---
title: "Privacy Policy — Lodge"
url: https://withlodge.com/privacy
description: "How Lodge handles information."
---

# Privacy Policy

ZenMail LLC · Florida, United States

Effective September 6, 2026

Lodge is operated by ZenMail LLC, a Florida limited liability company (“we,” “us,” or “our”). This policy explains how we handle personal information in connection with the Lodge website, applications, workspace, and related support and services.

Your data moves differently depending on how you use Lodge. Local work, company collaboration, connected AI providers, and hosted execution each involve different information and recipients. The sections below explain those differences.

## Who this policy covers

This policy covers visitors to withlodge.com, people who contact us, Lodge account holders, and people who use a company’s Lodge workspace. It does not replace the policies of an employer, customer, AI provider, or other service you connect. The ZenMail email application has a separate privacy policy.

ZenMail LLC is responsible for information we use to operate our business, including website, account, security, and support information. When an organization supplies personal information in its workspace and determines how it should be used, we process that information on the organization’s behalf under its instructions and applicable agreement. The organization is responsible for its own notices and lawful use of that information.

If your organization provides your Lodge account, contact its administrator about workspace access, sharing, and requests concerning company-controlled information. You can also contact us, and we will help direct your request.

## Information you and your organization provide

You do not need to provide workspace content to browse the website. Some information is necessary to create an account, connect a service, or respond to a request; without it, the relevant feature or response may not be available.

Our website contact form prepares a draft in your email application. We receive the name, email, company, message, and other details in that draft only if you send the email. Website analytics measures selected actions, such as opening a draft, without collecting the form contents.

- Account and membership information: account identifiers, email address, display name, optional profile image, company and project memberships, roles, and authentication status.

- Workspace content: projects, assignments, discussions, documents, files, instructions, knowledge, AI results, and other information you or your organization choose to create, import, or share.

- Connections and permissions: information about connected accounts, credentials or access tokens needed for an authorized connection, and the permissions and settings you select.

- Support and business communications: your contact details and anything you choose to send, such as a question, attachment, diagnostic report, or rollout requirements.

- Commercial records: if you arrange paid services, the business contact, plan, order, billing, payment-status, and transaction information needed to manage that relationship.

## Information generated when you use Lodge

Our hosting and security providers process network and request information needed to serve and protect the Services, such as IP addresses, request times, browser information, and operational logs. This infrastructure processing is separate from the limited analytics described below.

The Lodge website sends PostHog selected page and interaction events, pseudonymous browser and session identifiers, browser and device characteristics, and limited error categories. We retain the referring website’s origin for attribution. The analytics boundary removes URL query strings and fragments, form values, page text, and raw error messages and stacks. We do not enable website session replay, automatic capture of page elements, or advertising pixels.

Lodge application telemetry records selected product actions, performance, and outcomes. It can associate events with pseudonymized account, company, and project identifiers. Pseudonymous information can still be personal information; it is not the same as anonymous data. Product telemetry is designed to exclude workspace messages, prompts, files, and AI output.

Operational records that form part of your workspace—such as an agent’s activity, approvals, results, and receipts—may contain work information needed to show what happened. Those records are different from product analytics.

## Local work and hosted work

Local workspace records and files are stored on your device. Local work is not uploaded to company collaboration storage merely because you create it locally. Signing in and using account, licensing, update, or telemetry features still involves limited communication with our services.

When you use shared company features, the information needed for collaboration is stored and processed in hosted systems and made available to authorized workspace members. When you use hosted execution, the selected instructions, context, files, results, and execution records are processed on hosted computers. A persistent computer or snapshot may retain files between runs.

Local execution does not mean that every part of a task stays on your device. A cloud AI model, connected application, website, or tool you authorize may receive the information needed to carry out the task. Your deployment, selected services, permissions, and organization settings determine those data flows.

## AI providers and connected applications

An AI request may include your instructions, relevant conversation context, selected documents or files, tool definitions, and tool results. A connected application may receive requests to retrieve, create, or change information. We process and transmit that information to carry out the features and actions you or your organization authorize.

