Back to Home

Privacy Policy

Last updated: July 2026

1. Introduction

At Zeteo, our foundation is built on the belief that your financial data is yours and yours alone. This Privacy Policy explains in plain English how we collect, use, protect, and handle your personal information when you use our app and website.

Our promise to you: We do not sell your personal or financial data to anyone. You are our customer, not our product.

2. Information We Collect

We only collect information necessary to provide you with financial clarity:

  • Information you provide to us: This includes your name, email address, and login credentials when you create an account.
  • Financial Information: To power your budgets and forecasts, we retrieve your account balances, transaction history, and institutional data. We do this exclusively through our secure partner, Plaid (more on that below).
  • Usage & Device Information: We automatically collect anonymous diagnostic data, such as your device type, operating system version, and how you navigate the app. This helps us squash bugs and improve the experience.

3. Third-Party Integrations (Plaid)

Your security is paramount. We do not ask for, see, or store your bank usernames or passwords. Instead, we use Plaid Inc. ("Plaid") to securely connect to your financial institutions.

When linking an account, you will provide your credentials directly to Plaid, and they provide us with a secure, read-only token to access your transaction data. Information shared with Plaid is treated by Plaid in accordance with their privacy policy, which we strongly encourage you to review: Plaid End User Privacy Policy. Zeteo users can manage or disconnect their bank connections directly within the Zeteo app or through the Plaid Portal.

4. How We Use Your Information

We use your data strictly to operate and improve Zeteo:

  • To provide our core services, such as 30-day forecasting, rollover budgeting, and group expense splitting.
  • To perform smart auto-categorization and recurring subscription detection.
  • To respond to your customer support inquiries.
  • To track app performance and squash bugs.

5. Legal Basis for Processing (GDPR)

For users in the EU/EEA, we process your personal data under the following legal bases:

Processing ActivityLegal Basis
Creating and managing your accountPerformance of contract (Art. 6(1)(b))
Connecting your bank accounts via PlaidPerformance of contract; explicit consent
Analyzing transactions and managing budgetsPerformance of contract
Sending push notificationsConsent (you may withdraw at any time in device settings)
Parsing receipt text to itemize group bills (Anthropic — Smart Split)Performance of contract — processing occurs only when you initiate a receipt scan
Managing premium subscriptions (RevenueCat)Performance of contract (Art. 6(1)(b))
Product analytics (PostHog — anonymized)Legitimate interests — improving the service
Error monitoring (Sentry — PII-scrubbed)Legitimate interests — maintaining service reliability
Marketing communicationsConsent (separate opt-in required)

6. How We Share Your Information

As stated above, we do not sell your data. However, we do share data with trusted service providers to run our platform, under strict confidentiality agreements:

  • Service Providers: We share data with trusted service providers to operate our platform:
    • Supabase and AWS for secure database hosting
    • Plaid for bank connections
    • PostHog for product analytics
    • Sentry for error monitoring (we scrub Personally Identifiable Information before it hits our crash reporters)
    • Firebase (Google) for push notifications via Firebase Cloud Messaging
    • RevenueCat for subscription management
    • Anthropic for AI-powered receipt parsing in Smart Split
  • Firebase (Google LLC)— We use Firebase Cloud Messaging (FCM) to deliver push notifications to your device on both iOS and Android. Your device push token is shared with Firebase solely for this purpose. Push notifications require your consent: on iOS and on Android 13 and later, your operating system asks you to grant notification permission, and you can withdraw it at any time in your device settings. Google's privacy policy governs Firebase's handling of this data. Firebase is a Google service operating under Google's Data Processing Addendum.
  • Anthropic, PBC — When you use Smart Split receipt scanning, the text extracted from your receipt photo is sent to Anthropic's Claude API to itemize the bill. Your receipt photo never leaves your device — only the extracted text is processed, and we never log or store the raw receipt text on our servers. Under Anthropic's commercial data policy, this data is not used to train Anthropic's models and is automatically deleted from Anthropic's systems within 30 days.
  • RevenueCat, Inc. — We use RevenueCat to manage Zeteo Premium subscriptions. When you purchase or restore a subscription, your app account identifier and App Store purchase information are shared with RevenueCat to validate the purchase and manage your subscription status. RevenueCat never receives your bank, transaction, or other financial data. RevenueCat's handling of this data is governed by its privacy policy.
  • Legal Requirements: We may disclose information if required to do so by law, court order, or subpoena.
  • Business Transfers: If Zeteo is involved in a merger, acquisition, or sale of assets, your data may be transferred, but it will remain subject to the promises made in this Privacy Policy.

