Privacy
What happens to what you send Zala Secure, what is kept, who else processes it, and how to have everything deleted.
Last updated 20 September 2026. Zala Secure is in pilot. This policy covers Zala Secure; Zala Life and Zala Savings have their own, listed on the Privacy page. The Zala Secure terms of use sit alongside it.
1. Who we are
Zala Secure is operated by Zala Software FZ-LLC, VUNE2496, Compass Building – Al Hulaila, Al Hulaila Industrial Zone–FZ, Ras Al Khaimah, United Arab Emirates, the controller of the personal data described here. Write to info@zala-me.com about anything on this page.
Zala Secure is used through the website at secure.zala-me.com and its installable app, the Telegram bot @zala_secure_bot, Zala Secure on WhatsApp, the address check@zala-me.com, the phone apps for Android and iPhone, and the browser extension.
2. Where Zala Secure is offered
Zala Secure is not offered to people who live in the European Union, the European Economic Area, the United Kingdom or Switzerland. Before your first check it asks which country you live in, and turns the answer away if it is one of those. The answer is kept so the question is asked once, and a refusal is not undone by answering again — if you chose wrongly, write to info@zala-me.com.
3. What happens to a message you check
- It is checked, then discarded. We do not store the message you send.
- Identifiers are removed before any AI sees it. Card numbers, one-time codes and similar are removed. Phone numbers, account numbers (IBANs) and the personal part of email addresses are replaced with one-way codes; an address's domain is kept, because it is often the evidence.
- A redacted copy is held for 15 minutes after a check, only so it can be offered back to you if you answer “was it a scam?” and are asked whether you would like to share it. If you don't, it is deleted automatically.
- Voice notes are sent to Google Cloud (Vertex AI, in the Netherlands) to be transcribed, then the text is checked and redacted like any message. Audio cannot be redacted before it is transcribed; it is not stored.
- Screenshots are held encrypted only while the check runs, and deleted as soon as their text has been read.
- Links. To see where a link goes, Zala may open it from our servers — never from your device. A link carrying a code personal to you is opened only if the other checks can't settle it, and the result tells you when that happened.
4. What we keep
Your account and your checks
- Your account — your Telegram account id, stored as a one-way code, or your Zala account if you use the website. Kept until you ask us to delete it. When you ask the bot to watch a domain, the chat id is also stored so the scheduled report can reach you.
- The verdict of each check — the band, which checks fired, the cost, and whether you answered “scam” or “fine”; never the message. Used to measure whether Zala is right. Kept until you ask us to delete it.
- Which organisations you hear from — sender domains, and one-way codes for account and phone numbers, to tell you when a sender is not who it claims to be. Kept until you ask us to delete it.
- The country you said you live in, so the question is asked once. Kept until you ask us to delete it.
- Counts for limits and cost — how many checks you made per hour and per day. Kept for 25 hours.
- A redacted copy you chose to share, to improve detection after a person reviews it. Kept until you send
/forget. - An example on the website — only if, when sharing, you separately agreed it may be shown. A person removes names and anything that could point to you first, and it is shown without any link to who shared it. Kept until you send
/forget, or we remove it. - Numbers, accounts, wallets and websites you report — a one-way code of what you reported, and a separate one-way code for you as a reporter, neither readable. Shown to others only once three different people have reported it, and a report counts only from an account a few days old — for that, the date your account first ran a check is kept. Kept until you send
/forget. - Daily self-test — which of Zala's checks passed, with timings and cost, run on samples written for the test and never on anyone's messages. The last 14 days.
Protections you switch on
- Breach monitoring — your Zala account id, one-way codes of your email addresses, and the names of breaches already reported to you. Until you switch it off.
- Domains you watch — the domain names, what their records looked like, the last 50 changes found, and for the Exposure monitor the look-alike domain names found. Until you stop watching them.
- The watch list — each link, wallet, IBAN or phone number you add (up to 20), re-checked daily, with only each engine's last result for comparison. Deleted when you remove it.
- Alerts on your devices — each device's push address, issued by its browser (Apple, Google or Mozilla), and a connected Telegram chat if you connect one. Until you turn them off or disconnect (
/unlink). - The weekly note, “your week in charts”, monthly summary and scam calendar — your chat or account id and language. Until you turn them off. Charts sent to Telegram are drawn as pictures when they are sent and not kept.
