Privacy
Last updated 8 September 2026. This describes what Zero kW collects, why, who else sees it, and how to get rid of it. It is written to be checked against the software rather than to cover every eventuality, so where it is specific, that is on purpose.
The short version
- We do not sell your data, and we do not share it for anyone else's advertising.
- We do not use analytics, advertising pixels or trackers, and nothing we wrote loads from anywhere but this server. Our hosting provider injects one script of its own into every page; we block it and we explain that below rather than leave it unmentioned.
- Your energy data is used to produce your reports, alerts and events, and for nothing else.
- You can delete everything yourself, from your account page, without asking us.
- We only reach your equipment or your utility account after you authorize it, and only for as long as you leave that authorization in place.
What we collect
Because you gave it to us
Your email address, and optionally your name, company, ZIP code and whether your site is residential or commercial. Sites you add: a label, an address if you enter one, the ZIP, and the utility and rate schedule that apply. Your password, which is stored only as a bcrypt hash — we cannot read it, and neither can anyone who obtains the database.
If you asked to be told when we open, we hold the email address you gave and, if you entered one, the ZIP code — nothing else. It is used to send one email, when we open. Replying to that email takes you off the list, and signing up removes you from it automatically.
If you add colleagues to your account, we hold their email address and the role you gave them, so that they can sign in. They are covered by everything below: they can ask us to delete their own record, and erasing the account erases them with it.
Because you connected a meter
Interval electricity readings — typically a kW or kWh figure every 15 minutes — either from a file you upload or, where you have authorized it, pulled from your utility. With them come the meter's identifier and service class as the utility labels them. This is the most sensitive data on the platform: interval readings describe when a building is occupied and when it is empty. It is used to produce your reports, to settle events against what actually happened, and for nothing else.
Because you connected equipment
What each device reports about itself — type, state, power, setpoints — and a record of every instruction we send it and how it responded. The access token the vendor issued us stays on our server; we never receive or store your password for their service.
Because you used the site while signed in
Which pages you opened, when, and which buttons you pressed — recorded only while you are signed in, so that we can see which parts of the product are actually used and which are not. We record the page name and the name of the action (for example "upload" or "analyze"), never what you typed, never what you uploaded, and never the contents of a form. We do not record your IP address or your browser here, and we do not track anyone who is not signed in. It is not shared with anyone, it is not used for advertising, and it is deleted with your account.
Because the software runs
Alerts and reports we have sent you, kept so we do not send the same one twice. Your subscription status if you are on a paid plan. Ordinary web server logs, which include IP addresses and are kept by our hosting provider on their own rotation. Our staff's administrative actions are logged for security; if you delete your account, your identifiers are removed from those records and only the action itself remains.
Cookies
Two, both strictly necessary, neither used for tracking:
- A session cookie so you stay signed in while you are using the
site. It is
HttpOnlyandSameSite=Lax, so it is not readable by scripts and does not travel with requests from other sites. - A "keep me signed in" cookie, only if you tick that box. It holds a random token, not your password, and you can drop it everywhere from your account page.
There is no consent banner because we set nothing that would need consent — no analytics, no advertising, no third-party cookies of our own.
One thing we did not put there
Our hosting provider adds a small analytics script of its own to every page it serves, from a domain they control. We did not ask for it, it is not ours, and we get nothing from it. We cannot stop them writing it into the page, so we send a Content-Security-Policy that tells your browser to load scripts only from this server, which is what stops it running. We have also asked them to switch it off at source. We would rather tell you it exists than claim a clean page and be caught out by anyone who looks.
Who else sees it
Four categories, and no others. We do not sell data, and we do not provide it to data brokers, advertisers or analytics companies.
- Our hosting provider stores the database and serves these pages, so they hold the data at rest as any host does.
- Stripe, if you buy a plan. They receive your email address and handle the payment; card details are entered on Stripe's own pages and never reach this server. Stripe keeps their own records to meet their tax and accounting obligations, which is why deleting your account here does not erase your payment history there.
- Your utility or device vendor, but only the ones you authorize, and only to the extent of asking for your data or sending an instruction you have agreed to.
- Anyone we are legally required to give it to, which has not happened.
Utility and device authorizations
When you connect a utility account or a device, you are sent to that company to sign in. We never see those credentials. They give us a token, we store it, and it is the only thing that lets us act on your behalf.
We ask for the narrowest permission that does the job: reading your usage, and where you have enrolled in a demand-response program, temporarily adjusting equipment during an event and returning it to the state it was in before. We do not use those permissions for anything other than the service you signed up for.
You can disconnect at any time from your account page, which destroys the token immediately. You can also revoke us from within the vendor's own app, and we would encourage doing both.
How long we keep it
Your energy readings are kept indefinitely, at the resolution they arrive in. We do not expire, thin or average them. The value of interval data is in the comparison — this August against last August — and a quarter hour we discard cannot be got back, because your utility will not re-issue it forever and most customer portals only offer a rolling window of a few months. Keeping it is what lets a report next year say something a report this year cannot.
Indefinitely means we never delete it on our own initiative. It does not mean we keep it against your wishes — see below. Sign-in links and half-finished authorizations expire in minutes, and "keep me signed in" tokens expire on their own and are cleared automatically: holding a measurement forever is a different thing from leaving a credential lying about.
When you delete your account, it goes immediately and completely. There is no grace period and no archived copy, which is worth knowing in both directions.
Your choices
- See it. Your account page shows your sites, reports and connections. Ask us and we will send you the rest in a machine-readable form.
- Correct it. Settings on your account page.
- Stop the emails. Turn off peak alerts or monthly reports in Settings. We will still send the few messages the account itself needs, like a password reset.
- Delete it. On your account page, under Delete your account and data. It is immediate, it is complete, and it does not go through us.
- Disconnect a vendor without deleting anything else, from the same page.
If you are in California, the CCPA gives you rights to know, delete, correct and opt out of sale or sharing. The controls above are how you exercise the first three. There is nothing to opt out of for the fourth, because we do not sell or share personal information, and we do not use it for cross-context behavioral advertising. We will not discriminate against you for exercising any of these.
Security, and its limits
Passwords are bcrypt hashes. Vendor tokens are held outside the web root where the server cannot serve them as files, and are never written to logs. Sign-in and authorization links are single-use and short-lived. Staff access needs a second factor. Every page is served with a Content-Security-Policy restricting scripts to this server, which limits what an injected or unexpected script can do — including the one described above.
None of that is a guarantee, and a policy that claimed otherwise would be worth less than one that does not. If we ever discover a breach affecting your data, we will tell you what happened and what was exposed rather than describe it in general terms.
Children
Zero kW is for people who pay an electricity bill. It is not directed at children under 13 and we do not knowingly collect their information. If you believe a child has given us something, tell us and we will delete it.
Changes, and how to reach us
If this policy changes in a way that affects what we do with data already collected, we will email you before it takes effect rather than quietly changing the date at the top.
Questions, requests, or anything that looks wrong: privacy@zerokw.com. A person reads it.