Privacy Policy
1. Scope
This Privacy Policy explains what personal data Zala collects, why, and how it's handled, including data processed through our AI, hosting, authentication, and messaging sub-processors. It applies to the web app, our iOS and Android apps, and the Telegram and WhatsApp bots.
2. Data We Collect
Account & identity data
- Name and email address (via Clerk, our authentication provider)
- Authentication identifiers (Clerk user ID) and, if you sign in via Google or another social provider, basic profile info from that provider
Financial data you submit
- Expenses, income entries, categories, payment methods, notes, dates, and amounts you enter
- Receipt and invoice images you upload or send via Telegram or WhatsApp
- Savings goals, budgets, spending-alert thresholds, and account/asset balances you choose to track
Connector data
- Your Telegram chat ID and, if you link WhatsApp, your WhatsApp phone number — used solely to connect bot messages to your account
- Message content you send to the bot (text or voice notes) for the purpose of logging an expense/income
Billing data
- Subscription plan, trial status, and payment status. We never see or store your card number. If you subscribe on the web, payment is handled by Clerk Billing and Stripe; if you subscribe inside the Android app the purchase is handled entirely by Google Play, and if you subscribe inside the iOS app it is handled entirely by Apple. In both cases we receive only the fact that a subscription is active, when it renews or expires, and the amount, via RevenueCat
Usage & technical data
- Basic usage metrics (e.g., number of AI requests this month, feature usage) needed to enforce plan limits
- Standard web logs (IP address, browser type, timestamps) for security and troubleshooting
3. How We Use Your Data
- To provide core functionality: storing and displaying your ledger, computing dashboards/reports, and syncing across the web app, the iOS and Android apps, Telegram and WhatsApp
- To parse receipts, free-text, and voice messages into structured expense/income entries using AI
- To generate the "Insights" AI summaries and goal suggestions you request
- To send you notifications you've opted into (spending alerts, scheduled expense/income reminders, goal-achieved messages) via email, Telegram or WhatsApp
- To enforce plan limits and process subscription payments
- To maintain security, prevent abuse, and comply with legal obligations
We do not sell your personal data, and we do not use your financial data to serve you third-party advertising.
4. AI Processing Disclosure
When you scan a receipt, send a chat/voice message to log an expense, or ask an Insights question, the relevant text/image is sent to Anthropic's Claude API for processing, and the resulting structured data or written response is returned to Zala and stored in your ledger. If you send a voice note, it's first sent to OpenAI's transcription API to convert it to text, then that text is sent to Anthropic's Claude as described above. Anthropic and OpenAI each process this data as our sub-processors under their own API data-handling terms; treat any data you submit to either AI feature the same way you'd treat any other sensitive data you share with a service provider.
5. Sub-processors and Third Parties We Share Data With
We share the minimum data necessary with the following providers to operate the Service:
- Anthropic — AI processing of receipts, chat/voice messages, and insights (see Section 4)
- OpenAI — transcribing voice notes to text before they're passed to Anthropic (see Section 4)
- Clerk — authentication, session management, and subscription billing
- Stripe — payment processing for subscriptions (via Clerk Billing's managed Stripe account) and for one-time quota top-up purchases (via a separate Stripe account we operate directly)
- Sentry — error monitoring and crash diagnostics, to help us find and fix bugs
- PostHog — product analytics, so we can see which features are actually used and where people get stuck. Hosted in the European Union. We send only your Clerk user ID and counts of actions (for example, “3 transactions added” or “a plan was created”). We never send amounts, balances, merchant names, notes, categories, or any other content from your ledger.
- Google Analytics — web analytics for our website and web app, so we can see how many people visit, which pages they reach, and where they stop. It records page views, approximate location (country or city level), and technical details about your browser and device. It sets cookies in your browser, except for visitors in the EU, the EEA and the UK, where it runs without cookies (see Section 11). It does not receive your name, email address, or anything from your ledger.
- Microsoft Clarity — session recordings and heatmaps for our website and web app, so we can see where the interface confuses people. It records how a page is laid out and where you click, scroll and tap. It is configured to mask text, so recordings are not intended to show your amounts, balances, merchant names or notes — see Section 11 for what that does and does not guarantee. It sets cookies in your browser. It does not load at all for visitors in the EU, the EEA and the UK, who are never recorded (see Section 11).
