The short version: Zoruko reads the one repository you grant, never touches your ad accounts, encrypts what it stores, and deletes your data when you ask. The sections below spell that out precisely.
01Who we are and what this covers
Zoruko ("we", "us") operates the service at zoruko.dev: an agent that audits your app or website code for broken ad signal setups and ships fixes as pull requests you review. This policy explains what data we collect when you use the site and the product, why we collect it, who processes it on our behalf, and the rights you have over it.
02Data we collect
- Account identity: your GitHub username and account id when you connect GitHub, and your name, email address and profile picture when you sign in with Google.
- Onboarding answers: what you advertise, your tracking stack, your role, team size, and the optional company and contact details you choose to share.
- Repository data: only the single repository you select through the GitHub App installation. We read it to produce findings and to open fix pull requests.
- Billing data: subscription status, plan, and credit usage. Payments are processed by Stripe; your full card number never reaches our servers.
- Usage records: audits run, fixes requested, credits spent, and the technical logs needed to keep the service reliable.
03What we never collect
- Your ad account credentials, tokens, or campaign data. Zoruko works entirely from your code, not your ad accounts.
- Repositories you have not explicitly selected. The GitHub App token is scoped to the one repo you grant.
- Your end users' personal information in plain form. User-level fields handled by monitoring code run inside your infrastructure and are hashed before anything reaches Zoruko.
We do not sell personal data, and we do not use your code to train models for other customers.
04How we use it
Onboarding answers tailor the diagnosis to your stack. Repository access powers the audit and the pull requests. Account identity ties your workspace, credits and billing together. Usage records meter credits and help us find and fix reliability problems. Where GDPR applies, we process this data to perform our contract with you and for our legitimate interest in operating and securing the service.
05Who processes data for us
We run on a small set of infrastructure providers, each receiving only what its role requires:
- GitHub: repository access and identity, under the app installation you control.
- Google Sign In: authentication when you choose the Google fast path.
- Google Cloud / Firebase: application hosting and database (EU region, europe-west1).
- Google Gemini API: analyzes excerpts of the selected repository to produce audit findings and fixes.
- Stripe: subscription payments and invoices.
- Meta: measurement of our own marketing site only, and only after you accept the cookie banner.
06Cookies and tracking
Essential cookies (your session, your workspace, your consent choice) are always on because the product cannot work without them. Analytics and ad measurement cookies (Meta Pixel, Google Analytics) are off until you accept the consent banner, and declining never blocks any functionality. Server measurement honors the same consent choice.
07Storage, security and retention
OAuth tokens are encrypted at rest (AES-256-GCM) and all traffic runs over TLS. Data lives in Google Cloud's EU region. We keep workspace data while your workspace is active; disconnecting GitHub revokes repository access immediately, and we delete stored data on request.
08Your rights
You can request a copy, correction, or deletion of your data at any time by emailing us. If you are covered by data protection law such as GDPR, KVKK, or LGPD, those rights apply in full and we respond within the statutory window.
09Children
Zoruko is a developer tool and is not directed at children under 16. We do not knowingly collect their data.
10Changes to this policy
When this policy changes we update the date at the top; for material changes we notify you in the product or by email before they take effect.