Privacy Policy
Last updated: 11 July 2026
1. Introduction
Control Zero (the “Service”) is a product built and operated by Typeless Pte Ltd, a private limited company incorporated in Singapore (“Typeless,” “we,” “our,” or “us”). This Privacy Policy describes how we collect, use, disclose, and safeguard information in connection with the Control Zero website, the Control Zero cloud platform, the self-managed and air-gapped deployments, and the Control Zero browser extension.
This is the single, authoritative Privacy Policy for Control Zero. It is a living document that we update from time to time; the current version will always be published on this page (see Section 15).
2. Scope
This Policy applies to:
- the Control Zero marketing website (controlzero.ai);
- the Control Zero cloud platform (app.controlzero.ai and api.controlzero.ai);
- the Control Zero browser extension, where available;
- the software development kits, command-line tools, and integrations we provide.
For self-managed and air-gapped deployments, the customer operates the software on its own infrastructure and is the controller of the data processed there. In those deployments Typeless does not receive or store that customer’s operational data unless the customer configures the deployment to send such data to Typeless, or provides it to Typeless for support, diagnostics, licensing, security, or account administration. The customer’s own privacy notice governs its deployment. This Policy then applies to our website and to any account, licensing, or support information the customer shares directly with us.
3. Information We Collect
Information you provide
- Account information (such as name, work email, and organization);
- Authentication information, API keys, session tokens, and related security credentials, which are protected using appropriate hashing, encryption, access controls, and key-management practices depending on the credential type;
- Configuration you create (policies, projects, environments, rules);
- Communications you send us (support requests, feedback).
Information collected automatically
- Usage and telemetry data (feature usage, API calls, request metadata);
- Log data (IP address, timestamps, error and diagnostic information);
- Device and browser information (browser type, operating system, extension version).
Browser extension data
Depending on the extension version and your organization’s configuration, the browser extension may handle user-generated content, form and composer input, website content, page URLs and domains, browser-surface metadata, organization and user identifiers, policy decisions and rule matches, and locally cached policy rules, as described in Section 5.
4. How We Use Information
- To provide, operate, secure, and maintain the Service;
- To apply the data-loss-prevention and governance policies configured by your organization;
- To create audit and enforcement records for your organization’s administrators;
- To authenticate users and manage access;
- To provide support and to send service and security notices;
- To detect, prevent, and address security incidents, abuse, and technical problems;
- To comply with legal obligations and enforce our agreements.
We do not sell personal data, and we do not use the content processed on behalf of a customer to train machine-learning models.
5. The Browser Extension
The Control Zero browser extension, where available or in preview, is an administered control that helps enforce an organization’s data-loss-prevention rules on supported web-based AI chat surfaces (such as Claude, ChatGPT, Gemini, and Perplexity). When installed and configured, it requires a Control Zero account and configuration from an administrator; without one it remains idle.
- On-device scanning.Depending on the extension version and your organization’s configuration, text that you type, paste, submit, or otherwise place into supported AI chat interfaces may be evaluated on your device against organization-configured rules. This scanning is intended to occur locally in the browser unless your organization configures a mode, endpoint, or support workflow that sends additional data for evaluation, logging, diagnostics, or evidence capture.
- What may leave the device.The extension may transmit policy-decision records and related metadata to your Control Zero backend at api.controlzero.ai or to your organization’s self-managed endpoint. Depending on configuration, transmitted fields may include rule identifiers, severity, action taken, page URL or domain, timestamp, extension version, organization and account identifiers, user or device identifiers where enabled, and evidence fields such as matched text, redacted excerpts, or hashes where configured. The extension may transmit matched snippets, redacted excerpts, or message content only where enabled by your organization or required to provide the configured feature. The exact fields depend on your organization’s configuration.
- Rules and caching. The extension retrieves the rules scoped to the browser surface from your Control Zero backend and caches them locally, refreshing periodically.
- Administrator control. Your organization configures whether the extension warns, masks, blocks, logs, permits override, or captures evidence. Typeless provides the software but does not control customer policy choices or customer administrator actions.
Where required by browser-store policy or applicable law, the extension may also present in-product privacy disclosures and consent or acknowledgement flows before handling user data. The extension operates alongside third-party AI services that have their own privacy practices. Typeless is not responsible for, and this Policy does not cover, the data practices of those third-party services (see Section 11).
6. Legal Bases and Your Rights
We aim to process personal data in accordance with applicable data-protection laws, including Singapore’s Personal Data Protection Act 2012 (“PDPA”) and, where applicable, the EU/UK General Data Protection Regulation (“GDPR”). Where we act as a data intermediary or processor for a customer, we process personal data on that customer’s instructions.
Where the GDPR applies and Typeless acts as a controller, our lawful bases may include: contract, for account and service administration; legitimate interests, for security, fraud prevention, diagnostics, product operation, enforcement, and business-to-business communications; consent, where required; and compliance with legal obligations. Providing account, authentication, configuration, and usage data may be necessary to create an account, administer access, provide the Service, comply with security requirements, or enter into or perform a contract; if you do not provide required data, some or all Service features may not be available.
