Zaplog.

Zaplog · Legal

Privacy Policy

What Zaplog collects, why, who it goes to, and how long we keep it — written module by module, because Zaplog is a messenger, a community platform, an AI assistant, a health tracker and a cloud drive sharing one account.

Effective: Last updated:

Zaplog Inc. ("Zaplog", "we", "us", "our") operates the Zaplog apps for Android and iOS, the Zaplog web and desktop clients, and the website at zaplog.ai (together, the "Services").

This Privacy Policy explains what information we collect, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. It is written feature by feature, because Zaplog is not one app — it is a messenger, a communities platform, a podcast player, an AI assistant, a nutrition tracker, a cloud drive, a notes app, a web browser, and a day planner sharing one account.

Contents

1. Summary — the short version

This summary is for orientation only. The sections that follow control.

QuestionShort answer
Do you sell my data?No. We do not sell personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined under US state privacy laws.
Do you show ads?No. Zaplog contains no advertising SDKs.
Do you use analytics or tracking SDKs?No. Zaplog ships with no third-party analytics, attribution or crash-reporting SDKs.
How do I sign up?With a phone number and a one-time code sent by SMS or voice call. There is no password. Email is optional and secondary.
Are my chats encrypted?Yes — message bodies, attachments and call signalling in Chats are end-to-end encrypted using the Signal protocol. Important exception: we hold an escrowed backup of your account archive key so you can restore your history on a new phone. That means Zaplog is technically capable of recovering archived message history. See section 7.
What is not end-to-end encrypted?ZapCloud files, Notes, Organized planner data (including cycle and mood logs), browser history and bookmarks, ZapFit data and meal photos, Zaplog AI conversations, Stories, Rooms content, and your profile. These are encrypted in transit and at rest, but we can technically access them.
Where does my AI prompt go?To our AI model provider, under contract. Prompts are not used to train anyone's models.
Do you read my SMS messages?No. On Android, Zaplog can act as your default SMS app, and those messages stay in the operating system's own message store — they are never uploaded to us. iOS does not allow this at all, and the web client has no SMS role.
Do you upload my contacts?Yes, in part — to find which of your contacts use Zaplog, and to store contacts you save inside Zaplog. See section 3.7 and section 15.
Can I delete everything?Yes. Settings → Account → Delete account. A 30-day grace period applies. See section 11.
Minimum age?13, or 16 in the EEA, UK and other countries with a higher digital-consent age. Creating a Room requires 18+.
Do you take payments?Yes — for Zaplog Pro, an optional paid subscription. Zaplog never sees or stores your card number. See section 3.21.
Does this cover iOS and web?Yes. This policy covers Android, iOS and the web client. Where a feature or permission works differently on a platform, we say so.

2. Who this policy applies to and what it covers

2.1 Scope

This policy covers:

  • The Zaplog app for Android, the Zaplog app for iOS, and the Zaplog web and desktop clients.
  • The zaplog.ai website and the zaplog.net invite-link domain.
  • Our backend services, which store and synchronise your data and run the features described here.
  • Our Trust & Safety moderation console, used by authorised Zaplog staff.

It does not cover third-party services you reach through Zaplog — websites you visit in the built-in browser, podcast feeds you subscribe to, news articles you open in Discover, or the Google and Microsoft accounts you connect to Zappy. Those are governed by their own privacy policies.

2.2 Controller

For users in the EEA, UK and Switzerland, Zaplog Inc. is the data controller for the processing described here, except where this policy says otherwise. Where you post content inside a Room, the Room's moderators exercise independent control over moderation decisions in that Room; Zaplog remains the controller of the underlying platform data.

2.3 Roles you may hold

  • Account holder — you have a Zaplog account.
  • Room member or moderator — you participate in, or help run, a community.
  • Non-user — you do not have an account but your information reaches us because a Zaplog user saved you as a contact, messaged you by SMS, or mentioned you. See section 15.

3. Information we collect, feature by feature

3.1 Account creation, onboarding and profile

What we collect

DataSourceRequired?
Phone number (E.164)YouRequired — it is your account identifier
One-time verification code and its delivery statusGenerated by us; delivered via our SMS providerRequired
Country / regionSelected by you at onboarding; pre-filled from your SIM or network country codeRequired
First name (and optional last name)YouRequired
Date of birthYouRequired. Write-once — it cannot be changed in-app after onboarding
GenderYouRequired. Write-once
UsernameYouRequired
BioYouOptional (defaults to a placeholder line)
Profile photo and cover photoYouOptional
Email addressYou, via Account SettingsOptional, secondary, verified by one-time code
Chosen theme and appearance settingsYouOptional

Why. Your phone number authenticates you and lets other people find you. Date of birth enforces our minimum-age rules and Room age gates. Gender is used for the ZapFit energy-requirement calculation and profile display. Country determines SMS routing and regional defaults.

Note on your SIM. On Android and iOS we read the country code your SIM and mobile network report, purely to guess the right country for phone-number formatting; on the web we use your browser's locale. We do not read your SIM's stored phone number, and we do not collect device serial numbers, the Android advertising ID or Android ID, or Apple's advertising identifier (IDFA) or identifier for vendors (IDFV).

3.2 Authentication and sessions

  • Sign-in method: phone number plus a six-digit one-time code delivered by SMS, with a voice-call fallback. There is no password, no email/password login, no Google or Apple sign-in for your account, and no anonymous accounts.
  • SMS auto-fill: both mobile platforms can fill the code in for you — Android through its verification-code API, which gives Zaplog the single matching message and nothing else, and iOS through the keyboard's one-time-code suggestion, which Apple handles entirely and which gives Zaplog no access to your messages at all. On the web you type the code.
  • Session tokens are issued by our authentication service and stored on your device.
  • Linked devices: you can pair a web or desktop client by scanning a QR code that you approve on your phone. We record an installation identifier, platform, device name (the manufacturer and model your operating system reports on Android and iOS, or the browser and platform on the web), last-seen timestamp, primary-device flag and revocation state. Registering a new primary phone revokes all other linked devices.

3.3 Chats — messaging

Zaplog's Chats tab contains one-to-one and group messaging with end-to-end encryption.

Content that is end-to-end encrypted (we store ciphertext only, and cannot read it with the keys held on our servers alone — subject to the escrow disclosure in section 7.4):

  • Message text
  • Photos, videos, documents and other attachments
  • Voice notes and video notes
  • Stickers you send, including stickers you create
  • Poll questions and options sent in chat
  • Live location coordinates shared in a chat
  • Contact cards you share
  • Call signalling metadata

Data we necessarily hold in readable form so the system can function:

  • Sender and recipient account identifiers, and group membership
  • Message timestamps and delivery/read state
  • Control-message type and target (for example: "this is a delete-for-everyone instruction for message X")
  • Disappearing-message timers (expires_in_seconds)
  • The storage path of an encrypted attachment object
  • A flag indicating content was removed by moderation
  • Typing indicators and presence (transient)

Related features and what they mean for your data

FeatureWhat happens
Voice notesRecorded with your microphone, encrypted, uploaded. An on-device transcript may be generated by your platform's own speech recognition — Android's recogniser or Apple's on-device Speech framework — and the transcript stays on your device unless you send it.
Video notesRecorded with your camera and microphone, encrypted, uploaded.
Disappearing messagesThe timer is enforced on your devices and by a server sweep that purges expired rows and media.
View-once mediaMarked view-once; purged server-side after viewing by our media sweeper.
Locked chatsHidden behind your device biometric. The lock is enforced on-device; we do not receive your biometric data.
Starred and pinned messagesStored as encrypted references tied to your account.
Scheduled sendThe encrypted message is held until the scheduled time.
Message reactions, replies, threads, message infoMetadata associating your account with a message.
Chat themes, drafts, chat searchStored locally on your device.
StickersStickers you create (including with on-device subject cutout) and custom packs sync to your account.
GIFsSearched and fetched from a third-party GIF library. Your search terms reach that provider; it does not receive your Zaplog identity.
Live locationWhile sharing is active, a foreground service sends your precise location, encrypted, to the chat until you stop or the timer ends.
Screenshot and screen-recording detectionAndroid and iOS both tell the app when someone screenshots or records the screen, and we may notify the other participant. The web client cannot detect this at all, so treat the signal as a courtesy, never a guarantee.
TranslationIf you tap to translate a message, that message's text is sent to our AI provider. This is the only circumstance in which we transmit that message's plaintext, and it happens only on your explicit tap.
"Catch me up" and reply draftsIf you tap these, up to the most recent 40 messages (capped at roughly 8,000 characters) of that conversation are sent to our AI provider to produce a summary or a suggested reply. Only on your explicit tap.
Blocked accountsWe record which accounts you have blocked so we can enforce it.

