Privacy Policy
Last updated August 11, 2026
1. Scope and Roles
This Privacy Policy explains how Zinner ("Zinner," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use the Zinner application, websites (including zinnerapp.com), and related services (the "Service"). It is written in English and intended to meet transparency expectations under United States state privacy laws (including the California Consumer Privacy Act as amended by the CPRA), Canadian privacy principles, the EU/UK General Data Protection Regulation ("GDPR"), and China’s Personal Information Protection Law ("PIPL"), along with related cybersecurity and consumer rules.
Depending on context, Zinner acts as a "business" or "controller" of personal information. Where we process data solely on behalf of an enterprise customer under a separate agreement, we act as a "service provider" or "processor," and that agreement controls. This Policy covers consumer users of the Zinner app and website.
If you do not agree with this Policy, please do not use the Service. For definitions not defined here, we use meanings commonly used in GDPR and CCPA.
2. Categories of Personal Information We Collect
Identifiers and account data: phone number, Apple user identifier, account IDs, device identifiers, and basic profile fields you provide (such as display name).
User-generated relationship content: notes, tags, messages you draft, uploaded images or screenshots, voice or text prompts, and similar materials you choose to store. This may include information about third parties that you voluntarily enter. You are responsible for having a lawful basis to include third-party information.
Usage and diagnostics: app interactions, feature usage events, crash logs, performance metrics, approximate network information, language settings, and device type. Payment metadata: subscription status and entitlement signals from Apple; we do not receive full payment card numbers when Apple processes payment.
Support communications: emails and messages you send to support or legal channels. Cookies and similar technologies on the website for security, preferences, and analytics where enabled.
3. Sources of Information
We collect information directly from you, automatically from your device when you use the Service, and from service providers that help us authenticate, host, analyze, or process AI requests. We do not buy sensitive personal information from data brokers for advertising profiles.
4. Purposes of Processing
We process personal information to: provide and maintain the Service; create and secure accounts; sync your data across devices; operate AI assistance features; personalize in-product experience; prevent fraud and abuse; analyze performance; communicate service notices; process subscriptions via Apple; comply with law; and establish, exercise, or defend legal claims.
We do not use your private relationship notes to train public foundation models in a way that makes them available to other customers, unless we obtain separate explicit consent or use de-identified aggregated signals that cannot reasonably identify you.
5. Legal Bases — Europe (GDPR / UK GDPR)
Where GDPR applies, we rely on: (a) contract performance to provide the Service you request; (b) legitimate interests for security, product improvement, and fraud prevention, balanced against your rights; (c) consent for optional cookies, certain marketing, or specific AI processing that requires consent; and (d) legal obligation where we must retain or disclose information.
You may withdraw consent at any time without affecting prior lawful processing. You may object to legitimate-interest processing in accordance with Article 21 GDPR.
6. United States Privacy Disclosures (including California)
In the preceding 12 months, we may have collected the categories listed in Section 2. We use them for the business purposes described in Section 4. We do not "sell" personal information for money. If we engage in "sharing" for cross-context behavioral advertising as defined by CPRA, we will provide a Do Not Sell or Share mechanism and honor Global Privacy Control signals where required.
California residents may request access, deletion, correction, and information about our practices, and may not be discriminated against for exercising rights. Metrics and contact methods are in Sections 14–16. Other U.S. state laws (Virginia, Colorado, Connecticut, Utah, and similar) provide rights to access, delete, correct, and opt out of targeted advertising or certain profiling; we will process authenticated requests consistent with applicable statutes.
7. China PIPL and Cybersecurity Disclosures
If you are in mainland China, we process personal information under PIPL principles of legality, legitimacy, necessity, and good faith. We will provide notice and obtain consent where required, including separate consent for sensitive personal information and cross-border transfers when applicable.
Sensitive personal information may include intimate relationship details you choose to store. We process such information only as necessary to provide features you actively use, with heightened safeguards. You may withdraw consent, subject to impacts on feature availability.
We implement security measures consistent with China’s Multi-Level Protection Scheme expectations as applicable to our systems and vendors. If a security incident affects your rights, we will notify you and regulators as required.
