Zenea
Privacy Policy
Last updated: August 8, 2026
1. Who We Are
Zenea is a personal well-being and social reflection app. The service provider and privacy contact details are listed in the Contact section below.
2. What This Policy Covers
This Privacy Policy explains how Zenea collects, uses, stores, shares, protects, and deletes information when you use the Zenea app, website, account features, check-ins, private reflection tools, Notes, Mind Games, sharing, chat, Discovery, translations, notifications, Zenea Premium, and related services.
This policy is intended to describe the product as it works today. If Zenea adds materially different data handling later, we will update this policy.
3. Information We Collect
Account and sign-in information: email address, username, authentication identifiers, authentication provider, password reset and verification status, and session data. If you sign in with Apple or Google, they may provide account identifiers and basic profile information according to your settings with those providers. We do not store your plain-text password.
Profile and onboarding information: display name, username, profile photo or avatar, avatar moderation status, preferred language, date of birth or age-related information when provided, onboarding status, settings, blocked users, connection status, and contact aliases you choose locally or in your account.
Well-being and reflection content: check-ins, mood selections, tags, notes, Thought Drift entries, My Grounding notes, My Direction notes, Clear Mind or Untangle a Thought notes, Inner Compass notes, morning and night routine notes, Night Routine entries, saved cards, preferences, deletion states, timestamps, and related metadata.
Mind Games and local gameplay data: game progress, saved games, scores, best scores, streaks, difficulty choices, timers, mistakes, hints, haptic settings, favorites, and similar gameplay settings or results. Mind Games data is currently stored on your device unless a feature clearly says it syncs to your account.
Notes information: note text, titles, sections, rich text, note type, color, tags, timestamps, encryption metadata, encrypted note payloads, and encrypted Notes key backups where available.
Social and shared content: public Discovery posts, Discovery replies and messages, reveal choices, shared moments, comments, reactions, reaction likes, direct chat messages, chat image metadata, uploaded compressed chat images, connection requests, saved or hidden items, reports, blocking information, and timestamps.
Notifications: if you enable push notifications, we process push tokens, notification preferences, delivery state, seen state, and related settings so we can send notifications you have requested or allowed.
Purchase and subscription information: if you buy, restore, or manage Zenea Premium through the App Store or Google Play, we process store product identifiers, transaction identifiers, purchase tokens, subscription status, entitlement status, renewal or expiration dates, cancellation or refund state where provided by the store, environment, and store event data needed to verify the purchase, provide access, restore purchases, handle renewals or cancellations, prevent fraud, and keep billing records. We do not receive your full payment card details from the app stores. Zenea does not currently use RevenueCat.
Website and support information: if you contact us, request deletion, sign up for updates, or use the website, we process the information you provide and technical records needed to operate the website, respond to you, and protect the service.
Technical, security, and service information: device and app information needed for the service, app version, platform, settings, service logs, IP addresses or similar records that may be created by our hosting, authentication, storage, translation, moderation, payment, notification, and security providers, and information needed to detect abuse, investigate reports, debug errors, and protect Zenea.
Local device data: some content and preferences may be stored or cached locally on your device so the app can load quickly, work more reliably, support offline or transitional states, or migrate older local content into your account. Local storage may be cleared by your device, operating system, app reinstall, app settings, or account deletion flows.
We do not currently use third-party product analytics or crash reporting tools such as Sentry, Firebase Crashlytics, PostHog, Amplitude, or Mixpanel. If we add analytics or crash reporting later, we will update this Privacy Policy.
4. Why We Use Information
We use information to create and secure your account; authenticate you; provide check-ins, private reflection tools, Notes, Mind Games, sharing, chat, Discovery, notifications, Zenea Premium, and account settings; sync content across devices where account storage is available; show your content to the people or areas you choose; rank Discovery content around mood, language, age-range safety, tags, concepts, and recency; remember preferences and local gameplay state; moderate profile photos and reported content; prevent spam, abuse, fraud, and unsafe behavior; verify purchases and restore subscriptions; respond to support, deletion, or legal requests; maintain, debug, and improve the app; and comply with law.
Depending on where you live, our legal reasons for processing may include providing the service you request, your consent, our legitimate interests in operating and protecting Zenea, and legal obligations. Where we rely on consent, you can withdraw consent through available app controls or by contacting us, subject to legal or technical limits.
5. Privacy of Your Content
Private reflection tools and Notes are private by default. This includes Thought Drift, My Grounding notes, My Direction notes, Clear Mind or Untangle a Thought notes, Inner Compass notes, morning and night routine notes, and Night Routine entries. They are processed so we can save them, sync them to your account where available, show them back to you, and support deletion or account controls.
Mind Games are local gameplay features for focus, memory, and logic. Their progress, saved games, settings, statistics, and results are currently stored on your device and are not used for advertising tracking or shared with other users.
Notes are encrypted on your device before they are saved locally or synced to your account. The encrypted note content may include the note text, title, sections, format, and rich text. Some Notes metadata, such as creation date, note type, color, tags, and sync information, may remain unencrypted so the app can sort, filter, sync, and display your notes correctly.
For email/password accounts, Zenea can store an encrypted backup of the Notes encryption key so encrypted Notes can be unlocked on another device after sign-in. That key backup is encrypted on your device with a key derived from your password before it is stored. If the Notes encryption key cannot be recovered, encrypted Notes may not be readable on a new device. OAuth-only accounts may not have the same recovery path unless a supported recovery feature is added.
Check-ins are private by default. They become visible to others only when you choose to share them with contacts or publish them to Discovery.
