup flows. This data belongs to the Creator's Brand — see Section 4.
Consumer Account Data (/me): If you create a cross-brand Consumer Account, we collect your account identity (email, login credential), your assessment/scorecard results across every Brand you've interacted with, your purchase history across every Brand, and your community memberships across every Brand. This data is not owned by any single Creator — see Section 4.
Community & Member-Generated Content: If you join a Creator's community, we collect the posts, comments, images, and other content you contribute, your membership and moderation status, and any reports, strikes, or moderator actions associated with your account. See Section 7.
Content Data: Newsletters, scorecard configurations, digital products, product images, and other content a Creator creates or uploads. Creators may apply a visible watermark to their own product images — this is a Creator-controlled display feature and does not involve any additional data collection about you.
Purchase & Refund Data: If you buy a digital product, we collect your purchase record and, where applicable, refund requests and refund status. See Section 8 for how this is shared (or, more precisely, not shared).
Usage Data: Browser type, IP address, pages visited, features used, and interaction patterns, to operate and improve the Platform.
Security & Payment Diagnostic Logs: When you sign in, sign out, request a password reset, set up payments, or a subscription or purchase is charged, refunded, or cancelled, we record a diagnostic event describing what happened. Each event records the outcome, the IP address and approximate location (country, region, and at most city) the request came from, a coarse description of your device (for example "desktop / Chrome / macOS" — not a device fingerprint), which of our hostnames served the request, and, for payment events, the amount, currency, and the relevant payment-provider reference. Email addresses are stored only as an irreversible cryptographic hash, never in readable form. We do not record precise location, and we never store card numbers or security codes. Retention and anonymization of these logs are described in Section 9.
Payment Data: Payment information is processed by our payment provider (Stripe). We do not store full credit card numbers.
4. Our Roles: When Zcope Is a Processor vs. a Controller
Zcope plays two different legal roles depending on whose data is involved, and this determines who you should contact if you want to access, correct, or delete your data.
When Zcope is a Data Processor — Publisher-owned data. Creators/Publishers use Zcope to run their own audience business: collecting Subscriber email addresses, mailing-list signups, and scorecard/assessment form submissions from people who interact with their Brand. For this data, the Creator/Publisher is the Data Controller — they decide why the data is collected and what it's used for — and Zcope is the Data Processor, holding and processing it on the Creator's behalf and instructions.
If you are a Subscriber, list member, or form respondent and want to exercise a data-subject right over this data, your primary point of contact is the Creator/Publisher whose Brand you interacted with — they control that relationship and are best placed to act on your request. Zcope will assist a Creator in fulfilling a valid request.
When Zcope is a Data Controller — cross-brand Consumer (/me) accounts. Separately, audience members can create one cross-brand Consumer Account that holds their account identity, their assessment/scorecard results across every Brand they've interacted with, their purchase history, and their community memberships. For this data, Zcope is the Data Controller — we decide how the Consumer Account works and what it's used for, independent of any single Creator/Publisher.
If you want to access, correct, delete, or export your Consumer Account data, contact Zcope directly at privacy@zcope.app. No individual Creator/Publisher can act on your behalf for this data, and — as described in Section 8 — no individual Creator/Publisher can even see your activity with other Creators on the Platform.
5. How We Use Your Data
We use collected data to:
- Provide the Service: Host content, deliver emails, process scorecards, manage subscriber lists, run Consumer Accounts, and operate communities
- AI Features: Process content through AI systems for voice profiling, business-profile generation, copy suggestions, and content generation when you or a Creator uses these features
- Safety Screening: Content — including Community posts, comments, and images — may be processed by automated systems to detect prohibited content as described in our Acceptable Use Policy
- Compliance: Maintain records required by law, including email logs (CAN-SPAM), suppression records, and enforcement audit trails
- Communication: Send service announcements, policy updates, and security alerts
- Improvement: Analyze usage patterns to improve Platform features and performance
6. AI Content Processing
When you or a Creator use AI-powered features, content may be processed by third-party AI services (currently Google Gemini). This processing is used to:
- Analyze writing style for voice profiling, drawing on material a Creator provides — uploaded files, submitted website or social-profile URLs, or pasted profile text — to build a business profile used for generation
- Generate content suggestions, marketing copy, and assessments based on prompts and the business profile above
- Screen text content for safety and policy compliance
- Screen uploaded images using AI-powered visual content analysis to detect content that violates our Acceptable Use Policy, including images posted in Communities
Image screening occurs at the time of upload. We do not retain separate copies of images for screening purposes — the analysis is performed on the image as stored on the Platform. Images that violate our policies may be automatically removed.
