Privacy Policy

Last updated: February 24, 2026

Zentia ("we", "our", "us") operates the Zentia mobile and web application ("the App" or "the Service"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our personal finance management application.

By using Zentia, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

a) Account Information

When you create an account, we collect:

  • Email address (required for authentication)
  • Password (encrypted and stored securely via Supabase authentication)
  • Profile information (optional):
  • Full name
  • Profile picture/avatar
  • Country

This information is collected directly from you during account registration and profile setup.

b) Financial Data

Zentia is designed to help you manage your personal finances. We collect the following financial information that you voluntarily provide:

  • Transactions: Income and expense entries, including:
    • Amount
    • Date
    • Description
    • Category
    • Account association
    • Currency and exchange rates (for multi-currency accounts)
  • Categories: Custom and default income/expense categories with associated icons and colors
  • Accounts: Financial accounts you create, including:
    • Account name
    • Description
    • Currency
    • Initial balances and balance adjustments
  • Budgets: Budget plans you create, including:
    • Budget amount
    • Period (daily, weekly, monthly, yearly)
    • Associated categories and accounts
    • Start and end dates
  • Planned Expenses: Future expenses you plan, including:
    • Amount
    • Due date
    • Category
    • Recurrence settings
  • Transaction Tags: Custom tags you assign to transactions

All financial data is provided directly by you and stored securely in our database. Financial data is processed as part of contract performance and under enhanced security measures.

c) Usage and Preference Data

We collect information about how you use Zentia and your preferences:

  • User Settings:
    • Preferred currency
    • Theme preference (light, dark, or system)
    • Language preference
    • Number format preferences (locale, decimal display, date format)
    • Onboarding completion status
  • Notification Preferences:
    • Budget alert settings
    • Planned expense reminders
    • Daily reminder preferences
    • Activity reminder settings
  • AI Chat Interactions (currently disabled):
    • If AI features are enabled in the future, this would include conversations and messages with our AI assistant
    • Token usage data (for service optimization)
    • Conversation metadata

d) Technical Information

We automatically collect certain technical information:

  • Device Information: Device type, operating system, app version
  • IP Address: Collected for security and authentication purposes
  • Authentication Data: Session tokens and authentication state (managed by Supabase)
  • Error Logs: Technical error information for debugging and service improvement

Note: We do not use third-party analytics services, tracking pixels, or advertising networks. We do not track your behavior across other websites or apps. For detailed information about cookies and browser storage, please see our Cookie & Tracking Policy.

2. How We Use Your Information

We use the collected information for the following purposes:

Service Provision

Core Functionality: To provide and maintain the Zentia app, including:

  • Transaction tracking and management
  • Budget creation and monitoring
  • Financial reporting and insights
  • Account balance calculations
  • Multi-currency support and conversions

Cross-Device Synchronization: To synchronize your financial data across all devices where you access Zentia using the same account

AI Features (currently disabled): If enabled in the future, to power our AI assistant that would help you:

  • Answer questions about your finances
  • Generate financial insights and reports
  • Provide personalized financial advice (informational only)

Notifications: To send you reminders and alerts based on your preferences:

  • Budget threshold alerts
  • Planned expense reminders
  • Daily activity reminders
  • Inactivity reminders

Service Improvement

  • Performance Optimization: To improve app performance, fix bugs, and enhance user experience
  • Feature Development: To understand how features are used and develop new functionality
  • Error Resolution: To diagnose and resolve technical issues
  • Automatic Categorization: To improve automatic categorization features based on user corrections (corrections are processed as part of requests but are not stored separately for this purpose)

Legal and Security

  • Security: To protect your account and prevent unauthorized access
  • Legal compliance: To comply with applicable laws and regulations
  • Terms enforcement: To enforce our Terms and Conditions

Communication

  • Account management communications
  • Service updates and policy changes

We do NOT sell, rent, or trade your personal or financial data to third parties for marketing or advertising purposes.

