Privacy
Privacy Notice
Last updated: July 20, 2026
This notice explains how Zro handles data for its regional open-source model inference service.
Who operates Zro
MoonMath operates Zro and is responsible for the processing described in this notice. For privacy questions or requests, email privacy@moonmath.ai.
Data we process
We process prompts, completions, web-search queries, account identifiers, API-key metadata, selected inference regions, token and cost totals, billing records, security and reliability logs, and website or product events. We use this data to provide inference and tools, authenticate and secure the service, administer accounts, calculate usage, collect payment, prevent abuse, diagnose failures, and comply with legal obligations.
Purposes and legal bases
We process service, account, and billing data as necessary to perform our contract with you. We process limited security, fraud-prevention, reliability, and operational data for our legitimate interests in operating and protecting Zro. We process records when necessary to comply with accounting, tax, or other legal obligations.
Gateway and inference locations
Every inference request is authenticated and routed by our LiteLLM gateway in the European Union. Your API key determines whether model inference may run in Europe, the United States, or either region. If United States is enabled, prompt content may be transferred from the EU gateway to US inference infrastructure, the completion is generated there, and the response returns through the EU gateway. Region selection applies to model inference only; it does not determine where account, billing, authentication, analytics, web-search, or other service-provider processing occurs.
International transfers
Selecting United States instructs Zro to transfer inference request content to and process it on US infrastructure. Some service providers may also process personal data outside your country. Where data-protection law requires a transfer mechanism, we rely on an applicable adequacy decision, contractual safeguards such as Standard Contractual Clauses, or another lawful mechanism.
Prompt and request retention
By default, we do not retain prompt text, completion text, or request bodies after the inference request is processed. If you enable a feature that expressly stores content, such as history, request logging, debugging, or exports, we retain the related content and metadata until you delete or disable that feature or for the period stated when you enable it.
Training use
We do not use customer prompts, completions, request bodies, histories, or logs for model training, fine-tuning, evaluation datasets, or product analytics unless you separately and explicitly agree to that use.
Analytics and cookies
Google Analytics and browser-side PostHog EU process website and product events, device or browser information, page paths, and a Zro account identifier when you are signed in. We do not send prompt or completion bodies to these analytics services. PostHog product analytics is hosted in its EU cloud. We also send minimized server-side operational events to PostHog EU to measure account and service workflows.
Service providers
We use service providers including Clerk for authentication, Dodo Payments for billing, PostHog EU and Google Analytics for analytics, Brave Search for optional web search, and hosting or infrastructure providers for the gateway, database, networking, and inference. They receive only the data needed for their role and process it under their own locations, contractual terms, and legal obligations.
Infrastructure location
We operate inference across multiple regions. Account, billing, authentication, and operational vendors may process limited metadata required to provide their services.
Web search
When an agent invokes Zro web search, Zro sends the search query and the parameters needed to perform that search to the Brave Search API. We do not send the full conversation to Brave Search. Brave may process the query and related request metadata to return search results.
Retention
We retain account identifiers, API-key metadata, billing status, token totals, and usage-event records while your account is active and afterward only as needed for security, dispute resolution, accounting, tax, or other legal requirements. Analytics events are retained according to our configured provider retention periods. We delete or anonymize data when it is no longer needed for these purposes.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, or portability of personal data, or object to certain processing. You may also complain to your local data-protection authority. To exercise a privacy right, email privacy@moonmath.ai.
