Zmooz

Last updated 1 September 2026

Privacy Policy

Zmooz ("we", "us") converts website designs into WordPress block themes at https://zmooz.com and provides the Zmooz Connect WordPress plugin. This policy explains what personal data we collect, why, who we share it with and the choices you have. Questions: privacy@zmooz.com.

1. Data we collect

We collect only what the service needs to work:

  • Account data — when you sign in with Google or GitHub we receive your name, email address, profile picture and the provider's account identifier.
  • Your designs — the design files you upload for conversion and the WordPress themes we generate from them.
  • Usage data — conversion history, credit balance and purchases, timestamps, and the IP address of requests (used for rate limiting and abuse prevention).
  • Payment data — handled by Stripe. We never see or store your card number; we keep Stripe's customer and payment identifiers and the receipt details Stripe returns.
  • Plugin pairing data — when you connect a WordPress site with Zmooz Connect: your site URL, a one-way hash of the connect key and access token, pre-flight check results (PHP version, memory limit and similar) and deploy progress events.
  • Error and diagnostic data — when something breaks, Sentry records the error, the request that caused it and technical details about the browser or server. We do not send your design files to Sentry.
  • Messages you send us — support emails and their contents.

2. Google account data

If you sign in with Google we request only your basic profile: name, email address and profile picture. We use it to create your Zmooz account, sign you in, show your name and avatar in the app and send you service emails about your conversions and purchases. We do not request or access any other Google data such as Drive, Gmail, Calendar or Contacts.

We do not sell Google account data, use it for advertising, or share it with anyone except the hosting provider that stores our database (see section 5). Zmooz's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

You can revoke Zmooz's access at any time at https://myaccount.google.com/permissions. Revoking access signs you out; your Zmooz account and data stay until you ask us to delete them (section 8).

3. How we use your data

We use personal data to:

  • run the service — convert your designs, deliver your themes and drive the Zmooz Connect deploy;
  • manage your account, credits and payments;
  • answer support requests;
  • keep the service secure — rate limiting, fraud and abuse prevention, debugging;
  • meet legal obligations such as tax and accounting records.

4. AI processing of your designs

Part of the conversion is automated with Anthropic's Claude models. We send excerpts of the uploaded design (the HTML and text of individual sections) to Anthropic's API so it can label sections and check that the file is a design export. We do not send your account data. Anthropic processes this content as our service provider and, under its commercial API terms, does not use API inputs or outputs to train its models.

5. Who we share data with

We do not sell personal data and we do not run advertising or third-party analytics. We share data only with the providers that run the service, each bound by a contract to process it on our instructions:

  • Hetzner Online GmbH (Germany) — servers, database and object storage for uploads, themes and backups.
  • Stripe — payment processing and receipts.
  • Anthropic — AI processing described in section 4.
  • Sentry — error monitoring.
  • Google and GitHub — sign-in only; they tell us who you are, we tell them nothing about your use of Zmooz.

6. Cookies

We use only strictly necessary cookies: a session cookie that keeps you signed in and a short-lived cookie that remembers an upload while you sign in. There are no advertising, tracking or third-party analytics cookies, so we do not show a cookie banner.

7. How long we retain data

We retain personal data only as long as the purpose it was collected for requires:

  • Uploaded designs and generated themes are deleted automatically when the download window shown on your dashboard ends (seven days by default).
  • Account and conversion records are kept while your account is active.
  • Payment records are kept for as long as tax and accounting law requires.
  • Plugin pairing tokens are deleted when you disconnect the plugin or when a new connect key replaces them; connect keys expire after fifteen minutes.
  • Server and error logs are kept only as long as needed for security and debugging.

8. Your rights and how to delete your data

You can ask us to access, correct, export or delete your personal data, or object to how we use it, by emailing privacy@zmooz.com. We answer within 30 days. If you ask us to delete your account we remove your account record, conversions, uploads and themes; we keep only what tax law requires. If you are in the EU or UK you also have the right to complain to your data protection authority.

You can also revoke Zmooz's access to your Google or GitHub account from those providers, and disconnect any WordPress site from Tools → Zmooz Deploy → Disconnect, which revokes that site's token immediately.

9. Security

All traffic uses HTTPS. Connect keys and plugin access tokens are stored only as one-way SHA-256 hashes, so a copy of our database cannot be used to impersonate a site. Access to production systems is limited to the people who operate the service. Nightly database backups are stored with the same provider as the service.

10. The Zmooz Connect WordPress plugin

The plugin sends data to zmooz.com only after you paste a connect key and click Connect. It then sends: the connect key and your site URL (once, to pair); pre-flight check results and deploy progress events, each with the access token (while you deploy); a request to download your generated theme; and a revoke request when you disconnect. It never sends your site's content, users or visitor data, and it adds nothing to your site's public pages.

11. International transfers

Our servers and storage are provided by Hetzner Online GmbH in the European Union. Stripe, Anthropic and Sentry are based in the United States and process data under standard contractual clauses or an equivalent lawful transfer mechanism.

12. Children

Zmooz is not directed at children and we do not knowingly collect data from anyone under 16.

13. Changes to this policy

When we change this policy we update the date at the top and, for significant changes, notify you by email or in the app before they take effect.

14. Contact

Zmooz — privacy@zmooz.com — https://zmooz.com