Effective date: March 30, 2026 · Last updated: October 5, 2026
Privacy Policy
What this is
ZenFi's privacy policy. It covers what data we collect, why, and what happens to it. We've written it in plain English because the legalese versions nobody reads aren't actually protecting anyone.
Who we are
ZenFi is a personal finance app. For anything privacy-related, email privacy@usezenfi.com.
What we collect
When you sign up, we collect your name and email, and your phone number if you choose to give it. Once you're using the app, we also collect the transactions and bank statements you connect or upload, plus the spending patterns we pull from that data. We keep short-lived authentication tokens to keep your session active, and we log errors so we can fix bugs.
If you connect your email account, ZenFi accesses it to find financial emails like bank alerts, transaction receipts, and account statements. We read those emails to extract transaction data. We don't read or store personal correspondence, and we don't keep raw email content beyond what's needed to parse the transaction.
If you set up SMS tracking, your phone forwards bank alert texts to ZenFi. We read them to extract the transaction. Messages that don't look like bank alerts are discarded without being stored.
We don't buy data about you from other companies. We don't collect things we don't use.
Signing in with Google or Apple
You can create a ZenFi account with your Google or Apple account instead of an email and password. Google or Apple confirms who you are and sends us a unique account ID, your email address and, if you allow it, your name. That's all. We don't get your Google or Apple password, and signing in this way doesn't give ZenFi access to your inbox, contacts, photos or anything else in that account.
If you use Apple's Hide My Email, we only see the private relay address Apple creates for you, and our emails reach you through Apple's relay.
The name Google or Apple shares is only a starting point. We ask you to confirm your name as it appears on your bank account, because we use it to match the bank accounts you add to you. You can also add a phone number, but you don't have to.
For Apple sign-ins, we keep an encrypted token from Apple so that when you delete your account, we can tell Apple to remove ZenFi's access. When you delete your account, we also remove the link between ZenFi and your Google or Apple account. You can remove ZenFi's access yourself at any time from your Google Account or Apple ID settings. Your use of Google or Apple sign-in is also covered by their own privacy policies.
Why we collect it
We collect account data because it's necessary to run the service. You agreed to that when you signed up. We look at usage and error data to improve things, and that falls under legitimate interest.
If you're in the EU or UK, you can object to that at any time. Email privacy@usezenfi.com and we'll sort it out.
AI and your financial data
AI is how ZenFi works. We use a third-party AI service provider to read your bank alerts and organise your money. The app tells you what this involves and asks for your permission before any of your data is sent. Because ZenFi can't track your money without it, agreeing is required to use the app.
What is sent: the text of bank SMS alerts you forward to ZenFi; financial emails (bank alerts) from an email account you connect; transaction descriptions, amounts, dates and balances; and the spending and budget totals used to write your insights.
What it's used for: pulling transactions out of alerts and emails, sorting transactions into categories, naming merchants and spotting recurring payments, and writing your insights and budget alerts.
What is never sent:your password, PIN, BVN or email login details, or personal emails that aren't financial.
How it's protected:the provider processes your data only to deliver ZenFi to you, under a data processing agreement that requires the same or equal protection as this policy. It may not use your data to train its AI models, for advertising, or for any purpose of its own. Data is sent over encrypted connections, and the analysis is specific to you. We don't use your data to train shared models or to improve the service for other people.
You can read this explanation again in the app under Settings, Terms & Privacy, How ZenFi uses AI. To stop all AI processing of your data, delete your account or email privacy@usezenfi.com.
Email access
When you connect an email account, we access it with the credentials you provide. We only read emails that look like financial messages. We're not interested in the rest of your inbox, and we don't store it.
You can revoke email access at any time from the app settings. When you do, we stop reading your inbox and delete any stored credentials.
Who sees your data
We don't sell it. We share it with our hosting and database providers, and with the AI service provider described above. Each processes it under a data agreement. Payment processors handle subscription payments. If you sign in with Google or Apple, they verify who you are and so know you use ZenFi. We don't send them your financial data. Law enforcement gets access if the law requires it.
That's the full list. We'll update this page if it changes.
How long we keep it
Account and financial data stays as long as your account is active, plus 30 days after deletion in case it was accidental. Backups are purged within 90 days.
Security
We encrypt the connection between your device and our servers, and we hash passwords so they're never stored in a form anyone can read. If you sign in with Google or Apple, you don't have a ZenFi password at all unless you choose to set one.
The sensitive parts of your financial data are encrypted inside the database too: the amount on each transaction, its description, and your account balances. Every account has its own key, and those keys are held in a separate key management service that our servers have to call to unlock them. A stolen copy of the database, on its own, is just scrambled text.
ZenFi can still read this data when it needs to, because it has to show you your transactions and sort them into categories. So it isn't the kind of encryption where only you hold the key. The point is narrower: your real numbers and descriptions don't sit in plain text, so a leak of the raw data wouldn't hand them over.
We also keep login tokens short-lived, limit who on the team can reach the database, and run security reviews periodically. No system is unbreakable. If a breach ever affects your data, we'll tell you what happened and when.
Cookies
We only use cookies to keep you logged in. There's no ad tracking or analytics. Block all cookies and the app won't work.
Your rights
You can request a copy of your data, fix anything wrong, delete your account, or get everything exported. If you're in the EU or UK, you can also object to how we process your data or complain to your local data protection authority.
Email privacy@usezenfi.com. We'll respond within 30 days.
Changes
We'll email you if we make significant changes and update the date at the top. Typo fixes and minor clarifications won't get a separate notice.