Privacy Policy
Last updated: April 2026
1. Introduction
At Zeteo, our foundation is built on the belief that your financial data is yours and yours alone. This Privacy Policy explains in plain English how we collect, use, protect, and handle your personal information when you use our app and website.
Our promise to you: We do not sell your personal or financial data to anyone. You are our customer, not our product.
2. Information We Collect
We only collect information necessary to provide you with financial clarity:
- Information you provide to us: This includes your name, email address, and login credentials when you create an account.
- Financial Information: To power your budgets and forecasts, we retrieve your account balances, transaction history, and institutional data. We do this exclusively through our secure partner, Plaid (more on that below).
- Usage & Device Information: We automatically collect anonymous diagnostic data, such as your device type, operating system version, and how you navigate the app. This helps us squash bugs and improve the experience.
3. Third-Party Integrations (Plaid)
Your security is paramount. We do not ask for, see, or store your bank usernames or passwords. Instead, we use Plaid Inc. ("Plaid") to securely connect to your financial institutions.
When linking an account, you will provide your credentials directly to Plaid, and they provide us with a secure, read-only token to access your transaction data. Information shared with Plaid is treated by Plaid in accordance with their privacy policy, which we strongly encourage you to review: Plaid End User Privacy Policy. Zeteo users can manage or disconnect their bank connections directly within the Zeteo app or through the Plaid Portal.
4. How We Use Your Information
We use your data strictly to operate and improve Zeteo:
- To provide our core services, such as 30-day forecasting, rollover budgeting, and group expense splitting.
- To perform smart auto-categorization and recurring subscription detection.
- To respond to your customer support inquiries.
- To track app performance and squash bugs.
5. How We Share Your Information
As stated above, we do not sell your data. However, we do share data with trusted service providers to run our platform, under strict confidentiality agreements:
- Service Providers: We use Supabase and AWS for secure database hosting, Plaid for bank connections, PostHog for product analytics, and Sentry for error monitoring. (Note: We scrub Personally Identifiable Information before it hits our crash reporters).
- Legal Requirements: We may disclose information if required to do so by law, court order, or subpoena.
- Business Transfers: If Zeteo is involved in a merger, acquisition, or sale of assets, your data may be transferred, but it will remain subject to the promises made in this Privacy Policy.
6. Data Security, Breach Notification, and Retention
We treat your data with bank-level security protocols:
- Encryption: Data is encrypted in transit using 256-bit TLS encryption, and at rest using AES-256 encryption.
- Isolation: We employ Row-Level Security (RLS) on our databases, ensuring that your data can mathematically only be accessed by you.
- Breach Notification: In the event of a data breach that poses a real risk of significant harm, we will notify affected users and the Office of the Privacy Commissioner of Canada as required by PIPEDA.
- Retention: We retain your data only for as long as your account is active. After account deletion, your financial data is removed from active systems within 30 days. Anonymized, aggregated data may be retained for service improvement.
7. Your Privacy Rights
As a Canadian company, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and the British Columbia Personal Information Protection Act (PIPA).
Depending on where you live (such as California under the CCPA or Europe under the GDPR), you have specific legal rights. We believe all our users deserve these protections worldwide:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Delete: You can delete your account and all associated financial data at any time from within the app settings.
- Right to Opt-Out: You can opt out of promotional emails (though we don't send many!) without affecting your service.
8. Children's Privacy
Zeteo is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from minors. If we learn we have collected such information, we will delete it immediately.
9. Changes to this Policy
We may update this policy as we add new features (like AI insights) or as regulations change. When we make material changes, we will notify you via email or a prominent notification within the app.
10. Contact Us
We believe in transparency. If you have questions about how we handle your data, or wish to exercise your privacy rights, please reach out to us at privacy@zeteoapp.com.