We do not sell your content to AI providers. Content is processed solely for the purposes listed above.
7. Communities & Member-Generated Content
Creators/Publishers can host member communities on their Brand. If you join a community as a Member, we collect and process:
- Membership data: your membership status, role (member or moderator), and join date
- Posts, comments, and reactions: the text, images, and other media you post
- Moderation records: reports you file or that are filed against you, moderator actions taken on your content or account, and any strikes or warnings recorded against your account for policy violations. These records are retained for the life of your account and up to 24 months after account closure.
AI content screening. Like all public content on the Platform, Community posts, comments, and images are screened by automated AI systems before they become publicly visible, to detect content that violates our Acceptable Use Policy. This screening does not constitute pre-approval or endorsement of your content. If your content is removed based on AI screening, you have a right to appeal — see our Acceptable Use Policy for the appeals process.
Publisher moderation. The Creator/Publisher who owns a community is its primary moderator and can view, remove, and act on Member content and memberships within their own community. Community data is scoped to the Creator's Brand — a Creator cannot see your posts or activity in another Creator's community.
8. Data Sharing & Disclosure
We do not sell your personal data. We may share data in the following circumstances:
- Service Providers: Application hosting (Vercel), database and authentication (Supabase, running on Amazon Web Services), email delivery (Resend), payment processing (Stripe), AI processing (Google Gemini — see Section 6), and bot and abuse protection on public forms (Cloudflare Turnstile) — only as needed to provide the Service
Our own software. Some parts of the Platform are separate software products built and run by 2morrow.ai, LLC — the same company that operates Zcope — rather than by an outside vendor. These are our customer-support tool (TicketZero) and our product-feedback tool (yrFeedback). Because they are operated by the same company, no data is shared with a third party when you use them; they are named here so you know what you are using. Both appear only on our own account-holder and marketing pages — they are never present on a Creator's public site, and they never handle Subscriber or audience data.
- Legal Requirements: When required by law, subpoena, court order, or government request
- Mandatory Reporting: We are legally required to report child sexual abuse material (CSAM) to NCMEC and may report other illegal content to appropriate authorities
- Safety: To protect the safety of our users, the public, or our Platform
- Business Transfers: In connection with a merger, acquisition, or sale of assets (with notice to affected users)
- Refund History: If you purchase a digital product, your refund history is visible only to the Creator/Publisher whose product you purchased. We do not share your refund or purchase history with any other Creator on the Platform.
The cross-brand privacy wall, and its limits. Your Consumer Account is partitioned so that no individual Creator/Publisher can see your activity, purchases, or assessment results with any other Creator on the Platform. This wall is a real product feature, and it is a core part of how we protect your privacy from other Creators.
However, the wall is a product feature that limits what Publishers see — it is not a legal shield against Zcope itself or against legal process. Zcope operates the underlying systems and, unlike any individual Creator, maintains a global view of your account across all Brands. Where we are legally required to do so — in response to a valid subpoena, court order, law-enforcement request, or other legal process — we will disclose the full scope of your cross-brand Consumer Account data, not just your activity with a single Creator. Consistent with our Terms of Service, we act on legal-process disclosures only where the request is valid, verified legal process — we do not honor informal requests (e.g., a phone call or email merely claiming law-enforcement affiliation).
9. Data Retention
We retain data for as long as your account is active or as needed to provide the Service. After account termination or a deletion request:
- Account data: Deleted within 30 days of termination request, except as required by law
- Subscriber data (Publisher-owned): Retained per the Creator's Brand until deleted by the Creator or required by law.
- Creator-initiated routine deletion. When a Creator deletes a Subscriber as a routine account-management action, we apply a 90-day soft-delete grace period before the data is permanently erased, so accidental deletions can be recovered; during this window the data is not accessible through the Creator's audience-facing tools but has not yet been purged.
- Data subject erasure request. Where the deletion is instead a request from the data subject themself (the Subscriber) exercising their own right to erasure — for example, under GDPR Article 17 — the 90-day grace period does not apply. We process that request without undue delay and, in any event, within 30 days, subject only to the narrow retention carve-outs described elsewhere in this section (e.g., email delivery/suppression logs and compliance records, retained on the limited legal/anti-spam bases described below — not as a data-subject-erasure exception).