3.4 Stories

  • Photos and videos you capture or select, plus any text, drawings, stickers or layouts you add in the editor.
  • Your audience setting per story: all contacts, all contacts except a list, or only a chosen list.
  • View records — which accounts viewed your story and when.
  • An expiry timestamp, currently 24 hours from posting.

3.5 Calls — audio, video and screen sharing

  • One-to-one and group audio and video calls, and Rooms voice channels, run over a specialist real-time media service.
  • Call media (your audio and video streams) is relayed by that provider's infrastructure. We do not record calls, and Zaplog has no call-recording feature.
  • We store call metadata: participants, direction, start and end time, duration, call type, and outcome (answered, missed, declined).
  • Screen sharing uses your platform's own screen-capture mechanism — Android's media projection, iOS's broadcast picker, or your browser's share-screen picker. In every case you choose what to share and the operating system shows you that capture is active. Anything visible on your screen while sharing is transmitted to the other participants.
  • Access tokens for the call service are minted by our backend for each session.
  • We use the proximity sensor and audio-routing controls during calls; these do not produce data we retain.

3.6 SMS and MMS

This feature is Android-only. Apple does not permit third-party apps to handle SMS on iOS, and the web client has no SMS role. On Android, Zaplog can be set as your default SMS app.

What this means: Zaplog reads, writes, sends and receives SMS and MMS through Android's system telephony provider so it can act as your messaging app. Nothing equivalent exists on iOS or the web, so if you use those clients this subsection does not apply to you at all.

What it does not mean: we do not upload your SMS or MMS messages, your text-message contacts, or your carrier message history to our servers. That content stays on your device. Your carrier still processes messages you send and receive, and standard carrier rates apply.

We request the RECEIVE_WAP_PUSH and MMS permissions solely to receive multimedia messages, and we register a headless service so Android can route "respond via message" actions to Zaplog.

You can change your default SMS app at any time in Android Settings, or decline the role and use the rest of Zaplog normally on any platform.

3.7 Contacts and contact discovery

Reading your contacts. With your permission, Zaplog reads your device contact list to show you names and photos next to phone numbers, and to let you start chats and calls.

We are aware that the privacy-preserving standard here is hashed or private-set-intersection matching, and moving to it is on our roadmap. Until then:

  • We use these numbers only to compute matches and to power the contacts you see in Zaplog.
  • We do not sell them, use them for advertising, or share them with any third party for that third party's own purposes.
  • If you decline the Contacts permission, Zaplog still works — you can start chats by entering a phone number directly.

Saved contacts. When you save a contact inside Zaplog, we store the contact's name and phone number on our servers, associated with your account, so it syncs across your devices. This is stored in readable form. Contacts you save may include people who are not Zaplog users — see section 15.

Writing contacts. With your permission, Zaplog can add a contact to your device address book when you choose to save someone.

3.8 Rooms (ZapRooms) — communities

Rooms is a public and private community platform. Content you post in a Room is not end-to-end encrypted, and depending on the Room's settings may be visible to anyone.

Content and activity we collect

  • Posts — text, links, images, polls and AMA posts (which may include a selfie), titles, bodies, flairs, and scheduled-post timing.
  • Comments and replies, including nested threads.
  • Votes and Boost points — your upvotes and downvotes, and the Boost point totals derived from them.
  • Awards you give and receive.
  • Flairs — post flairs and user flairs, which may be assigned by you or by moderators, and may follow you across Rooms.
  • Channels — text channels, chat channels and voice channels, including chat messages posted in Room channels (these are not end-to-end encrypted).
  • Room direct messages and modmail.
  • Membership and role data — which Rooms you joined, your roles, your custom permissions, your join date, and whether you follow a Room.
  • Presence — heartbeats used to show live online counts in a Room.
  • Saved posts, subscriptions and unread/mention state.
  • Invite links you create or use, in the form zaplog.net/<code>.

Moderation and Trust & Safety data

Running a community platform requires records. We collect and retain:

  • Reports you file about content, Rooms or profiles, and reports filed about you.
  • Moderation queue entries, removal reasons, and the moderation log.
  • Appeals you submit and their outcomes.
  • Moderator notes about members, watch-lists, warnings, timed mutes and bans (both Room-level and platform-level).
  • Automated moderation signals: banned-word and pattern matches, link and invite policy hits, mention-spam and capitalisation triggers, attachment-policy hits, crowd-control actions, minimum-account-age checks, and ban-evasion indicators.
  • Records of actions taken by Room moderation bots. These bots are deterministic rule engines configured by Room owners — they are not AI models and they do not send your content to an AI provider.
  • Platform notices and account restriction records.

Age gating. A Room's owner sets its minimum age to either 13 — Zaplog's own minimum, and the default — or 18 for an adults-only Room. We use your stored date of birth to evaluate eligibility. Creating a Room requires you to be 18 or older, and this check fails closed — if we cannot confirm your age, you cannot create a Room.

Moderators. If you are a moderator, other moderators and Zaplog staff can see the moderation actions you take. Moderation logs are retained for accountability and appeals.

3.9 Pod (ZapPodcasts)

  • Subscriptions and library — the shows you follow, synced to your account.
  • Playback state — episode progress, continue-listening position, queue, playback speed, sleep-timer state.
  • Downloads — episodes stored on your device for offline listening.
  • Search queries you enter in the podcast catalogue.
  • Transcripts — where a show provides them, we fetch and parse transcript files.

Third parties. Catalogue search and show metadata come from a third-party podcast catalogue provider. Episode audio, artwork and transcripts are fetched directly from the podcast's own feed and hosting provider. When your device downloads or streams an episode, the podcast's host receives your IP address and user-agent, and may count it as a download. Some podcast hosts use analytics-prefix services in their audio URLs. Zaplog does not send your identity to these hosts.

3.10 Zaplog AI

The Zaplog tab is an AI answer engine.

What we collect and transmit

  • Your prompts, including follow-up questions.
  • Attachments you add — images (sent to the model as encoded image data), and documents including PDFs and Office files, from which we extract text.
  • Voice input — captured with your microphone and converted to text by your platform's on-device speech recognition (Android's recogniser, Apple's Speech framework, or your browser's speech API) before being sent as a prompt.
  • Generated output — answers, generated images, artifacts, and PDF reports you export.
  • Web search activity — in normal search and Deep Research mode, we derive queries from your prompt and send them to search providers, then fetch and extract the text of result pages.

Where it goes. Prompts and attachments are sent to our AI model provider, which hosts every model Zaplog uses. Search queries go to independent search providers.

Storage. Zaplog AI conversations are stored on our servers in readable form — the session title, the full message history, timestamps and pinned state — so they sync across your devices. Attachments are stored in private storage. These are not end-to-end encrypted. You can delete a session at any time.

