Zala — Making AI Useful
Zala Savings

Privacy

What Zala Savings collects, why, which companies ever see it, and how to delete everything.

This policy explains what we collect and why, in plain language. If anything here is unclear, or you want to exercise a data right described below, contact us at info@zala-me.com.

Effective date: September 15, 2026 · Operated by Zala Software FZ-LLC

1. Scope

This Privacy Policy explains what personal data Zala collects, why, and how it's handled, including data processed through our AI, hosting, authentication, and messaging sub-processors. It applies to the web app, our iOS and Android apps, and the Telegram and WhatsApp bots.

Who Zala is for. Zala is not offered to people who live in the European Union, the European Economic Area, the United Kingdom or Switzerland. We ask which country you live in and keep your answer, and we do not provide the Service to residents of those countries.

2. Data We Collect

Account & identity data

  • Name and email address (via Clerk, our authentication provider)
  • Authentication identifiers (Clerk user ID) and, if you sign in via Google or another social provider, basic profile info from that provider
  • The country you tell us you live in, when you told us, and the country your connection came from at that moment

Financial data you submit

  • Expenses, income entries, categories, payment methods, notes, dates, and amounts you enter
  • Receipt and invoice images you upload or send via Telegram or WhatsApp
  • Savings goals, budgets, spending-alert thresholds, and account/asset balances you choose to track

Connector data

  • Your Telegram chat ID and, if you link WhatsApp, your WhatsApp phone number — used solely to connect bot messages to your account
  • Message content you send to the bot (text or voice notes) for the purpose of logging an expense/income

Bank message data

  • The text of bank transaction messages you choose to give us — by forwarding one to the Telegram or WhatsApp bot, by pasting one into the app, or, on Android, by turning on bank-message capture and selecting which apps and senders Zala may read
  • What we keep from a message: the amount, currency, date, merchant name, and the last four digits of the card or account it names. We do not store the original message text. A message that is held for your review stores these same parsed fields and nothing more
  • The sender IDs your bank messages arrive from (for example "EmiratesNBD"), so messages from senders you have not approved are never read. You can see this list, and switch any sender off, in Settings

Billing data

  • Subscription plan, trial status, and payment status. We never see or store your card number. If you subscribe on the web, payment is handled by Clerk Billing and Stripe; if you subscribe inside the Android app the purchase is handled entirely by Google Play, and if you subscribe inside the iOS app it is handled entirely by Apple. In both cases we receive only the fact that a subscription is active, when it renews or expires, and the amount, via RevenueCat

Usage & technical data

  • Basic usage metrics (e.g., number of AI requests this month, feature usage) needed to enforce plan limits
  • Standard web logs (IP address, browser type, timestamps) for security and troubleshooting

3. How We Use Your Data

  • To provide core functionality: storing and displaying your ledger, computing dashboards/reports, and syncing across the web app, the iOS and Android apps, Telegram and WhatsApp
  • To parse receipts, free-text, voice messages and bank transaction messages into structured expense/income entries using AI
  • To generate the "Insights" AI summaries and goal suggestions you request
  • To send you notifications you've opted into (spending alerts, scheduled expense/income reminders, goal-achieved messages) via email, Telegram or WhatsApp
  • To enforce plan limits and process subscription payments
  • To maintain security, prevent abuse, and comply with legal obligations

We do not sell your personal data, and we do not use your financial data to serve you third-party advertising.

4. AI Processing Disclosure

When you scan a receipt, send a chat/voice message to log an expense, ask an Insights question, or give us a bank message naming a merchant we do not recognise, the relevant text/image is sent to Anthropic's Claude API for processing, and the resulting structured data or written response is returned to Zala and stored in your ledger. If you send a voice note, it's first sent to OpenAI's transcription API to convert it to text, then that text is sent to Anthropic's Claude as described above. In the bank-message case, what is sent is the merchant name alone — not the message, not the amount, not your card or account digits — and the answer is remembered against that merchant, so the same shop is never sent twice. Anthropic and OpenAI each process this data as our sub-processors under their own API data-handling terms; treat any data you submit to either AI feature the same way you'd treat any other sensitive data you share with a service provider.