8. AI Processing Specifics
AI features may send prompts, selected notes, or media you choose to model inference systems operated by us or subprocessors to generate outputs. You should avoid submitting government ID numbers, live payment credentials, or special-category data unless necessary.
AI outputs may be logged temporarily for safety, abuse prevention, debugging, and quality review. Retention is limited to what is needed for those purposes unless a longer period is required by law. You can delete source notes in-product; deletion propagates to active systems within a commercially reasonable time.
9. Cookies and Similar Technologies
Our marketing website may use essential cookies for security and load balancing, and optional analytics cookies. In Europe, non-essential cookies are used only with consent where required. You can control cookies through browser settings and, where provided, our cookie banner preferences.
10. Sharing and Recipients
We share personal information with: cloud infrastructure providers; authentication and messaging vendors; AI model providers acting as processors; analytics providers; professional advisors; authorities when legally required; and successors in a merger or acquisition under continuing confidentiality commitments.
We require processors to protect data under contracts with confidentiality, security, and purpose limitation clauses. We do not sell your relationship notes to third parties for their independent marketing.
11. International Transfers
We may process information in the United States and other countries where we or our processors operate. For GDPR transfers, we use appropriate safeguards such as Standard Contractual Clauses and transfer impact assessments where required. For China cross-border transfers, we will complete security assessments, standard contracts, or certification routes as mandated before transferring personal information outside mainland China when those rules apply.
By using the Service from your region, you understand that your information may be processed in countries with different data protection laws than your home country, subject to the safeguards above.
12. Retention
We retain account data for the life of the account and for a reasonable period thereafter for security and legal claims. Relationship content is retained until you delete it or delete your account, subject to backups. Billing entitlements may be retained as needed for accounting. Diagnostics are typically retained for shorter windows unless needed for investigations.
When retention ends, we delete or de-identify information, unless law requires longer storage.
13. Security Measures
We implement administrative, technical, and organizational measures appropriate to risk, including access controls, encryption in transit, least-privilege practices, logging, and vendor due diligence. No method of transmission or storage is perfectly secure. You can help by using device passcodes and reporting suspected unauthorized access promptly.
14. Your Rights and Choices
Depending on your region, you may have rights to access, correct, delete, port, restrict, or object to certain processing, and to withdraw consent. California residents have CCPA/CPRA rights described above. European residents may lodge a complaint with a supervisory authority. China residents may exercise PIPL rights to know, decide, access, copy, correct, and delete personal information, subject to statutory exceptions.
To exercise rights, email privacy@zinnerapp.com with sufficient detail to verify your identity and request. We will respond within timelines required by applicable law (for example, 45 days under CCPA with possible extension, or one month under GDPR with possible extension).
15. Children’s Privacy
The Service is not directed to children under 18 (or higher age of majority). We do not knowingly collect personal information from children. If you believe a child provided personal information, contact privacy@zinnerapp.com and we will take appropriate steps to delete it.
16. Do Not Track and Global Privacy Control
Some browsers send Do Not Track signals. There is no consistent industry response standard; we treat legally recognized opt-out signals such as Global Privacy Control as required under applicable U.S. state law for selling or sharing.
17. Automated Decision-Making
We do not make solely automated decisions that produce legal or similarly significant effects about you without human involvement, as those terms are understood under GDPR. AI suggestions inside the product are assistive tools you control.
18. Third-Party Content You Store About Others
If you store information about other people (for example, notes about a prospect), you must have a lawful reason to do so and must not use the Service to violate others’ privacy, publicity, or safety rights. We process such information as part of your User Content under your instructions as a user of a productivity tool, while still applying security and abuse protections.
19. Changes to this Policy
We may update this Policy periodically. Material changes will be indicated by updating the "Last updated" date and, where required, by additional notice or consent. Continued use after an update means you acknowledge the updated Policy, except where mandatory law requires explicit consent.
20. Controller Contact and Representatives
Controller: Zinner. Website: https://zinnerapp.com/. Privacy email: privacy@zinnerapp.com. Legal email: legal@zinnerapp.com. Support: support@zinnerapp.com. If we appoint an EU or UK representative under GDPR Article 27, contact details will be posted on this page. For China-facing inquiries requiring a local contact method, use privacy@zinnerapp.com and mark the subject "PIPL Request."