Platform availability:Zeteo is distributed through the Apple App Store and is in testing on Google Play. Our data practices are the same regardless of how you obtained the app. Where you obtain Zeteo through Google Play (including a testing track), the disclosures in our Google Play Data Safety form are kept consistent with this Privacy Policy, which is the analog to Apple's App Store privacy labels.

7. Analytics and Tracking Technologies

We use the following analytics and monitoring tools:

  • PostHog: We capture anonymized in-app usage events (e.g., which features you use, which screens you visit) to understand how users interact with Zeteo and improve the product. These events do not include your financial data, account balances, or personally identifiable information. You may opt out of analytics in app settings.
  • Sentry: We capture error reports when the app crashes or encounters an unexpected error. These reports include technical stack traces and device metadata. Personal and financial data is scrubbed before transmission to Sentry.

We do not use advertising identifiers (IDFA) or participate in cross-app tracking. Zeteo complies with Apple's App Tracking Transparency framework.

8. Data Security, Breach Notification, and Retention

We protect your data with multiple verifiable security controls:

  • Encryption:Data is encrypted in transit using TLS. Your data is encrypted at rest by our infrastructure provider, Supabase (hosted on AWS), including AES-256 encryption at the storage layer. Sensitive credentials such as bank connection tokens are further protected using Supabase Vault's authenticated encryption.
  • Isolation: We enforce Row-Level Security (RLS) on every application table, so your records are accessible only to you and, for shared group activity, the other members of that group — enforced at the database layer, not just the application layer.
  • Sessions: For your security, sessions expire after a period of inactivity, after which you will be prompted to sign in again.
  • Vulnerability reporting: If you believe you have discovered a security vulnerability in Zeteo, please report it responsibly to security@zeteoapp.com. We aim to acknowledge reports promptly and to work with researchers in good faith. We do not currently operate a published bug-bounty program.
  • Breach Notification: In the event of a data breach that poses a real risk of significant harm, we will notify affected users and the Office of the Privacy Commissioner of Canada as required by PIPEDA.
  • Retention: We retain your data only for as long as your account is active. After account deletion, your personal and financial data is removed from our active database within 30 days. Encrypted backup copies maintained by our infrastructure provider (Supabase/AWS) may persist for up to an additional 30 days beyond that date before being permanently purged as part of the backup rotation cycle. Anonymized, non-re-identifiable aggregated data may be retained indefinitely for service improvement purposes.

9. Group Data, Shared Records, and People You Invite

Zeteo lets you track shared expenses and IOUs with other people in a group. This creates data that belongs to more than one person, which affects how visibility and deletion work.

  • Shared visibility: When you add a shared expense, balance, settlement, or IOU to a group, the details you enter are visible to the other members of that group. That visibility is how shared tracking works, and it is not something we can hide from the people you are splitting with.
  • Deletion of shared records: When you delete your account or an entry, records that other group members still rely on — for example, a shared expense that determines what someone else owes — may be retained in a reduced or de-identified form so that the remaining members' records stay accurate. Where we retain such records, we disassociate your personal identifiers to the extent we can. This is a recognized limit on the right to erasure (under GDPR, PIPEDA, and similar laws) where deletion would unfairly affect other people's legitimate interests.
  • People you invite (non-users): When you invite someone by name or email, we process that person's personal data to deliver the invitation and set up the shared group. Our lawful basis is performing the invitation you asked us to send and our legitimate interest in operating the group feature. A person who was invited but has not created a Zeteo account can ask us to remove their information at any time by emailing privacy@zeteoapp.com.

10. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate personal data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to the shared-data limits described below and to legal retention requirements.
  • Right to Data Portability: Request a copy of your data in a machine-readable format (JSON or CSV) to transfer to another service. We will provide the export within 30 days of a verified request.
  • Right to Restrict Processing: Request that we limit how we use your data in certain circumstances.
  • Right to Object: Object to our processing of your data where we rely on legitimate interests as our lawful basis.
  • Right to Opt-Out of Sale (California): We do not sell your personal data. This right is satisfied by our data practices.
  • Right to Non-Discrimination (California): We will not discriminate against you for exercising any CCPA rights.

To exercise any of these rights, contact us at privacy@zeteoapp.com, or, where available, through your in-app account settings. We will respond within 30 days, except where applicable law allows a longer period (for example, California requests may take up to 45 days, extendable to 90 with notice — see the section below). For GDPR portability requests, we will provide your data within 30 days in JSON or CSV format.

Account and data deletion can also be requested via zeteoapp.com/delete-account, which documents both the in-app self-serve flow and the email request path.

EU/EEA users also have the right to lodge a complaint with your local data protection supervisory authority at any time.

As a Canadian company, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA), the British Columbia Personal Information Protection Act (PIPA), and, for Quebec residents, the Act respecting the protection of personal information in the private sector, as amended by Quebec Law 25. We believe all our users deserve strong protections worldwide.

11. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by CPRA:

  • Right to Know: You may request the categories and specific pieces of personal information we have collected about you in the past 12 months, the categories of sources, our business purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: We do not sell or share your personal information for cross-context behavioral advertising.
  • Right to Limit Use of Sensitive Personal Information: We use your financial data only to provide the service you requested.
  • Right to Non-Discrimination: We will not discriminate against you for exercising these rights.

To submit a California privacy request, email privacy@zeteoapp.com or use the account settings in the app. We will respond within 45 days (extendable to 90 days with notice).

12. Children's Privacy

Zeteo is intended for users 18 years of age or older. If we become aware that a user under 18 has created an account, we will suspend the account within 24 hours of identification and delete the associated personal data from our active systems, subject to the shared-record limits in Section 9 and the retention and backup-rotation timelines in Section 8.

Because our group feature lets an adult member invite other people, it is possible for an adult to invite a minor into a group. Zeteo is not directed to minors, and an invitation does not create an account. If we learn that an invited person is under 18, we will remove their information from the group and will not create an account for them. If you believe a minor's information has been added to a group, contact us at privacy@zeteoapp.com and we will remove it.

13. Changes to this Policy

We may update this policy as we add new features (like AI insights) or as regulations change. When we make material changes, we will notify you via email or a prominent notification within the app.

AI features: Any AI-powered insights we add in the future will be advisory only and do not constitute financial, tax, or legal advice. We do not use your identifiable financial data to train third-party AI models. Where we use AI today (such as Smart Split receipt parsing), processing is limited to delivering the feature you requested, as described in Section 6.

14. Governing Law

This Privacy Policy is governed by the laws of the Province of British Columbia, Canada, except where preempted by applicable law.

Notwithstanding the foregoing choice of law, nothing in this Privacy Policy limits any rights you may have under applicable data protection laws in your jurisdiction, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), PIPEDA, BC PIPA, or Quebec Law 25.

If you use Zeteo from outside the United States or Canada, you retain all mandatory rights granted by the consumer-protection and data-protection laws of your place of residence, and nothing in this Policy waives those rights.

15. Contact Us

We believe in transparency. If you have questions about how we handle your data, or wish to exercise your privacy rights, please reach out to us at privacy@zeteoapp.com.