Legal
Privacy Policy
Last updated: October 4, 2026
Zeno is built on a simple idea: you should be able to understand and control your recurring spending without handing over your bank login or your privacy. This policy explains what we collect, why, and the choices you have.
1. Overview
This Privacy Policy applies to the Zeno marketing website (zenoapp.in), the Zeno waitlist, and the Zeno mobile application once it launches (together, the “Service”). Zeno is operated by the Zeno team (“Zeno,” “we,” “us”). By using the Service you agree to the practices described here.
Our guiding principles are straightforward: we collect the minimum we need, we keep your sensitive financial data encrypted on your device rather than on our servers, we never require your bank login, and we do not sell your personal data.
2. Data we collect
Waitlist data
When you join the waitlist, we record your email address and the date and time you signed up, in a private spreadsheet only we can open (stored by Google; see section 6). That is all we need to email you about availability.
In-app subscription data
Inside the app, Zeno builds a picture of your recurring charges — service names, amounts, billing cadence, renewal dates, free-trial end dates, and the notes or tags you add. This subscription data is stored encrypted on your device and is not uploaded to Zeno servers.
Account & contact data
If you create a paid Zeno plan at launch, we (or our app-store billing partners) will process the information needed to manage that subscription, such as your store account identifier and plan status. We do not receive or store your full payment card numbers.
Family sharing data
If you create or join a Family (household) plan, we store your household membership and the combined spend totals needed to show a shared view to members. Each member’s individual subscription details stay encrypted on their own device — the shared view is built from aggregated totals, not from other members’ raw lists.
Diagnostics
To keep the app working, we may use crash reporting and anonymized, aggregated diagnostics — for example which screens load slowly or where the app crashes. These are configured to avoid identifying you personally and never include your subscription contents. Crash reporting is currently inert and only activates if we enable it with a monitoring provider (see Section 6). We do not run website analytics. The app sends anonymous counts of a few product events — an import finishing (CSV or email), a share card being made, the free plan’s limit being reached, and which plan a purchase was — with no account, device identifier, or subscription content attached, so we can tell whether those features work.
What we do not collect
- No bank credentials. Zeno never asks for, sees, or stores your online-banking username, password, or login. A bank connection is not currently offered; if Zeno ever adds one it would be entirely optional and handled by a regulated account-aggregation provider (such as Plaid) that authenticates you directly — Zeno would receive only the transaction information needed to detect subscriptions, never your credentials.
- No full payment card data. Billing is handled by the app stores.
- No sale of data. We do not sell, rent, or trade your personal information, and we do not use it for third-party advertising.
3. How we use your data
We use the limited data we hold only to:
- email you about waitlist status, launch availability, and important Service updates;
- operate core app features — detecting subscriptions, sending renewal and trial warnings, and guiding cancellations;
- provide and manage any paid Zeno plan you choose;
- diagnose crashes, fix bugs, and improve performance using aggregated diagnostics;
- protect the Service against fraud, abuse, and security threats; and
- comply with our legal obligations.
We process this data because it is necessary to provide a Service you requested, because you have consented (for example to Gmail access or the AI spend coach), or because we have a legitimate interest in keeping the Service secure and reliable.
4. On-device storage & encryption
Your subscription data lives on your phone. It is written to an encrypted on-device store, protected by your device’s secure keystore and, where you enable it, a biometric or passcode lock. Because this data is not held on Zeno servers, no Zeno employee can read your subscription list, and a breach of our infrastructure cannot expose it.
5. Optional Gmail access
To help you discover subscriptions you may have forgotten, Zeno can offer optional, read-only access to your email (for example a Gmail inbox). This is strictly opt-in and works as follows:
- access is read-only — Zeno can scan for receipts and renewal notices, but cannot send, delete, or modify your mail;
- scanning happens locally on your device to identify subscription-related messages; the contents of your inbox are not uploaded to Zeno servers;
- you can disconnect at any time from within the app or your Google account settings, which revokes Zeno’s access; and
- we only use this access to surface subscriptions to you — never for advertising or profiling.
Zeno’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
6. Third parties & service providers
We share data only with providers that help us run the Service, and only as needed. We use each provider only when the related feature is enabled. They currently include:
- Email delivery — Resend, to send waitlist and sign-in emails;
- Hosting & infrastructure — Netlify, to serve the website (including the waitlist form), and Render, to run the API and its database;
- Waitlist storage — Google (Google Sheets, through Google Apps Script), where your waitlist email address and sign-up time are kept;
- App stores & billing — Apple App Store and Google Play for distribution, and RevenueCat to manage paid-plan entitlements;
- AI coaching provider — Anthropic (Claude) or Groq, whichever we have configured. Only if you turn on the optional AI spend coach and grant consent, a summary of your subscriptions (service names, amounts, categories, and the in-app insights — but not your name, email, bank data, or any subscription discovered from your email) is sent to generate suggestions and return them to you;
- Crash reporting — Sentry, only if we enable it; it is inert until then and never receives your subscription contents;
- Bank-connection aggregator (such as Plaid) — a planned, optional integration that is not currently available. If we ship it and you opt in, it would retrieve transactions solely for subscription detection, and never your banking credentials.
These providers are bound to use the data only to perform services for us. Some of them are located in the United States; where your data is transferred internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses where applicable. We may also disclose information if required by law or to protect the rights and safety of users and the public.
7. Data retention
We keep waitlist emails until launch and for a reasonable period afterward to invite you in, or until you ask us to remove you. On-device subscription data remains on your device until you delete it or uninstall the app. Diagnostic data is retained only as long as needed to investigate issues and is then deleted or further aggregated.
On the server side, we retain your account record (such as your store account identifier, plan status, and any household membership) until you delete your account, after which it is erased. Sign-in (magic-link) tokens are short-lived and expire after 10 minutes. Operational server logs are retained for up to 30 days and then deleted.
8. Your rights & choices
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can:
- unsubscribe from waitlist emails using the link in any email;
- delete on-device data directly in the app, or by uninstalling it;
- disconnect optional Gmail access at any time; and
- ask us to access or delete the data we hold by emailing privacy@zenoapp.in.
We will not discriminate against you for exercising any of these rights.
9. Children’s privacy
Zeno is not directed to children. The Service is intended for users who are at least 16 years old (or 13 where permitted by local law with appropriate consent). We do not knowingly collect personal data from children under these ages. If you believe a child has provided us data, contact privacy@zenoapp.in and we will delete it.
10. Security
We take security seriously. Sensitive subscription data is encrypted on-device and can be protected with a biometric or passcode lock. Data in transit between the app and any Zeno service is encrypted using industry-standard transport security. No system is perfectly secure, but our architecture is deliberately designed so the most sensitive data never leaves your device.
11. Waitlist & pre-launch
While Zeno is in pre-launch, the waitlist is the primary way we interact with you. We use your email only to keep you informed about availability and launch. We will not add you to unrelated marketing without your consent, and you can leave the waitlist at any time.
12. Changes to this policy
We may update this Privacy Policy as the Service evolves — and we will publish a finalized version before the app launches. When we make material changes we will update the “Last updated” date above and, where appropriate, notify you by email.
13. Contact us
Questions about your privacy or this policy? Email us at privacy@zenoapp.in and we will get back to you.