Privacy Policy
Last updated: September 6, 2026
This policy explains how Zliding, operated by Dídac Cervera Garcia and Joel Pegueroles Pallarès (Tax IDs / DNI 23921650V and 48163385K respectively), Calle Pare Palau, 5, Entresuelo 2, 43001, Tarragona, Spain (“Zliding”, “we”), processes personal data when you use zliding.com (the “Service”). We are the data controller for the processing described here. Contact: .
1. Data we collect
- Account data. You can sign in with Google or by email code, through our authentication provider, Clerk. Signing in with Google gives us your name, email address and profile picture; signing in by email code gives us just your email address. If you set an interface language from Account settings, we store that preference against your account.
- Workspace and brand data. Information you provide about your business (including onboarding answers such as revenue range, team size, goals and referral source), a website URL you submit, and the brand profile we build from it, including content extracted from that website.
- Content. Media you upload (images, logos), prompts and inputs you provide, and content generated for you (slides, text, campaign proposals).
- TikTok connection data. If you connect TikTok: your TikTok profile information, video list metadata and the access tokens needed to publish on your behalf. Tokens are stored encrypted.
- Billing data. Subscriptions are handled by Polar (merchant of record). Every account has a billing record with Polar from sign-up: we send Polar your account email and your account identifier so that your plan (the free plan included) can be managed there. We receive your plan and subscription status; we do not receive full payment card details.
- Usage and device data. Product analytics events, pages visited, interactions, and technical data such as browser type and approximate location derived from IP. Sentry client-side monitoring records error details and performance information to help us detect, diagnose and resolve errors. It does not record Replay continuously: a Replay is recorded only when an error occurs.
- Server-side diagnostics and performance. When an error happens on our servers, or when we sample a request to measure performance, Sentry receives a diagnostic event. An error event contains the technical error message and stack trace produced by our code, an internal error code, an internal workspace identifier, the release and environment, the URL of the failing request, a limited set of request headers (your browser and operating system, preferred language, referring page, the origin and host of the request, the content type of the request, and, for Server Actions, an internal action identifier), and the data your browser sent with the action that failed. Because the error message and that data come from the operation you were performing, they can include content you provided, such as a prompt or a form field. A performance eventcontains timing information for a sampled request — the route and how long each step took — and does not include the content you submitted. Before any event is sent we remove all cookies and the headers that carry your IP address, and we automatically redact strings that look like access tokens or API keys. We do not enable Sentry's default collection of personal data, and we do not send navigation breadcrumbs from our servers.
- Consent record. When you are signed in, we store your cookie and telemetry consent decision and its history against your account: whether you accepted or rejected, the policy version you saw, where the choice came from, and when you made it. We keep this as proof of consent. It does not include your IP address or browser user agent.
- Email delivery record. For each account email we send, we keep a status record (pending, sent, failed, skipped), a retry count, and the timestamps of the attempts. This exists to avoid sending the same email more than once and to stop retrying an address that keeps failing. If you opt out of an email (see Section 2), we also record when you did.
- Contact form. When you send us a message through our contact form, we receive the email address you give us, an optional name and the text of your message. We do not store the message in our own database — it is delivered to our inbox by our email provider (Brevo), with your address set as the reply-to. The form is protected by Cloudflare Turnstile, which checks that the submission is not automated; Cloudflare receives your IP address and browser signals as part of that check. To stop the form being used to flood our inbox, we also store a keyed one-way hash of your IP address together with a submission count in our rate-limiting store. We never store your IP address itself, the hash cannot be reversed to it or linked back to your message, and the counter key is kept indefinitely (see Section 7).
- Sign-up velocity check. When you create a workspace, we compute a keyed one-way hash of your IP address (using a different key from the contact form) and count how many workspaces were created from that hash in a ten-minute window, to stop scripted bulk sign-ups. We never store your IP address itself, the hash is not linked to your account, and the counter key is kept indefinitely in the same rate-limiting store (see Section 7).
2. Why we process it (legal bases)
- To provide the Service (contract): account, account-onboarding emails, workspaces, content generation, publishing, billing status.
- Lifecycle and product emails (legitimate interests): a small number of emails prompted by what you do in the product — for example, a nudge if you have not published anything yet, or an offer to talk if you are getting real use out of Zliding. These are separate from the account-onboarding emails above, are sent through the same provider and address, and every one carries a one-click opt-out link that stops all of them; opting out never affects the account-onboarding emails, which you cannot opt out of while your account exists. You can also object to this processing at any time (see Section 8).
- Product analytics (consent): PostHog analytics. We use it only after you accept it in the consent banner.
- Error monitoring, performance and session replay (legitimate interests): Sentry helps us keep the Service secure, reliable and working correctly by detecting, diagnosing and resolving errors and performance issues. This processing applies regardless of your PostHog analytics choice or a Global Privacy Control signal. We do not enable Sentry's default collection of personal data. Before events are sent, we sanitize error messages, tokens, email addresses, cookies and request headers. Replay does not record continuously; it starts only after an error, masks all text and form inputs, and blocks media.