4a. Bank Message Capture

Zala can read a bank's transaction message and turn it into an expense. How the message reaches us differs by platform, and in every case it reaches us because you chose to give it to us:

  • Telegram and WhatsApp: you forward the message to the bot.
  • iPhone and iPad: iOS does not let any app read your messages, and we do not attempt to. You copy a message and paste it in, or use "Add › From a message". The app checks only whether your clipboard contains text so it can offer to use it; it never reads the clipboard's contents unless you tap Paste.
  • Android: if you turn on bank-message capture, you grant notification access and choose which apps Zala may read notifications from. Only the apps you tick are read. For chat apps, a message is additionally ignored unless it comes from a sender you have already approved.

What Zala does not do, on any platform: it does not read your messages in the background without the permission above, it does not read messages from apps or senders you have not selected, it does not store the original text of any message, and it does not upload your contacts or your message history. Android's notification access can be revoked at any time in your phone's Settings, and turning the feature off in Zala stops it immediately.

Roughly half of what a bank sends is not a purchase — one-time codes, salary credits, refunds, balance alerts and payment reminders. These are recognised and discarded rather than recorded. A message we cannot confidently read is either flagged for you to categorise or, if you have turned on "review before adding", held until you confirm it. Anything held is not an expense: it is in no total, budget or goal until you add it, and you can discard it.

5. Sub-processors and Third Parties We Share Data With

We share the minimum data necessary with the following providers to operate the Service:

  • Anthropic — AI processing of receipts, chat/voice messages, and insights (see Section 4)
  • OpenAI — transcribing voice notes to text before they're passed to Anthropic (see Section 4)
  • Clerk — authentication, session management, and subscription billing
  • Stripe — payment processing for subscriptions (via Clerk Billing's managed Stripe account) and for one-time quota top-up purchases (via a separate Stripe account we operate directly)
  • Sentry — error monitoring and crash diagnostics, to help us find and fix bugs
  • PostHog — product analytics, so we can see which features are actually used and where people get stuck. Hosted in the European Union. We send only your Clerk user ID and counts of actions (for example, “3 transactions added” or “a plan was created”). We never send amounts, balances, merchant names, notes, categories, or any other content from your ledger.
  • Google Analytics — web analytics for our website and web app, so we can see how many people visit, which pages they reach, and where they stop. It records page views, approximate location (country or city level), and technical details about your browser and device. It sets cookies in your browser, except for visitors in the EU, the EEA and the UK, where it runs without cookies (see Section 11). It does not receive your name, email address, or anything from your ledger.
  • Microsoft Clarity — session recordings and heatmaps for our website and web app, so we can see where the interface confuses people. It records how a page is laid out and where you click, scroll and tap. It is configured to mask text, so recordings are not intended to show your amounts, balances, merchant names or notes — see Section 11 for what that does and does not guarantee. It sets cookies in your browser. It does not load at all for visitors in the EU, the EEA and the UK, who are never recorded (see Section 11).
  • Upstash — database hosting for your ledger data (Redis)
  • Vercel — application hosting, serverless functions, and file storage for receipt images (Blob storage). Vercel also provides the visitor counts on our website. That measurement uses no cookies at all: visitors are counted using a value derived from the request itself, which is discarded after 24 hours, so it cannot be used to recognise anyone or to follow them anywhere
  • Telegram — delivering and receiving bot messages, if you link Telegram
  • Meta (WhatsApp Cloud API) — delivering and receiving bot messages, if you link WhatsApp. Meta receives your WhatsApp phone number and the content of the messages you exchange with our bot, and handles them under its own terms
  • Google Play — if you subscribe inside the Android app, Google is the seller of record. Google handles the payment, holds your payment details, and applies its own refund and cancellation rules. We never receive your card details
  • Apple — if you subscribe inside the iOS app, Apple is the seller of record. Apple handles the payment, holds your payment details, and applies its own refund and cancellation rules. We never receive your card details
  • RevenueCat — receives app-store purchase events so we know whether your subscription is active. It receives your Clerk user ID, the product you bought, and the status and dates of the subscription. It never receives anything from your ledger

We do not permit these providers to use your data for their own independent purposes; they process it only to provide their service to us.