Read-aloud. Answers can be read aloud using your platform's own text-to-speech — Android's engine, Apple's speech synthesiser, or your browser's. No audio is sent to us.

3.11 Zappy — the assistant in your Chats

Zappy is an AI assistant that appears as a conversation in your Chats tab and can act across the whole app on your instruction. It is the most far-reaching feature in Zaplog and deserves its own disclosure.

What Zappy can access when you ask it to

AreaExamples of what it can read or do
ChatsList chats, read a conversation, count messages, send a message, mark read, pin, mute, show statistics
Email (Gmail / Outlook, if you connect them)Read, search, send, draft, organise mail; list folders; look up a person
Google Workspace / Microsoft 365 (if connected)Drive and OneDrive files, Docs/Sheets/Slides creation, Calendar events, Contacts, Tasks and To Do
ZapCloudSearch, list, read, link, star, trash, create folders, report storage use
ZapFitLog food, water, weight, exercise, recipes; read today's totals and trends; suggest; manage fasts
OrganizedRead your plan, create and update tasks, create reminders, report statistics
NotesCreate, search, read and append to notes
Rooms, Stories, CallsRoom overviews and search, post or delete a Story, place a call, list recent calls
Account and systemAccount overview, linked devices, privacy settings, blocked list, browser history, podcast library, notifications, cross-app search

What this means for your data. When you give Zappy an instruction, the content it needs to answer — chat excerpts, email bodies, file text, note contents, health figures, planner entries — is sent to our AI provider as part of the prompt. Zappy only reads what a given instruction requires; it does not continuously scan your data.

Memories. Zappy can remember facts you tell it. These are stored as memories associated with your account and injected into its context on later turns. You can ask Zappy to forget something, or clear memories in settings.

Automations. You can ask Zappy to act on a schedule or a trigger. We store the automation definition and use device alarms and background workers to run it, which may produce proactive messages from Zappy.

Trust settings. Every action that changes something is gated behind a confirmation step. You can pre-approve a limited, hand-picked set of low-risk actions on your own data. "Trusted people" is a list you control of the only people Zappy may message on your behalf.

Connectors. Connecting Google or Microsoft uses OAuth. We never see your Google or Microsoft password. The resulting access and refresh tokens are encrypted with a key held in your device's hardware-backed keystore. You can disconnect a connector at any time in Zappy settings, and revoke Zaplog's access from your Google or Microsoft account security settings.

Storage. Zappy's transcript, memories, automations and attachments are encrypted on your device before upload using your account archive key. Our servers hold ciphertext for these.

3.12 Fit (ZapFit) — nutrition and health

ZapFit processes health data. In several jurisdictions this is special-category or consumer health data with heightened protection. See section 13.

Profile and plan

  • Date of birth, biological sex, height, current and goal weight, unit system.
  • Dietary pattern (for example vegetarian, vegan, keto), allergies, and foods you avoid.
  • Free-form onboarding answers, which may include your motivations, obstacles, training habits, sleep, stress and weigh-in rhythm, and step goal.
  • Derived calorie and macronutrient targets.

Logs

  • Food entries with nutrient breakdowns, water logs, exercise logs, fasting sessions, custom foods and recipes.
  • Weight logs, and body measurements: body-fat percentage and neck, chest, waist, hip, arm and thigh circumference.
  • Goals, adaptive-review outcomes and reminders.

Meal scanning

  • Photos you take of meals, nutrition labels and barcodes.
  • Meal photos and label photos are uploaded to private storage and sent to our AI provider for analysis. Your plain-language corrections are sent too, so the estimate can be refined.
  • Barcodes are looked up against a public food-product database directly from your device; generic-food nutrition comes from a public nutrition database via our servers.

Platform health integrations

ZapFit can read from your device's health store with your explicit permission — Health Connect on Android, and Apple Health on iOS where that integration is available in your version of the app. The web client has no health-store access. On Android we read and write:

DirectionData types
ReadSteps, active calories burned, sleep sessions, weight, exercise sessions
WriteWeight — your ZapFit weigh-ins are written back to Health Connect

Important: weight and exercise records imported from Health Connect are stored as ZapFit entries on our servers. If you do not want scale or wearable data leaving your device, do not grant Health Connect permission — the rest of ZapFit works without it.

We will never use health-store data for advertising, and we will never sell it. Google Play's Health Connect policy and Apple's HealthKit rules both require this, and we commit to it independently on every platform.

Storage. ZapFit data is stored on our servers in readable form. It is not end-to-end encrypted.

Export. ZapFit is the one module with a built-in data export — you can export your ZapFit data across 18 data tables, up to five times per day.

3.13 Cloud (ZapCloud)

  • Files and folders you upload, including file names, sizes, types, folder structure, timestamps and version history.
  • Camera and photo backup — if you enable it, ZapCloud uploads photos and videos from selected albums (by default Camera, Pictures and DCIM; optionally all folders). You control whether videos are included, whether uploads may use cellular data, image quality, and HEIC conversion.
  • Document scanning — pages captured with your camera and converted to PDF or JPEG.
  • On-device analysis for search — we run optical character recognition and image labelling on your device to make your files searchable by their text and contents. The extracted text and labels are stored with the file so search works across your devices.
  • Thumbnails generated for previews.
  • Share links you create, including their revocation state, optional password and access-count limits, and records of shares to other Zaplog accounts.
  • Duplicate detection using content hashes.
  • Trash — deleted items and their storage objects, kept for 30 days.
  • Offline files and storage-analyzer results.

Encryption. ZapCloud content is encrypted in transit and at rest. It is not end-to-end encrypted — Zaplog can technically access it, and does so only for the purposes in section 5.

Not a backup service. ZapCloud is a sync and storage feature, not a guaranteed backup. Keep your own copies of anything irreplaceable.

3.14 Notes

  • Note titles and bodies, folders, and pinning, sorting and search state.
  • Attachments — photos, drawings and scanned documents.
  • Voice recordings and their transcripts. Transcription runs on your device, using Android's speech recogniser or Apple's on-device Speech framework.
  • AI summarisation and writing tools — if you tap these, the note or transcript text is sent to our AI provider.
  • Reminders you set, and widget and share-target activity.

Notes sync to your account and are not end-to-end encrypted.

3.15 Web browser

Zaplog includes a full web browser.

  • History, bookmarks and bookmark folders, per-site preferences, and reader-mode state — these sync to your account and are not end-to-end encrypted.
  • Downloads and open tabs stay on your device and do not sync.
  • Private (incognito) tabs use a separate browser profile. Private browsing is excluded from sync entirely — it is not recorded in history and is not uploaded to us.
  • Search suggestions — as you type, we may query suggestion endpoints operated by independent search engines. Those providers receive your partial query and your IP address.
  • Tracker blocking — we ship a blocklist that is applied on your device.
  • AI page assist — if you invoke it, the page's text is sent to our AI provider.
  • Websites you visit set their own cookies and receive your IP address and user-agent directly. Zaplog is not a party to that.

3.16 Organized — the day planner

Organized contains some of the most sensitive data in the app.

  • Tasks and time blocks, including titles, notes, scheduled times and durations, recurring rules and per-occurrence overrides.
  • Routines and focus sessions — rounds, breaks, ambient-sound choice, streaks and history.
  • Energy budget entries.
  • Week reviews.
  • Mood check-ins — your selected mood and any free-text note.
  • Menstrual cycle logs — period start and end dates, used to predict cycle phase.
  • Device calendar import — with your permission, we read events from your device calendar to show them alongside your plan.
  • AI planning — if you describe your day by typing, dictating or photographing it, that description (and image) is sent to our AI provider, which proposes blocks you accept or discard.
  • Alarms, notifications and widget state.

