Private by design,
explained plainly.
Effective 15 July 2026. Zextha does not use analytics, advertising trackers, or non-essential tracking cookies.
Anonymous exploration
Maps created while signed out remain in browser memory or session storage. Zextha does not automatically upload anonymous projects to Supabase. Clearing the tab or browser data can remove them.
Accounts and private projects
Google sign-in is optional. Through Supabase, it uses only basic Google identity information—your email and profile—to create and protect your private Zextha account. Zextha does not request access to Gmail, Google Drive, Google Calendar, or other Google services. When signed in, Zextha stores your email, display name, private projects, project versions, compilation events, evidence, questions, scenarios, orders, and credit ledger entries so purchases and long-running work can be recovered. Database row-level security restricts user-facing access to the owner.
Shared map links
Zextha creates a map link only after you explicitly choose to share that map. Anyone with the unlisted link can explore its read-only snapshot for seven days. Your name, email, account details, credits, and Project Orbit history are not included. The raw link token is not stored, and you can revoke an active link from Project Orbit.
AI and research providers
Idea and map inputs may be sent from Zextha’s server to model providers through Mesh API. Deep Compile may also send bounded research queries to Tavily and supply retrieved evidence to model providers for analysis. Provider names and processing may change, but secret keys remain server-side. Do not submit confidential, regulated, or personal information you are not authorized to process.
Payments
Razorpay processes checkout and payment details. Zextha stores order identifiers, payment status, amount, and credit entries—not card or bank credentials. If an account is deleted, private project data is removed while payment audit records may be pseudonymized and retained when legally necessary.
Abuse prevention and retention
Temporary keyed hashes may be used for fair-use limits; raw IP history is not kept as product history. Project Orbit history expires automatically seven days after a project’s last update. Active Deep Compiles are protected until they finish or fail. Payment and credit audit records are kept separately when required for purchase integrity or legal obligations. Account export and deletion remain available from Identity Orbit.
Your choices
You may use free anonymous exploration without an account, export signed-in data, delete individual projects, sign out, or delete the account. Download a map before its seven-day Project Orbit window ends if you want to keep an offline copy. The optional sound preference lasts only for the current tab session.