21. Region-Specific Summaries
United States: You can request access, deletion, and correction, and opt out of sale or sharing where applicable. We honor verifiable consumer requests and appeal processes required by state law.
Europe: We process under GDPR bases listed above; you may access, erase, restrict, port, object, and complain to your authority. Cross-border transfers use Standard Contractual Clauses or equivalent safeguards.
China: We process under PIPL notice and consent rules, protect sensitive personal information with heightened care, and follow required cross-border transfer mechanisms before exporting personal information when applicable.
22. Contact for Complaints
If you have an unresolved privacy concern, contact privacy@zinnerapp.com. European users may contact their local data protection authority. California users may contact the California Privacy Protection Agency for questions about CCPA. China users may also seek remedies through competent regulators or courts under PIPL.
Annex A — Detailed Processing Activities
Account lifecycle processing includes creating credentials, verifying phone or Apple identity, storing session tokens, detecting anomalous login patterns, and deleting accounts upon verified request.
AI assistance processing includes packaging user-selected context, sending it to inference endpoints, returning generated text or structured suggestions, and optionally storing safety logs. Media analysis processing includes temporary buffering of images you upload for OCR or visual understanding, then discarding raw media according to retention rules unless you save results to your workspace.
Security processing includes rate limiting, abuse classification, malware scanning of uploads, and audit logging of administrative access. Product analytics may measure feature adoption in aggregated or pseudonymous form to decide roadmap priorities.
Annex B — Categories under CCPA Taxonomy
Identifiers; personal information under Cal. Civ. Code 1798.80; commercial information (subscription status); internet or electronic activity; geolocation approximations derived from IP (not precise GPS by default); audio or visual information if you upload media; and inferences drawn to provide product features (for example, organizing tags). We do not intentionally collect biometric templates for identity recognition.
We disclose categories of personal information to service providers for business purposes such as hosting, authentication, analytics, customer support, and AI inference. We do not disclose relationship-note contents for third-party advertising.
Annex C — Sensitive Personal Information
Depending on your usage, notes may include sensitive personal information such as intimate life details. California residents may have rights to limit use of sensitive personal information to purposes necessary to provide the Service. Europe treats certain data as special-category data; we do not seek to process special-category data unless you choose to enter it, in which case we rely on your explicit consent or other GDPR Article 9 conditions where applicable. China treats intimate personal information as sensitive under PIPL and requires heightened notice and consent.
We recommend minimizing sensitive details stored in the Service. You control what you type and upload.
Annex D — Subprocessors (Illustrative)
We use reputable cloud hosting, database, object storage, error monitoring, and AI inference providers. A current list of core subprocessors can be requested at privacy@zinnerapp.com. Processors are bound by data-protection agreements prohibiting use of personal information for their own advertising.
When we replace a material subprocessor that processes personal information, we will update internal records and, where GDPR requires, provide notice mechanisms for enterprise customers. Consumer users are informed through Policy updates when changes are material to privacy risk.
Annex E — Data Subject Request Process
Submit requests to privacy@zinnerapp.com. We verify identity using account factors (for example, control of the phone number or Apple ID associated with the account). Authorized agents for California requests must provide proof of authorization. We will explain denials and, where required, provide an appeal path.
We may ask clarifying questions to locate data efficiently. Excessively repetitive or manifestly unfounded requests may be refused or charged a reasonable fee where law allows.
Annex F — Breach Notification
If a personal-data breach likely to result in a risk to your rights occurs, we will notify regulators and affected users in accordance with GDPR timelines (without undue delay and, where feasible, within 72 hours to authorities when required), U.S. state breach laws, and PIPL/CSL notification duties for China-regulated incidents.
Notifications will describe the nature of the incident at a high level, likely consequences, and measures taken or proposed to address the incident, subject to law-enforcement delays and security needs.
Annex G — Retention Schedule (Summary)
Active account profile: life of account. Workspace notes and media: until user deletion. Authentication logs: typically 30 to 180 days. Safety and abuse logs: typically up to 24 months unless needed longer for investigations. Backup cycles: rolling windows that expire automatically. Legal hold overrides may apply.
De-identified analytics may be retained longer because they are no longer personal information under applicable definitions when reasonably irreversible.