- Upstash — database hosting for your ledger data (Redis)
- Vercel — application hosting, serverless functions, and file storage for receipt images (Blob storage). Vercel also provides the visitor counts on our website. That measurement uses no cookies at all: visitors are counted using a value derived from the request itself, which is discarded after 24 hours, so it cannot be used to recognise anyone or to follow them anywhere
- Telegram — delivering and receiving bot messages, if you link Telegram
- Meta (WhatsApp Cloud API) — delivering and receiving bot messages, if you link WhatsApp. Meta receives your WhatsApp phone number and the content of the messages you exchange with our bot, and handles them under its own terms
- Google Play — if you subscribe inside the Android app, Google is the seller of record. Google handles the payment, holds your payment details, and applies its own refund and cancellation rules. We never receive your card details
- Apple — if you subscribe inside the iOS app, Apple is the seller of record. Apple handles the payment, holds your payment details, and applies its own refund and cancellation rules. We never receive your card details
- RevenueCat — receives app-store purchase events so we know whether your subscription is active. It receives your Clerk user ID, the product you bought, and the status and dates of the subscription. It never receives anything from your ledger
We do not permit these providers to use your data for their own independent purposes; they process it only to provide their service to us.
6. Data Storage, Security, and Retention
Your data is stored in cloud infrastructure in the regions offered by our hosting providers. We use reasonable technical and organizational measures to protect it, including encrypted transport (HTTPS), access controls on our database and file storage, and automated daily backups retained for 7 days to help recover from accidental data loss. No system is 100% secure, and we can't guarantee absolute security.
7. Your Rights
Who controls your data. Zala Software FZ-LLC, Al Hulaila Industrial Zone, Ras Al Khaimah, United Arab Emirates, is the controller of the personal data described in this policy. You can reach us at info@zala-me.com.
If you are in the United Arab Emirates, your rights arise under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).
If you are in the European Economic Area or the United Kingdom, your rights arise under the GDPR or UK GDPR. You have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to withdraw consent where processing is based on it. Withdrawing consent does not affect processing carried out before you withdrew it.
If you are elsewhere, you may have similar rights under your local law (for example, the CCPA in California).
You may complain to a supervisory authority. If you are in the EEA or UK, you have the right to lodge a complaint with your local data protection authority. We would prefer you raise it with us first at info@zala-me.com so we can try to resolve it.
How to exercise these rights. Most are available directly in the app — editing or deleting entries, disconnecting a bot, deleting your account. For anything else, email info@zala-me.com. We respond within one month, as the GDPR requires, and sooner where we can.
7a. Why We Are Allowed to Process Your Data
Where the GDPR applies, we rely on the following legal bases:
| What we process | Why | Legal basis |
|---|---|---|
| Account and identity data | To create and operate your account | Performance of a contract (Art. 6(1)(b)) |
| Financial entries, receipts, messages you submit | To provide the record-keeping service you asked for | Performance of a contract (Art. 6(1)(b)) |
| Sending receipt images, messages and voice to our AI providers | To turn what you submit into structured entries and insights — the core function of the service | Performance of a contract (Art. 6(1)(b)) |
| Subscription and billing records | To take payment and meet accounting obligations | Contract, and legal obligation (Art. 6(1)(b), (c)) |
| Security logs, abuse prevention, backups | To keep the service and your data safe | Legitimate interests (Art. 6(1)(f)) |
| Optional notifications through Telegram or WhatsApp | Because you chose to connect that channel | Consent (Art. 6(1)(a)), withdrawable at any time by disconnecting |
We do not use your financial data for advertising, and we do not sell it.
7b. How to Delete Your Account
You can permanently delete your Zala account and all associated data at any time, directly from the app:
- Web app: Sign in at savings.zala-me.com, open the account menu, and choose Danger Zone → Delete Account.
- iOS app: Go to the Account screen → Danger Zone → Delete account.
- Android app: Go to the Account screen → Danger Zone → Delete Account.
If you can't sign in, email info@zala-me.com from the address on your account and we'll process the request manually.
What happens next
- Deletion isn't instant. Requesting it starts a 7-day grace period, during which you can sign back in and choose "Cancel deletion" if you change your mind or didn't request it yourself. We also email the address on file to confirm the request and give you that window to undo it.
