Last updated July 2026 · Beta version
This Privacy Policy explains what information Zaza collects, why we collect it, and the choices you have. Zaza is designed to feel calm and low-noise — that principle guides how we handle your data too.
When you create an account we collect an email address, a display name, and a username. You can optionally add a bio, avatar or photo, interests, door status, mood music selection, and profile layout.
When you use Zaza you create content: posts, Pages (journal entries), reflections, comments, reactions, Sets activity, Knocks messages, Mic Up participation, campfire chat, wellness notes, and feedback submissions. This content is stored so the service can display it to the audience you chose.
To keep the service running we collect limited technical information: device type, browser, approximate region, IP address (for security and abuse prevention), push-notification subscription IDs, service-worker health, and error reports. We collect aggregate product analytics — for example, which features are used, how long sessions last, and where errors happen — to prioritise improvements.
Zaza does not sell your data and does not run third-party advertising trackers.
Zaza uses cookies, local storage, authentication tokens, and similar technologies to:
These technologies are used only as necessary to operate and improve the platform.
The Living Nature background can sync with local weather. We derive approximate location from your device's coarse location or IP address only when this feature is enabled, and we do not store precise coordinates.
Sets: content posted in a Set is visible to members of that Set. Set owners can moderate and remove content.
Knocks: conversations are visible to you and the other participant. We store message content on our servers so it can be delivered across devices. Messages are not end-to-end encrypted during beta.
Mic Up: we store session metadata (host, participants, join/leave times, roles, campfire chat) to run the feature. Room audio is not recorded by default. If we introduce recording, it will be opt-in and clearly labelled before it starts.
If you enable push notifications, we register a subscription with our push provider and link it to your account so we can deliver Knocks, replies, Mic Up alerts, and other relevant events. You can turn notifications off in Settings or from your device.
Some features — such as Journey Reviews and coach prompts — send a limited slice of your own content to a large-language-model provider so it can generate a reflection back to you. These providers process the content on our behalf under data-processing terms and do not use it to train public models. Generated reflections are saved to your account and are visible only to you unless you choose to share them.
You remain responsible for anything you publish, regardless of whether it was created with AI assistance. See the Community Guidelines for the rules on AI-assisted content.
Current Mood Music uses public search APIs (such as iTunes and Deezer) to find song metadata and 30-second previews. When you search, your query is proxied through our servers to reduce rate-limits; we do not tie individual searches to your identity in analytics.
We use vetted providers to run Zaza: hosting and database (Supabase / Cloudflare), authentication, push notifications (OneSignal), transactional email (via notify.zazasocial.app), music search (iTunes, Deezer), and AI reflections. Each processes only the data it needs to perform its function.
By using Zaza, you understand that information may be processed and stored in the United States and other jurisdictions where our service providers operate.
Data protection laws may differ between jurisdictions.
Beta testers help us shape Zaza. In addition to the data above, we may collect: crash logs, feedback submissions and screenshots you send from the Beta Hub, feature usage in early experiments, and admin-visible activity indicators (for example, last-seen timestamps) so we can support you and troubleshoot. Beta status is stored as a role on your account and can be removed on request.
We share personal data only with the providers above, when required by law, to protect users or the platform, or with your explicit consent. We do not sell personal data.
Active account data is kept for as long as your account exists. When you delete your account, we remove your profile and content from active systems within 30 days, subject to short backup windows and legal holds. Aggregate, de-identified analytics may be retained indefinitely.
Zaza uses industry-standard security measures including encrypted transport, row-level security, signed URLs, access controls, authentication protections, and infrastructure safeguards.
While we work hard to protect user data, no system can guarantee absolute security. Please use a strong, unique password and report suspected issues to hello@zazasocial.app.
Zaza is not intended for children under 16. If you believe a child has created an account, contact us and we will remove it.
We may update this Policy as Zaza grows. Material changes will be announced in-app or by email. Continued use means you accept the updated Policy.
Privacy questions: hello@zazasocial.app.
Questions? Reach out from the Beta Hub or email hello@zazasocial.app.