3.17 Discover — the news reader

  • Topics you personalise, articles you save (synced to your account), and reading activity within the reader.
  • Headlines and article metadata come from a third-party news aggregator. Opening an article takes you to the publisher's site, which receives your IP address directly.

3.18 Notifications

  • We store a push token issued by your platform's push notification service — the mobile push service on Android and iOS, and the browser's web-push service on the web client — so we can deliver notifications to your device.
  • We store your notification preferences, including per-chat, per-Room and per-module settings.
  • Push notification content is generated by our backend. For end-to-end encrypted chats, we deliver a signal that causes your device to fetch and decrypt the message locally rather than sending message content through the push service.

3.19 Device, technical and usage information

  • Installation identifier — a random identifier the app generates itself. It is not derived from, and not tied to, any platform identifier: not the Android ID or Android advertising ID, and not Apple's IDFA or identifier for vendors.
  • Device name derived from the manufacturer and model your operating system reports, or the browser and platform on the web, shown to you in Linked Devices.
  • Platform and app version.
  • Last-seen timestamp and online-seconds total — cumulative foreground time, which drives the Levels / StarLevel progression feature.
  • IP address and connection metadata, received by our servers and our providers as an inherent part of internet communication.
  • Encryption device records — a per-installation device identifier, registration identifier, public identity key and device name, used to route encrypted messages to the right devices.
  • Rate-limit counters per operation, used to prevent abuse.

We do not collect the Android advertising ID or Android ID, Apple's IDFA or identifier for vendors, the IMEI, MAC address or SIM serial number, and we do not fingerprint your device or your browser. Zaplog never asks for iOS App Tracking Transparency permission, because we do not track you across other companies' apps or websites.

3.20 Support, Trust & Safety and staff access

  • Support correspondence you send to support@zaplog.ai or through in-app help, and Trust & Safety modmail.
  • Staff console records — our internal moderation tooling keeps staff authentication and session records, an append-only audit log of every staff action, and staff notes about accounts under review.

Access is restricted to authorised personnel, requires multi-factor authentication and network-level restrictions, and every action is logged.

3.21 Payments and subscriptions

Zaplog is free to use. Zaplog Pro is an optional paid subscription that unlocks the features identified as Pro inside the app. If you never subscribe, nothing in this subsection applies to you.

How you can pay, by platform

Where you subscribeWho processes the payment
Zaplog for AndroidGoogle Play Billing
Zaplog for iOSApple App Store billing
Zaplog web client and zaplog.aiStripe

Zaplog never receives your full card number. Card, bank and wallet details are entered directly with Stripe, Google or Apple and are held by them. We could not disclose your card number if we were asked to, because we do not have it.

What we store about your subscription

  • Your subscription status — one of active, canceled, grace (a renewal failed and the store is retrying), paused (a Play-specific pause), or expired.
  • Which store or processor the subscription came through.
  • The date your current paid period ends, and whether it is set to cancel at the end of that period.
  • Processor references — a customer and subscription identifier from Stripe, or a purchase token and order identifier from Google Play, or the equivalent from Apple. These let us match a payment to your account and provide support.
  • The last raw status the store reported, kept for support investigations.

What we store about payment events

We keep a log of the billing notifications the stores and Stripe send us — the event type, its identifier, when it arrived, and its contents. This is how a payment, cancellation, refund or failed renewal actually reaches your account, and it is also our record if a payment is later disputed.

What we never store: your full card number, CVC, bank account number, or any credential that could be used to make a payment.

What the processors receive

  • Stripe receives your payment details, billing name, billing address and country where required for tax, your email if you provide one at checkout, your IP address, and an identifier that lets us match the payment to your Zaplog account. Stripe acts as an independent controller for its own fraud-prevention and regulatory obligations, and its handling of your data is governed by its own privacy policy.
  • Google and Apple process store purchases entirely within their own systems. We receive confirmation that a purchase exists and its current state. We do not receive your payment details, and in most cases we do not receive your store account email.

Refunds, disputes and chargebacks. If you dispute a charge with your bank, we receive notice of the dispute from Stripe and may submit evidence in response — your subscription record, the billing events log, and the account activity that shows the service was provided. We do this to answer the dispute, and we do not use it for any other purpose. How disputes are handled commercially is set out in section 17 of the Terms of Service.

Tax and accounting. We keep transaction records for as long as tax, accounting and anti-fraud law requires — typically seven years — even after you cancel or delete your account. This is a legal obligation and it survives a deletion request. See section 11.

Advertising. We do not use payment or subscription data for advertising, and we do not sell it. Whether you subscribe has no effect on how your content is treated, and Pro does not change the privacy protections described anywhere else in this policy.

3.22 Cookies, local storage and similar technologies

This subsection is mainly about the web client and zaplog.ai. The Android and iOS apps do not use cookies for their own operation; they store the equivalent data in the app's own storage on your device.

CategoryWhat it doesCan you refuse?
Strictly necessaryKeeps you signed in, secures your session, prevents cross-site request forgery, balances load, and remembers a consent choice you madeNo — the web client cannot work without these
FunctionalRemembers your theme, language, layout and similar preferencesYes, with reduced convenience
Payment and fraud preventionSet by our payment processor at checkout to detect fraudulent transactionsNo, if you are completing a purchase
AnalyticsNone. We run no analytics or tracking cookies, on any surfaceNot applicable
AdvertisingNone. We set no advertising cookies and permit no third-party ad trackersNot applicable

We also use browser local storage and equivalent technologies to hold your session and cached content so the web client works offline and loads quickly.

Your choices. You can clear or block cookies and site data in your browser settings; blocking strictly necessary cookies will sign you out and break the web client. Where the law requires a consent banner for non-essential cookies, we show one and honour your choice, and you can change it at any time from the footer of zaplog.ai.

Do Not Track and Global Privacy Control — see Appendix B.

Inside Zaplog's built-in browser, websites you visit set their own cookies. Those are the websites' cookies, not ours, and private tabs use a separate profile that is cleared when you close them.

4. Device permissions and why we ask for them

Every permission below is requested in context, at the moment the feature needs it. You can decline any of them and continue using the rest of Zaplog, and you can revoke any of them later in your device settings.

Permission models differ by platform, so this section is split three ways.

4.1 Android permissions

PermissionUsed forOptional?
INTERNET, ACCESS_NETWORK_STATEAll network communicationRequired
CAMERAStories, video notes, video calls, meal and label scanning, barcode scanning, document scanning, QR device pairing, sticker creationOptional
RECORD_AUDIO, MODIFY_AUDIO_SETTINGSVoice notes, video notes, calls, Notes recordings, voice input for Zaplog AI and ZappyOptional
READ_MEDIA_IMAGES, READ_MEDIA_VIDEO, READ_MEDIA_VISUAL_USER_SELECTED, READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGEAttaching and saving photos and videos; ZapCloud photo backup. Android 14+ partial access is supported — you can grant access to selected items onlyOptional
MANAGE_EXTERNAL_STORAGE (all-files access)ZapCloud file management across your device storage and backup of arbitrary foldersOptional — ZapCloud works in a limited mode without it
READ_CONTACTS, WRITE_CONTACTSShowing contact names, contact discovery, saving contactsOptional
READ_SMS, WRITE_SMS, SEND_SMS, RECEIVE_SMS, RECEIVE_MMS, RECEIVE_WAP_PUSHActing as your default SMS app. Content stays on your deviceOptional
READ_PHONE_STATEDetecting your SIM/network country for phone-number formatting, and handling call interruptionsOptional
ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATIONLive location sharing in chat and the location picker. We do not request background location and Zaplog cannot track you when the sharing service is not runningOptional
READ_CALENDARShowing your device calendar events alongside your Organized planOptional
Health Connect: READ_STEPS, READ_ACTIVE_CALORIES_BURNED, READ_WEIGHT, READ_EXERCISE, READ_SLEEP, WRITE_WEIGHTZapFit activity and weight trackingOptional
POST_NOTIFICATIONS, USE_FULL_SCREEN_INTENTMessage, call and reminder notifications; incoming-call screensOptional
USE_EXACT_ALARM, SCHEDULE_EXACT_ALARM, VIBRATE, WAKE_LOCK, RECEIVE_BOOT_COMPLETEDReminders, focus timers, fasting timers, scheduled sends and Zappy automations firing on time and surviving rebootOptional
DETECT_SCREEN_CAPTURE, DETECT_SCREEN_RECORDINGTelling the other person in a chat that a screenshot or recording was takenRequired for that feature
FOREGROUND_SERVICE and its media-projection, media-playback, location, microphone, camera, data-sync and special-use typesKeeping calls, podcast playback, screen sharing, live location and uploads running reliably in the backgroundRequired for those features

