Your Tickets Are Not Our Data
ZenBriefr reads ticket content to generate summaries and drafts, then lets it go. No raw ticket storage, no training on your data, and sensitive identifiers are redacted before AI processing. Here is exactly how it works.
What Happens When an Agent Clicks Summarize
Ticket content is fetched over TLS
ZenBriefr reads the ticket through Zendesk's API using OAuth. All transmission is encrypted in transit. Nothing is written to disk.
Contact and financial identifiers are redacted
Before summarization content leaves our servers, email addresses, phone numbers, Social Security numbers, and payment card numbers are replaced with placeholder tokens. The mapping lives in memory only, for the duration of the request.
AI processing runs under zero-retention terms
We use OpenAI's business API, not consumer ChatGPT. Your content is never used to train models and is deleted under OpenAI's zero-retention data-handling terms.
The result comes back, the content is discarded
Placeholders are restored to their original values locally and the summary appears in the sidebar. Raw ticket content is discarded when the request completes. The generated summary is cached briefly, keyed by a one-way content hash, so repeat requests are fast, then expires automatically within 24 hours.
Stored vs. Never Stored
| Data | Stored? | Details |
|---|---|---|
| Raw ticket conversations | Never | Processed in memory, discarded when the request completes. |
| Attachments and files | Never | Viewed in real time through a secure proxy. OCR text is held in memory only and cleared automatically. |
| Reply drafts and translations | Never | Generated, inserted into your composer, and not retained. |
| Generated summaries | Briefly | Cached against a one-way content hash so repeat requests are instant, auto-deleted within 24 hours. |
| Account metadata | Yes | Zendesk subdomain, admin email, and user ID for authentication. OAuth tokens are encrypted at rest. |
| Knowledge index (optional features) | Yes | Your published Help Center articles and short, redacted resolution snippets from solved tickets, used to ground suggestions. Deleted with your account, or sooner on request. Full details in the privacy policy. |
Who Touches Your Data
OpenAI (API)
Generates summaries, drafts, and translations under zero-retention API terms. Never trains on your content.
Supabase
Stores account authentication data with encrypted tokens, plus the optional knowledge index.
Stripe
Handles all billing through Stripe-hosted checkout. Your card number never touches ZenBriefr's servers.
Zendesk OAuth
ZenBriefr connects through Zendesk's own OAuth flow. Revoke access anytime from your Zendesk admin panel.
Where We Stand, Honestly
What we do today
- GDPR-aligned processing: data minimization, documented legal basis, deletion on request
- CCPA-aligned privacy-by-design approach
- Selective PII redaction before summarization content reaches the AI provider
- TLS 1.3 in transit, OAuth tokens encrypted at rest
- Data Processing Agreement (DPA) available on request
- Security brief for your vendor-review process on request
What we don't claim
- We do not yet hold a SOC 2 certification. We implement security, availability, and confidentiality controls, and we will pursue certification as the company grows.
- We are a small, focused company. If your review needs specifics our docs don't cover, ask us and you'll get a direct answer from the person who built the system.
Need a DPA or a Security Brief?
Email support@zenbriefr.com and we'll get you what your review needs. The full details are always in our privacy policy.
Start Free Trial →