Privacy Policy
This policy explains what Zenidhi ("Zenidhi", "we", "us") collects when you use the Zenidhi mobile app, why we collect it, how we protect it, and the choices and rights you have. We've written it in plain language on purpose.
Using our browser extension instead? It handles data very differently: it has no account and stores almost nothing, so it has its own, browser extension privacy policy.
Who we are
Zenidhi is a personal expense tracker and financial goal planner for individuals in India. You tell us about your income and goals, and, if you connect a credit card, the app reads your bank's transaction alert emails and your monthly card statements so your spending appears automatically. It then helps you see your cash flow and plan toward what matters. We act as the "Data Fiduciary" for the personal data you give us under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act").
What we collect
We only collect what the app needs to work for you:
- Your identity: your mobile number (used to create and sign in to your account) and the name you choose to show.
- The financial details you enter: your stated monthly income, expenses, debts, savings, salary day, the transactions you log, the accounts and categories you create, your goals, and any notes or sentiment tags you add.
- Your credit card details, if you connect one: the issuing bank, the card product, and the last 4 digits only. We never ask for, and never store, a full card number, CVV, PIN, or expiry.
- Transaction alert emails, if you connect Gmail (automatic tracking): with your explicit Google consent, we read your mailbox read-only and search only for transaction alert emails from the banks we support that match the last 4 digits of a card you added. From those emails we extract the amount, date, merchant name, and card reference, and store those as your transactions. We do not read, index, or store your personal mail, and we cannot send, delete, or change anything in your inbox. See Google user data below.
- Card statement emails and their attachments, if you connect Gmail (automatic tracking): under the same read-only Gmail grant, we also look for the monthly card statement your bank emails you, from the same list of supported bank senders, and we fetch the PDF attached to it. Most banks lock that PDF with a password, and we cannot read a locked statement until you choose to enter that password in the app. Until you do, all we hold is a file we are unable to open. When you do enter it, the password is sent to our backend only to unlock the file for that read: it is never written to our database or logs, and there is no field for it anywhere on our servers. After a successful unlock the app also saves the password in your phone's secure keychain (iOS Keychain or Android Keystore), so next month's statement opens without asking again. That copy lives only on your device and is never synced to us; it is erased when your bank rejects it, when you sign out, and when you delete your account. From the unlocked statement we store the transactions, the totals, and the billing period, so we can show your spend timeline and check our reward audit against the figures your bank itself reported. We also keep the original file, because statement layouts differ by bank and change without notice, and keeping it is how we correct a bad read and improve our parsing. It is deleted when you delete your account. We do not look for, fetch, or store attachments on any other mail.
- Contacts (only if you use bill-splitting): when you open the contact picker to split an expense, the app reads the names and phone numbers stored on your device and sends those numbers to our server to check which of them are Zenidhi users, so it can show you who you can split with. That check is a lookup only: we do not save your address book, and we never message your contacts or use them for marketing.
- Receipt photos, only when you attach one: if you scan or pick a receipt for a split, the image is processed to read the line items (see "Who we share it with").
- Notification token: if you turn on reminders, a device push token so we can send the alerts you asked for.
- Basic technical data: the minimum needed to keep the service running securely and reliably.
- How you use the app (product analytics): which screens you open, which features you use, when you sign up and finish setting up, the app version you are running, and, on iOS, the fact that you took a screenshot and on which screen. This is tied to your account so we can tell a returning user from a new one. It deliberately excludes the substance of your money: the app strips your name, phone number, email, date of birth, UPI ID, card last-4, merchant names, and every rupee amount before anything leaves your device.
We do notread your SMS or call logs, we do not track your location, we do not record or replay your screen, we do not track you across other companies' apps or websites, and we do not sell your data.
Why we use it (purpose & lawful basis)
We process your data on the basis of your consent, which you give when you create your account, and use it to: run the core expense-tracking and goal-planning features; calculate your surplus, budgets, and goal plans; send the reminders you opt into; provide support; keep the service secure; and meet legal obligations. We use it only for these purposes and do not repurpose it without asking you again.
Who we share it with
We do not sell your personal data and we do not share it with third parties for their own marketing. We use a small number of trusted service providers strictly to operate the app, and they act on our instructions as data processors:
- Our cloud backend and database provider, which stores your data on our behalf under contractual confidentiality and security obligations.