We do not use private workspace content to train general-purpose AI models by default. The permission to operate Lodge in our Terms of Service does not grant permission for that training. If we ever offer a separate optional use of your content, we will explain it and obtain the permission required for that use.

AI providers and other connected services have their own terms, retention rules, and account settings, including any model-training controls. Those can differ between consumer accounts, business accounts, API plans, and custom endpoints. Check the provider and configuration you choose; this policy does not promise that every third-party service has the same practices.

[Terms for AI and connected tools](https://withlodge.com/terms#ai-and-actions)

## How we use information

If you ask to hear about Lodge, we may send the updates you request. You can ask us to stop promotional communications. Necessary messages about your account, security, purchases, or an active support request may continue.

- Provide the workspace, process authorized work, and make shared information available to the people and agents you authorize.

- Authenticate users, administer accounts and memberships, manage access, and support your selected deployment.

- Respond to inquiries, troubleshoot problems, provide support, and deliver agreed rollout or implementation services.

- Understand product use through limited analytics and improve performance, reliability, usability, and security.

- Manage plans, orders, payments, and business records, and send necessary account or service communications.

- Detect misuse, investigate incidents, enforce our agreements, resolve disputes, and comply with legal obligations.

## Legal bases for processing

Where applicable law requires a legal basis, we rely on the basis appropriate to the activity: performing a contract with you or taking steps you request before a contract; our legitimate interests in operating, securing, supporting, and improving Lodge; meeting a legal obligation; or your consent where required.

When we rely on legitimate interests, those interests must be balanced against your rights. When processing relies on consent, you may withdraw it for future processing without affecting processing that was lawful before withdrawal. For organization-controlled workspace data, the organization determines the applicable purposes and legal basis, and we act on its instructions.

## When information is shared

Current infrastructure includes Cloudflare for the website and related infrastructure, WorkOS for identity, Supabase for hosted data services, and PostHog for selected analytics. Not every provider receives every category of information. Additional providers depend on the features and connections you use. Contact us for information relevant to your company’s deployment.

We do not sell personal information or share it for cross-context behavioral advertising. We do not exchange personal information for financial incentives. We may use aggregated or de-identified statistics that do not reasonably identify you, and we do not attempt to re-identify that information except where legally permitted to verify de-identification.

- Within your workspace, with members, administrators, and agents who have access under your organization’s permissions and policies.

- With providers supporting hosting, storage, authentication, analytics, communications, security, and other functions needed to operate Lodge. We limit access to the purpose for which the provider is engaged.

- With AI providers, connected applications, and other recipients when you or your organization authorize the relevant connection, sharing, or action.

- With professional advisers or authorities when necessary to comply with law, establish or defend legal claims, investigate abuse, or protect people, rights, and security.

- With parties to a proposed or completed merger, financing, acquisition, or transfer of the business, subject to appropriate confidentiality and data-protection requirements.

[PostHog privacy information](https://posthog.com/privacy)

## Browser storage and analytics choices

The website uses local storage to remember your light or dark appearance preference and to hold PostHog’s pseudonymous analytics identifiers. Local storage is kept by your browser and is distinct from cookies. Authentication and other protected services may use cookies or similar storage to maintain access and security.

Our website analytics does not initialize or capture events when your browser sends a supported Do Not Track or Global Privacy Control signal. Those signals do not disable essential hosting or security processing and do not change your organization’s application settings.

You can use your browser’s controls to block or clear site storage. Clearing storage can reset your appearance preference and analytics identifier; it does not by itself stop new analytics events. To suppress website analytics, enable a supported privacy signal or use a browser control that blocks the analytics requests. Contact us if you need help with a privacy choice.

## How long information is kept

We keep information for the time reasonably needed for its purpose. Relevant factors include whether an account or customer relationship remains active, whether the information is needed for an ongoing project or support request, security and audit needs, contractual commitments, applicable retention duties, and unresolved claims.

