Zeni ("Zeni", "we", "us") is operated by the Sahur team. Depending on where you downloaded the App, the data controller and seller of record is Le Ngoc Truong An for the Apple App Store (iOS) and Nguyen Hoang Hai for Google Play (Android); in this Policy "Sahur", "we", or "us" refers to them. This Privacy Policy explains what data the Zeni mobile app (the "App") — a personal and group money/expense tracker — collects, why, how we use it, and your rights. By using the App you agree to this Policy.
In short: Zeni does not sell your data, does not use it for advertising, and includes no analytics, crash-reporting, or tracking SDKs — your data is not used to track you. Some content you enter (spending text and receipt photos) is sent to Google Gemini to turn it into transactions (see §1c).
a) Account & identity — When you sign in with Sign in with Apple or Google Sign-In (handled by Firebase Authentication), we receive a user ID, your email, display name, and profile photo (if provided). Sign in with Apple may relay a private (proxy) email if you choose to hide your address.
b) Financial profile — Setup answers stored in Cloud Firestore: financial goals, income range, spending concerns, budget target, chosen AI-assistant personality, and selected categories.
c) Financial transaction data — The core of the App: amounts, categories, notes/descriptions, your raw input text, dates, income/expense type, wallets, savings "jars", budgets, spending limits, recurring items, group advances, and payment-source labels. For payment sources we store only a card's last 4 digits and the bank name/code — we never store your full card number.
d) Content sent to AI (Google Gemini) — To turn what you type (e.g. "coffee 45k") and your receipt images into structured transactions, that content is sent to Google Gemini. This happens when you enter a transaction by chat, scan/upload a receipt, or when the App detects recurring subscriptions from your transaction history. We ask for your explicit permission before using the AI features, and we do not send your data to the AI for advertising.
e) Receipt images — Receipt photos you capture or select are stored in Google Cloud Storage under your account for content extraction.
f) Location (optional) — If you grant permission, the App uses your approximate location while in use to tag where you spent (e.g. "District 1, HCMC"); the coordinates are converted to a place name via your device's OS. You can disable this anytime and still use the App.
g) Voice (optional) — For voice entry, audio is transcribed to text by Apple's on-device speech recognition. Zeni does not store audio.
h) Group data — When you invite a member, we process the invitee's email to deliver the invitation. In a shared group, other members can see the group's shared transactions and balances.
i) Subscriptions & purchases — Zeni Pro status, product IDs, expiry and trial state, processed by Apple / Google Play and managed via RevenueCat. We receive purchase status and an app-user identifier (your Firebase user ID). We never receive or store your full card or bank details.
j) Notifications — With your permission, a device token (FCM) to send reminders and alerts. The token is removed when you sign out.
k) Minimal technical data — Anti-abuse and usage counters (monthly AI / receipt-scan usage). Basic device/OS/app-version info needed to run the App.
What we do NOT collect: no analytics, crash-reporting, advertising, or tracking SDKs; no IDFA; no "Ask App Not to Track" prompt. Your data is not used to track you across other apps or websites.
To: create and secure your account; record, categorise and display your transactions and budgets; parse your text and receipts into transactions using AI; personalise suggestions; send reminders you opt into; process and restore purchases; provide support; and prevent fraud/abuse. We do not sell your personal data and do not use your financial data for advertising. Zeni is not a bank or financial adviser, and nothing in the App is financial, tax, or legal advice.
We process data to perform our contract with you (providing the App), based on your consent (e.g. location, AI features, notifications), and for our legitimate interests (security, fraud prevention). You may withdraw consent at any time.
We share data only with service providers that process it on our behalf, bound to protect it to a standard equal to this Policy:
To support invite-by-email, a user's basic profile (email, name, photo) may be looked up by other signed-in users within the App. We may disclose data if required by law or to protect rights and safety.
Zeni's primary data is stored in Google Cloud's asia-southeast1 (Singapore) region. Some providers may process data in other countries (e.g. the United States); where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses.
We keep your data while your account is active. Group-invite emails in the send queue auto-delete after 7 days. Transactions you created in a shared group may be retained by that group after you leave or delete your account, so the group's shared records stay intact. Content sent to Google Gemini is processed by Google under its terms; Zeni does not retain that content after the call.
Depending on your region (Vietnam's Decree 13/2023/NĐ-CP, GDPR, CCPA/CPRA), you may have rights to access, correct, delete, export, or restrict processing of your data, and to object or withdraw consent. California residents have the right to opt out of the sale or sharing of personal information; we do not sell or share your personal information as defined by the CCPA/CPRA. To exercise these, contact [email protected].
You can delete your account and data inside the App: Settings → Delete account. You may also request deletion at https://zeni.sahur.app/delete or by email. Deletion removes your profile, transactions, wallets, jars, budgets and associated personal data, revokes your Apple sign-in, and removes you from your groups. Some data may persist briefly in backups before permanent deletion, shared-group data may be retained as described in §6, and some billing records may be retained as required by law. Note: deleting your account does not automatically cancel an active subscription — cancel that separately in your App Store settings.
