← Back to Zaza

Privacy Policy

Last updated July 2026 · Beta version

This Privacy Policy explains what information Zaza collects, why we collect it, and the choices you have. Zaza is designed to feel calm and low-noise — that principle guides how we handle your data too.

Information you give us

When you create an account we collect an email address, a display name, and a username. You can optionally add a bio, avatar or photo, interests, door status, mood music selection, and profile layout.

When you use Zaza you create content: posts, Pages (journal entries), reflections, comments, reactions, Sets activity, Knocks messages, Mic Up participation, campfire chat, wellness notes, and feedback submissions. This content is stored so the service can display it to the audience you chose.

Information we collect automatically

To keep the service running we collect limited technical information: device type, browser, approximate region, IP address (for security and abuse prevention), push-notification subscription IDs, service-worker health, and error reports. We collect aggregate product analytics — for example, which features are used, how long sessions last, and where errors happen — to prioritise improvements.

Zaza does not sell your data and does not run third-party advertising trackers.

Cookies and local storage

Zaza uses cookies, local storage, authentication tokens, and similar technologies to:

  • Maintain login sessions
  • Remember preferences
  • Improve performance
  • Store user settings
  • Support security features
  • Reduce repetitive onboarding prompts

These technologies are used only as necessary to operate and improve the platform.

Weather, location, and background

The Living Nature background can sync with local weather. We derive approximate location from your device's coarse location or IP address only when this feature is enabled, and we do not store precise coordinates.

Sets, Knocks, Mic Up

Sets: content posted in a Set is visible to members of that Set. Set owners can moderate and remove content.

Knocks: conversations are visible to you and the other participant. We store message content on our servers so it can be delivered across devices. Messages are not end-to-end encrypted during beta.

Mic Up: we store session metadata (host, participants, join/leave times, roles, campfire chat) to run the feature. Room audio is not recorded by default. If we introduce recording, it will be opt-in and clearly labelled before it starts.

Notifications

If you enable push notifications, we register a subscription with our push provider and link it to your account so we can deliver Knocks, replies, Mic Up alerts, and other relevant events. You can turn notifications off in Settings or from your device.

AI-assisted features

Some features — such as Journey Reviews and coach prompts — send a limited slice of your own content to a large-language-model provider so it can generate a reflection back to you. These providers process the content on our behalf under data-processing terms and do not use it to train public models. Generated reflections are saved to your account and are visible only to you unless you choose to share them.

You remain responsible for anything you publish, regardless of whether it was created with AI assistance. See the Community Guidelines for the rules on AI-assisted content.

Music previews

Current Mood Music uses public search APIs (such as iTunes and Deezer) to find song metadata and 30-second previews. When you search, your query is proxied through our servers to reduce rate-limits; we do not tie individual searches to your identity in analytics.

Third-party providers

We use vetted providers to run Zaza: hosting and database (Supabase / Cloudflare), authentication, push notifications (OneSignal), transactional email (via notify.zazasocial.app), music search (iTunes, Deezer), and AI reflections. Each processes only the data it needs to perform its function.

International users

By using Zaza, you understand that information may be processed and stored in the United States and other jurisdictions where our service providers operate.

Data protection laws may differ between jurisdictions.

Beta testing disclosures

Beta testers help us shape Zaza. In addition to the data above, we may collect: crash logs, feedback submissions and screenshots you send from the Beta Hub, feature usage in early experiments, and admin-visible activity indicators (for example, last-seen timestamps) so we can support you and troubleshoot. Beta status is stored as a role on your account and can be removed on request.

How we use your data

  • Provide, personalise, and secure the service.
  • Deliver content to the audience you chose.
  • Send account, safety, and product notifications.
  • Improve reliability and prioritise fixes using aggregate analytics.
  • Investigate abuse, fraud, and policy violations.
  • Comply with legal obligations.

Sharing

We share personal data only with the providers above, when required by law, to protect users or the platform, or with your explicit consent. We do not sell personal data.

Retention

Active account data is kept for as long as your account exists. When you delete your account, we remove your profile and content from active systems within 30 days, subject to short backup windows and legal holds. Aggregate, de-identified analytics may be retained indefinitely.

Your choices

  • Edit your profile at any time from Settings.
  • Turn off notifications, sound, and background features.
  • Use Quiet Hours to silence Zaza on a schedule.
  • Delete individual posts, Pages, and messages.
  • Delete your account from Settings, or by emailing us.
  • Request a copy of your account data by contacting hello@zazasocial.app. Where technically feasible, exports will be provided in a reasonable and commonly used format.

Security

Zaza uses industry-standard security measures including encrypted transport, row-level security, signed URLs, access controls, authentication protections, and infrastructure safeguards.

While we work hard to protect user data, no system can guarantee absolute security. Please use a strong, unique password and report suspected issues to hello@zazasocial.app.

Children

Zaza is not intended for children under 16. If you believe a child has created an account, contact us and we will remove it.

Changes to this Policy

We may update this Policy as Zaza grows. Material changes will be announced in-app or by email. Continued use means you accept the updated Policy.

Contact

Privacy questions: hello@zazasocial.app.

Related

Questions? Reach out from the Beta Hub or email hello@zazasocial.app.