Skip to content
zebly
SecurityRequest early access

Security & data

Last updated September 24, 2026

Zebly is an executive assistant that works across your tools and acts on your behalf. It should always be clear what it can do and when it will ask first. This page explains that in plain language. The Privacy Policy has the details.

The short version

  • No AI training during early access. Nothing we collect is used to train AI models, ours or anyone else's. No opt-out needed. Google and Slack data are never used for training.
  • You decide what Zebly can reach. Connect only the tools you want, at the level you choose, and disconnect any of them at any time.
  • It asks before it acts. Zebly acts within limits you approve. When something falls outside them, it stops and asks.
  • Personal stays personal. Personal calendars can share busy times only, so Zebly never sees what the events are.
  • It speaks as your assistant, never as you. Zebly identifies itself as your AI assistant when it contacts people.

How Zebly works with your tools

Area What Zebly does with your permission What it won't do
Calendars Reads availability and the calendars you choose. Creates events you've approved and checks they landed. Move or delete existing events without your instruction. Read details from availability-only calendars.
Slack Works in conversations it's part of. Messages you and the colleagues you've approved. Mirror or export your workspace. Train on Slack data. Take instructions from anyone but you.
Email Reads your connected mailbox to notice meeting requests and follow replies. Coordinates with people from its own assistant mailbox, for tasks you've approved. Send email as you unless you explicitly turn that on.
Notes, docs, and tasks (as you connect them) Reads what's relevant to your requests. Updates pages or tasks you ask it to. Share documents outside the audience you approve.

Approvals come first. Every action traces back to something you approved, with its limits visible to you: who's involved, what may be shared, how many follow-ups, when it expires. Zebly re-checks your approval right before acting.

Other people's messages are information, not instructions. A reply or a document can inform what Zebly does next. It can't expand what you approved, add people, or change what gets shared.

The AI suggests; software decides. The model can propose an action, but Zebly's software checks your approvals and permissions before anything is sent, booked, or changed.

How we protect your data

  • Data is encrypted in transit, and connection credentials are encrypted at rest.
  • Each person's and company's data is kept separate.
  • Requests from connected services are verified before we act on them.
  • Links for connecting accounts are single-use and expire.
  • We keep only what active work needs, and we keep secrets and message content out of our logs.
  • We use frontier AI models from providers that don't train on your data and don't keep it after processing. The one exception: like every frontier AI provider, they may keep content their safety systems flag for possible abuse, for a limited time under their own policy, and never for training.

Zebly is a new product in early access. We don't hold security certifications yet, and we won't claim any until we do.

Disconnecting and deleting

  • Disconnect any tool from Zebly at any time. For Google, you can also revoke access at myaccount.google.com/permissions.
  • Delete imported data if you also want Zebly to remove what it brought in from that tool.
  • Delete your account to stop all work and remove your data. Things already sent to others, such as invitations and messages, stay with them.

Google user data

Zebly's use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

Report a vulnerability

If you think you've found a security issue, email security@zebly.com with a description and steps to reproduce it. Please:

  • give us reasonable time to fix it before disclosing it publicly
  • don't access, change, or delete other people's data; use your own account or test accounts
  • don't degrade the service, or use social engineering or physical attacks

We'll acknowledge your report and keep you updated. We won't pursue legal action against good-faith research that follows these guidelines. [CONFIRM safe-harbor wording with counsel.]

© 2026 Zebly

  • Privacy
  • Terms
  • Security
  • Contact