Privacy Policy
Last updated July 28, 2026
This policy covers Zorva (the web app at zorva.app) and the Zorva Flow Capture browser extension. Both are part of the same product: the extension records a user's click-through of a web application, and the captured data is uploaded into that user's Zorva account for AI-generated documentation.
What we collect
When you use the Flow Capture extension to record a session, we collect:
- Website content — screenshots of the page you record, taken as you click through it.
- User activity— the elements you click and your scroll position during a recording, used to highlight the right spot in each screenshot and, if you enable video, to drive the recorded walkthrough's zoom effects.
- Web history (session-scoped) — the URL and page title of each screen you capture during a recording session. We do not track browsing outside an active capture session.
- Whatever else is visible on the page you choose to record— because screenshots capture the page as-is, this can include personally identifiable information, authentication information, or financial information if it happens to be visible on screen (for example, a name, email address, or account balance shown in the product you're documenting). We don't target or extract this specifically, but we don't redact it either — avoid capturing screens containing data you don't want stored.
The extension only records when you explicitly start a session. It does not run in the background or capture anything outside an active recording.
How we use it
Captured screenshots are sent to Google's Gemini API to generate a written description of each step, which becomes your flow's documentation. Captured data is otherwise used only to display your flows and generated documents back to you inside Zorva.
Where it's stored
Captured screenshots, videos, and flow data are stored in our database and file storage (provided by Supabase). Data is scoped to your organization's account — only members of your organization can see it. We do not sell captured data, and we do not share it with anyone outside of the service providers named in this policy (Supabase for storage, Google for AI description generation), who process it solely to provide Zorva's functionality to you.
Retention and deletion
Captured data is retained until you delete the flow or project it belongs to, at which point it is permanently removed. If you'd like your account and its data deleted entirely, contact us using the email below.
Account access
Zorva accounts are created for you by an administrator (invite-only) — there is no public signup. Your login is a standard email and password managed through our authentication provider (Supabase Auth).
Children's privacy
Zorva is a B2B product intended for business use and is not directed at children.
Changes to this policy
If this policy changes materially, we'll update the date at the top of this page.
Contact
Questions about this policy or your data can be sent to:
Karthik Lakshmanan
karthiklakshmanan.professional@gmail.com
+91 96774 34707