Your organization may control the retention of shared workspace content. Local copies are also affected by your device and backup settings. Persistent hosted computers, snapshots, backups, and records kept for legal or security reasons can have different retention needs from active workspace content.

Signing out, removing a member, or revoking a connection is not the same as erasing all information. Deletion requests are handled under applicable law and customer agreements. We cannot automatically delete copies that another workspace member or independent provider lawfully controls; we can help identify the relevant party.

## How we protect information

We use technical and organizational safeguards designed to limit unauthorized access and protect the Services. Controls include authentication, access restrictions, protected credential handling, transport security, and controls around authorized execution. The controls that apply depend on the feature and deployment.

Protect your devices, accounts, backups, provider credentials, and administrative access. No security measure eliminates every risk. We will provide incident notices where required by applicable law or an agreement with your organization. Report a suspected issue to hello@withlodge.com.

[Read about Lodge security](https://withlodge.com/#security)

## International processing

ZenMail LLC is based in the United States. We and our providers may process information in the United States and other countries where the relevant services operate. The website’s PostHog analytics uses its US ingestion region. Connected services may process information in locations determined by their own arrangements.

Where a transfer is restricted by applicable data-protection law, the relevant transfer must have a permitted legal basis and required safeguards, such as an adequacy decision or approved contractual terms. Contact us for information about the arrangements relevant to your data. A specific residency or transfer commitment applies only where we have agreed it with your organization.

## Your privacy rights

Depending on your location and the law that applies, you may ask to access, correct, delete, or receive a portable copy of personal information; restrict or object to certain processing; withdraw consent; or appeal a decision about a request. You may also have the right to complain to a data-protection authority. We will not unlawfully discriminate against you for exercising these rights.

Send requests to hello@withlodge.com and describe your relationship with Lodge and what you would like us to do. We may need proportionate information to verify your identity or an authorized agent’s authority. Do not send passwords, provider keys, or unnecessary sensitive information. We respond within the time required by applicable law, explain applicable exceptions, and provide any required appeal information.

For company-controlled workspace content, contact your administrator first or ask us to direct the request. Some records may need to remain available to your organization or be kept under a legal obligation even when your personal account access ends.

[Make a privacy request](mailto:hello@withlodge.com)

## Additional information for US residents

Where state privacy laws apply, the categories described in this policy include identifiers and account details; professional or business information; commercial information; internet, device, and usage information; and the communications and workspace content you provide. We obtain these from you, your organization, your use of the Services, and authorized connected services. We use and disclose them for the purposes and to the recipient categories described above.

Workspace content can contain sensitive information if you or your organization provide it. We process that content to supply the requested services and for other purposes permitted by the applicable agreement and law, rather than inferring sensitive traits for advertising. The same retention criteria described above apply to each category.

We do not sell personal information or share it for targeted advertising across unrelated services. If a state law gives you access, correction, deletion, portability, opt-out, sensitive-data, authorized-agent, or appeal rights, you can contact us as described above. The website also honors supported Global Privacy Control signals for analytics.

## Children

Lodge is a work product intended for adults, not children under 18. We do not knowingly collect personal information from children through direct use of our Services. If you believe a child has provided personal information to us, contact hello@withlodge.com so we can investigate and take appropriate action. Organizations are responsible for the lawful content they place in their workspaces.

## Changes and contact

We may update this policy as Lodge or our information practices change. We will update the effective date and provide additional notice of material changes, and obtain consent, where required by law. A new policy does not remove rights you have under applicable law or a customer agreement.

For privacy questions and requests, contact ZenMail LLC, Florida, United States, at hello@withlodge.com. Please mention Lodge so we can route your request correctly.

[Email ZenMail LLC about privacy](mailto:hello@withlodge.com)

[Read the Terms of Service](https://withlodge.com/terms)

Questions? [hello@withlodge.com](mailto:hello@withlodge.com)
