Skip to content

Privacy notice

This notice describes what Zyven (operated by Kryonix Labs) collects, why, and what you can do about it. It describes how the product works today. Zyven currently runs against provider sandbox environments; it does not yet process live bank or payment data.

What we collect

  • Account data you give us: your email address, a password (stored only as a salted scrypt hash), your business name and notification preferences.
  • Payment-processor data (Square): when a business owner connects Square, Zyven reads merchant profile, payments, refunds and payouts using read-only OAuth scopes. Zyven never receives card numbers.
  • Bank data (Plaid): when a business owner connects a bank account through Plaid Link, Zyven receives account balances, masked account identifiers and transactions. Your bank login credentials are entered only with Plaid and are never seen or stored by Zyven. Plaid's own end-user privacy policy applies to Plaid's handling of your data.
  • Usage and security records: sign-in and logout events, provider connect and disconnect events, approval decisions and error records with correlation IDs. These records do not contain passwords or provider tokens.

We do not use advertising cookies or third-party analytics on this site.

Why we use it

Only to compute your own business's cash position, payout timing, runway forecasts, profit figures and daily briefs, and to answer your questions about your own business inside the app. We do not sell your data and we do not share it with other businesses.

How we protect it

  • All traffic uses HTTPS with HSTS.
  • Provider access tokens are encrypted at rest (AES-256-GCM) and are overwritten when you disconnect a provider.
  • Each business's data is isolated by business identifier on every request.
  • Sessions expire after one hour and can be revoked immediately by signing out. Multi-factor authentication is not yet offered.

Kryonix Labs does not hold SOC 2, ISO 27001 or PCI DSS certifications. Our security practices are described in our information security policy, available on request.

Who else processes your data

  • Render hosts the application and its database in a managed cloud environment.
  • Plaid and Square provide the financial data you choose to connect, under their own terms.
  • OpenAI may receive summarised financial figures (never credentials, tokens or account numbers) when our background worker is configured to draft money-move suggestions with a language model. Suggestions are drafts only; Zyven does not move money, and approving a suggestion records your decision without initiating a transfer.

How long we keep it

Our retention target is: synced transactions are kept while your account is active plus 90 days, and deletion requests are completed within 30 days. Automated purging is not yet implemented; deletion is performed manually by our team as described on the delete account page. Platform backups may retain deleted records for a limited period after deletion.

Your choices

  • Disconnect Square or a bank account at any time from the Integrations page.
  • Turn daily email briefs on or off in Settings. New accounts start with email off.
  • Request a copy or deletion of your data by emailing [email protected] from your account email.

Changes and contact

We will update this page when the product's data handling changes. Contact [email protected] with privacy or security questions.

Operated by Kryonix Labs. Questions: [email protected]. Last updated 2026-09-28.