- An SMS provider, used only to deliver your login code.
- AI providers (Anthropic and OpenAI), used for four narrow jobs. Anthropic works out which category a transaction belongs to when our own rules can't, receiving the merchant text and amount but not your name, phone number, or card number. Anthropic reads your monthly card statement to extract its transaction rows: an unlocked statement PDF is sent as-is, and a password-locked one is unlocked on our backend first and only its extracted text is sent, never the password. Anthropic also ranks which statement rows a card's reward rules likely excluded, receiving merchant names, amounts, and dates. Anthropic or OpenAI reads a receipt image you choose to attach. Both providers process this under enterprise API terms that prohibit using it to train their models, and we do not permit any such training on your data.
- A product analytics provider (PostHog), which receives the usage events described above so we can see where the app is confusing or broken and fix it. It receives no rupee amounts, no merchant names, and no contact details, only an account identifier and what you did. Screen recording and session replay are switched off, and we do not use this data for advertising.
Google user data (Gmail) & Limited Use
If you turn on automatic card tracking, you grant Zenidhi read-only Gmail access (the https://www.googleapis.com/auth/gmail.readonlyscope) on Google's own consent screen. Zenidhi's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We use Gmail data only to find your bank's transaction alert emails and monthly card statements, and to turn them into the spending, card, reward, and cash-flow features you see in the app.
- We do not use Gmail data for advertising, and we do not sell it or transfer it to anyone for advertising, marketing, or credit-scoring purposes.
- We do not allow Gmail data to be used to train generalised AI or machine-learning models, ours or a provider's.
- No human at Zenidhi reads your email, except where you explicitly ask us to for support, where it is necessary for security or to comply with law, or on aggregated and anonymised data for internal operations.
- You can withdraw the grant at any time: in the app, Settings → Your data → "Disconnect Gmail", which revokes our access at Google, or from your Google Account permissions. Deleting your Zenidhi account revokes it and erases the transactions we derived from it.
Where your data is stored (cross-border transfer)
Our backend infrastructure is currently hosted outside India (in the United States) by our cloud provider, as is our product analytics provider. Your data is encrypted in transit and protected by those providers' security controls. Such transfers are permitted under the DPDP Act today; if the Government of India restricts transfers to any country, we will comply. By using the app you consent to this processing location.
How we protect it
All communication between the app and our servers is encrypted in transit using TLS/HTTPS. Sensitive identifiers are stored using secure device storage on your phone, and access to backend data is restricted. No system is perfectly secure, but we apply reasonable security safeguards appropriate to financial information.
How long we keep it
We keep your data for as long as your account is active. When you delete your account, we permanently erase your associated data, except where we are required to retain limited records to comply with law or resolve disputes. See how to delete your account.
Your rights
Under the DPDP Act you can, at any time:
- Access & export your data: in the app, open Settings → Your data → "Export my data".
- Correct your information by editing it in the app.
- Delete your account and data: in the app, Settings → Your data → "Delete my account". It completes immediately and irreversibly; you can also request it on the web (see below).
- Disconnect Gmail without deleting your account: Settings → Your data → "Disconnect Gmail". This revokes our access at Google and we stop reading any new mail. The spending history already built from your mail stays, because it is your own record and the app still shows it to you; deleting your account is the switch that erases that too, including any statement file we had stored.
- Withdraw consent by deleting your account; we then stop processing your data.
- Raise a grievance with our Grievance Officer.
Children
Zenidhi is intended only for users aged 18 and above. We do not knowingly create accounts for, or collect data from, anyone under 18. If we learn that we have, we will delete it.
Data breaches
If a personal data breach occurs, we will notify the Data Protection Board of India and affected users in accordance with the DPDP Act and its rules (within the prescribed timeline).
Grievance Officer & contact
For any question, request, or complaint about your data, contact our Grievance Officer:
Grievance Officer, Zenidhi
Email: support@zenidhi.com
We acknowledge requests promptly and aim to resolve them within the timelines required by the DPDP Act and the Consumer Protection (E-Commerce) Rules, 2020.
Changes to this policy
We may update this policy as the product evolves or the law changes. Material changes will be reflected by a new effective date, and we may ask you to accept the updated policy in the app. See also our Terms of Service.