- Server-side diagnostics and performance (legitimate interests): keeping the Service secure, available and working correctly, and understanding what makes it slow. As described in Section 1, error events can include content from the request that failed; performance events do not. We limit this processing by sampling only a fraction of requests, removing cookies and the headers that carry your IP address, redacting values that look like credentials, and restricting who can access these events. This processing does not use cookies and does not depend on your cookie consent. You can object to it at any time (see Section 8).
- Contact form and its abuse prevention: we handle the message you send us so we can answer it. To keep the form from being used to flood our inbox or relay spam, we also run a Cloudflare Turnstile bot check and cap how many messages can be sent from the same connection in a short window, using a keyed one-way hash of your IP address (legitimate interests). You can object to this at any time (see Section 8).
- Sign-up velocity check: to stop scripted bulk sign-ups, we cap how many workspaces can be created from the same connection in a ten-minute window, using a keyed one-way hash of your IP address (legitimate interests). Ordinary shared connections such as a household or office are well under the cap. You can object to this at any time (see Section 8).
- Legal obligations: accounting, tax and responding to lawful requests.
- Legitimate interests: preventing abuse, enforcing our terms, defending legal claims.
3. AI processing
We use third-party AI models (accessed through the OpenRouter gateway) to analyze your brand and generate content. Your prompts, brand data and relevant content are sent to those providers to produce results. Depending on the provider and its data practices, those providers may retain or use your data to train or improve their models. Do not submit sensitive or confidential information to the Service. See the AI Transparency Notice for details. We do not make automated decisions about you that produce legal or similarly significant effects.
4. Your content is public by default
Media you upload and media generated for you are stored on publicly accessible URLs. Anyone with the link can access them, and they may be cached by CDNs. Do not include personal data you do not want public in uploaded or generated media. When you publish to TikTok, your content is transferred to TikTok and becomes subject to TikTok’s own policies.
5. Who we share data with
We share personal data with service providers that help us run the Service (see the Subprocessors page for the current list): application hosting (Vercel), cloud database and storage providers, Brevo (account-onboarding and lifecycle emails), Polar (billing, as merchant of record — for every account, not only paying ones), analytics (PostHog), error monitoring (Sentry), background job infrastructure (Trigger.dev), website analysis (Firecrawl), AI providers via OpenRouter, and Cloudflare Turnstile (bot protection on our contact form; Brevo also delivers contact-form messages). If you connect TikTok, data is shared with TikTok as an independent controller. We do not sell your personal data and we do not share it for cross-context behavioral advertising.
6. International transfers
Our providers may process data outside your country, including in the United States. Where personal data is transferred out of the EEA/UK, we rely on appropriate safeguards such as adequacy decisions or Standard Contractual Clauses. Sentry is configured to use its European data region (Germany).
7. Retention
We keep personal data while your account is active and as long as needed for the purposes above. Billing records are kept for the periods required by tax and accounting law. When you delete content or your account, we delete or anonymize the associated data within a reasonable period, subject to legal retention duties, backups and content already published to third-party platforms. Your consent record is kept as proof of consent for as long as your account exists and is erased when your account is deleted. Email delivery records and opt-out status are kept for as long as your account exists, to honor your opt-out and avoid re-sending to a failing address, and are erased when your account is deleted. Contact-form messages are not stored in our database; Brevo keeps transactional delivery logs under its own retention policy. The hashed-IP counters used for the contact form and the sign-up velocity check are kept indefinitely in our rate-limiting store, which has no per-key expiry; they hold only a keyed hash and a count, cannot be reversed to an IP address, and are not linked to any account or message.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to restrict or object to processing, and to withdraw consent at any time (without affecting prior processing). EEA/UK residents can lodge a complaint with their supervisory authority (in Spain, the AEPD; in the UK, the ICO).
California residents: you have the rights to know, delete and correct, and the right not to be discriminated against for exercising them. We do not “sell” or “share” personal information as defined by the CCPA/CPRA.
To exercise your rights, use . We respond within 30 days. We may need to verify your identity via your account email. For lifecycle and product emails specifically, the fastest way to object is the opt-out link in the email itself — it takes effect immediately, rather than waiting on a 30-day response.
9. Cookies, analytics and reliability monitoring
We use essential cookies for sign-in and preferences. PostHog analytics run only after you give consent and remain blocked when Global Privacy Control applies. You can withdraw consent at any time; withdrawal stops future PostHog analytics and does not affect processing that took place before withdrawal. Sentry error monitoring, performance tracing and error-triggered session replay are separate reliability processing under the legitimate-interest basis described in Section 2; they do not depend on your PostHog analytics choice or on Global Privacy Control. Details and choices are described in the Cookie Policy.
10. Security
We use encryption in transit, encrypt sensitive tokens at rest at the application level, and limit access to personal data. See the Security page for an overview. No system is 100% secure; if a breach affects you, we will notify you and the authorities as required by law.
11. Age requirement
The Service is for adults aged 18+. We do not knowingly process data of anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
12. Changes
We will post updates to this policy here and, for material changes, notify you by email or in-product notice before they take effect.
13. Contact
Privacy questions and requests: .