Short version: We collect only what's necessary to run the service. We don't sell your data. We don't share it with third parties for advertising. We use Google OAuth solely to verify your identity.
1 Who We Are
Zerith is an AI-powered keyword research tool operated by ToolTab. Our website is tooltab.io and the Zerith app is available at zerith.tooltab.io.
2 Information We Collect
We collect the following when you use Zerith:
- Account information — When you sign in via Google OAuth, we receive your name, email address, and profile picture from Google. We do not receive your Google password or access to any other Google services.
- Search queries — The keyword topics you enter, used to generate AI-powered keyword research results.
- Search history — Past searches saved to your account so you can reference them later (Pro and Agency plans).
- Usage data — Basic counters (e.g. searches today) used to enforce plan limits.
- Plan information — Your current subscription plan (Free, Pro, or Agency). Payment processing is handled by Paddle; we do not store payment card details.
3 How We Use Google OAuth
We use Google OAuth exclusively to authenticate your identity — so you can sign in without creating a separate password. When you click "Continue with Google":
- Google confirms your identity and shares your name and email with us.
- We do not request access to Gmail, Google Drive, Google Calendar, or any other Google service.
- We do not read, store, or process any Google account data beyond your name and email address.
- Authentication is managed via Clerk. You can review Clerk's privacy policy at clerk.com/privacy.
4 How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Zerith service.
- Authenticate you and manage your account.
- Enforce plan limits (e.g. daily search quotas).
- Save your search history so you can access past results.
- Send transactional emails (e.g. account confirmation). No marketing emails unless you opt in.
- Diagnose bugs and improve service reliability.
We do not use your search queries or personal data for AI model training.
5 Data Storage & Security
Your data is stored on Cloudflare's infrastructure (D1 database and KV storage), distributed globally with industry-standard security. You can review Cloudflare's privacy policy at cloudflare.com/privacypolicy.
Authentication tokens are cryptographically signed (RS256) and verified on every request. We do not store raw passwords.
6 Data Sharing & Third Parties
We do not sell, trade, or rent your personal information. We share data only with the following service providers:
- Clerk — identity and authentication management
- Cloudflare — infrastructure, database, and security
- Anthropic — AI keyword generation (search query text is sent to Anthropic's API and is not linked to your account or stored by Anthropic beyond their standard API data handling)
- Paddle — payment processing for Pro and Agency subscriptions
We may disclose information if required by law or to protect the rights and safety of our users.
7 Cookies & Local Storage
We use minimal browser storage:
- Clerk session cookies — required for authentication and cannot be disabled while using the app.
- Theme preference — stored in
localStorage to remember dark/light mode. Contains no personal data.
- Anonymous search counter — stored in
localStorage to track free anonymous searches. Contains no personal data.
We do not use advertising cookies or third-party tracking cookies.
8 Your Rights
You have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to correct inaccurate data.
- Deletion — request that we delete your account and associated data.
- Portability — request your search history in a machine-readable format.
- Withdraw consent — disconnect Google OAuth at any time via myaccount.google.com/permissions.
To exercise any of these rights, contact us via the details in Section 9. We will respond within 30 days.
9 Contact Us
If you have questions or requests regarding this privacy policy or your personal data:
10 Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we'll update the "Last updated" date at the top of this page. For significant changes, we'll notify signed-in users via email. Continued use of Zerith after changes constitutes acceptance of the updated policy.