Annex H — Your Responsibilities
You should not upload others’ highly sensitive data without permission. You should use device security features. You should review AI outputs before sending messages to real people. You should keep your contact email or phone current so we can reach you about security or privacy notices.
If you use the Service in a workplace device context, your organization may have additional monitoring policies outside Zinner’s control. Review your employer’s policies separately.
Annex I — Advertising, Analytics, and Product Research
We may use aggregated or de-identified information to understand feature adoption, improve onboarding, and plan capacity. Where analytics tools place cookies or SDK identifiers on the marketing site or app, European users receive consent choices for non-essential analytics where required.
We do not use the contents of your private relationship notes to build advertising audiences for unrelated third-party advertisers. If that practice ever changes, we will update this Policy and obtain any required consent or opt-out mechanism first.
Push notifications, if enabled, are used for product and account notices. You can disable notifications in operating-system settings. Marketing emails, if used, include unsubscribe mechanisms required by CAN-SPAM, CASL, and ePrivacy rules.
Annex J — Record-Keeping and Lawful Requests
We may preserve and disclose information when we believe in good faith that disclosure is required by law, regulation, legal process, or governmental request; to protect the rights, property, or safety of Zinner, our users, or the public; or to investigate fraud and security incidents.
Where legally permitted and practical, we will notify affected users of legal demands for their content, unless notice is prohibited or would create risk. Enterprise or law-enforcement guidelines may be requested through legal@zinnerapp.com.
We may retain a minimal record of fulfilled privacy requests to demonstrate compliance and prevent fraudulent repeat requests.
Annex K — De-identification and Aggregation
We may create de-identified or aggregated datasets from Service usage. We commit not to attempt to re-identify de-identified data except for testing our de-identification quality or as required by law, and we require recipients of de-identified data to make similar commitments where required by CCPA/CPRA or analogous laws.
Aggregated benchmarks (for example, percentage of users enabling a feature) do not identify any individual and may be retained indefinitely.
Annex L — Contact Channels Recap
Privacy requests and PIPL/GDPR/CCPA exercises: privacy@zinnerapp.com. Legal process and notices: legal@zinnerapp.com. Product support: support@zinnerapp.com. Website: https://zinnerapp.com/. App Store listing: https://apps.apple.com/app/id6800319141.
When emailing, include your account phone number or Apple identity hint, the country from which you use the Service, and a clear description of your request so we can route it correctly under the applicable regional regime.
Annex M — Mobile Permissions and Device Data
Depending on your device settings and feature use, the app may request permission to access photos or media for uploads, notifications for reminders, and network access for sync. Operating systems control these permissions; denying a permission may disable related features without affecting unrelated features.
We do not require continuous background location tracking for core relationship-management features. If a future feature uses precise location, we will request permission and update this Policy before collecting that data.
Crash and performance diagnostics may include device model, OS version, and memory state. These fields help us reproduce bugs and are retained under the diagnostics windows described above.
Annex N — Customer Support Interactions
When you contact support, we process the content of your message, attachments you send, and account metadata needed to resolve the ticket. Support threads may be stored in a helpdesk system operated by a processor under contract.
Please avoid sending unnecessary sensitive data in support tickets. If you must share screenshots, redact third-party personal information that is not required for troubleshooting.
We may use anonymized support themes to improve documentation and product reliability.
Annex O — Policy Interpretation
This Privacy Policy should be read together with the Terms of Use. If there is a conflict about personal-information practices, this Privacy Policy controls for privacy subject matter. English is the controlling language of this Policy.
Headings are convenience labels only. Failure to enforce a provision is not a waiver. If a provision is found unenforceable, the remaining provisions stay in effect.
For questions about how a specific feature processes data, email privacy@zinnerapp.com with the feature name and your region so we can provide a concrete explanation under the relevant legal regime.
We may publish concise feature-level privacy notes for major launches. Those notes supplement this Policy and do not reduce the rights described here. If a feature-level note conflicts with this Policy, the document that provides stronger protection for users will control for that conflict, except where mandatory law requires a specific rule.
Thank you for trusting Zinner with sensitive relationship context. Our goal is to keep that trust by minimizing collection, limiting purposes, securing systems, and honoring regional privacy rights in clear English for every ambitious professional who uses the product.