Privacy Policy
This policy explains what Zenidhi ("Zenidhi", "we", "us") collects when you use the Zenidhi mobile app, why we collect it, how we protect it, and the choices and rights you have. We've written it in plain language on purpose.
Who we are
Zenidhi is a personal expense tracker and financial goal planner for individuals in India. You tell us about your income and goals, and — if you connect a credit card — the app reads your bank's transaction alert emails so your spending appears automatically. It then helps you see your cash flow and plan toward what matters. We act as the "Data Fiduciary" for the personal data you give us under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act").
What we collect
We only collect what the app needs to work for you:
- Your identity: your mobile number (used to create and sign in to your account) and the name you choose to show.
- The financial details you enter: your stated monthly income, expenses, debts, savings, salary day, the transactions you log, the accounts and categories you create, your goals, and any notes or sentiment tags you add.
- Your credit card details, if you connect one: the issuing bank, the card product, and the last 4 digits only. We never ask for, and never store, a full card number, CVV, PIN, or expiry.
- Transaction alert emails, if you connect Gmail (automatic tracking): with your explicit Google consent, we read your mailbox read-only and search only for transaction alert emails from the banks we support that match the last 4 digits of a card you added. From those emails we extract the amount, date, merchant name, and card reference, and store those as your transactions. We do not read, index, or store your personal mail, and we cannot send, delete, or change anything in your inbox. See Google user data below.
- Contacts (only if you use bill-splitting): when you open the contact picker to split an expense, the app reads the names and phone numbers stored on your device and sends those numbers to our server to check which of them are Zenidhi users, so it can show you who you can split with. That check is a lookup only — we do not save your address book, and we never message your contacts or use them for marketing.
- Receipt photos, only when you attach one:if you scan or pick a receipt for a split, the image is processed to read the line items (see "Who we share it with").
- Notification token: if you turn on reminders, a device push token so we can send the alerts you asked for.
- Basic technical data: the minimum needed to keep the service running securely and reliably.
We do not read your SMS or call logs, we do not track your location, and we do not sell your data.
Why we use it (purpose & lawful basis)
We process your data on the basis of your consent, which you give when you create your account, and use it to: run the core expense-tracking and goal-planning features; calculate your surplus, budgets, and goal plans; send the reminders you opt into; provide support; keep the service secure; and meet legal obligations. We use it only for these purposes and do not repurpose it without asking you again.
Who we share it with
We do not sell your personal data and we do not share it with third parties for their own marketing. We use a small number of trusted service providers strictly to operate the app, and they act on our instructions as data processors:
- Our cloud backend and database provider, which stores your data on our behalf under contractual confidentiality and security obligations.
- An SMS provider, used only to deliver your login code.
- AI providers (Anthropic and OpenAI), used for two narrow jobs: working out which category a transaction belongs to when our own rules can't, and reading a receipt image you choose to attach. For categorisation we send the merchant text and amount — not your name, phone number, or card number. Both providers process this under enterprise API terms that prohibit using it to train their models, and we do not permit any such training on your data.
Google user data (Gmail) & Limited Use
If you turn on automatic card tracking, you grant Zenidhi read-only Gmail access (the https://www.googleapis.com/auth/gmail.readonlyscope) on Google's own consent screen. Zenidhi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:
- We use Gmail data onlyto find your bank's transaction alert emails and turn them into the spending, card, and cash-flow features you see in the app.
- We do not use Gmail data for advertising, and we do not sell it or transfer it to anyone for advertising, marketing, or credit-scoring purposes.
- We do notallow Gmail data to be used to train generalised AI or machine-learning models — ours or a provider's.
- No human at Zenidhi reads your email, except where you explicitly ask us to for support, where it is necessary for security or to comply with law, or on aggregated and anonymised data for internal operations.
- You can withdraw the grant at any time: in the app, Settings → Your data → "Disconnect Gmail", which revokes our access at Google, or from your Google Account permissions. Deleting your Zenidhi account revokes it and erases the transactions we derived from it.
Where your data is stored (cross-border transfer)
Our backend infrastructure is currently hosted outside India (in the United States) by our cloud provider. Your data is encrypted in transit and protected by that provider's security controls. Such transfers are permitted under the DPDP Act today; if the Government of India restricts transfers to any country, we will comply. By using the app you consent to this processing location.
How we protect it
All communication between the app and our servers is encrypted in transit using TLS/HTTPS. Sensitive identifiers are stored using secure device storage on your phone, and access to backend data is restricted. No system is perfectly secure, but we apply reasonable security safeguards appropriate to financial information.
How long we keep it
We keep your data for as long as your account is active. When you delete your account, we permanently erase your associated data, except where we are required to retain limited records to comply with law or resolve disputes. See how to delete your account.
Your rights
Under the DPDP Act you can, at any time:
- Access & exportyour data: in the app, open Settings → Your data → "Export my data".
- Correct your information by editing it in the app.
- Deleteyour account and data: in the app, Settings → Your data → "Delete my account". It completes immediately and irreversibly; you can also request it on the web (see below).
- Disconnect Gmailwithout deleting your account: Settings → Your data → "Disconnect Gmail".
- Withdraw consent by deleting your account; we then stop processing your data.
- Raise a grievance with our Grievance Officer.
Children
Zenidhi is intended only for users aged 18 and above. We do not knowingly create accounts for, or collect data from, anyone under 18. If we learn that we have, we will delete it.
Data breaches
If a personal data breach occurs, we will notify the Data Protection Board of India and affected users in accordance with the DPDP Act and its rules (within the prescribed timeline).
Grievance Officer & contact
For any question, request, or complaint about your data, contact our Grievance Officer:
Grievance Officer, Zenidhi
Email: shyamsaitejam@gmail.com
We acknowledge requests promptly and aim to resolve them within the timelines required by the DPDP Act and the Consumer Protection (E-Commerce) Rules, 2020.
Changes to this policy
We may update this policy as the product evolves or the law changes. Material changes will be reflected by a new effective date, and we may ask you to accept the updated policy in the app. See also our Terms of Service.