Your Tickets Are Not Our Data

ZenBriefr reads ticket content to generate summaries and drafts, then lets it go. No raw ticket storage, no training on your data, and sensitive identifiers are redacted before AI processing. Here is exactly how it works.

No raw ticket storage • Zero-retention AI processing • DPA available on request

What Happens When an Agent Clicks Summarize

1

Ticket content is fetched over TLS

ZenBriefr reads the ticket through Zendesk's API using OAuth. All transmission is encrypted in transit. Nothing is written to disk.

2

Contact and financial identifiers are redacted

Before summarization content leaves our servers, email addresses, phone numbers, Social Security numbers, and payment card numbers are replaced with placeholder tokens. The mapping lives in memory only, for the duration of the request.

3

AI processing runs under zero-retention terms

We use OpenAI's business API, not consumer ChatGPT. Your content is never used to train models and is deleted under OpenAI's zero-retention data-handling terms.

4

The result comes back, the content is discarded

Placeholders are restored to their original values locally and the summary appears in the sidebar. Raw ticket content is discarded when the request completes. The generated summary is cached briefly, keyed by a one-way content hash, so repeat requests are fast, then expires automatically within 24 hours.

Stored vs. Never Stored

Data Stored? Details
Raw ticket conversations Never Processed in memory, discarded when the request completes.
Attachments and files Never Viewed in real time through a secure proxy. OCR text is held in memory only and cleared automatically.
Reply drafts and translations Never Generated, inserted into your composer, and not retained.
Generated summaries Briefly Cached against a one-way content hash so repeat requests are instant, auto-deleted within 24 hours.
Account metadata Yes Zendesk subdomain, admin email, and user ID for authentication. OAuth tokens are encrypted at rest.
Knowledge index (optional features) Yes Your published Help Center articles and short, redacted resolution snippets from solved tickets, used to ground suggestions. Deleted with your account, or sooner on request. Full details in the privacy policy.

Who Touches Your Data

🤖

OpenAI (API)

Generates summaries, drafts, and translations under zero-retention API terms. Never trains on your content.

🗄️

Supabase

Stores account authentication data with encrypted tokens, plus the optional knowledge index.

💳

Stripe

Handles all billing through Stripe-hosted checkout. Your card number never touches ZenBriefr's servers.

🔑

Zendesk OAuth

ZenBriefr connects through Zendesk's own OAuth flow. Revoke access anytime from your Zendesk admin panel.

Where We Stand, Honestly

What we do today

  • GDPR-aligned processing: data minimization, documented legal basis, deletion on request
  • CCPA-aligned privacy-by-design approach
  • Selective PII redaction before summarization content reaches the AI provider
  • TLS 1.3 in transit, OAuth tokens encrypted at rest
  • Data Processing Agreement (DPA) available on request
  • Security brief for your vendor-review process on request
📋

What we don't claim

  • We do not yet hold a SOC 2 certification. We implement security, availability, and confidentiality controls, and we will pursue certification as the company grows.
  • We are a small, focused company. If your review needs specifics our docs don't cover, ask us and you'll get a direct answer from the person who built the system.

Need a DPA or a Security Brief?

Email support@zenbriefr.com and we'll get you what your review needs. The full details are always in our privacy policy.

Start Free Trial →