Shared moments can show your name, profile information, mood, text, tags, comments, and reactions to the contact or contacts you choose. Shared history may remain visible to the other person even if a connection later changes, subject to deletion, blocking, moderation, and account controls.
Discovery is designed to be anonymous by default. Public Discovery posts can be shown to other users without your real profile identity. Discovery replies and Discovery chat remain anonymous unless both people choose to reveal identity. Anonymity is not a promise that content can never be connected to an account: reports, safety reviews, backend records, legal requests, and abuse prevention may require Zenea to connect content to accounts.
Direct chats are visible to the participants of the conversation. Chat images are resized and compressed before upload; originals are not uploaded by Zenea. Chat images use access-controlled storage and signed URLs when loaded. Unless a feature clearly says it is end-to-end encrypted, assume Zenea may need access to content for delivery, sync, safety, moderation, debugging, deletion flows, and legal compliance.
Profile photos are profile data, not private Notes content. Zenea limits where profile photos are displayed in ordinary app surfaces, for example by hiding them from non-connections and anonymous Discovery contexts unless identity is revealed according to the app rules. You should not upload a profile photo that you need to keep confidential.
6. Third-Party Services
We use service providers to run Zenea. These may include Supabase for authentication, database, storage, functions, and backend infrastructure; Apple and Google for sign-in when you choose those methods; Google Cloud Translation when you explicitly request translation of Discovery or Shared text; Expo, Apple, Google, or similar providers for push notifications when notifications are enabled; Apple App Store and Google Play for purchases, subscriptions, refunds, subscription management, and store notifications; moderation, hosting, email, diagnostics, security, and support providers needed to operate the app and website.
Third-party services may process information according to their own terms and privacy policies when you choose to use them or when they are needed to provide the service. We require providers we use to process information only as needed to provide their services, comply with law, protect security, or follow their own terms.
We do not sell your personal information. We do not use your personal content for third-party advertising tracking.
7. Translation
Translation is on-demand. When you tap a translation control, the text to be translated and the target language may be sent to Google Cloud Translation. Zenea may cache translated text so the same translation does not need to be requested again.
8. Reports, Blocking, Moderation, and Safety
Users can report people, posts, replies, messages, shared moments, comments, profile photos, or other content. Reports may include the reporter, reported account, reason, content snapshot, timestamps, related identifiers, and review actions.
Blocking can stop future interactions and hide people from parts of the app. Some historical content may remain visible in a limited, read-only, unavailable, deleted-user, or anonymized form so each user can keep their own history and so Zenea can preserve safety records where needed.
We may review, remove, restrict, preserve, or report content and accounts when needed to protect users, Zenea, or the public, enforce our Terms of Use, comply with law, investigate abuse, prevent fraud, or respond to safety concerns.
9. Retention and Deletion
We keep account information and content while your account is active or as needed to provide Zenea. You can delete specific data in the app where controls are available, and you can delete your account in the app. If you cannot access the app, you can request account and data deletion by contacting support@zenea.app.
The delete account, delete all data, or similar in-app controls are intended to remove the account data covered by that flow, including account/profile data and private reflection or Notes content covered by the flow, and to clear related local caches where the app supports it.
Some data may remain for a limited time in backups, service logs, store billing records, subscription event records, fraud-prevention records, legal records, safety records, support records, or content history visible to other users when retention is necessary for legitimate safety, history, legal, billing, fraud-prevention, or technical reasons.
When an account is deleted, profile identity is removed or anonymized where possible. Some historical shared moments, comments, reactions, chats, reports, safety records, service logs, backups, legal records, billing records, or content visible to other users may remain for legitimate safety, history, legal, billing, fraud-prevention, or technical reasons. Where possible, deleted users are shown without personal identity, for example as a deleted or unavailable user.
Deleting your Zenea account does not automatically cancel an App Store or Google Play subscription. You must manage or cancel subscriptions through the store account where the subscription was purchased.
10. Your Choices and Rights
You can update profile information, email, username, password, language, profile photo, blocked users, notification settings, and other settings in the app where available.
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal information; withdraw consent where processing is based on consent; and lodge a complaint with your local data protection authority.
To exercise rights, use the in-app controls or contact support@zenea.app. We may need information to verify your account before completing a request.
11. Age and Safety
Zenea is intended for users who are at least 13 years old, or the minimum age required to use online services in their country without appropriate guardian consent. If we learn that an account was created by someone who is not allowed to use Zenea, we may delete or restrict it.
12. Security
We use reasonable technical and organizational measures to protect information, including HTTPS/TLS in transit, authenticated access, row-level access rules, private storage where appropriate, local-device protections provided by the operating system, app-level encryption for Notes content, moderation controls, and safety controls.
No system is perfectly secure. You should not share information in Zenea that you would not want the intended recipients, store providers, service providers, or safety reviewers to see where access is necessary to provide, protect, or comply with the service.
13. International Processing
Zenea and its providers may process and store information in countries other than your own. Where required, we rely on appropriate legal safeguards for such transfers.
14. Changes
We may update this Privacy Policy as Zenea changes. If changes are significant, we may notify you in the app, on the website, by store listing, or require you to accept the updated policy before continuing to use account-creation or other features.
15. Contact
Zenea is operated by Elin Stella Alisdey, a sole trader registered in Sweden, who is responsible for the service and is the controller for personal data processed through Zenea. Organisation number: 950616-9680.
For privacy questions, account deletion requests, safety concerns, or rights requests, contact support@zenea.app.
