Skip to content
Zushy Back to the diagnostic form →

Last updated · August 31, 2026

Privacy, explained plainly.

This policy explains what Zushy intends to collect during the early Make.com diagnostic pilot, why it is needed, and how people can control their information.

Pre-launch draft. Zushy’s legal operator name, contact address, final data region, and deletion workflow must be confirmed before collection begins.
On this page ScopeWhat we collectHow we use itSharingRetentionSecurityYour choicesContact

1. Who this policy covers

This policy applies when someone visits the Zushy website, sends a Make.com automation issue, provides optional evidence, or communicates with Zushy about that issue.

Zushy is an independent diagnostic service. It is not affiliated with or endorsed by Make.com.

2. Information we collect

Information you provide

  • Your name and work email address.
  • Your description of what a scenario should do and what happened instead.
  • The symptom and business-impact categories you select.
  • Additional sanitized evidence only if Zushy requests it separately.
  • Messages exchanged while reviewing the case.

Technical information

Cloudflare and Supabase may process ordinary request information such as IP address, browser type, device information, timestamps, and security logs. For submission rate limiting, Zushy converts the requesting network address into a keyed hash before storing a temporary counter; the raw address is not stored in the case record. Zushy does not currently use advertising cookies or behavioral profiling.

Information we do not ask for

Do not send passwords, API keys, access tokens, credentials, payment data, government identifiers, health information, or unsanitized client records. Remove unnecessary names, email addresses, customer content, identifiers, and image metadata from any evidence Zushy later requests.

3. Why we use information

Zushy uses case information to:

  • review the evidence and identify likely failure points;
  • reply with useful next checks and ask for missing evidence;
  • operate, secure, and troubleshoot the pilot;
  • prevent misuse and comply with legal obligations; and
  • improve the diagnostic process using de-identified patterns where practical.

Zushy does not sell personal information, use case contents for advertising, or make decisions about people solely through automated profiling.

Legal basis where required

Depending on where you live, processing may be necessary to take steps you request before providing the diagnostic service, to perform the service, to pursue legitimate interests in operating and securing the pilot, or to comply with law. Where consent is the appropriate basis, you may withdraw it for future processing.

4. When information is shared

Zushy uses Cloudflare Pages to deliver the public website, Supabase to validate and privately store submissions, and Cloudflare Turnstile to prevent automated abuse. These providers process information only as needed to provide and secure their respective services. Zushy may also disclose information to professional advisers under duties of confidentiality, or when required by law or necessary to protect people and the service.

The final policy must identify the selected Supabase data region and any international-transfer safeguards before submissions are enabled. Zushy does not authorize providers to use case content for their own advertising.

5. How long information is kept

The intended pilot rule is to keep the case record only while the diagnosis is active and for up to 90 days after the last case correspondence. Optional evidence is intended to be deleted no later than 30 days after the case closes, with deletion from routine backups following the backup cycle.

Some information may be kept longer when reasonably necessary to meet a legal obligation, resolve a dispute, prevent abuse, or establish legal claims. De-identified information that can no longer reasonably identify a person may be kept longer.

6. Security and evidence handling

Submissions are sent over HTTPS to a server-side validation function. Case records cannot be listed from the public website, public evidence uploads are disabled for the initial pilot, and privileged database credentials are not included in browser code. Zushy also uses field allowlists, request-size controls, duplicate protection, rate limiting, and automated-abuse verification. Access is intended to be limited to people who need it for the diagnostic. No internet service can promise absolute security.

You remain responsible for sanitizing any evidence requested later and for confirming that you are authorized to share information relating to colleagues, customers, or other third parties.

7. Your choices and rights

Depending on applicable law, you may ask to access, correct, delete, restrict, or object to the use of your personal information, or request a portable copy. You may also withdraw consent where processing relies on consent and complain to the relevant data-protection authority.

Zushy may need to verify your identity before completing a request. Some rights are subject to legal exceptions.

8. Children

The diagnostic pilot is intended for adults acting for themselves or an organization. Zushy does not knowingly collect information from children.

9. Changes to this policy

Zushy may update this policy as the pilot, its providers, or legal obligations change. The date at the top will be updated, and material changes will be highlighted before they take effect where reasonably possible.

10. Privacy contact

The legal operator name, physical or registered address, and monitored privacy contact must be inserted here before the form begins accepting submissions. Until then, this page is a working draft and should not be treated as the final notice.

Zushy
© 2026 Zushy
PrivacyTerms