Effective date: March 30, 2026 · Last updated: June 9, 2026
Privacy Policy
What this is
ZenFi's privacy policy. It covers what data we collect, why, and what happens to it. We've written it in plain English because the legalese versions nobody reads aren't actually protecting anyone.
Who we are
ZenFi is a personal finance app. For anything privacy-related, email privacy@usezenfi.com.
What we collect
When you sign up, we collect your name and email. Once you're using the app, we also collect the transactions and bank statements you connect or upload, plus the spending patterns we pull from that data. We keep short-lived authentication tokens to keep your session active, and we log errors so we can fix bugs.
If you connect your email account, ZenFi accesses it to find financial emails like bank alerts, transaction receipts, and account statements. We read those emails to extract transaction data. We don't read or store personal correspondence, and we don't keep raw email content beyond what's needed to parse the transaction.
We don't buy data about you from other companies. We don't collect things we don't use.
Why we collect it
We collect account data because it's necessary to run the service. You agreed to that when you signed up. We look at usage and error data to improve things, and that falls under legitimate interest.
If you're in the EU or UK, you can object to that at any time. Email privacy@usezenfi.com and we'll sort it out.
AI and your financial data
ZenFi uses AI to categorise your transactions and find patterns in your spending. That analysis is specific to you. We don't use your data to train shared models or make the service better for other people.
Email access
When you connect an email account, we access it with the credentials you provide. We only read emails that look like financial messages. We're not interested in the rest of your inbox, and we don't store it.
You can revoke email access at any time from the app settings. When you do, we stop reading your inbox and delete any stored credentials.
Who sees your data
We don't sell it. We share it with our hosting and database providers, who process it under data agreements. If ZenFi adds paid features, payment processors join that list. Law enforcement gets access if the law requires it.
That's the full list. We'll update this page if it changes.
How long we keep it
Account and financial data stays as long as your account is active, plus 30 days after deletion in case it was accidental. Backups are purged within 90 days.
Security
We encrypt the connection between your device and our servers, and we hash passwords so they're never stored in a form anyone can read.
The sensitive parts of your financial data are encrypted inside the database too: the amount on each transaction, its description, and your account balances. Every account has its own key, and those keys are held in a separate key management service that our servers have to call to unlock them. A stolen copy of the database, on its own, is just scrambled text.
ZenFi can still read this data when it needs to, because it has to show you your transactions and sort them into categories. So it isn't the kind of encryption where only you hold the key. The point is narrower: your real numbers and descriptions don't sit in plain text, so a leak of the raw data wouldn't hand them over.
We also keep login tokens short-lived, limit who on the team can reach the database, and run security reviews periodically. No system is unbreakable. If a breach ever affects your data, we'll tell you what happened and when.
Cookies
We only use cookies to keep you logged in. There's no ad tracking or analytics. Block all cookies and the app won't work.
Your rights
You can request a copy of your data, fix anything wrong, delete your account, or get everything exported. If you're in the EU or UK, you can also object to how we process your data or complain to your local data protection authority.
Email privacy@usezenfi.com. We'll respond within 30 days.
Changes
We'll email you if we make significant changes and update the date at the top. Typo fixes and minor clarifications won't get a separate notice.