Legal

Privacy Policy

We built MyZolve to give you clarity and control over your life situations — and we hold ourselves to the same standard when it comes to your personal data.

Effective: March 29, 2026  ·  Employee of Choice Inc.

🔒 Overview

MyZolve is a Life Navigation OS built and operated by Employee of Choice Inc. ("we," "us," or "our"). This Privacy Policy describes how we collect, use, store, and protect information about you when you use the MyZolve platform, including our website at myzolve.com, our mobile applications, and all associated services (collectively, the "Service").

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

💡 Our commitment: We do not sell your personal information to third parties. We do not use your CaseVault documents, triage inputs, or personal situation data for advertising purposes.

📄 Data We Collect

We collect information you provide directly, information generated as you use the Service, and limited technical data.

Account Information

When you create an account, we collect:

  • Name and email address
  • Password (stored as a hashed, non-reversible value — we never store your plaintext password)
  • Profile information you choose to add (e.g., role, organization type)
  • Account preferences and settings

Navigator & Triage Submissions

When you use the Navigator or submit a triage inquiry, we collect:

  • The free-text description of your situation
  • Domain classifications (e.g., Work, Identity, Health, Legal, Financial)
  • Risk and urgency assessments generated from your input
  • Session history to provide continuity across conversations
  • Patterns and themes identified across your submissions (used only to improve your personal experience)

CaseVault Documents

CaseVault is your private case management space. We store:

  • Case titles, descriptions, and notes you create
  • Strategy notes and timeline entries you add
  • Documents and evidence files you upload
  • Case status, domain tags, and risk classifications

🔒 Your CaseVault data is private by default. It is never shared with your employer, any third party, or other users without your explicit action.

Academy Progress

If you use MyZolve Academy, we store:

  • Course enrollment and completion status
  • Module progress, quiz responses, and earned certificates
  • XP (experience points) and progression data

MyZolve Money (Financial Data)

If you connect or use the MyZolve Money features, we may collect:

  • Linked financial account names and balances (read-only, via your explicit authorization)
  • Transaction categories and spending patterns you configure
  • Budget containers, financial goals, and plan data you enter
  • Uploaded financial documents for AI-assisted review (e.g., pay stubs, benefit statements)

Communications

If you use the messaging feature to communicate with a Life Navigation Guide or advocate, we store:

  • Message content and timestamps
  • Consultation session notes (where applicable)

Technical & Usage Data

We automatically collect limited technical information when you use the Service:

  • IP address and general geographic region
  • Device type, browser, and operating system
  • Pages visited, features used, and session duration
  • Error logs and performance data

How We Use Your Data

Purpose Data Used
Provide the Service — powering Navigator, CaseVault, and all core features Account info, triage inputs, case data, session history
AI-Powered Triage — generating risk assessments, domain detection, and action steps Your Navigator submissions (sent to AI provider; see AI Processing)
Personalization — remembering your history, surfacing relevant insights Session history, case patterns, domain preferences
Financial Analysis — categorizing transactions, generating money insights and plans Financial account data (with your authorization)
Support & Communications — responding to questions, facilitating advocate connections Account info, messages, case context you share
Security & Fraud Prevention — detecting abuse, protecting user accounts IP addresses, usage patterns, authentication events
Service Improvement — fixing bugs, improving AI accuracy, developing new features Aggregated, de-identified usage data and error logs
Legal Compliance — meeting our legal obligations Account records, as required by law

We do not use your personal situation data, triage inputs, or CaseVault content to train AI models for use outside of your personal experience, and we do not sell this data to advertisers or data brokers.

🤖 AI Processing

MyZolve uses artificial intelligence to power its Navigator, triage engine, financial analysis, and JournAI features. When you submit text to these features, your input is processed by AI systems.

How AI Processing Works

Your Navigator inputs and relevant context are sent to OpenAI (our primary AI processing partner) to generate responses, domain classifications, risk assessments, and action recommendations. This data transmission occurs securely over encrypted connections.

ℹ OpenAI processes your inputs to generate AI responses. Per our agreement with OpenAI, your data submitted via API is not used to train their general models. See OpenAI's Enterprise Privacy for details.

What Is and Is Not Sent to AI

  • Sent: Your free-text Navigator inputs, relevant session history for context continuity, financial documents you submit for AI review
  • Not sent: Your password, payment card details, government-issued ID numbers

AI Output Disclaimer

AI-generated responses are informational only and do not constitute legal advice, financial advice, or professional counsel. Always consult a qualified professional for decisions with significant legal or financial consequences.

🔗 Third-Party Services

We use a limited set of trusted third-party services to operate the platform:

OpenAI

Used for all AI-powered features (Navigator, triage, financial analysis, JournAI). Your text inputs are transmitted to OpenAI for processing. OpenAI's privacy policy governs their handling of this data.