The App is a general-audience finance tool and is not directed to children. We do not knowingly collect data from children below the minimum digital-consent age in your country. If you believe a child has provided us data, contact [email protected] and we will delete it.
We use industry-standard measures (encrypted transport, authenticated access, server-side security rules) on Google's infrastructure. No method is 100% secure, but we work to protect your data.
We may update this Policy. Material changes will be notified in-app or by updating the effective date above.
Zeni ("Zeni", "chúng tôi") do nhóm Sahur vận hành. Tùy theo nơi bạn tải Ứng dụng, đơn vị kiểm soát dữ liệu và nhà phát hành là Le Ngoc Truong An đối với Apple App Store (iOS) và Nguyen Hoang Hai đối với Google Play (Android); trong Chính sách này "Sahur" hay "chúng tôi" là chỉ những cá nhân đó. Chính sách này giải thích ứng dụng Zeni ("Ứng dụng") — công cụ quản lý chi tiêu cá nhân & nhóm — thu thập dữ liệu gì, vì sao, dùng thế nào và quyền của bạn. Khi sử dụng Ứng dụng, bạn đồng ý với Chính sách này.
Tóm tắt: Zeni không bán dữ liệu, không dùng cho quảng cáo, và không tích hợp SDK phân tích/báo lỗi/theo dõi nào — dữ liệu của bạn không bị dùng để theo dõi bạn. Một số nội dung bạn nhập (văn bản chi tiêu & ảnh hoá đơn) được gửi tới Google Gemini để bóc tách thành giao dịch (xem §1c).
a) Tài khoản & danh tính — Khi bạn đăng nhập bằng Đăng nhập với Apple hoặc Google (qua Firebase Authentication), chúng tôi nhận mã người dùng, email, tên hiển thị và ảnh đại diện (nếu có). Đăng nhập với Apple có thể dùng email ẩn (proxy) nếu bạn chọn ẩn địa chỉ.
b) Hồ sơ tài chính — Câu trả lời thiết lập lưu trong Cloud Firestore: mục tiêu tài chính, khoảng thu nhập, mối bận tâm chi tiêu, hạn mức ngân sách, tính cách trợ lý AI, và danh mục bạn chọn.
c) Dữ liệu giao dịch tài chính — Phần cốt lõi: số tiền, danh mục, ghi chú/mô tả, văn bản gốc bạn nhập, ngày, loại thu/chi, ví, hũ tiết kiệm, ngân sách, hạn mức, khoản định kỳ, ứng tiền nhóm, nhãn nguồn thanh toán. Với nguồn thanh toán, chúng tôi chỉ lưu 4 số cuối thẻ và tên/mã ngân hàng — không bao giờ lưu số thẻ đầy đủ.
d) Nội dung gửi tới AI (Google Gemini) — Để chuyển câu bạn gõ (vd "cà phê 45k") và ảnh hoá đơn thành giao dịch, nội dung đó được gửi tới Google Gemini. Việc này xảy ra khi bạn nhập giao dịch bằng chat, quét/tải ảnh hoá đơn, hoặc khi app phát hiện khoản đăng ký định kỳ từ lịch sử giao dịch. Chúng tôi xin phép rõ ràng trước khi dùng các tính năng AI và không gửi dữ liệu cho AI vì mục đích quảng cáo.
e) Ảnh hoá đơn — Ảnh hoá đơn bạn chụp/chọn được lưu trong Google Cloud Storage theo tài khoản để trích xuất nội dung.
f) Vị trí (tuỳ chọn) — Nếu bạn cấp quyền, app lấy vị trí gần đúng khi đang dùng để gắn nơi bạn chi tiêu (vd "Quận 1, TP.HCM"); toạ độ được hệ điều hành chuyển thành tên địa điểm. Bạn có thể tắt bất cứ lúc nào và vẫn dùng được app.
g) Giọng nói (tuỳ chọn) — Khi nhập bằng giọng nói, âm thanh được nhận dạng trên thiết bị bằng dịch vụ của Apple. Zeni không lưu tệp âm thanh.
h) Dữ liệu nhóm — Khi bạn mời thành viên, chúng tôi xử lý email người được mời để gửi lời mời. Trong nhóm chung, các thành viên khác thấy được giao dịch & số dư chung của nhóm.
i) Đăng ký & mua hàng — Trạng thái Zeni Pro, mã sản phẩm, thời hạn, trạng thái dùng thử — do Apple / Google Play xử lý và quản lý qua RevenueCat. Chúng tôi nhận trạng thái mua và một định danh người dùng (Firebase user ID). Chúng tôi không nhận hay lưu thông tin thẻ/ngân hàng đầy đủ.
j) Thông báo — Khi bạn cho phép, một mã thiết bị (FCM) để gửi nhắc nhở & cảnh báo. Token bị xoá khi bạn đăng xuất.
k) Dữ liệu kỹ thuật tối thiểu — Bộ đếm chống lạm dụng & hạn mức (số lần AI/quét hoá đơn theo tháng); thông tin cơ bản về thiết bị/HĐH/phiên bản để chạy app.
