zillie Apply

Zillie Privacy Policy

Last updated: 26 September 2026

The short version

1. Who we are

Zillie is operated by Grace London Clinic Ltd, trading as Zillie, a company registered in England and Wales.

2. Our two roles

We are the controller for personal data about: - people who use a Zillie account on behalf of a practice; - people who apply for access or book a call with us; - anyone who contacts us; and - billing, security and running our business.

We are a processor for personal data a practice gives us to handle for its own purposes, including: - patient photographs and videos; - patient testimonials; - patient consent records; and - anything else about a practice's patients that it uploads.

For this data the practice is the controller. We use it only on the practice's documented instructions, under our Data Processing Agreement. The practice is responsible for having a lawful basis to use it and for telling its patients how their information is used.

3. What we collect and why

Account users. Name, email address, role, the practice you work for, your permissions and sign-in information. We use it to run your account, keep it secure and support you.

Applicants. What you tell us in your application: your details, your practice, what you practise, your regulator and registration number if given, your website and social accounts, and your answers to our onboarding questions. We also collect any call you book with us. We use it to decide on your application, which we check by hand, and to prepare for your call.

Practice content. Material a practice gives us so Zillie can write in its voice: its website, documents, service information, FAQs, existing posts, brand details, images and videos, and the drafts and posts made in Zillie. We may also read the practice's own public website.

Voice and video. Where a practice chooses to create a Zillie voice, it gives us a recording of a real person's voice. Our voice provider uses it to create a voice clone, which we use with the practice's images to make short video clips. The practice must have that person's permission first. Every clip Zillie makes is marked as AI-generated. When the account closes, we delete the voice clone from our voice provider.

Connected social accounts. When a practice connects an account (for example YouTube, Facebook, Instagram, Threads, LinkedIn or Bluesky), we receive what that platform's connection provides: - account or channel name and identifiers; - access tokens, which we store encrypted; - the posts published through Zillie and their publishing status; and - performance figures such as views and likes.

We never ask for social media passwords.

Post performance. For posts published through Zillie, we read the figures each platform makes available, such as YouTube views and likes and Bluesky likes. We read them regularly for up to 60 days after publication, then stop. We use them to show a practice how its content is performing and to plan future content.

Booking links. Links in your posts route through Zillie so clicks through to your booking page can be counted. We record that a link was clicked and when, and nothing that identifies the person who clicked it — no IP address, no device details, no cookie. They are forwarded straight to your own page.

Social listening. Where a practice turns it on, we search public posts on Bluesky and YouTube for the names the practice tells us it is known by, so it can see what's being said about it. We store a link to the public post, a short excerpt, the date and a tone label. Instagram, Facebook and X have no public search we can use, so they aren't included.

Research on public content. To show a practice what works in its field, we study publicly available posts from UK practices on platforms such as YouTube and Bluesky. We record measurements of how each post is put together: for example, whether it opens with a question, how long its opening is, and whether it's structured as a list. We record which account it came from only in a form that lets us count accounts. We never copy another practice's content for publication, and results are shown only as patterns across many posts.

Emails we send. We email applicants and account users about applications, bookings and their account. We keep a record of each email: who it went to, which kind of email it was, when, and whether it was delivered. We don't use open tracking or click tracking. Zillie doesn't email patients. Consent requests are sent by the practice itself.

Practices we contact. We may email UK practices, using business contact details they publish, to tell them about Zillie. We keep the practice's name, the contact's name and business email, and what was sent. You can ask us to stop at any time by replying to the email or writing to privacy@gracelondon.clinic, and we won't contact you again.

Technical information. IP address, browser and device details, sign-in times and security logs, used to keep the service secure and working.

4. Our lawful bases

Where we are the controller, we rely on:

Where we are a processor, the practice decides the lawful basis. For patient health information, the practice is also responsible for having a valid condition for processing special category data, normally the patient's explicit consent.

5. Patient material and consent

Photographs, videos and testimonials of patients can reveal information about their health. That is special category data under UK data protection law, and it needs extra care.

6. How we use AI

Zillie uses AI to: - read a practice's material and learn how it writes; - draft posts; and - check drafts against the advertising and professional rules the practice works under.

Every AI-written post is a draft. It is checked against the rules, and then a named, authorised person at the practice must approve it before it can be published. Zillie can't publish anything on its own, and only someone with reviewing rights can approve a post.

Our rule checks help practices, but they aren't legal or regulatory advice. The practice remains responsible for what it publishes.

We don't use AI to make decisions about people that have legal or similarly significant effects on them.

We use AI providers' business services, under terms that don't permit them to use the data we send to train their models.

7. YouTube and Google

Zillie uses YouTube API Services so practices can connect a YouTube channel, publish videos they have approved, and see how those videos perform. By connecting YouTube you agree to the YouTube Terms of Service (https://www.youtube.com/t/terms). Google's Privacy Policy (https://policies.google.com/privacy) explains how Google handles your data.