3. Data Storage and Security

Storage Location

Your data is stored securely using Supabase, a cloud-based backend-as-a-service platform. Supabase implements security standards aligned with GDPR and holds certifications including SOC 2 Type II. Supabase uses:

  • PostgreSQL databases hosted on secure cloud infrastructure
  • Row Level Security (RLS) policies to ensure data isolation between users
  • Encrypted connections (HTTPS/TLS/SSL) for all data transmission
  • Encryption at rest using AES encryption (industry-standard)
  • Data centers: Data may be stored in various regions depending on your Supabase project configuration. For users in the European Economic Area (EEA), data is typically stored in European data centers when available

Security Measures

We implement multiple layers of security to protect your personal information:

  • Data Encryption:
    • All data transmitted between your device and our servers is encrypted using HTTPS/TLS/SSL
    • Data at rest is encrypted using AES encryption (industry-standard)
  • Authentication: Secure authentication handled by Supabase with encrypted password storage
  • Access Controls: Database access is restricted through Row Level Security (RLS) policies
  • Secure Storage: Financial data is stored in encrypted databases with access limited to authorized personnel and systems
  • Security Audits: Supabase implements regular security audits and penetration testing
  • Abuse Protection: Protection mechanisms against DoS (Denial of Service) and brute-force attacks
  • Key Management: Authentication credentials are securely managed and regularly rotated

Data Retention

  • Active Accounts: We retain your data as long as your account is active
  • Deleted Accounts: When you delete your account, your account will be deactivated immediately and your personal data will be deleted or anonymized within a maximum period of 30 days, except where we are required to retain it for legal obligations
  • Backup Data: Deleted data may persist in backups for up to 90 days before permanent deletion
  • Extended Retention: We may retain certain data longer when required by:
  • Legal obligations
  • Regulatory requirements
  • Tax or accounting requirements
  • Dispute resolution purposes

Important: While we implement industry-standard security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we are committed to protecting your data to the best of our ability.

Data Breach Notification

In the event of a security breach that affects your personal data, we will notify you in accordance with applicable laws. Under GDPR, we are required to notify relevant supervisory authorities within 72 hours of becoming aware of a breach, and affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms.

4. Data Sharing and Third-Party Services

We use the following third-party services to operate Zentia:

a) Supabase (Backend Services)

  • Purpose: Authentication, database hosting, and data storage
  • Data Shared: All account and financial data necessary for app functionality
  • Privacy Policy: https://supabase.com/privacy
  • Compliance: Supabase implements security standards aligned with GDPR and holds certifications including SOC 2 Type II. HIPAA compliance depends on the specific plan and Business Associate Agreement (BAA)
  • Security Features:
  • Data encryption at rest using AES encryption
  • Data encryption in transit using TLS/SSL
  • Regular security audits and penetration testing
  • Regular key rotation schedules
  • Location: Data may be stored in various regions depending on your Supabase project configuration. For users in the European Economic Area (EEA), data is typically stored in European data centers when available
  • Privacy Inquiries: Privacy inquiries regarding Supabase can be directed to their privacy team through their website

b) OpenAI (AI Features - Currently Disabled)

Note: AI-powered features are currently disabled in Zentia. The following information applies only if and when AI features are enabled in the future.

  • Purpose: Powering our AI assistant for financial insights and chat functionality (when enabled)
  • Data Shared (if enabled):
  • Your financial transaction data (amounts, categories, dates)
  • Your questions and conversation history
  • Account summaries and financial metrics
  • Privacy Policy: https://openai.com/policies/privacy-policy
  • Data Processing: If enabled, OpenAI would process your data to generate responses but does not use your data to train their models for other users (as of our last update)
  • Important: If AI features are enabled in the future, your financial data would be sent to OpenAI's servers for processing. We will notify users before enabling any AI features.

c) Stripe (Payment Processing)

  • Purpose: Processing subscription payments for Zentia Plus
  • Data Shared: Email address, payment information (handled securely by Stripe), subscription status
  • Privacy Policy: https://stripe.com/privacy
  • Note: Payment card details are never stored on our servers

d) Exchange Rate API (Currency Conversion)

  • Purpose: Real-time currency conversion for multi-currency accounts
  • Data Shared: Currency codes and amounts (for conversion requests only)
  • Privacy Policy: https://www.exchangerate-api.com/privacy

Website Cookies and Tracking

For detailed information about how we use cookies and browser storage on our website (www.zentiaapp.com), including localStorage usage and authentication cookies, please see our Cookie & Tracking Policy.

Summary: We only use essential cookies for authentication (managed by Supabase) and localStorage for user preferences. We do not use any tracking cookies, analytics services, or advertising pixels.

Legal Disclosures

We may disclose your information if required by law or in good faith belief that such disclosure is necessary to:

  • Comply with legal obligations, court orders, or government requests
  • Protect and defend our rights or property
  • Prevent or investigate possible wrongdoing in connection with the Service
  • Protect the personal safety of users or the public
  • Protect against legal liability

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.

5. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal data:

Access and Portability

  • Right to Access: You can access all your data through the Zentia app
  • Right to Data Portability: You can export your financial data (we are working on export features)

Correction and Deletion

  • Right to Rectification: You can update your account information and financial data at any time through the app
  • Right to Deletion: You can delete your account and all associated data directly through the app (Settings > Account > Delete Account) or by contacting us at support@zentiaapp.com

Withdrawal of Consent

You can withdraw consent for certain data processing activities (e.g., notifications) through app settings. Withdrawing consent may limit your ability to use certain features.

Account Deletion

You can delete your account in two ways:

Option 1: Delete Account via App (Recommended)

  1. Open the Zentia app and navigate to Settings
  2. Scroll to the "Account" section
  3. Tap "Delete Account"
  4. Enter your current password to confirm
  5. Follow the on-screen instructions to complete the deletion
  6. Your account will be deactivated immediately and all associated data will be deleted or anonymized within a maximum period of 30 days, except where we are required to retain it for legal obligations

Option 2: Delete Account via Email

  1. Contact us at support@zentiaapp.com with the subject "Account Deletion Request"
  2. Include your account email address
  3. We will verify your identity and your account will be deactivated immediately. Your data will be deleted or anonymized within a maximum period of 30 days
  4. You will receive confirmation once your data has been deleted

Note: Some information may be retained for legal or regulatory purposes even after account deletion.

Fresh Start (Data Reset)

If you want to keep your account but delete all your financial data, you can use the "Fresh Start" feature:

  1. Open the Zentia app and navigate to Settings
  2. Scroll to the "Account" section
  3. Tap "Fresh Start"
  4. Enter your current password to confirm
  5. This will permanently delete all your transactions, accounts, categories, budgets, and planned expenses
  6. Your account will remain active, allowing you to start fresh

Note: The Fresh Start action cannot be undone. All deleted data will be permanently removed.

Right to Restriction of Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.

Right to Lodge a Complaint

If you are located in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your local data protection authority (supervisory authority) if you believe we have not addressed your concerns adequately. You can find your local authority at: https://edpb.europa.eu/about-edpb/about-edpb/members_en

Cookies and Tracking Technologies

We use cookies and similar technologies to provide, protect, and improve our services. This section explains how we use these technologies.

Essential Cookies

We use essential cookies that are strictly necessary for the website and application to function properly:

  • Authentication Cookies: Managed by Supabase to maintain your login session and ensure secure access to your account. These cookies are essential and cannot be disabled without affecting the service functionality.
  • Security Cookies: Used to protect against security threats and ensure the integrity of your session.

Essential cookies do not require your consent as they are necessary for the service to function.

Analytics and Performance Cookies

Currently, we do not use analytics cookies or tracking technologies. If we implement analytics in the future, we will:

  • Obtain your explicit consent before using any non-essential cookies
  • Provide clear information about what data is collected and how it is used
  • Allow you to manage your cookie preferences through our settings

Managing Your Cookie Preferences

You can manage cookies through your browser settings:

  • Most browsers allow you to refuse or accept cookies
  • You can delete cookies that have already been set
  • Disabling essential cookies may prevent you from using certain features of Zentia
  • For detailed instructions, please see our Cookie & Tracking Policy

Note: Blocking essential cookies will prevent you from logging into Zentia, as authentication requires these cookies to function.

Automated Decision-Making

Zentia does not use automated processing that produces legal effects or similarly significantly affects you. We do not make automated decisions about you based solely on automated processing of your personal data.

International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), United Kingdom, or Switzerland. These countries may have different data protection laws than your country of residence.

Service Providers and Data Processing Locations

Our service providers may process your data outside the EEA:

  • Supabase: Our backend infrastructure provider. For EEA users, data is typically stored in European data centers when available. However, some processing may occur in other regions.
  • OpenAI: If AI features are enabled in the future, data may be processed in the United States.
  • Stripe: Payment processing occurs in the United States and other jurisdictions.
  • Exchange Rate APIs: Currency conversion services may process data in various locations.

Safeguards for International Transfers

When we transfer your personal data outside the EEA, we implement appropriate safeguards to ensure your data receives an adequate level of protection:

  • Standard Contractual Clauses (SCCs): We use Standard Contractual Clauses approved by the European Commission with our service providers. These clauses ensure that your data is protected to EU standards even when processed outside the EEA.
  • Adequacy Decisions: Where applicable, we rely on adequacy decisions by the European Commission recognizing that certain countries provide an adequate level of data protection.
  • Binding Corporate Rules: Some service providers may have binding corporate rules in place that ensure adequate protection.
  • Other Legal Mechanisms: We may use other appropriate legal mechanisms approved by data protection authorities to ensure data protection.