Permissions we deliberately do not request: background location, Bluetooth, call log, phone dialling, account list, or full package visibility.

To review or revoke: Android Settings → Apps → Zaplog → Permissions. Health permissions are managed separately in Health Connect.

4.2 iOS permissions

iOS asks for fewer, broader permissions than Android, and several Android features have no iOS equivalent.

PermissionUsed forOptional?
CameraStories, video notes, video calls, meal and label scanning, barcode and QR scanning, document scanning, sticker creationOptional
MicrophoneVoice notes, video notes, calls, Notes recordings, voice input for Zaplog AI and ZappyOptional
PhotosAttaching and saving photos and videos, and ZapCloud photo backup. iOS limited-library access is supported — you can grant access to selected photos onlyOptional
ContactsShowing contact names, contact discovery, saving contactsOptional
Location — While Using the AppLive location sharing in chat and the location picker. We do not request Always-on locationOptional
CalendarShowing your device calendar events alongside your Organized planOptional
Apple HealthZapFit activity and weight tracking, where this integration is available in your version of the appOptional
NotificationsMessage, call and reminder notificationsOptional
Local Network / BluetoothNot requested
Tracking (App Tracking Transparency)Never requested. Zaplog does not track you across other companies' apps or websites, so this prompt does not apply to us
Screen recordingScreen sharing during a call, using the system broadcast picker you controlOptional
Background App RefreshKeeping calls, podcast playback, uploads and reminders working when the app is not in frontOptional

Not available on iOS: the default-SMS-app role, all-files device storage access, and exact-alarm scheduling. Reminders and timers on iOS use the system notification scheduler, which Apple controls.

To review or revoke: iOS Settings → Zaplog, or Settings → Privacy & Security. Health permissions are managed in the Health app.

4.3 Web and desktop client

The web client asks the browser, not the operating system, and only when you use the feature:

Browser permissionUsed for
Camera and microphoneCalls, voice notes, and anything you record in the browser
Screen captureScreen sharing during a call, using the browser's own picker
NotificationsWeb push for messages and calls
ClipboardCopy and paste inside the app, on your action
StorageKeeping you signed in and caching content for offline use — see section 3.22

The web client has no access to your contacts, your device photo library, your calendar, your health data, your SMS, or your file system beyond files you explicitly choose to upload or download. Signing in to the web client requires approving a pairing code on your phone, and you can revoke it at any time from Settings → Linked devices.

To review or revoke: your browser's site-settings panel for zaplog.ai.

5. How we use your information

We use personal information only for the purposes below.

  1. Providing the Services — authenticating you, delivering messages and calls, syncing your files, notes, planner and library across devices, playing podcasts, running searches, and generating AI responses you asked for.
  2. Personalising your experience — showing your contacts, your Rooms, your recommended topics in Discover, your ZapFit targets derived from your own figures, and your planner.
  3. Safety, moderation and integrity — detecting and acting on spam, harassment, illegal content, ban evasion and abuse; operating reports, appeals, mutes, bans and Room automod; enforcing rate limits and age gates.
  4. Security — verifying devices, managing encryption keys, detecting unauthorised access, and protecting against fraud.
  5. Taking payment — processing subscriptions, applying and removing entitlements, handling renewals, cancellations, refunds and disputed charges, preventing payment fraud, and keeping the tax and accounting records the law requires.
  6. Support — answering your questions and investigating problems you report.
  7. Reliability and improvement — diagnosing failures and improving features. We do this without third-party analytics SDKs; where we use aggregate operational data we do not use it to build profiles of you.
  8. Legal compliance — responding to lawful requests, enforcing our Terms, and establishing or defending legal claims.
  9. Communicating with you — service messages such as verification codes, security alerts and material changes to this policy.

What we do not do: we do not use your information for advertising, we do not sell it, we do not use your private content to train AI models, and we do not use Health Connect or other health data for any purpose beyond the ZapFit and Organized features you use.

7. Encryption and security

7.1 End-to-end encryption in Chats

Zaplog Chats uses the Signal protocol — X3DH and PQXDH key agreement with the Double Ratchet, including post-quantum key encapsulation. Message bodies are encrypted with a per-message content key using AES-256-GCM, and that key is delivered separately to each of the recipient's registered devices. Attachments are encrypted with AES-CTR and authenticated with HMAC-SHA256 so they can be streamed and seeked without decrypting the whole file.

7.2 What end-to-end encryption covers

Chat message bodies and attachments, voice and video notes, stickers, live location shared in chat, call signalling metadata, and Zappy's transcript, memories, automations and attachments (which are sealed on your device under your account archive key).

7.3 What it does not cover

ZapCloud files, Notes, Organized items including mood and cycle logs, browser history and bookmarks, ZapFit data and meal photos, Zaplog AI conversations and attachments, Stories, all Rooms content including Room channel chat, your profile, and your saved contacts.

These are protected by encryption in transit and encryption at rest, and by record-level access controls that restrict each record to its owner. But Zaplog is technically capable of accessing them, and does so only for the purposes in section 5 — principally support you request, Trust & Safety enforcement, and legal compliance.

7.4 Key escrow — an honest disclosure

If you want a strictly no-escrow guarantee, Zaplog is not currently the right tool for that specific threat model.

7.5 Device-side protections

  • App Lock and Locked chats use your device biometric — Android's biometric prompt, or Face ID and Touch ID on iOS. In both cases the operating system tells Zaplog only whether the check passed. Your fingerprint or face data never leaves your device and is never available to Zaplog.
  • Screen guard blocks screenshots inside the app using Android's secure-window flag. iOS does not let apps block screenshots, so on iOS the app hides sensitive content when it moves to the background and notifies the other participant instead.
  • Sensitive local secrets, including OAuth tokens for Zappy connectors and your archive key, are wrapped with a key held in your device's hardware-backed secure store — the Android Keystore, or the iOS Keychain backed by the Secure Enclave.
  • Deleting your account, and disabling screen guard, require biometric confirmation.

7.6 Server-side protections

  • All traffic between the app and our servers is encrypted in transit.
  • Record-level access controls are our primary access boundary — each record is readable only by the accounts entitled to it.
  • Staff access to our moderation tooling requires multi-factor authentication and network-level restrictions, and every action is written to an append-only audit log.
  • Access tokens for real-time calling are short-lived and issued per session.

No system is perfectly secure. We cannot guarantee absolute security, and we ask you to protect your device with a lock screen and to keep the app updated.

7.7 Breach notification

If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where the GDPR requires it, and notify affected users without undue delay where required by that or other applicable law.

8. How we share information

We share personal information only in the circumstances below.