What we access: your channel's identifiers and name, the access permissions you grant on Google's consent screen, the videos you publish through Zillie and their status, and their view and like counts.

How we use it: only to provide the YouTube features you've chosen to use in Zillie. We don't sell it, use it for advertising, or share it except with the service providers who run Zillie for us.

Limited Use: Zillie's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Removing access: you can disconnect YouTube in Zillie, or revoke Zillie's access at any time at https://myaccount.google.com/permissions. We check daily whether access is still granted. When access is removed or the account is disconnected, we stop using it and delete everything we obtained from the YouTube API for that account — tokens, channel details, video identifiers and performance readings — within 30 days. Your own posts and their text stay with you.

8. Other connected platforms

Where a practice connects Meta (Facebook, Instagram and Threads), LinkedIn or Bluesky, we access only what's needed for the features it uses. Each platform's own privacy policy also applies. Accounts can be disconnected in Zillie at any time.

9. Who we share data with

We don't sell personal data. We share it only with the providers who help us run Zillie, under contracts that protect it:

Provider What they do for us Where
Supabase Database and sign-in Ireland (EU)
Microsoft Azure Hosting the Zillie application and website, and making video clips West Europe (Netherlands)
Anthropic AI drafting and analysis United States
OpenAI Creating images for posts United States
ElevenLabs Voice cloning, where a practice chooses to create a Zillie voice (receives a voice sample of a real person) Outside the UK (see section 10)
Resend Sending our emails Ireland (EU)
Google / YouTube YouTube connection and public search Global
Meta Facebook, Instagram and Threads connection Global
LinkedIn LinkedIn connection Global
Bluesky Bluesky connection and public search United States

We may also share data where the law requires it, or to protect our rights or the safety of others.

10. Transfers outside the UK

Some providers process data outside the UK, including in the United States. Where they do, we rely on UK adequacy regulations or on safeguards such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

11. How long we keep data

Data How long
Account information While the account is open, then 30 days after closure
Practice content (posts, media, documents) While the account is open, then 30 days after closure
Billing and financial records 6 years, as UK law requires
Applications that don't go ahead, and the calls booked from them Contact details removed 90 days after the application closes
Emails we sent you 12 months
Invitations you sent that were never accepted 12 months
Records of AI requests 12 months
Security and sign-in logs 12 months
Public mentions of your practice 12 months
Research measurements 12 months
Usage records 24 months
Booking-link clicks 24 months
Post performance figures Collection stops 60 days after each post; figures are kept while the account is open
Patient media As the practice instructs; deleted or returned when the account closes
Patient consent records and the compliance trail Kept while the account is open. After closure, returned to the practice in its data export and deleted from Zillie 30 days later, unless the law requires us to keep them
Social account tokens Until disconnected or no longer needed
Voice clones Until the practice deletes them or the account closes, then deleted from our voice provider
Contact records for practices we've emailed 12 months from the last contact, or removed straight away if you ask us to stop

We may keep data longer where needed to deal with a legal claim, meet a legal obligation or investigate a security incident.

12. How we protect data

No online service can be completely secure. Practices should keep their own accounts, devices and users secure too.

13. Data Processing Agreement

When we process personal data for a practice, our Data Processing Agreement applies (Schedule 1 of our Terms). It covers: - our instructions and confidentiality; - security; - sub-processors; - helping with individuals' rights requests; - breach notification; - international transfers; - deletion or return of data; and - audits.

14. Your rights

You have the right to: - see the data we hold about you; - have it corrected; - have it deleted; - restrict or object to how we use it; - take a copy to another provider; and - withdraw consent where we rely on it.

Some rights depend on the circumstances.

Email privacy@gracelondon.clinic to use them. We'll respond within one month.

If your information is held by a practice that uses Zillie, such as a patient photograph, please contact the practice directly. If you contact us instead, we'll pass your request to the practice and help it respond.

15. Complaints

Please contact us first so we can put things right. You can also complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/.

16. Cookies

In the Zillie application we use only what's needed to sign you in, keep your session secure and remember your settings: one cookie for the sidebar state, and browser storage for your sign-in session and screen preferences. We don't use advertising or analytics cookies, and booking links set no cookies. In the application, fonts are served from our own servers, so loading a page doesn't tell anyone else you visited. Our marketing website at zillie.ai loads its typeface from Google Fonts, so Google receives your IP address when you open a page there. The post checker on our website runs entirely in your browser; what you paste into it isn't sent to us or anyone else.

17. Children

Zillie is for adults acting for professional practices. Accounts aren't for anyone under 18. If a practice uses Zillie for material involving a child, the practice is responsible for having the right permission and safeguards.

18. Changes

We'll update this policy as Zillie and the law change. If a change matters, we'll tell account users before it takes effect. The date at the top shows the latest version.

19. Contact

Grace London Clinic Ltd (trading as Zillie) 64 Park Road, Hythe, Kent, CT21 6ET privacy@gracelondon.clinic Company number 15660834 · ICO registration ZB874887