- Your dashboards' history — for each account, when you used a check or tool, what kind it was, its result and the channel (web, phone, Telegram, WhatsApp or email) — never what you checked. Kept 90 days, so your dashboards and charts can show your recent weeks; removed with
/forget. - Monthly cleanup — which items you marked done this month, and the counts your phone reports (permissions revoked, apps reviewed or removed), never the apps.
Your Trust Book and Security Inbox
The Trust Book (Trust Memory). Only when you say so — “I dealt with them” after a check, or adding someone yourself — Zala remembers who you deal with, so it can show what changed next time. For each account, wallet, phone number, email, domain and tax registration number it keeps a keyed token that is different for every account holder, so the same IBAN in two people's books can't be linked, plus a hint for you to recognise it: the last four characters, or the domain. A phone number or website you save as the way to reach someone is kept in full, because that is what you asked for. It also keeps the range of amounts you paid them, the latest amount each one asked for (so a sudden change can be pointed out), the name of the program their PDFs were made with, and the shape of their invoice numbers — never the invoice or the message. To say “you checked this before”, it keeps tokens of what you checked, with dates and counts, up to 500. Remove any entry or the whole book in the app or with /trustbook forget. Nothing in it is shared with anyone, including your family.
The Security Inbox. When you paste or forward a security alert — a sign-in, a password or recovery change, a new beneficiary, a SIM change — or the phone app's message guard recognises one and you have switched on “add security alerts to my inbox”, Zala keeps the event: which service, what kind of change, when, how many messages said so, where it came from, whether the sender was confirmed, and your answer. Never the message. From the phone, an app gaining a sensitive permission is recorded as the kind of permission only, never which app. Up to 200 events; clear them any time.
What you keep track of with Zala
Only what you enter yourself, for your own dashboards. Nothing here is shared with anyone, including your family, and a field that looks like a password, code or card number is refused.
- Your lists — identity copies you shared (which document, who has it, why, until when, whether you asked them to delete it), consents you gave, documents you received from others (name, sender, dates, and a SHA-256 fingerprint if you add one), your important accounts and how each is protected (never a password or code), your devices, temporary guest access, and subscriptions and trials. Up to 200 in each list; edit or remove any entry.
- Checklists — which items you ticked, and when. Never the setting or code itself.
- Verifications — who you verified, a short description of the request, which steps you did and the outcome, to give you a receipt. Challenge questions stay with you. Up to 50.
- Payment cooling-off — the payee's name, the amount as you typed it, the reason, your ticks, where to tell you the pause has ended (your Telegram chat or your account's notifications — the phone app reminds you itself), and, if bank details changed, who confirmed them and how (never a number in your note). A new account you confirm is saved to your Trust Book as a token, as above. Up to 50.
- Monthly rehearsal — which scenario you did each month and how many best moves you chose.
- What changed — when Trust Memory notices a changed account or number, the name of the party and the kind of change, for 60 days, to show on your Home. Never the values.
- A recovery plan — what you said happened, roughly when, your bank's name if you gave it, and which steps you ticked, until you close it.
- Checked, not kept — calendar invites you inspect, crypto addresses you compare, and the live call companion (only a count of which prompt was tapped). A purpose-bound ID copy is drawn in your browser; the image is never uploaded.
Family
- Family alerts — one-way codes of both people, the guardian's chat id, and the name the protected person chose to be shown as, to tell a guardian, with the protected person's agreement, that a check came back high risk — never what was checked. The history of alerts sent, including “I just got scammed” and “Talk to family before I pay”, is kept so the guardian can see it again. Until either side ends it.
- Asking family for a second opinion — only when you press it: what you were asked to do, what Zala found, and the part of the message you chose to include, with codes, card and account numbers removed, sent to the family members who agreed to your alerts, with their answer. Deleted after about a day.
- A practice week — only if you start it: which practice messages were sent, and whether you checked each one, opened its practice link, or let it pass. Your family sees the counts only if you chose to share them. Stop it at any time.
- A parent-setup link carries your language, your phone number and name, and an invitation code inside the link itself, in the part after “#”, which browsers never send to a server.
Business teams
- A team — the team name, members' display names, shared supplier-account codes and watched domains, and an activity feed of what kind of check each member ran and its outcome; never a message, account number or supplier name. Until a member leaves or the team is deleted.