Authentication Provider

We use secure, standards-based email authentication (magic link login). Email delivery is handled by a third-party transactional email service. Your email address is shared with this provider solely for the purpose of delivering authentication emails.

Payment Processing

If you purchase credits or a subscription, payments are processed by Stripe, Inc. Stripe handles your payment card information directly — we never see or store your full card number. Stripe's privacy policy governs their data handling.

Cloud Infrastructure

The Service runs on cloud infrastructure provided by third-party hosting providers. Your data is stored on servers in the United States. Our infrastructure providers maintain industry-standard security certifications.

Analytics

We use lightweight, privacy-focused analytics to understand aggregate usage patterns (e.g., which features are used most). We do not use behavioral advertising platforms or cross-site tracking systems.

What We Do Not Do

  • We do not sell your data to any third party
  • We do not share your situation details, CaseVault content, or triage inputs with employers, institutions, or other users
  • We do not use Facebook Pixel, Google Ads remarketing, or other behavioral ad platforms

🛡 Data Storage & Security

Where Your Data Is Stored

All user data is stored in a PostgreSQL database hosted in the United States. Uploaded files are stored in secure cloud object storage. Data is not transferred outside the United States in the ordinary course of business.

Security Measures

We implement the following security controls:

  • Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS 1.2+ (HTTPS)
  • Encryption at rest: Sensitive data fields (including OAuth tokens for any connected integrations) are encrypted at rest using AES-256-GCM
  • Password hashing: Passwords are stored using bcrypt hashing — plaintext passwords are never stored
  • Access controls: Database access is restricted to application-level credentials; no direct public database access
  • Authentication: We use secure, time-limited magic link authentication to reduce password-based attack surfaces
  • HTTPS enforcement: All connections are forced to HTTPS with HSTS headers

Data Retention

We retain your account and case data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required by law to retain records. Anonymized, aggregated data may be retained indefinitely for service improvement purposes.

Security Incidents

In the event of a data breach that affects your personal information, we will notify you by email within 72 hours of becoming aware of the breach, to the extent required by applicable law.

👑 Your Rights

You have meaningful control over your data. The following rights are available to all users, regardless of jurisdiction:

Access

You may request a copy of all personal data we hold about you. We will respond within 30 days.

Correction

You may update or correct your account information at any time through the Settings page in the app.

Deletion

You may request deletion of your account and all associated personal data. To initiate account deletion, contact us at privacy@myzolve.com. We will complete deletion within 30 days. Note: deletion is permanent and irreversible.

Export / Data Portability

You may request an export of your CaseVault data, Navigator history, and Academy records in a machine-readable format (JSON). Contact us at privacy@myzolve.com to request a data export.

Opt-Out of Non-Essential Communications

You can unsubscribe from promotional emails at any time using the unsubscribe link in any email we send. Transactional and security-related emails (e.g., login links, account alerts) cannot be unsubscribed from while your account is active.

California Residents (CCPA / CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), including the right to know, right to delete, right to correct, right to opt-out of sale (we do not sell personal information), and the right to non-discrimination. To exercise any CCPA rights, contact privacy@myzolve.com.

EEA / UK Residents (GDPR)

If you are located in the European Economic Area or United Kingdom, you have rights under GDPR including the right to access, rectify, erase, restrict processing, and port your data. You also have the right to lodge a complaint with your local supervisory authority. Our legal basis for processing your data is your consent (for AI processing of your inputs) and performance of our contract with you (for providing the Service).

🍪 Cookies & Tracking

Essential Cookies

We use strictly necessary cookies and browser local storage to maintain your authentication session. Without these, you would be logged out on every page visit. These cannot be disabled without breaking core functionality.

Analytics

We use a privacy-focused, first-party analytics system to count page views and understand aggregate feature usage. This system does not use third-party cookies and does not track you across websites.

What We Do Not Use

  • No third-party advertising cookies
  • No cross-site behavioral tracking
  • No social media tracking pixels (Meta Pixel, TikTok Pixel, etc.)

Local Storage

We use browser local storage to maintain your login session token and user preferences. This data is stored on your device and is not transmitted to third parties.

👶 Children's Privacy

The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@myzolve.com and we will delete that information promptly.

Users between 13 and 18 should use the Service only with the consent of a parent or legal guardian.

🔄 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Effective" date at the top of this page
  • Send an email notification to registered users for significant changes
  • Display a notice within the Service

We encourage you to review this Policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated Policy.

Contact Us

For any privacy-related questions, requests, or concerns, please contact us:

Employee of Choice Inc. — Privacy Team

Email: privacy@myzolve.com

Product: MyZolve — myzolve.com

Entity: Employee of Choice Inc.

We aim to respond to all privacy requests within 5 business days and resolve them within 30 calendar days.