8.1 With other users, because that is the point

  • Chats — your messages, name, photo, presence and read receipts are visible to your correspondents.
  • Stories — visible to the audience you choose, and you can see who viewed them.
  • Rooms — your posts, comments, votes (in aggregate), flairs, awards and Room profile are visible according to the Room's settings. Public Rooms may be visible to anyone.
  • Calls — participants see your name, photo, and whatever your camera or shared screen shows.
  • Contact discovery — people who have your number in their address book may see that you are on Zaplog.
  • ZapCloud share links — anyone with the link (subject to any password or access limit you set) can access the shared file.

You control much of this in Privacy settings, including who can see your profile photo, last seen and status, and whether you are searchable by username.

8.2 With Room moderators

Moderators of a Room you participate in can see your content in that Room, your Room membership and roles, reports about you, and moderation history within their Room. They cannot see your private chats, your files, your health data or your planner.

8.3 With service providers

We share the minimum necessary with the categories of provider described in section 9. They act on our instructions under contract, and are not permitted to use your information for their own purposes.

We may disclose information if we believe in good faith that it is reasonably necessary to:

  • comply with a valid law, regulation, legal process or enforceable governmental request;
  • enforce our Terms of Service, including investigation of potential violations;
  • detect, prevent or address fraud, security or technical issues; or
  • protect against harm to the rights, property or safety of Zaplog, our users or the public, including in an emergency involving a risk of death or serious physical injury.

Where we are legally permitted to do so, we will make reasonable efforts to notify you of a legal request for your information before disclosing it, unless we are prohibited from doing so, the request relates to an emergency, or notice would be counterproductive.

8.5 Business transfers

If Zaplog is involved in a merger, acquisition, financing, reorganisation or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy, and the receiving entity will be bound by commitments at least as protective as those here.

8.6 With your direction

When you connect Google or Microsoft to Zappy, share a file, post to a public Room, or open a link, information moves at your direction.

8.7 What we never do

We do not sell personal information. We do not share it for cross-context behavioural advertising. We do not disclose your content to data brokers. We do not provide your private content to third parties for their own marketing.

9. Who receives your information

We do not publish the names of the vendors behind our infrastructure. What matters for your privacy is what kind of company receives your information, what they get, and what they are allowed to do with it — so this section sets that out by category. Every provider below is bound by a written contract that limits them to acting on our instructions and forbids them from using your information for their own purposes.

If you are exercising a right under the GDPR, UK GDPR or a US state privacy law and need the specific identity of a recipient, ask us at support@zaplog.ai and we will provide it.

Category of recipientWhat they do for usWhat they receive
Cloud infrastructure and database providerStores and synchronises your account, content and files; runs our backendSubstantially all server-side data described in this policy, plus IP address and connection metadata
AI model providerHosts every model Zaplog uses — Zaplog AI, Zappy, translation, chat recaps, meal and label analysis, note summarisation, planning and browser assistPrompt content, attached images and extracted document text, and the generated output. Not used to train any models
Real-time communications providerTransports audio, video and screen sharing for calls and Rooms voice channelsReal-time media streams, per-session access tokens, IP address
SMS and voice providerDelivers your verification codesYour phone number and the code
Mobile platform push serviceDelivers notifications to your deviceYour push token and the notification payload. For encrypted chats we send a wake signal, not message content
Mobile platform services on your deviceLocation for live location sharing; verification-code auto-fill; on-device document scanning, barcode reading, text recognition and image labelling; Health ConnectThe on-device features process locally and send us nothing. Location reaches us only while you are actively sharing it
Map providerMap imagery in the location picker and live locationMap tile requests, which reveal the area you are viewing, and your IP address
GIF and sticker libraryGIF and sticker searchYour search terms and IP address. Never your Zaplog identity
Podcast catalogue providerShow metadata and catalogue searchYour search terms
Podcast feeds and audio hostsEpisode audio, artwork and transcriptsYour IP address and user-agent, directly, when you stream or download. Not your Zaplog identity
News aggregatorDiscover headlinesQuery terms
Food and nutrition databasesBarcode and generic-food lookupsThe barcode or search term. The barcode lookup happens from your device
Independent search enginesWeb search and address-bar suggestions for Zaplog AI, Deep Research and the browserQuery terms and IP address. We use several providers and none of them receive your Zaplog identity
Websites you visit, or that we fetch for an AI answerSource pagesRequest metadata including IP address and user-agent
Google and Microsoftonly if you connect them to ZappyGmail or Outlook, Drive or OneDrive, Docs, Calendar, Contacts and TasksZaplog acts on your account strictly within the scopes you approved. You can revoke this at any time
Payment processor — StripeTakes payment for Zaplog Pro on the web client and zaplog.ai; handles refunds and payment disputesYour payment details, billing name and address, country for tax, email if given at checkout, IP address, and a reference matching the payment to your account. Stripe never gives us your card number
App stores — Google Play and AppleTake payment for Zaplog Pro inside the Android and iOS apps, and handle their own refundsEverything about the transaction stays inside the store. We receive only that a subscription exists and its current state
Security and network protection providerProtects our internal staff toolingStaff request metadata. No end-user content flows through it in normal operation

What no one on this list may do: use your information for their own products, sell it, combine it with data from other customers to profile you, or use it for advertising. None of these providers is an advertising, analytics, attribution or data-broker company, because Zaplog uses none of those.

One exception on roles. Our payment processor and the app stores act as independent controllers for their own fraud-prevention, regulatory and tax obligations, not purely on our instructions. That is inherent to processing a payment, and your relationship with them is governed by their own privacy policies as well as this one.

If we add a category of recipient, or materially change what an existing category receives, we will update this section and — where the law requires it — notify you or ask for your consent.

10. International data transfers

Zaplog Inc. is based in the United States, and our infrastructure and providers operate in the United States and other countries. If you use Zaplog from outside the United States, your information will be transferred to and processed in the United States and potentially elsewhere, where data protection laws may differ from those in your country.

Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on:

  • the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum, incorporated into our agreements with providers; and
  • supplementary technical measures, including encryption in transit and at rest, and end-to-end encryption for the categories listed in section 7.2.

You can request a copy of the relevant transfer safeguards by writing to support@zaplog.ai.

11. How long we keep information

DataRetention
Account and profileFor as long as your account exists
Chat messagesUntil you or the other participant deletes them, the disappearing-message timer expires, or your account is deleted. Encrypted copies already delivered to another person's device are outside our reach
Disappearing and view-once mediaPurged by a scheduled server sweep after expiry or viewing
StoriesHidden after 24 hours. In the current release the record and media persist until you delete the story or your account. See section 3.4
Call metadataFor as long as your call history exists, or until you clear it
SMS / MMSNever uploaded. Retained on your device by Android's system message store. Not applicable on iOS or the web
Rooms posts and commentsRetained while the Room exists. On account deletion, they are kept and re-attributed to a deleted-account placeholder so conversations remain coherent — see below
Moderation records — reports, mod log, bans, appeals, notesRetained after account deletion where necessary for platform safety, ban-evasion prevention and legal defence
ZapCloud filesUntil you delete them. Deleted items sit in Trash for 30 days, after which both the database rows and the underlying storage objects are permanently purged
Notes, Organized items, browser history, podcast libraryUntil you delete them, using tombstoned sync so deletions propagate across your devices
ZapFit dataUntil you delete it or your account
Zaplog AI sessionsUntil you delete the session or your account
Zappy memories, transcript, automationsUntil you clear them or your account is deleted
Verification codesMinutes — they expire quickly and are not retained after use
Device and session recordsUntil the device is revoked, plus a short period for security investigation
Subscription records — status, period end, processor referencesWhile the subscription exists, and for the tax-record period below
Transaction, invoice, refund and dispute recordsSeven years, or the period your local tax and accounting law requires. This is a legal obligation and it survives account deletion and erasure requests
Billing event logSeven years, alongside the transaction records it explains
Support correspondenceUp to 24 months after resolution
Staff audit logRetained for accountability. This is an append-only record of staff actions, not of your content
BackupsEncrypted backups may retain data for up to 90 days after deletion before rotating out
Legal holdsWhere we are legally required to preserve information, retention is extended for the duration of that obligation

11.1 Account deletion in detail

Go to Settings → Account → Delete account. You must type DELETE and confirm with your biometric.

