Zeiterfassungsbuchhaltungsdurchführung

Privacy

Privacy policy

One policy for all of Zebu: this website, your account, your workspace, billing, emails, the desktop and mobile apps, the browser extension and connecting your own AI assistant.

I will never sell your data.This includes your personal information, time entries, invoices and client details. The service providers listed below process data only to run Zebu.

Who is responsible

Alan Woo, Leuschnerdamm 13, 10999 Berlin, Germany. Email hello@zebu.work, or use the contact form in the Impressum.

I have no data protection officer. The law does not require one for me.

Two roles

For this website, the waitlist, your account and billing, I decide how data is used. I am the controller.

The data you put into your workspace belongs to you: your team’s time, your clients and contacts, invoices, estimates, expenses and receipts. For that data, your business is the controller and I am your processor. I use it only to run the service for you, under the data processing agreement. People whose data is in your workspace should contact you first.

Visiting this website

zebu.work is hosted by statichost.eu in the EU. Like any web server, it receives your IP address, the page you ask for, the time and your browser details, in order to deliver and protect the site.

I count visits with GoatCounter: pages, referrers, browser and device type, screen size and approximate location. GoatCounter sets no cookies and, according to its privacy policy, does not store raw IP addresses.

If you choose a theme, the site stores it in your browser as zebu-theme until you clear it. A zebu-typed flag keeps the logo animation from repeating and lasts for the browser tab. Demos on the site use made-up data and run in your browser.

Downloads and the release list on the downloads page come from app-downloads.zebu.work, served by Cloudflare. The desktop app and the Firefox extension check the same address for updates. Cloudflare sees your IP address and the file requested.

The waitlist

If you join the waitlist, Zebu stores your email address and language. It sends one email to confirm the address (double opt-in), and later your invitation. The basis is your consent. I keep the entry until you sign up, or until you ask me to remove it.

Contacting me

The contact form sends your name, email and message to Zebu’s application server, which forwards it to me by email through Brevo. The server does not keep it. I use your details only to answer.

I delete enquiries 12 months after they are closed. Business letters I must keep under German tax law are kept for 6 years.

Your account

To give you an account, Zebu stores your name, email address, a hash of your password (never the password itself) or your passkey’s public key, your language, time zone and settings. Your workspace admin may also add a cost rate or other details about you.

When you sign in, Zebu stores the session with your IP address and browser details. Sessions end after about two weeks without use, or when you log out. Zebu records when a workspace was last used, at most once an hour, so unused free workspaces can be found and removed.

Your workspace

Each workspace has its own database and its own file folder. It holds what you and your team enter: time entries, projects, tasks, clients, contacts, invoices, estimates, expenses, receipts and imports.

Only your team, as your roles allow, can see it. I access it only to run the service, to fix a problem you report, or when the law requires it.

You can export everything at any time. When the owner deletes the workspace, its live data is removed immediately. Copies in the backups are gone within 90 days.

Invoices and estimates you send

When you email an invoice, estimate or reminder, Brevo delivers it on your behalf. The sender name is your workspace’s; the sending address is Zebu’s.

Invoice emails contain a tiny image loaded from Zebu’s own server. When your client’s mail program loads it, Zebu records that the email was opened. When your client opens the invoice link or downloads the PDF or XML, Zebu records that too. Each record holds the time, the browser details and a one-way hash of the IP address, never the IP itself. For estimates, Zebu records only when the link was first viewed. Your own visits are not counted.

You see this as “Email opened” and “Viewed by client” in the app. The records stay with the invoice until you delete it or the workspace.

Billing

Payments go through Stripe. Card and bank details go straight from your browser to Stripe; they never reach Zebu’s servers. Stripe also collects your billing address and works out VAT with Stripe Tax.

Zebu stores only Stripe’s customer and subscription ids, the payment method type and its last four digits, and Stripe’s fingerprint of the card or account. The fingerprint and the owner’s email address are used to allow one free trial per customer.

On the sign-up and billing pages, Stripe’s payment form may set its own cookies to prevent fraud. I keep invoices and payment records for up to 10 years, as German tax law requires.

Emails Zebu sends you

Brevo delivers Zebu’s emails: address confirmation, waitlist confirmation and invitation, password resets, team invitations, trial reminders, billing notices and warnings before an unused workspace is deleted. These are service emails. I do not send newsletters. Brevo records whether each email was delivered and opened; clicks on links are recorded in anonymised form. Invoice read receipts come from Zebu’s own server, as described above.

Desktop and mobile apps

The apps store your workspace address, your sign-in token and your preferences on your device. They talk only to your workspace, plus the update check described above for the desktop app.

Idle detection reports only that you were active and when, never what you were doing.

Using the browser extension

The extension talks to one server: your own Zebu workspace, at a name.zebu.work address or your own install. It contacts nothing else. No analytics, no tracking, no third parties.

Your browser stores the workspace name, its sign-in token, your saved starting points, the project last used on each site, and your settings. It also keeps the name and email your workspace returns, so you can see which account is connected.

It sends your workspace the time entries you create or edit: project, task, date, duration and a note. The note can include the page’s title, its address and any text you had selected. Page details are read only when you act. It never watches your browsing or keeps a list of the pages you visit.

The “Track time” button appears on GitHub, GitLab, Jira, Linear, Asana, Trello, Bitbucket, ClickUp and Basecamp. Other sites need your permission first. Idle detection is off unless you turn it on, and reports only how long the machine was idle, never what you were doing.

All its code ships inside the package. Disconnecting clears the token; uninstalling removes everything it stored.

Connecting your own AI assistant

AI assistant access (MCP) is off until you turn it on. Once you connect an assistant, it can read and draft what your role allows. That data then goes to the AI provider you chose, under that provider’s terms.

The optional coding-agent hook sends your workspace the event type, time, the agent session’s id, the repository path and its git remote. It never sends your prompts, the answers or file contents.

Zebu itself sends no data to any AI provider. CSV and JSON imports match columns without AI.

Cookies and browser storage

Zebu uses no advertising or tracking cookies. On app.zebu.work and workspace addresses it sets:

The app also keeps display preferences, such as theme and sort order, in your browser’s local storage. These are needed for the service, so they need no consent.

Hosting, backups and security

The app runs on a server of Hetzner Online GmbH in Helsinki, Finland. Encrypted backups are made every hour to a Hetzner Storage Box in the EU, and every night to hardware I control in Germany. Hetzner also keeps server images for 7 days. Backups are kept for at most 90 days.

Connections are encrypted. Passwords and access tokens are stored only as hashes. The admin area is reachable only over a private network. Healthchecks.io checks that Zebu’s scheduled jobs run; it receives no personal data.

Service providers

Transfers to the USA rely on the EU-US Data Privacy Framework where the provider is certified, and otherwise on the EU Standard Contractual Clauses.

How long data is kept

If Zebu is ever discontinued, I will email account holders at least 6 months before it ends, and you can export your data throughout that time.

Legal bases

Your rights

You can ask for access, correction, deletion, restriction or a copy of your data to take elsewhere. You can object to processing based on legitimate interests and withdraw consent. Write to hello@zebu.work.

You can also complain to a data protection authority. The one responsible for Zebu is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

Changes

I update this policy when Zebu changes. I tell account holders about important changes by email.

Last updated 23 September 2026