Zadd

Privacy policy

Last updated: August 7, 2026

Overview

Zadd is a personal finance app built around the United Arab Emirates, and usable from anywhere. This policy explains what information we collect, why we collect it, where it's stored, and your rights over it.

What we collect

  • Account info— your Apple Sign In identity: the name you choose to share and your email (or Apple's private relay address). Zadd never sees or stores a password.
  • App data — budgets, categories, accounts and transactions, investment holdings, gold and valuables, and customisations you create inside the app. This lives on your device, not on our servers.
  • AI processing data — when you use the AI features (automatic categorisation, insights, budget drafts), the app sends merchant names and computed figures to our backend for processing. Never account numbers, never bank credentials — Zadd has none to send.
  • Your spending pattern, for the read on your Insights page — to say something about your habits rather than repeat numbers you can already see, that feature sends the merchants you spent the most with this month and last, each with how many times you paid them and the total. Nothing else about them: not the dates, not the individual purchases, not your balances. It is what lets Zadd notice that eleven delivery orders is a habit and not eleven separate facts.
  • Bank alert context — if you set up the bank-messages automation, the text of a bank transaction alert is sent together with a small slice of your recent ledger: the amounts, dates and types of the transactions from the ten days around that alert, the last four digits of your cards, and the names you gave your accounts. Never merchant names, never balances, nothing from outside that window. That slice is what lets Zadd recognise a payment you already logged instead of asking you about it twice.
  • Usage counters — a daily count of your AI requests, kept to enforce fair-use limits.
  • Diagnostics — when automatic logging refuses something the AI proposed, we record the shape of that mistake: which check refused it, what kind of message it was, and how far off the figures or dates were. Never the message itself, never merchant or account names, never your actual amounts or balances. It exists so a bad pattern can be found before it becomes your problem.

Where it's stored

Your financial ledger is stored on your iPhone. Our backend (Supabase, a managed Postgres platform) stores only your sign-in identity and AI usage counters, with row-level security so only your own signed-in session can touch rows tagged with your user ID.

AI requests are processed transiently: the merchant names, figures and bank alert context sent for categorisation, insights or automatic logging are not written to our database.

Who we share with

  • Anthropic — our AI provider. Merchant names, computed figures, the spending pattern described above, and — if you set up the bank-messages automation — the text of bank transaction alerts with the name-free ledger slice described above are processed through the Anthropic API to answer your request or file the transaction, and are not used to train their models. Only bank-style transaction alerts ever leave your phone: verification codes and personal messages are checked on-device and destroyed immediately, never stored, never uploaded. Their privacy policy is at anthropic.com/privacy.
  • Supabase — our backend infrastructure provider. Their privacy policy is at supabase.com/privacy.
  • Apple — when you sign in with Apple, the standard Apple Sign In flow applies.

We don't sell or rent your data to anyone, for anything.

Your rights

  • Access and export — your data is visible inside the app at all times. We can provide a structured export on request.
  • Delete your data — your ledger lives on your phone; deleting the app deletes it. To remove your Zadd account (sign-in identity and usage counters), email privacy@zadd-ae.com — in-app deletion arrives before public launch.
  • Use Zadd without AI — signed out, the AI features simply switch off and nothing leaves your phone.

Security

Connections to our backend use TLS 1.2+. Sign-in is handled by Apple — there is no Zadd password to steal. Authentication tokens are stored in the iOS Keychain on-device, and the app offers Face ID lock.

Contact

Questions about this policy? Email privacy@zadd-ae.com.

This policy may change as Zadd evolves. We'll update the "Last updated" date above and, for material changes, notify you in the app.