- Suppliers' bank accounts — when you check an invoice while signed in, a one-way code of the supplier's name and of the IBAN, never either in the clear, to warn you if a supplier's account changes.
- Scam-spotting rounds — how many members took a round, the team's total right, and which messages were missed how often; never a member's own answers or score.
The phone app
- The device checkup — which apps can control your screen or read your texts, and your phone's settings — is read on the phone and never leaves it. A connected phone sends Zala only how many risks were found.
- Connecting a phone uses a one-time code from your account; Zala keeps only a hash of the phone's token, the platform and the model, and “Disconnect” removes it.
- Background checkup and Permission Watch (Android): the checkup runs on the phone twice a day, and you are warned on the phone when an app gains a sensitive permission. The app is named only on your phone; only counts are sent.
- Letting your family see your phone's health: off unless you turn it on. Family members you already accepted see the counts, never which apps, and get a message when serious risks rise.
- Call warnings (Android): the number of an incoming call is sent to Zala to look up community reports, and isn't kept.
- Link shield (Android): a link you tap is sent to Zala to check its address, then handed to your browser; the address isn't kept.
- Message guard (Android): with notification access you grant, messages from WhatsApp, SMS and Telegram, and security alerts in Gmail and Outlook, are read on the phone by fixed rules. Nothing is sent or kept, except as the Security Inbox above describes if you switch it on.
- Usage Access (Android, optional): when each app was last opened, read on the phone only.
- iPhone: the message filter checks texts from unknown senders on the phone and sends nothing; Share → Zala Secure checks what you share like a message you paste.
Checked, not kept
- Emails forwarded to check@zala-me.com are accepted only from an address verified on a Zala account, authenticated by its own mail provider; they are checked like any message, answered by email, and not kept.
- Playbooks and the file sandbox. What you investigate is sent to Zala's server in the EU, checked, and not kept; your account records only that a playbook ran and its outcome. A link may be opened in the isolated renderer — its own server with no keys, reaching only that website — to take a picture. A file is read in memory and dropped; web-page and SVG files are opened in the isolated renderer with every network request blocked. The file — and a file attached to a message you check, in Telegram, WhatsApp, the web app or an email you forward to check@zala-me.com — is also scanned on Zala's own file scanner in Frankfurt — antivirus signatures (ClamAV), our detection rules, and a reading of macro and PDF code that never runs it — which holds it in memory, returns what it found and keeps nothing, not even the file's name. Files are never sent to public malware databases or outside sandboxes; only a file's SHA-256 fingerprint may be asked of abuse.ch's MalwareBazaar.
- Privacy check and Safe Open — a website you check is fetched by Zala's server, read, and not kept.
- Chats and screenshots. A long chat pasted in the app is read on your phone and not sent. Screenshots of a chat are sent to our server to read their words, which go back to your phone and are not kept; in a bot, only which stages each screenshot reached is kept, for 30 minutes.
- Scam drills run on your phone in the app; in a bot, each reply is read for what it does and dropped, and only the drill and the turn are kept, for 30 minutes. When a bot reads a result aloud, only the result's words go to Google Cloud Text-to-Speech in the EU, and aren't kept.
- In a Telegram group, Zala reads posts only to find links and requests for a code, keeps no words, and stores the group as a one-way code with on or off.
- Read in your browser, never sent: QR codes you scan, email headers you paste, Android app files you choose, the SMS-sender check, and “Report it for me”.
- In the phone app, the same checks are read by Zala's server, because the app can't run them itself: a QR code photo or screenshot, a chat you paste, your answers to the questions for buying and selling, jobs, rentals, trading platforms, Hajj and charity, and what you type in a scam drill. They are read and not kept; only the kind of check (or drill) and its result are recorded.
The browser extension (Chrome, Edge, Firefox and Safari; the same code in each) looks at the page you are on, and in WhatsApp Web at the address of each link in the chat you have open, on your device. It sends nothing about the pages you visit.
“What's going around” is published as counts per type of scam. It never includes a message, a sender, a link or a person, and a type is shown only once at least three different people ran into it that week. We never store passwords: the leaked-password check runs in your browser and sends only the first five characters of a one-way fingerprint to Have I Been Pwned.
