Privacy Policy
Last updated: July 22, 2026
The short version
- We collect what this policy describes: your account info, the financial data you connect or upload, product analytics, limited diagnostics, and the emails we exchange.
- Your data is never sold, never used for advertising, and we don’t allow our AI providers to train on it.
- Your bank login credentials are entered with Plaid, never with us — they don’t pass through our servers.
- AI classification sends transaction details to our AI provider to do its job, under terms that prohibit training on your data.
- You can export your books at any time, request a complete copy of your data, and delete your account whenever you want.
Who we are
ZennyAI is operated by Ruby LLC (“ZennyAI,” “we,” “us”). ZennyAI is a bookkeeping inbox that helps solopreneurs separate business and personal transactions. The service is offered to residents of the United States only, and your data is processed and stored with providers in the United States. You can reach us about anything in this policy at contact@zennyai.app.
What we collect
Account information
Your email address and authentication identifiers. If you sign in with Google or Apple, we receive the basic profile your provider shares (such as your name and email). We never see your password for those accounts. Email sign-ins require two-factor authentication; we store the enrollment needed to verify your codes, never the codes themselves.
Financial data you connect or upload
When you connect a bank or card account, we receive read-only transaction and account data (transactions, balances, account names and types) through Plaid. Your bank username and password are entered with Plaid, not with us, and never pass through our servers. Plaid’s handling of your data is described in the Plaid End User Privacy Policy. When you upload a CSV statement, we store the transactions parsed from it (along with the file’s name, for provenance) — not the file itself — and we store the transactions you enter manually.
Product analytics
We record which features are used — page views and product events tied to your account ID and email — so we can see what works and fix what doesn’t. Analytics events never include the contents of your transactions, and we do not record your sessions.
Diagnostics
When something breaks, our error monitoring captures the technical error and a visual replay of the moments before it — with all text masked and all images blocked, so the replay shows the shape of the problem, not your data. Ordinary sessions are never recorded; replays exist only when an error occurs.
Communications
Emails you send us (support, feedback) and the transactional emails we send you (sign-in codes and links, notifications you’ve asked for).
How we use your data
- To run the service: importing, classifying, and filing your transactions; showing your books; generating the exports you request.
- AI classification: to sort a transaction, we send its details (merchant, amount, account type, description) to our AI provider through an AI gateway. Our current providers state that they do not use commercial API inputs or outputs to train their models, and we configure and contract with them to limit use of your data to providing and securing the service.
- PDF statement reading:when you upload a statement PDF, we send its extracted text — which can include account names, balances, and partial account numbers as printed on the statement — to the same AI provider under the same no-training terms, solely to turn it into transactions for your books. Statements you don’t upload are never read.
- Security: protecting accounts, enforcing two-factor authentication, detecting abuse.
- Improving the product: understanding feature usage through the analytics described above.
- Talking to you: sign-in emails, service notifications, and replies to your messages.
We do not sell your data, share it with advertisers, use it for advertising of any kind, or allow it to be used to train AI models.
Who touches your data (service providers)
ZennyAI runs on infrastructure operated by companies that process data on our behalf, under agreements that limit what they can do with it:
- Plaid — bank connections (see their End User Privacy Policy)
- Supabase — database and authentication hosting
- Vercel — application hosting and the AI gateway that routes classification requests
- Anthropic — the AI model that classifies transactions
- Sentry — error monitoring and masked diagnostics
- PostHog — product analytics
- Resend — transactional email delivery
When paid subscriptions launch, payments will be processed by a payment provider (such as Stripe); your card number will go to them directly and never touch our servers. We will update this policy before that happens.
Cookies
We use cookies and similar browser storage for two things: keeping you signed in (essential) and the product analytics described above. We do not use them to serve third-party advertising. Your privacy choices and controls are described in this policy — questions about any of them go to contact@zennyai.app.
How long we keep it, and how you delete it
We keep your data for as long as your account is active — that’s the product: your books, kept. You can disconnect a bank at any time, which stops new data from flowing. You can delete your account and all its data yourself from Settings, or request deletion by emailing contact@zennyai.app. We process verified deletion requests within 30 days, subject to limited legal, security, and fraud-prevention exceptions, and residual copies in encrypted backups roll off within 30 days after that.
Security
- Data is encrypted in transit and at rest.
- Two-factor authentication is mandatory for email sign-ins — not optional, not buried in settings.
- Bank login credentials are entered with Plaid, never with us; the current integration receives read-only data and cannot move your money.
- Your settings page always shows exactly how your account is protected.
Your rights and choices
You can export your books from the app at any time — exports are a first-class feature, not a legal afterthought — and you can request a complete copy of all data associated with your account by emailing contact@zennyai.app. You can correct anything Zenny got wrong (that’s the product, too), disconnect accounts, and delete your account as described above. Depending on your state, you may have additional rights (such as access, deletion, and correction rights under the California Consumer Privacy Act and similar state laws); we honor these rights for all users regardless of state. To exercise any of them, email contact@zennyai.app.
Who ZennyAI is for
ZennyAI is for adults: you must be 18 or older, and a resident of the United States. We do not knowingly collect data from anyone under 18.
Changes to this policy
If we change this policy in a way that matters, we’ll email you and note it in the app before the change takes effect. The “last updated” date at the top always reflects the current version.
Contact
Ruby LLC
contact@zennyai.app