Privacy

Privacy Policy

Last updated: 2026-10-01

This policy explains what information we collect, why we collect it, who receives it, how long we keep it, and how you can ask us to show it to you or delete it. It covers:

  • people who visit zacharykysar.com; and
  • people we contact, or who contact us. Many of them are government buyers and business prospects.

Our products ayoai and Vinheim have their own websites. This policy does not cover those websites.

1. Who we are

We are Zachary Kysar, a sole proprietor in Windham, New Hampshire, USA. We do business as Zak Data Solutions. Our products ayoai and Vinheim are run by the same sole proprietorship. In this policy, "we", "us" and "our" mean Zachary Kysar.

2. What we collect from website visitors

Pages you visit

When you open one of our public pages, your browser sends our server a short record of the visit. We store:

  • the page address, without anything after a "?" or "#";
  • the address of the page you came from, cut down to the site name and page path;
  • a random ID that your browser creates for that tab, so we can group the pages you read in one visit;
  • your browser and device type, as your browser reports it;
  • your browser's language setting;
  • your country, as reported by Amazon CloudFront, the service that delivers our pages;
  • the tag from the link that brought you here, if it had one (see "Links in our emails" in section 3); and
  • the date and time.

We do not store your IP address in these records. We do not record visits to our sign-in page (/login), our admin pages (/admin), our unsubscribe pages (/unsubscribe) or the personal pages described in section 3 (/p/…). We began keeping these records on 29 September 2026.

Your IP address still reaches Amazon Web Services, which hosts the site, because that is how a page gets back to your browser. Amazon may keep technical logs of these requests.

Cookies and browser storage

Our code sets no cookies on our public pages. It keeps two small values in your browser's session storage, which your browser keeps for that tab only: the random tab ID, and the link tag if there is one.

Our sign-in pages use Amazon's sign-in service (Amazon Cognito). If you sign in, it keeps sign-in data in your browser, including cookies, so that you stay signed in. Only accounts we create can sign in.

No outside trackers

We use no outside analytics, advertising or social media trackers. Our pages load scripts, fonts and images only from our own site, so no company other than Amazon, which hosts the site, receives information from them. Links to other websites are ordinary links.

Messages you send through our contact form

If you use the contact form, we collect your name, your email address and your message. We also save a short label that says where you used the form. The label may be the page name, a tag from the link you followed, or your result on our Data-Quality Scorecard.

We store your message in our database. We also email it to our own inbox, with your address as the reply address, so we can answer you.

The scorecard runs in your browser, and your answers stay there. If you send us a message from the scorecard, the label includes only your overall score and tier.

Error reports

If something breaks on a page while you use it, your browser may send us an error report. The report includes the error details, the full address of the page (including anything after a "?") and your browser and device type. On our unsubscribe page, that address includes your email address. We email these reports to an internal inbox that our AI assistant reads (see section 3).

When something goes wrong, our server also writes details to our hosting provider's logs. These can include a page address or an email address.

3. What we keep about people we contact, and people who contact us

Where contact details come from

  • Government buyers and business prospects. We collect work contact details from public sources, such as agency websites and public contract notices (for example, on SAM.gov). When we find an address ourselves, our outreach draft can record where we read it and on what date, for example the web page that lists it. A first email without that record is flagged for the owner before he approves it.
  • People who write to us. We keep the details you send us.
  • People who signed up for ayoai or Vinheim. We may use the email address you signed up with to email you about that product. That email is signed by Zachary Kysar as the product's founder. We draft, approve and record it the same way as our other outreach emails.

What we keep

For each person or office we plan to contact, we may keep:

  • name, organization and work email address;
  • for a contracting officer named in a contract notice, a work phone number if the notice gives one;
  • a short note on why our work may suit them;
  • the emails we write to them: subject, text, attachments, and anyone we copy;
  • where and when we read their address, if we recorded it;
  • our record of who approved or rejected each email, when, and any reason given, and a record that it was sent, with the ID our email service gave it; and
  • notes about the contract opportunity the email is about, and its stage.

Personal pages

Some of our emails link to a page made for the organization we are writing to. Its address starts with zacharykysar.com/p/. The page shows the organization's name and our note on what we could build for it. It does not show your name or email address. These pages are hidden from search engines, but they need no sign-in, so anyone who has or guesses the link can open one.

When a personal page opens, we record that it opened and when. If someone opens the contact form on that page, we record that too.

Links in our emails

A link in one of our emails may carry a tag that names that email. If you follow it, the tag is saved with your page-visit records for that browser tab. This shows us which email led to which visits. Each email goes to a known person, so the tag can connect those visits to you.

What we do not track in email

Our emails are plain text. We add no tracking images, and we keep no record of whether you opened an email.

If our email to you can never be delivered, or if you mark it as spam, our email service tells us, and we add your address to our do-not-email list.

Emails you send us

If you email any @zacharykysar.com address, including a reply to one of our emails, we keep:

  • the full original message, stored by our email service;
  • a copy in our database of the sender's name and address, the recipient, the subject, the date and the text (up to about 30,000 characters); and
  • if our assistant drafts a reply, a copy of your message and address with that draft.

Email sent to our main address, zak@zacharykysar.com, is also forwarded to the owner's Gmail mailbox, where he reads and answers it. When we send an outreach email, a copy goes to our own inbox too. Please do not email us sensitive or controlled information.