5. Who else processes it
- Vercel runs Zala Secure, and Upstash holds the database described above — both in Frankfurt, Germany.
- Google Cloud (Vertex AI), europe-west4, the Netherlands — reads the wording of a redacted message to spot pressure and requests for credentials, and transcribes voice notes.
- Mistral AI, European Union — reads text out of screenshots.
- Clerk, United States — sign-in for the website (your email address and login).
- Telegram and Meta (WhatsApp) — carry messages between you and Zala Secure, under their own policies.
- Resend, a US company, receives what you send to check@zala-me.com and sends the replies, from its Ireland (EU) region; Google Workspace, our company email, passes check@zala-me.com on to it.
- Apple, Google and Mozilla push services — deliver alerts to devices where you turned them on; the content is encrypted for your device.
- Have I Been Pwned, operated from Australia — only if you check your email for breaches or switch on monitoring: your verified email address is looked up.
- Amazon Web Services, Frankfurt, Germany — hosts Zala's own file scanner, which receives a file you give the file sandbox or attach to a message you check, scans it in memory and keeps nothing.
- abuse.ch (MalwareBazaar), Switzerland — only in the file sandbox: a file's SHA-256 fingerprint, never the file.
- crt.sh and other public scam and domain sources (URLhaus, PhishTank, Phishing.Database, Google Web Risk, domain registries) — domain names and links only, never your message. Web Risk is matched against a local copy.
- mempool.space — only when you check a Bitcoin wallet: the address.
Crypto wallets are also matched against copies of the US Treasury's OFAC sanctions list and ScamSniffer's phishing-wallet list held on our servers. We do not sell your data, and we do not use it for advertising.
6. Why we are allowed to process it
- Checking a message you send, and showing you the result; your account, history of senders and limits: performance of a contract (GDPR Art. 6(1)(b)).
- Keeping a redacted copy you chose to share: consent (Art. 6(1)(a)), withdrawable with
/forget. - Verdict records used to measure and improve accuracy, and to prevent abuse: legitimate interests (Art. 6(1)(f)).
- Breach monitoring, family alerts and second opinions, a connected Telegram chat, the Trust Book, the Security Inbox, practice weeks, the lists, verifications and cooling-off pauses you keep, and the weekly note: consent, withdrawable at any time as described above.
7. Your rights
If you are in the UAE, your rights arise under the Personal Data Protection Law (Federal Decree-Law No. 45 of 2021). Wherever you are, you can ask to see, correct or delete what we hold, and withdraw consent.
/forgetin the bot, or the same button in the app, deletes everything you have shared — including copies already accepted into our test set, your Trust Book, Security Inbox, watched domains, cleanup progress, practice week, recovery plan, lists, checklist ticks, verifications, cooling-off pauses and rehearsal history.- To delete your account and everything else — your verdict records included — use Delete my account in the web app (at the foot of the page) or in the phone app (Account). We record the request, with your sign-in id so we can find the account, and delete the account and its data within 30 days. You can also email info@zala-me.com from the address you signed in with, or send the request from the Telegram account you use. How account deletion works.
- You may complain to your data protection authority. We would rather you tell us first.
8. Where your data goes
Zala Secure stores and processes personal data in the European Union, as listed above. The exceptions: sign-in for the website is operated by Clerk, in the United States, and email replies are sent by Resend, a US company, from Ireland; the email breach check looks your address up at Have I Been Pwned, operated from Australia; and we are established in the United Arab Emirates, so our own staff access the data from there. Where a transfer needs a safeguard, we rely on the Standard Contractual Clauses in our agreements with those providers; ask info@zala-me.com for a copy.
9. How it is protected
- Everything travels encrypted, and the database is reachable only with credentials held by the service.
- Identifiers are stored as one-way codes, computed with a secret key, so a stolen database does not reveal a phone number, an account number or a Telegram id.
- Messages are redacted before any AI provider sees them.
- We never ask for your password, a one-time code or your card details — in the bot, on the website, or anywhere else. If someone claiming to be Zala asks, it is not us.
10. Children
Zala Secure is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has used it, write to us and we will delete what we hold.
11. Changes
Zala Secure is in pilot and changes often. When this page changes in a way that matters, we update the date above, and we will tell people using the service if the change is significant. Questions about anything here: info@zala-me.com.
