Zeni

Privacy Policy

Effective date: 18 July 2026 · Last updated: 18 July 2026

Zeni ("Zeni", "we", "us") is operated by the Sahur team. Depending on where you downloaded the App, the data controller and seller of record is Le Ngoc Truong An for the Apple App Store (iOS) and Nguyen Hoang Hai for Google Play (Android); in this Policy "Sahur", "we", or "us" refers to them. This Privacy Policy explains what data the Zeni mobile app (the "App") — a personal and group money/expense tracker — collects, why, how we use it, and your rights. By using the App you agree to this Policy.

In short: Zeni does not sell your data, does not use it for advertising, and includes no analytics, crash-reporting, or tracking SDKs — your data is not used to track you. Some content you enter (spending text and receipt photos) is sent to Google Gemini to turn it into transactions (see §1c).

1. Data we collect

a) Account & identity — When you sign in with Sign in with Apple or Google Sign-In (handled by Firebase Authentication), we receive a user ID, your email, display name, and profile photo (if provided). Sign in with Apple may relay a private (proxy) email if you choose to hide your address.

b) Financial profile — Setup answers stored in Cloud Firestore: financial goals, income range, spending concerns, budget target, chosen AI-assistant personality, and selected categories.

c) Financial transaction data — The core of the App: amounts, categories, notes/descriptions, your raw input text, dates, income/expense type, wallets, savings "jars", budgets, spending limits, recurring items, group advances, and payment-source labels. For payment sources we store only a card's last 4 digits and the bank name/code — we never store your full card number.

d) Content sent to AI (Google Gemini) — To turn what you type (e.g. "coffee 45k") and your receipt images into structured transactions, that content is sent to Google Gemini. This happens when you enter a transaction by chat, scan/upload a receipt, or when the App detects recurring subscriptions from your transaction history. We ask for your explicit permission before using the AI features, and we do not send your data to the AI for advertising.

e) Receipt images — Receipt photos you capture or select are stored in Google Cloud Storage under your account for content extraction.

f) Location (optional) — If you grant permission, the App uses your approximate location while in use to tag where you spent (e.g. "District 1, HCMC"); the coordinates are converted to a place name via your device's OS. You can disable this anytime and still use the App.

g) Voice (optional) — For voice entry, audio is transcribed to text by Apple's on-device speech recognition. Zeni does not store audio.

h) Group data — When you invite a member, we process the invitee's email to deliver the invitation. In a shared group, other members can see the group's shared transactions and balances.

i) Subscriptions & purchases — Zeni Pro status, product IDs, expiry and trial state, processed by Apple / Google Play and managed via RevenueCat. We receive purchase status and an app-user identifier (your Firebase user ID). We never receive or store your full card or bank details.

j) Notifications — With your permission, a device token (FCM) to send reminders and alerts. The token is removed when you sign out.

k) Minimal technical data — Anti-abuse and usage counters (monthly AI / receipt-scan usage). Basic device/OS/app-version info needed to run the App.

What we do NOT collect: no analytics, crash-reporting, advertising, or tracking SDKs; no IDFA; no "Ask App Not to Track" prompt. Your data is not used to track you across other apps or websites.

2. How we use your data

To: create and secure your account; record, categorise and display your transactions and budgets; parse your text and receipts into transactions using AI; personalise suggestions; send reminders you opt into; process and restore purchases; provide support; and prevent fraud/abuse. We do not sell your personal data and do not use your financial data for advertising. Zeni is not a bank or financial adviser, and nothing in the App is financial, tax, or legal advice.

3. Legal bases (EEA/UK users)

We process data to perform our contract with you (providing the App), based on your consent (e.g. location, AI features, notifications), and for our legitimate interests (security, fraud prevention). You may withdraw consent at any time.

4. Sharing & processors

We share data only with service providers that process it on our behalf, bound to protect it to a standard equal to this Policy:

To support invite-by-email, a user's basic profile (email, name, photo) may be looked up by other signed-in users within the App. We may disclose data if required by law or to protect rights and safety.

5. International transfers

Zeni's primary data is stored in Google Cloud's asia-southeast1 (Singapore) region. Some providers may process data in other countries (e.g. the United States); where required, transfers rely on appropriate safeguards such as Standard Contractual Clauses.

6. Data retention

We keep your data while your account is active. Group-invite emails in the send queue auto-delete after 7 days. Transactions you created in a shared group may be retained by that group after you leave or delete your account, so the group's shared records stay intact. Content sent to Google Gemini is processed by Google under its terms; Zeni does not retain that content after the call.

7. Your rights

Depending on your region (Vietnam's Decree 13/2023/NĐ-CP, GDPR, CCPA/CPRA), you may have rights to access, correct, delete, export, or restrict processing of your data, and to object or withdraw consent. California residents have the right to opt out of the sale or sharing of personal information; we do not sell or share your personal information as defined by the CCPA/CPRA. To exercise these, contact [email protected].

8. Account & data deletion

You can delete your account and data inside the App: Settings → Delete account. You may also request deletion at https://zeni.sahur.app/delete or by email. Deletion removes your profile, transactions, wallets, jars, budgets and associated personal data, revokes your Apple sign-in, and removes you from your groups. Some data may persist briefly in backups before permanent deletion, shared-group data may be retained as described in §6, and some billing records may be retained as required by law. Note: deleting your account does not automatically cancel an active subscription — cancel that separately in your App Store settings.

9. Children's privacy

The App is a general-audience finance tool and is not directed to children. We do not knowingly collect data from children below the minimum digital-consent age in your country. If you believe a child has provided us data, contact [email protected] and we will delete it.

10. Security

We use industry-standard measures (encrypted transport, authenticated access, server-side security rules) on Google's infrastructure. No method is 100% secure, but we work to protect your data.

11. Changes to this Policy

We may update this Policy. Material changes will be notified in-app or by updating the effective date above.

12. Contact

Sahur — [email protected] — https://sahur.app
Data controllers: Le Ngoc Truong An (Apple App Store / iOS) · Nguyen Hoang Hai (Google Play / Android).