Our AI assistant

We use an AI assistant, called omni, to help run the business. It is built on Anthropic's Claude models, which it uses through Anthropic's Claude Code, and it runs on our own servers. This website itself does not call any AI service.

The assistant:

  • looks for contract opportunities and public contact details;
  • drafts outreach emails;
  • reads the email we receive, including replies to our emails, contact-form notices and error reports, so it can sort them, draft suggested replies and route those drafts to the owner for approval; and
  • keeps working notes about opportunities, contacts and messages, outside this website.

Our code calls received email a "read-only learning feed" for the assistant. The assistant reads it and learns from it, for example what an agency is asking for, and keeps what it learns in its written notes. Here, learning means writing notes. It does not mean training an AI model.

The owner approves every outreach email, including every reply the assistant drafts, before our system sends it. He does this on our admin site, or by replying "approved" to an email about that message.

4. Why we use it

We use this information to:

  • answer messages and business enquiries;
  • find and contact organizations that may need our services, including government buyers, and follow up with people who signed up for our products;
  • see which pages and emails are useful, for example which email led to a visit;
  • honour opt-outs, and avoid sending the same email twice;
  • keep a record of who approved each email and when;
  • find and fix problems with the site; and
  • keep the admin area secure.

We do not send your information to advertising companies or data brokers.

5. Companies that receive your information

  • Amazon Web Services (AWS). AWS hosts the site (AWS Amplify) and delivers its pages (Amazon CloudFront). It runs our database (Amazon DynamoDB), our email sending (Amazon SES) and our admin sign-in (Amazon Cognito) in its us-east-2 region, in Ohio, USA. AWS also receives email sent to our addresses, stores it (Amazon S3) and forwards it (AWS Lambda). It passes bounce and spam-complaint notices to us (Amazon SNS).
  • Anthropic. Our AI assistant runs on Anthropic's Claude models. When the assistant works on a message or a record described in section 3, the text it is working on is sent to Anthropic to be processed. Anthropic handles that text under its terms for our account.
  • Google. Email sent to zak@zacharykysar.com is forwarded to the owner's Gmail mailbox. Google holds that copy under its terms for Gmail.
  • GitHub. The source code of this website is stored on GitHub, in a private repository. The code includes the names and work email addresses of some government contacts we have written to.

This site takes no payments, so no payment company receives your information.

6. How long we keep it

InformationHow long we keep it
Page-visit recordsEach record is deleted automatically about 400 days after the visit.
Personal-page records (page opened, contact form opened)Each record is deleted automatically about 45 days after it is made.
Contact-form messagesNo fixed time limit. We keep them until we delete them.
Contact details, email drafts, approval and send records, and opportunity notesNo fixed time limit.
Emails you send us (stored original, database copy, Gmail copy, and copies kept with reply drafts)No fixed time limit.
Our AI assistant's working notesNo fixed time limit.
Do-not-email listNo end date, so that we do not email you again.
Error reports and server logsOur code sets no time limit.

7. Your choices

Stop our outreach emails

Every outreach email we send ends with an opt-out link. Open the link and press the Unsubscribe button. Opening the page alone changes nothing; that step stops email security scanners from unsubscribing you by accident. You can also email zak@zacharykysar.com with the word "Unsubscribe".

We then add your address to our do-not-email list. Before our system sends an outreach email, it checks that list for the person it is addressed to and for everyone copied on it. If our database cannot be read at that moment, the check does not stop the email.

The list covers every email our outreach system sends, including follow-ups about our products. If you write to us yourself, the owner may still reply to you personally. To get our emails again, email us and we will take your address off the list.

Page-visit records

Page-visit records are sent by code that runs in your browser. If you turn off JavaScript, or use a blocker that stops the request, no record is sent. We do not respond to "Do Not Track" or "Global Privacy Control" signals.

See, correct or delete your information

Email zak@zacharykysar.com to ask what information we hold about you, or to ask us to correct or delete it.

  • How we check it is you. We write to the email address the request is about, and we act once we get a reply from that address.
  • How we handle it. By hand. We will tell you what we found and what we did, including anything we could not delete and why.
  • Page-visit records. These do not include your name or email address. We can find the ones tagged by a link in one of our emails to you. We usually cannot tell which other records are yours.

We keep your address on our do-not-email list even if you ask us to delete everything else, because that list is how we make sure we do not email you again.

8. Children

This site is for businesses and government buyers. It is not directed to children, and we do not knowingly collect information from children. Accounts on this site are for adults (18 or older) whom we invite; there is no public sign-up. If you think a child has sent us information, email us and we will delete it.

9. Security

Here is what we do today:

  • The site uses encrypted HTTPS connections, and it tells browsers not to use anything else.
  • Our pages run scripts only from our own site.
  • The admin area needs a sign-in. Only accounts we create, in our admin group, can open it. There is no public sign-up.
  • Our database is not open to the public. Only our server and our own tools can read it.
  • Opt-out links carry a secret signature, so other people cannot unsubscribe you.
  • Before we act on a bounce or spam-complaint notice, we check that it really came from Amazon.

No system is perfectly secure. If a security breach exposes your information, we will tell you when the law requires it.

10. Changes to this policy

When we change this policy, we will post the new version on this page and change the "Last updated" date at the top.

11. Contact

Questions and requests: zak@zacharykysar.com

By post: Zachary Kysar (Zak Data Solutions), 5 Farrwood Rd, Windham, NH 03087, USA