6. Data Storage, Security, and Retention

On our servers. Your ledger is stored in cloud infrastructure in the regions offered by our hosting providers, under access controls, with receipt images held separately in file storage. Every connection between your device, our servers, and each of the providers in Section 5 uses encrypted transport (TLS/HTTPS). Each account's data is stored under its own key and every request is authenticated before anything is read, so there is no path by which one account reaches another's. We keep automated daily backups for 7 days to recover from accidental data loss.

On your device. The apps keep a copy of the last ledger our server confirmed, so that you can still read your figures with no connection, and so that a failed save rolls back to real data rather than leaving an entry on screen that was never recorded. What that copy is protected by differs per platform:

  • iPhone and iPad — written with complete file protection, which means iOS encrypts it and it cannot be read at all while the device is locked.
  • Android — held in the app's private storage, which other apps on the device cannot reach.
  • Web — held in your browser's local storage for the site, readable only by this site in this browser.

On all three it is removed when you sign out, and it is read-only: nothing is edited or queued offline, so the copy only ever means "the last state the server confirmed". On a device other people use, signing out is what clears it — closing the app or the tab does not.

What our servers can see. To read a receipt, sort an expense into a category, or answer a question about your own spending, our servers have to be able to read what you enter — so they can. Sections 4 and 5 set out exactly who sees what, and when.

No system is 100% secure, and we can't guarantee absolute security.

7. Your Rights

Who controls your data. Zala Software FZ-LLC, VUNE2496, Compass Building – Al Hulaila, Al Hulaila Industrial Zone–FZ, Ras Al Khaimah, United Arab Emirates, is the controller of the personal data described in this policy. You can reach us at info@zala-me.com.

If you are in the United Arab Emirates, your rights arise under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021).

If you are in the European Economic Area or the United Kingdom — for example while travelling, since the Service is not offered to residents there — your rights arise under the GDPR or UK GDPR where it applies. You have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to withdraw consent where processing is based on it. Withdrawing consent does not affect processing carried out before you withdrew it.

If you are elsewhere, you may have similar rights under your local law (for example, the CCPA in California).

You may complain to a supervisory authority. If you are in the EEA or UK, you have the right to lodge a complaint with your local data protection authority. We would prefer you raise it with us first at info@zala-me.com so we can try to resolve it.

How to exercise these rights. Most are available directly in the app — editing or deleting entries, disconnecting a bot, deleting your account. For anything else, email info@zala-me.com. We respond within one month, as the GDPR requires, and sooner where we can.

7a. Why We Are Allowed to Process Your Data

Where the GDPR applies, we rely on the following legal bases:

What we processWhyLegal basis
Account and identity dataTo create and operate your accountPerformance of a contract (Art. 6(1)(b))
Financial entries, receipts, messages you submitTo provide the record-keeping service you asked forPerformance of a contract (Art. 6(1)(b))
Sending receipt images, messages and voice to our AI providersTo turn what you submit into structured entries and insights — the core function of the servicePerformance of a contract (Art. 6(1)(b))
Subscription and billing recordsTo take payment and meet accounting obligationsContract, and legal obligation (Art. 6(1)(b), (c))
Security logs, abuse prevention, backupsTo keep the service and your data safeLegitimate interests (Art. 6(1)(f))
Optional notifications through Telegram or WhatsAppBecause you chose to connect that channelConsent (Art. 6(1)(a)), withdrawable at any time by disconnecting

We do not use your financial data for advertising, and we do not sell it.

7b. How to Delete Your Account

You can permanently delete your Zala account and all associated data at any time, directly from the app:

  • Web app: Sign in at savings.zala-me.com, open the account menu, and choose Danger Zone → Delete Account.
  • iOS app: Go to the Account screen → Danger ZoneDelete account.
  • Android app: Go to the Account screen → Danger ZoneDelete Account.

If you can't sign in, email info@zala-me.com from the address on your account and we'll process the request manually.