These safeguards ensure that your personal data is protected in accordance with GDPR requirements, regardless of where it is processed.

Your Rights Regarding International Transfers

You have the right to obtain information about the safeguards we have in place for international data transfers. If you would like more details about the specific safeguards applicable to your data, please contact us at support@zentiaapp.com.

Children's Privacy and Minimum Age Requirement

Zentia is designed for adults and is not intended for children.

Minimum Age Requirement

You must be at least 16 years old to use Zentia. In some jurisdictions, the minimum age may be higher (for example, 18 years old in some countries). If you are under the age of 18, you represent that you have your parent's or guardian's permission to use the Service.

We do not knowingly collect personal information from individuals under the age of 16 (or the applicable minimum age in your jurisdiction).

For Parents and Guardians

If you are a parent or guardian and believe your child under the age of 16 has provided us with personal information without your consent, please contact us immediately at support@zentiaapp.com. If we become aware that we have collected personal information from a child under 16 without appropriate consent, we will take steps to delete such information promptly.

8. GDPR Compliance (European Users)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):

  • Right to Access: You have the right to request a copy of your personal data that we hold. We will provide this information within one month of your request.
  • Right to Rectification: You have the right to request correction of any inaccurate or incomplete personal data. You can also update most of your information directly through the app.
  • Right to Erasure (Right to be Forgotten): You have the right to request deletion of your personal data. You can delete your account and all associated data through the app settings or by contacting us.
  • Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.
  • Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
  • Right to Object: You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
  • Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing before withdrawal.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority (supervisory authority) if you believe we have not addressed your concerns adequately.

To exercise these rights, contact us at support@zentiaapp.com. We will respond within one month.

Legal Basis for Processing

  • Contract Performance: Processing is necessary to provide the services you requested when using the App or creating an account
  • Legitimate Interest: We process data to improve our services, ensure security, and prevent fraud
  • Consent: For certain optional features or communications, we obtain your explicit consent (e.g., notifications and AI features)
  • Legal Obligation: We may process data to comply with applicable legal requirements

9. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

Categories of Personal Information We Collect

We collect the following categories of personal information:

  • Identifiers: Email address
  • Financial Information: Transaction data, account balances, budgets, and planned expenses
  • Internet Activity Information: Usage data within the application, device information, and app interactions
  • Device Information: Device type, operating system, and technical identifiers
  • Right to Know: Request information about what personal information we collect, use, and disclose
  • Right to Delete: Request deletion of your personal information
  • Right to Opt-Out: Opt-out of the sale of personal information (we do not sell personal information)
  • Non-Discrimination: We will not discriminate against you for exercising your privacy rights

To exercise these rights, contact us at support@zentiaapp.com. We will respond within one month.

10. Changes to This Privacy Policy

This Privacy Policy applies only to the use of the Zentia app and does not cover any other websites, services, or applications that may be linked or integrated within the App.

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

When we make changes:

  • We will update the "Last updated" date at the top of this policy
  • For material changes, we will notify you through in-app notifications, email to your registered address, and prominent notice on our website

Your continued use of Zentia after changes become effective constitutes acceptance of the updated Privacy Policy. If you do not agree with the changes, you may delete your account and stop using the Service.

11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: support@zentiaapp.com

We will respond to your inquiry within 30 days.

12. Data Controller Information

Data Controller: Juan Santiago Pereira

Address: San Rafael, Mendoza, Argentina

Contact: support@zentiaapp.com

For users in the EEA, if you have concerns about how we handle your data, you have the right to lodge a complaint with your local data protection authority.

We are currently not required to designate a Data Protection Officer (DPO) under applicable data protection laws.

13. Jurisdiction and Governing Law

This Privacy Policy, and any disputes or claims arising out of or in connection with the use of Zentia, shall be governed by and construed in accordance with the laws of the Republic of Argentina.

Any legal disputes or claims arising from the use of the App shall be subject to the exclusive jurisdiction of the courts of Mendoza, Argentina. By using the App, you hereby consent to the jurisdiction of these courts for any such disputes.

In the event of a legal dispute, the parties involved agree to first attempt to resolve the matter through good-faith negotiations. If an amicable resolution cannot be reached, the dispute shall be submitted to the competent court.

This Privacy Policy is effective as of February 24, 2026 and applies to all users of Zentia.