The Service may make automated policy-enforcement decisions, such as warning, masking, blocking, logging, or allowing activity based on customer-configured rules. These decisions are intended to enforce organization policy and produce audit records; they are not intended by Typeless to produce legal or similarly significant effects concerning individuals unless a customer configures and uses them for that purpose.
Subject to applicable law, you may request to access, correct, delete, or export your personal data, to withdraw consent, or to object to or restrict certain processing. To exercise these rights, contact us at team@controlzero.ai. Where a request concerns data we process on behalf of an organization, we will refer it to that organization. If you are in Singapore and have a concern we cannot resolve, you may contact the Personal Data Protection Commission (PDPC). If you are in the EEA or UK, you may lodge a complaint with your local supervisory authority.
7. Data Sharing and Sub-processors
We do not sell personal data. We share information only as needed to operate the Service and only with the following categories of recipients:
- service providers and sub-processors that host infrastructure, deliver email, or provide analytics and error monitoring on our behalf, under confidentiality and data-protection obligations;
- your own organization and its administrators, in the case of enforcement and audit records;
- authorities or third parties where required by law, legal process, or to protect rights, safety, and the security of the Service;
- a successor entity in connection with a merger, acquisition, or sale of assets, subject to this Policy.
8. International Transfers
We may process and store information in Singapore and in other countries where we or our service providers operate. Where personal data is transferred across borders, we take steps intended to ensure it receives protection consistent with applicable law, including the PDPA transfer requirements and, where relevant, GDPR transfer mechanisms such as standard contractual clauses.
9. Data Security
We take reasonable and appropriate technical and organizational measures designed to protect information, including:
- encryption at rest for secrets and sensitive data;
- encryption in transit using TLS;
- access controls, authentication, and least-privilege practices;
- internal security reviews and dependency vulnerability scanning.
No method of transmission or storage is completely secure. While we work to protect information, we cannot and do not guarantee absolute security, and you provide information at your own risk.
10. Data Retention
We retain personal data for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. By default, audit and enforcement logs are retained for 90 days unless a different period is configured or required. For self-managed and air-gapped deployments, the customer controls retention on its own infrastructure. You may request deletion of your personal data as described in Section 6, subject to legal and operational limitations.
11. Third-Party Services and AI Providers
The Service, and in particular the browser extension, operates alongside third-party websites and AI providers (including, without limitation, Anthropic (Claude), OpenAI (ChatGPT), Google (Gemini), and Perplexity). These third parties are independent of Typeless and are governed by their own terms and privacy policies. Typeless does not control and is not responsible for the availability, content, security, or data practices of any third-party service, nor for how those providers collect, use, or retain the data you submit to them directly. Your use of those services is at your own risk and subject to their agreements.
12. Children
The Service is intended for organizations and their personnel and is not directed to children. We do not knowingly collect personal data from individuals under the age of 16. If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete it.
13. Disclaimers and Limitation of Liability
To the maximum extent permitted by applicable law, the Service and all related information are provided on an “as is” and “as available” basis, without warranties of any kind, whether express, implied, or statutory, including any implied warranties of merchantability, fitness for a particular purpose, non-infringement, or that the Service will be uninterrupted, error-free, or that it will detect or prevent every disclosure of sensitive information.
Control Zero is a cooperative control that assists an organization in enforcing its own policies; it is not a guarantee against data loss. Typeless is not responsible for a customer’s own configuration, administration, or use of the Service, for the acts or omissions of a customer’s users, or for the data practices of any third-party service or AI provider.
To the maximum extent permitted by law, Typeless and its affiliates, officers, employees, and agents will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of data, profits, revenue, or goodwill, arising out of or relating to this Policy or the Service. To the maximum extent permitted by law, Typeless’ total aggregate liability arising out of or relating to this Policy or the Service is limited to the amounts paid to Typeless for the Service in the twelve months before the event giving rise to the liability, or SGD 100 if no amounts were paid. Nothing in this section excludes or limits any liability that cannot be excluded or limited under applicable law. Additional terms, including further limitations of liability, may be set out in the agreement under which you access the Service, which will control in the event of a conflict.
14. Your Choices
- You can access and update account information within the Service.
- You may uninstall or disable the browser extension if permitted by your browser, device, and organization administrator settings. Enterprise-managed installations may need to be changed by your organization.
- You can opt out of non-essential marketing communications.
- You can contact us to exercise the data rights described in Section 6.
15. Changes to This Policy
This Privacy Policy is a living document. We will continue to update it as the Service, our practices, and applicable law evolve, and the current version will always be published on this page with the “Last updated” date above. Where a change is material, we will take reasonable steps to notify you. Updates apply from the stated effective date, except where applicable law requires notice, consent, or another legal basis before a change applies. Your continued use of the Service after an update takes effect may be subject to the updated Policy and any applicable customer agreement. We encourage you to review this page periodically.
16. Governing Law
This Policy is governed by the laws of Singapore, without regard to its conflict-of-laws principles, and is subject to any mandatory data-protection rights available to you under the law of your place of residence.
17. Contact Us
This Service is provided by Typeless Pte Ltd (Singapore). For privacy questions or to exercise your rights, contact our data protection contact at: team@controlzero.ai.