What happens next

  • Deletion isn't instant. Requesting it starts a 7-day grace period, during which you can sign back in and choose "Cancel deletion" if you change your mind or didn't request it yourself. We also email the address on file to confirm the request and give you that window to undo it.
  • Once the 7 days pass, we permanently delete: your ledger (all expenses, income, goals, plans, and settings), any receipt/invoice images you uploaded, and your Telegram (and WhatsApp, if linked) connector links. Your sign-in identity (email, name) is also deleted from our authentication provider.
  • Daily backups taken before your deletion date may retain a copy of your data for up to an additional 7 days after that backup was made, per our backup retention policy, after which it is also purged.
  • We keep a minimal audit record of the deletion itself (an internal account ID and the deletion timestamp only, no names, emails, or financial data) for fraud-prevention and legal record-keeping purposes.

8. International Data Transfers

Because our infrastructure and AI providers may process data outside your home country, your data may be transferred internationally. Where required, we rely on our providers' own compliance mechanisms (such as standard contractual clauses) for these transfers.

9. Data Breach Notification

If we become aware of a security incident that compromises your personal data, we will notify affected users and, where legally required, the relevant regulator, without undue delay (and, where applicable law sets a specific deadline — such as 72 hours under the UAE PDPL — within that deadline).

10. Children's Privacy

The Service is not directed to, and should not be used by, anyone under 18. We do not knowingly collect data from minors.

11. Cookies and Analytics

What changed on August 31, 2026. Until this date, this policy said there was no analytics code in the web app and that we recorded no session replays. That is no longer accurate for the web app, and this section has been rewritten to describe what we actually run. We would rather correct the record plainly than leave a promise standing that the product no longer keeps.

We use four kinds of analytics, and they collect different things:

  • PostHog runs entirely on our own servers. It never runs in your browser or app, sets no cookies, and sees only that an action of a given type happened and when — for example “a transaction was added”. It never sees the contents of your ledger. This is unchanged.
  • Google Analytics runs in your browser on our website (zala-me.com) and our web app (savings.zala-me.com). Outside the EU, the EEA and the UK it sets cookies, records page views, and collects technical information about your browser and device along with an approximate location. Inside them it sets no cookies at all — see below. Because both sites share one measurement configuration, a visit that starts on our website and continues into the web app is recorded as one journey. We do not track you onto websites we do not operate, and we do not use any of this for advertising.
  • Microsoft Clarity runs in your browser on the same two sites, outside the EU, the EEA and the UK, and records sessions — the layout of the page and where you click, scroll and tap — so we can see where people get stuck. It is configured to mask text content, which means a recording is intended to show the shape of a page and how you moved through it, not the numbers on it. Masking is a technical control and we test it, but we cannot promise it is perfect in every case, which is why we say plainly that we use it.
  • Vercel Web Analytics counts visits to our website. It uses no cookies and stores nothing on your device. Visitors are counted using a value derived from the request itself, which is discarded after 24 hours, so it cannot be used to recognise you on a later visit or to follow you anywhere else. It runs the same way everywhere, including in the EU and the UK.

If you are in the EU, the EEA or the UK. You will not see a cookie banner on our website or in our web app, because we have arranged things so that there is nothing to ask you for. Google Analytics runs in cookieless mode for you: it writes nothing to your device and reads nothing from it, so we can see that a page was visited but cannot recognise you as the same person on a later visit. Microsoft Clarity does not load at all, so no session of yours is recorded and nothing about your visit is sent to Microsoft. This applies to both zala-me.com and savings.zala-me.com, and it is decided from the network location your request arrives from; if we cannot determine where you are, we treat you as though you were in the EU.

We chose this rather than putting a consent box in front of a personal finance app. Session recording is the part that genuinely warrants asking permission, and we would rather not run it in Europe than ask you for it. One thing we should be straight about: even in cookieless mode, Google still receives the IP address your request arrives from, uses it to work out an approximate location, and processes it outside the EU. Nothing is stored on your device, but that is not the same as nothing leaving it.

The mobile apps are different. There is no Google Analytics and no Clarity in the iOS app or the Android app. Neither records sessions, sets analytics cookies, or collects device or advertising identifiers.

If you would rather not be included. Browser privacy settings, tracking-protection features, and content blockers all prevent these tools from loading, and nothing in the Service depends on them — the app works exactly the same without them. Essential cookies required for authentication (via Clerk) are separate and cannot be turned off, because you could not stay signed in without them.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced in-app or by email before they take effect.

13. Contact

Privacy questions or data requests: info@zala-me.com.