  • A 30-day grace period begins. All your sessions are revoked.
  • Signing in again during those 30 days cancels the deletion.
  • After 30 days, a scheduled process purges your account data.
  • Rooms posts and comments are retained and re-attributed to an anonymous deleted-account placeholder, so threads other people participated in are not destroyed.
  • Rooms you created transfer ownership; groups you administered pass to another admin.
  • Messages already delivered to other people's devices cannot be reached by us. The app tells you this before you confirm.
  • Transaction and tax records are retained for the period in the table above. Deleting your account does not cancel a subscription bought through a store — cancel it in Google Play or the App Store as well, or it will keep renewing.

12. Your privacy rights and how to exercise them

12.1 Rights available to everyone, in the app

RightWhere
See and edit your profileSettings → Profile
Control who sees your photo, last seen, status and read receiptsSettings → Privacy
Control whether you are searchable by usernameSettings → Privacy
Block and unblock accountsSettings → Blocked accounts, or a user's profile
Manage or revoke linked devicesSettings → Linked devices
Review and revoke permissionsAndroid Settings → Apps → Zaplog → Permissions · iOS Settings → Zaplog · or your browser's site settings for zaplog.ai
Disconnect Zappy connectorsZappy → Settings → Connectors
Clear Zappy memoriesZappy → Settings
Delete individual messages, stories, posts, files, notes, planner items and AI sessionsIn each feature
Empty ZapCloud Trash immediatelyZapCloud → Trash
Manage or cancel your subscriptionSettings → Zaplog Pro, or Google Play / App Store subscriptions, depending on where you bought it
Export your ZapFit dataZapFit → Settings → Export
Delete your accountSettings → Account → Delete account

12.2 Rights under the GDPR and UK GDPR

If you are in the EEA, the UK or Switzerland you have the right to: access your personal data and receive a copy; rectify inaccurate data; erase your data; restrict processing; object to processing based on legitimate interests; data portability; withdraw consent at any time; and not be subject to a decision based solely on automated processing with legal or similarly significant effects.

You also have the right to lodge a complaint with your supervisory authority. A list of EEA authorities is at edpb.europa.eu; in the UK, the Information Commissioner's Office at ico.org.uk.

12.3 Rights under California law (CCPA / CPRA)

California residents have the right to know what personal information we collect, use, disclose and retain; to delete it; to correct it; to opt out of sale or sharing; to limit the use of sensitive personal information; and to non-discrimination for exercising these rights.

We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is no opt-out to offer. We use sensitive personal information — which for us includes precise geolocation when you share it, health data, and the contents of your communications — only to provide the features you asked for and for security and safety, which are permitted purposes that do not trigger the right to limit.

Categories of personal information we have collected in the last 12 months, using the CCPA's own categories: identifiers; customer records; characteristics of protected classifications (age, sex); commercial information (subscription and transaction records for Zaplog Pro); internet or network activity; geolocation; sensory data (audio, photographic, video); professional information (none); education information (none); inferences (limited to feature personalisation); and sensitive personal information as described above.

12.4 Rights under other US state laws

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island and other states with comprehensive privacy laws have rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale and certain profiling. We do not conduct targeted advertising, sale, or profiling with legal or similarly significant effects.

Where state law provides an appeal right, you may appeal a denied request by replying to our decision; we will respond within the period your state's law requires.

12.5 Rights elsewhere

We extend access, correction, deletion and portability rights to all users regardless of location, including under Brazil's LGPD, Canada's PIPEDA, Australia's Privacy Act and similar laws.

12.6 How to make a request

Email support@zaplog.ai from the email address on your account, or from within the app so we can associate the request with your account. Tell us what you want and which jurisdiction you are in.

  • We will verify your identity, usually by sending a code to your registered phone number. We ask for this because your phone number is your account.
  • We respond within 30 days (GDPR) or 45 days (US state laws), extendable once where the law permits, and we will tell you if we need the extension.
  • Requests are free unless they are manifestly unfounded or excessive.
  • One limit on erasure: we cannot delete transaction and tax records within their statutory retention period. We will delete everything else and tell you precisely what was retained and why.
  • You may use an authorised agent; we will ask for proof of authorisation and may still verify your identity directly.

13. Health and consumer health data

ZapFit and parts of Organized process information that several laws treat with heightened protection, including GDPR Article 9 special-category data, the Washington My Health My Data Act, Nevada SB 370, and similar state consumer-health-data laws.

What we treat as health data

  • Everything in ZapFit: your biological sex, date of birth, height, weight, body measurements, body-fat percentage, dietary pattern, allergies, avoided foods, food and water logs, exercise logs, fasting sessions, and your onboarding answers about sleep, stress, motivations and obstacles.
  • Health Connect records: steps, active calories, sleep sessions, weight and exercise.
  • Meal photos and nutrition-label photos.
  • Organized mood check-ins.
  • Organized menstrual-cycle logs, including period start and end dates and derived cycle-phase predictions.

Our commitments

  1. We collect this data only because you chose to use these features, and we ask for your explicit consent — through the feature itself and, for platform health data, through the separate health permission flow that Android (Health Connect) and iOS (the Health app) each run outside Zaplog.
  2. We use it only to operate the feature you are using: computing your targets, showing your trends, predicting your cycle phase, and generating the analysis you requested. This holds on every platform.
  3. We never use health data for advertising or marketing, and we never sell it. Google Play's Health Connect policy requires this; we commit to it independently and it applies to all health data in Zaplog, not just Health Connect data.
  4. We do not share health data with any third party except our infrastructure provider (which stores it) and our AI provider (which analyses a meal photo or planning description at your request).
  5. You can delete any health entry, delete your ZapFit profile, or export your ZapFit data at any time.
  6. Revoking the permission — in Health Connect on Android, or the Health app on iOS — stops all further reads immediately. Records already imported remain until you delete them.

Washington My Health My Data Act notice. If you are a Washington resident, you have the right to confirm whether we collect, share or sell your consumer health data, to obtain a list of third parties with whom we share it, to withdraw consent, and to have it deleted. We do not sell consumer health data, and we do not require a valid authorisation for sale because no sale occurs. To exercise these rights, email support@zaplog.ai with "MHMD request" in the subject line.

Not medical advice. ZapFit and Organized are wellness tools. Calorie estimates from a photo are estimates. Cycle predictions are estimates and must not be relied on for contraception or family planning. Nothing in Zaplog is medical advice, diagnosis or treatment. Talk to a qualified clinician about your health.

14. Children and teenagers

14.1 Minimum age

You must be at least 13 years old to use Zaplog. In the European Economic Area, the United Kingdom and any other country where the digital-consent age is higher, you must be at least 16, or the age your country specifies. Creating a Room requires you to be 18 or older.

We ask for your date of birth at onboarding and enforce a minimum of 13 at the database level. Your date of birth is write-once and cannot be edited in the app.

14.2 Protections for accounts under 18

  • Accounts belonging to users under 18 are not username-searchable by default.
  • Room age gates — 13 or 18 — are enforced against your stored date of birth, so an 18+ Room is closed to you.
  • Under-18 users cannot create Rooms.