- Once the 7 days pass, we permanently delete: your ledger (all expenses, income, goals, plans, and settings), any receipt/invoice images you uploaded, and your Telegram (and WhatsApp, if linked) connector links. Your sign-in identity (email, name) is also deleted from our authentication provider.
- Daily backups taken before your deletion date may retain a copy of your data for up to an additional 7 days after that backup was made, per our backup retention policy, after which it is also purged.
- We keep a minimal audit record of the deletion itself (an internal account ID and the deletion timestamp only, no names, emails, or financial data) for fraud-prevention and legal record-keeping purposes.
8. International Data Transfers
Because our infrastructure and AI providers may process data outside your home country, your data may be transferred internationally. Where required, we rely on our providers' own compliance mechanisms (such as standard contractual clauses) for these transfers.
9. Data Breach Notification
If we become aware of a security incident that compromises your personal data, we will notify affected users and, where legally required, the relevant regulator, without undue delay (and, where applicable law sets a specific deadline — such as 72 hours under the UAE PDPL — within that deadline).
10. Children's Privacy
The Service is not directed to, and should not be used by, anyone under 18. We do not knowingly collect data from minors.
11. Cookies and Analytics
What changed on August 31, 2026. Until this date, this policy said there was no analytics code in the web app and that we recorded no session replays. That is no longer accurate for the web app, and this section has been rewritten to describe what we actually run. We would rather correct the record plainly than leave a promise standing that the product no longer keeps.
We use four kinds of analytics, and they collect different things:
- PostHog runs entirely on our own servers. It never runs in your browser or app, sets no cookies, and sees only that an action of a given type happened and when — for example “a transaction was added”. It never sees the contents of your ledger. This is unchanged.
- Google Analytics runs in your browser on our website (zala-me.com) and our web app (savings.zala-me.com). Outside the EU, the EEA and the UK it sets cookies, records page views, and collects technical information about your browser and device along with an approximate location. Inside them it sets no cookies at all — see below. Because both sites share one measurement configuration, a visit that starts on our website and continues into the web app is recorded as one journey. We do not track you onto websites we do not operate, and we do not use any of this for advertising.
- Microsoft Clarity runs in your browser on the same two sites, outside the EU, the EEA and the UK, and records sessions — the layout of the page and where you click, scroll and tap — so we can see where people get stuck. It is configured to mask text content, which means a recording is intended to show the shape of a page and how you moved through it, not the numbers on it. Masking is a technical control and we test it, but we cannot promise it is perfect in every case, which is why we say plainly that we use it.
- Vercel Web Analytics counts visits to our website. It uses no cookies and stores nothing on your device. Visitors are counted using a value derived from the request itself, which is discarded after 24 hours, so it cannot be used to recognise you on a later visit or to follow you anywhere else. It runs the same way everywhere, including in the EU and the UK.
If you are in the EU, the EEA or the UK. You will not see a cookie banner on our website or in our web app, because we have arranged things so that there is nothing to ask you for. Google Analytics runs in cookieless mode for you: it writes nothing to your device and reads nothing from it, so we can see that a page was visited but cannot recognise you as the same person on a later visit. Microsoft Clarity does not load at all, so no session of yours is recorded and nothing about your visit is sent to Microsoft. This applies to both zala-me.com and savings.zala-me.com, and it is decided from the network location your request arrives from; if we cannot determine where you are, we treat you as though you were in the EU.
We chose this rather than putting a consent box in front of a personal finance app. Session recording is the part that genuinely warrants asking permission, and we would rather not run it in Europe than ask you for it. One thing we should be straight about: even in cookieless mode, Google still receives the IP address your request arrives from, uses it to work out an approximate location, and processes it outside the EU. Nothing is stored on your device, but that is not the same as nothing leaving it.
The mobile apps are different. There is no Google Analytics and no Clarity in the iOS app or the Android app. Neither records sessions, sets analytics cookies, or collects device or advertising identifiers.
If you would rather not be included. Browser privacy settings, tracking-protection features, and content blockers all prevent these tools from loading, and nothing in the Service depends on them — the app works exactly the same without them. Essential cookies required for authentication (via Clerk) are separate and cannot be turned off, because you could not stay signed in without them.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced in-app or by email before they take effect.
13. Contact
Privacy questions or data requests: info@zala-me.com.