- Email delivery & suppression logs: Even after a Subscriber's data is hard-deleted, we retain a record of the email address in our delivery, bounce, and suppression logs, for anti-spam protection, email-deliverability integrity (so a previously unsubscribed, bounced, or complained-about address is not silently re-added), and compliance/audit purposes.
- Community & moderation records: Life of account + up to 24 months after account closure. See Section 7.
- Purchase & refund records: Retained under the same 3–7 year compliance-records schedule as the other financial/compliance records described below.
- Compliance records: Email logs, suppression records, and enforcement audit trails are retained for the legally required period (typically 3–7 years)
- Security & payment diagnostic logs: Retained in identifiable form for 30 days, which is our troubleshooting and security-investigation window. After 30 days each record is irreversibly anonymized in place: the IP address is reduced to a network prefix, the device description is reduced to its coarse form, the approximate city is removed, the hashed email address is deleted, and the account identifier is replaced by a key derived using a secret that is then destroyed. Once that secret is destroyed the record cannot be linked back to you by anyone, including us — it is anonymous data, not merely pseudonymous. Anonymized records are permanently deleted after 13 months. If you exercise your right to erasure, the security events relating to your account are anonymized immediately rather than waiting for the 30-day point; payment records remain subject to the 3–7 year financial-records schedule described above, which is a legal-obligation carve-out that applies to the financial record itself.
- CSAM/legal reports: Preserved as required by law (minimum one year per the REPORT Act, which extended the prior federal preservation period)
10. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data (subject to legal retention requirements)
- Portability: Request your data in a machine-readable format
- Objection: Object to processing of your data for certain purposes
- Restriction: Request restriction of processing in certain circumstances
Who to contact. As explained in Section 4: for data owned by a Creator/Publisher (Subscriber and audience data), contact that Creator/Publisher first — they are the Data Controller for that data. For your Consumer Account (/me) data, contact Zcope directly — we are the Data Controller for that data.
GDPR (EU/EEA): You have all rights listed above under Articles 15–22 of the General Data Protection Regulation.
CCPA/CPRA (California): California residents have the right to know, delete, and opt-out of sale of personal information.
Colorado Privacy Act (Colorado): 2morrow.ai, LLC is a Colorado company. Colorado residents have the rights listed above — access, correction, deletion, and a portable copy of their personal data — together with the right to appeal a decision we make on such a request. To exercise a right, or to appeal, contact us at privacy@zcope.app. We do not sell personal data and we do not process personal data for targeted advertising.
FADP (Switzerland): Swiss residents have rights under the Federal Act on Data Protection.
To exercise your rights against Zcope directly (including for Consumer Account data, or if a Creator is unresponsive), contact us at privacy@zcope.app.
11. International Data Transfers
Zcope is based in the United States. If you access the Platform from outside the US, your data will be transferred to and processed in the United States.
For transfers of personal data from the EU/EEA, we rely on the Standard Contractual Clauses (SCCs) approved by the European Commission.
For transfers from the United Kingdom, we rely on those same SCCs together with the UK International Data Transfer Addendum issued by the Information Commissioner's Office.
For transfers from Switzerland, we rely on the SCCs with the adaptations recognised by the Swiss Federal Data Protection and Information Commissioner. We do not self-certify under the Swiss–US Data Privacy Framework and do not rely on it.
13. Children's Privacy
The Platform is not directed to children under 13 (or under 16 in the EU). We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will delete it promptly.
Creators who operate content that may be accessed by children — including community and content features — are responsible for implementing appropriate age verification and parental consent mechanisms.
14. Security
We implement industry-standard security measures including encryption in transit (TLS), encryption at rest, role-based access control, and regular security reviews. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Platform and updating the "Last Updated" date. Continued use of the Platform after changes constitutes acceptance.
16. Contact & Entity Information
Zcope is operated by 2morrow.ai, LLC, a Colorado limited liability company.
Mailing address: 2730 S Wadsworth Blvd Ste B #1013, Denver, CO 80227, United States
For privacy-related inquiries, including data-subject requests: privacy@zcope.app
For legal notices: legal@zcope.app
This document is provided for informational purposes and does not constitute legal advice. Consult a qualified attorney for advice specific to your situation.