14.3 We do not knowingly collect from children under 13

Zaplog is not directed to children under 13 and we do not knowingly collect personal information from them, consistent with the US Children's Online Privacy Protection Act (COPPA) and equivalent laws elsewhere. If we learn that we have, we will delete the account and its data promptly.

If you are a parent or guardian and believe your child under 13 has created an account, email support@zaplog.ai with the phone number on the account. We will verify the request and delete the account and its data. You may also ask us to stop any further collection.

14.4 A note on age verification

Age is currently self-declared. We do not run documentary or biometric age verification. We enforce the age you declare, and we act on credible reports that a user is below the minimum age.

15. Information about people who do not use Zaplog

If you use Zaplog, some information about people who are not Zaplog users may reach us:

  • Contact discovery sends the phone numbers in your address book to our servers so we can identify which are registered. Numbers that do not match an account are used only to compute that result.
  • Saved contacts — when you save a contact in Zaplog, that person's name and phone number are stored on our servers so they sync to your devices.
  • Content you post — a non-user's name, image or information may appear in a message, Room post or file you upload.
  • SMS — messages you exchange with non-users through Zaplog as your SMS app stay on your device and are not uploaded to us.

You are responsible for having a lawful basis to share other people's information with us. In some jurisdictions, uploading an address book requires the consent of the people in it.

If you are not a Zaplog user and want to know whether we hold information about you, or want it deleted, email support@zaplog.ai. We will need enough information — normally the phone number in question — to locate any records, and we will confirm what we hold and honour deletion where we are not legally required to retain it.

16. Advertising, selling and sharing — what we do not do

Being explicit, because this is unusual enough to be worth stating:

  • Zaplog contains no advertising. There is no ad SDK, no ad mediation, no sponsored content system.
  • Zaplog contains no third-party analytics SDK of any kind.
  • Zaplog contains no attribution, install-measurement or marketing-metrics SDK.
  • Zaplog contains no third-party crash-reporting SDK.
  • Zaplog contains no social-network SDK.
  • We do not sell personal information for money or other valuable consideration.
  • We do not share personal information for cross-context behavioural advertising.
  • We do not use your private content to train AI models — not ours, and not our provider's.
  • We do not use Health Connect or Apple Health data, or any health data, for advertising.
  • We do not use payment or subscription data for advertising, and subscribing to Zaplog Pro does not change how any of your data is handled.

If any of this changes, we will update this policy and give you advance notice, and where the law requires consent we will ask for it before the change takes effect.

17. Automated decision-making and profiling

We use automated systems in a few places:

  • Automated moderation in Rooms — banned-word and pattern matching, link and spam rules, rate limits, crowd control and ban-evasion signals. These can automatically remove content, queue it for human review, mute, or restrict an account.
  • Rate limiting and abuse prevention across the platform.
  • AI-generated outputs — answers, meal estimates, plan proposals and summaries.

Human review. Moderation actions with meaningful consequences — removals, bans and restrictions — can be appealed, and appeals are reviewed by a person. Room-level actions are appealed to the Room's moderators; platform-level actions are appealed to Zaplog's Trust & Safety team via modmail or support@zaplog.ai.

We do not make decisions that produce legal effects concerning you or similarly significantly affect you based solely on automated processing without the ability to obtain human review.

18. Changes to this policy

We may update this policy as Zaplog changes. When we do:

  • We revise the "Last updated" date and increment the version.
  • For material changes — a new category of data, a new purpose, a new class of recipient, or a change that reduces your rights — we will notify you in the app and, where we have your email address, by email, at least 30 days before the change takes effect, unless the change is required to take effect sooner by law.
  • Where a change requires your consent under applicable law, we will ask for it before the change applies to you.
  • Previous versions are available on request at support@zaplog.ai.

Continuing to use Zaplog after a change takes effect means you accept the updated policy. If you do not accept it, you can delete your account.

19. How to contact us

Privacy questions, rights requests, and anything else in this policy: support@zaplog.ai

Postal: Zaplog Inc. 33 N La Salle St Chicago, IL 60602 United States

EEA and UK representatives: if we are required to appoint an Article 27 representative, their details will be published here.

Data Protection Officer: if we are required to appoint one, their contact details will be published here. In the meantime, privacy matters are handled directly at support@zaplog.ai.

We aim to respond to every privacy enquiry within five business days, and to formal rights requests within the statutory period.

Appendix A — Google Play Data Safety mapping

This appendix summarises what Zaplog declares in the Google Play Data safety section. It is a summary; the body of this policy controls.

Data typeCollectedSharedPurposeOptional
NameYesWith other usersApp functionality, account managementNo
Email addressYesNoAccount managementYes
Phone numberYesWith other users; with SMS provider for verificationAccount management, app functionalityNo
Address book contactsYesNoApp functionality (contact discovery)Yes
Date of birth, genderYesNoApp functionality, age gatingNo
Photos and videosYesWith other users where you send or post themApp functionalityYes
Voice or sound recordingsYesWith other usersApp functionalityYes
Music files, other audioNot collected — podcast downloads are stored on your device only
Files and documentsYesWith recipients of your share linksApp functionalityYes
Calendar eventsYes (read from device)NoApp functionalityYes
Approximate and precise locationYesWith chat recipients when you shareApp functionalityYes
Messages — in-appYes (encrypted)With recipientsApp functionalityNo
Messages — SMS/MMSNot collected; processed on device onlyNoApp functionalityYes
Health and fitnessYesNoApp functionalityYes
App activity — in-app search history, other actionsYesNoApp functionality, personalisationPartly
Web browsing historyYes (sync; incognito excluded)NoApp functionalityYes
Installed appsNot collected
Device or other IDsYes (app-generated install ID only; no advertising ID)NoApp functionality, securityNo
Crash logs, diagnosticsNot collected by third-party SDK
Purchase historyYes — Zaplog Pro subscription state and transaction recordsWith our payment processor and the app stores, to take paymentApp functionality, account managementYes — only if you subscribe

Payment note: in-app purchases are processed by Google Play on Android and by the App Store on iOS. Payments on the web are processed by Stripe. Zaplog never receives or stores card numbers.

Security practices declared: data is encrypted in transit; certain data is end-to-end encrypted; you can request data deletion; the app follows the Play Families policy where applicable; the app has committed to Play's Health Connect data-use restrictions.

Appendix B — Region-specific disclosures

B.1 California — "Shine the Light"

California Civil Code § 1798.83 allows California residents to request information about disclosure of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.

B.2 California — Do Not Track

Zaplog's built-in browser does not respond to "Do Not Track" signals, because there is no consistent industry standard for them; it applies an on-device tracker blocklist instead. Zaplog itself does not track you across third-party websites on any platform, and our web client sets no analytics or advertising cookies.

B.3 Nevada

Nevada residents may submit a request to opt out of the sale of certain personal information. We do not sell personal information. You may still submit a request to support@zaplog.ai.

B.4 Colorado, Connecticut and other universal-opt-out states

We honour universal opt-out mechanisms such as Global Privacy Control where they apply. Because we do not sell or share personal information for targeted advertising, such a signal does not change how we process your data.

B.5 European Economic Area, UK and Switzerland

See sections 6, 10 and 12.2.

B.6 Brazil (LGPD)

Brazilian users have rights of confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent. Contact support@zaplog.ai.

B.7 Canada (PIPEDA / Law 25)

Canadian users may access and correct their personal information and may complain to the Office of the Privacy Commissioner of Canada. Quebec residents have additional rights of portability and de-indexing under Law 25.

B.8 Australia

Australian users may access and correct personal information under the Australian Privacy Principles, and may complain to the Office of the Australian Information Commissioner.