Chúng tôi KHÔNG thu thập: không SDK phân tích/báo lỗi/quảng cáo/theo dõi; không IDFA; không hộp thoại "Cho phép theo dõi". Dữ liệu của bạn không bị dùng để theo dõi bạn trên app/website khác.
Để: tạo & bảo mật tài khoản; ghi, phân loại & hiển thị giao dịch và ngân sách; bóc tách văn bản và hoá đơn thành giao dịch bằng AI; cá nhân hoá gợi ý; gửi nhắc nhở bạn chọn nhận; xử lý & khôi phục giao dịch; hỗ trợ; và chống gian lận/lạm dụng. Chúng tôi không bán dữ liệu cá nhân và không dùng dữ liệu tài chính cho quảng cáo. Zeni không phải ngân hàng hay cố vấn tài chính, và không có nội dung nào trong app là tư vấn tài chính, thuế hoặc pháp lý.
Chúng tôi xử lý dữ liệu để thực hiện hợp đồng với bạn (cung cấp Ứng dụng), dựa trên sự đồng ý (vd vị trí, tính năng AI, thông báo), và vì lợi ích hợp pháp (bảo mật, chống gian lận). Bạn có thể rút đồng ý bất cứ lúc nào.
Chúng tôi chỉ chia sẻ với nhà cung cấp dịch vụ xử lý thay mặt chúng tôi, bị ràng buộc bảo vệ dữ liệu ở mức tương đương Chính sách này:
Để hỗ trợ mời theo email, hồ sơ cơ bản (email, tên, ảnh) của người dùng có thể được người dùng đã đăng nhập khác tra cứu trong app. Chúng tôi có thể tiết lộ dữ liệu nếu pháp luật yêu cầu hoặc để bảo vệ quyền và an toàn.
Dữ liệu chính của Zeni được lưu tại khu vực asia-southeast1 (Singapore) của Google Cloud. Một số nhà cung cấp có thể xử lý dữ liệu ở quốc gia khác (vd Hoa Kỳ); khi cần, việc chuyển dữ liệu dựa trên biện pháp bảo vệ phù hợp như Điều khoản Hợp đồng Tiêu chuẩn (SCC).
Chúng tôi giữ dữ liệu khi tài khoản còn hoạt động. Email mời nhóm trong hàng đợi tự xoá sau 7 ngày. Giao dịch bạn tạo trong nhóm chung có thể được nhóm giữ lại sau khi bạn rời/xoá tài khoản, để hồ sơ chung của nhóm không bị hỏng. Nội dung gửi tới Google Gemini được Google xử lý theo điều khoản của Google; Zeni không lưu lại nội dung đó sau lời gọi.
Tùy khu vực (Nghị định 13/2023/NĐ-CP của Việt Nam, GDPR, CCPA/CPRA), bạn có thể có quyền truy cập, sửa, xoá, trích xuất, hạn chế xử lý, phản đối hoặc rút đồng ý. Cư dân California có quyền từ chối việc bán hoặc chia sẻ dữ liệu cá nhân; chúng tôi không bán hoặc chia sẻ dữ liệu cá nhân của bạn theo định nghĩa của CCPA/CPRA. Để thực hiện, liên hệ [email protected].
Bạn có thể xoá tài khoản và dữ liệu ngay trong Ứng dụng: Cài đặt → Xoá tài khoản. Bạn cũng có thể yêu cầu xoá tại https://zeni.sahur.app/delete hoặc qua email. Việc xoá loại bỏ hồ sơ, giao dịch, ví, hũ, ngân sách và dữ liệu cá nhân liên quan, thu hồi đăng nhập Apple, và rời các nhóm của bạn. Một số dữ liệu có thể tồn tại ngắn trong bản sao lưu trước khi xoá hoàn toàn, dữ liệu nhóm chung có thể được giữ như nêu ở §6, và một số bản ghi thanh toán có thể được giữ theo luật. Lưu ý: xoá tài khoản không tự động hủy gói đang hoạt động — hãy hủy riêng trong Cài đặt App Store.
Ứng dụng là công cụ tài chính cho công chúng nói chung, không hướng đến trẻ em. Chúng tôi không cố ý thu thập dữ liệu của trẻ dưới độ tuổi đồng ý số tối thiểu tại quốc gia bạn. Nếu nghi ngờ có trẻ đã cung cấp dữ liệu, liên hệ [email protected] để chúng tôi xoá.
Chúng tôi dùng các biện pháp theo tiêu chuẩn ngành (truyền mã hoá, truy cập xác thực, security rules phía máy chủ) trên hạ tầng Google. Không phương pháp nào an toàn 100%, nhưng chúng tôi nỗ lực bảo vệ dữ liệu của bạn.
Chúng tôi có thể cập nhật Chính sách. Thay đổi quan trọng sẽ được thông báo trong app hoặc bằng cách cập nhật ngày hiệu lực ở trên.