Legal

Privacy Policy

Effective June 15, 2026

This Privacy Policy explains how ZATECH(“we”, “us”) collects, uses, and protects your information when you use the ZATECHpersonal finance application (the “Service”). We are committed to handling your financial data responsibly.

1. Information We Collect

  • Account information: your name, email address, and authentication data.
  • Financial data: account details and transaction history retrieved from banks you connect via open banking (PSD2), and data from statement files you import.
  • Preferences: settings such as base currency, language, categories, and rules you create.
  • Technical data: limited logs and device/session information used to operate and secure the Service.
  • Advertising measurement data:if, and only if, you allow tracking when iOS asks, an advertising identifier and app events such as install, launch, sign-up, and bank connected. Never your transactions, balances, accounts, or merchants. See "Advertising Measurement" below.

2. How We Use Your Information

  • To aggregate, categorize, and display your transactions and financial summaries.
  • To categorize transactions automatically using AI, only when you enable AI categorization in the app (see "AI categorization" below).
  • To operate, secure, and support the Service, and to communicate with you about it.
  • To analyze usage with first-party product analytics so we can improve the app (we do not track you across other companies' apps or websites).
  • To record how the app is used, as replayable sessions, so we can see where it confuses people. These recordings show layout, taps, scrolling and navigation. They do not show your numbers: every piece of text, every amount and every image is masked before the recording leaves your device, so a balance or a shop name is never readable in one.
  • To send push notifications and product emails when you opt in.
  • To measure which of our advertising campaigns bring new users, on the terms described in "Advertising Measurement" below.

3. Sharing & Processors

We do not sell your personal data. We share data only with service providers who process it on our behalf, including:

  • Enable Banking (Enable Banking Oy, a licensed open-banking provider regulated under PSD2): to securely connect to your bank and retrieve your account and transaction data on your behalf. See enablebanking.com.
  • Anthropic(Anthropic PBC, our AI provider): to categorize transactions automatically, only with your in-app consent. See "AI categorization" below for exactly what is sent.
  • PostHog(product analytics and session replay, hosted in the EU): to understand how the app is used and improve it. Replays are masked on your device before they are sent, so text, amounts and images are never readable in them, and app logs are not attached. Recordings are kept for 30 days and then deleted. We use this only for first-party analytics; we do not use it to track you across other companies' apps or websites.
  • OneSignal: to deliver push notifications and product emails when you opt in.
  • RevenueCat: to manage subscriptions and validate purchases.
  • Meta(Meta Platforms Ireland Ltd): to measure which advertisements led people to install Brixa. See "Advertising Measurement" below for exactly what is sent under each answer to Apple's tracking prompt.
  • Hosting & database providers: to run the Service and store your data.

We do not store your bank login credentials.

AI Categorization

Brixa can sort your transactions automatically using an AI model operated by Anthropic PBC. This happens only if you enable AI categorization in the app (asked during onboarding; changeable anytime in Settings). If you keep it off, no transaction data is sent to Anthropic and you can categorize transactions manually or with rules.

When enabled, the following data is sent to Anthropic for processing only:

  • Transaction details: description, merchant/counterparty name, counterparty account number as it appears in the transaction, amount, currency, and date.
  • Your account display names and the account holder name as it appears on transfers.
  • The names of your spending categories.

We never send your bank login credentials (we do not have them), your email address, or your bank access tokens. Under our commercial agreement, Anthropic does not use this data to train its models and processes it solely to provide categorization results back to us, subject to confidentiality and security obligations consistent with this policy. Individual merchant names (not linked to you) may also be looked up via Google's Places service and Anthropic to identify unknown merchants; these lookups contain no amounts, dates, or account information.

Advertising Measurement

We advertise Brixa on Meta's platforms (Facebook and Instagram). To know which advertisements are worth paying for, we can tell Meta that an install, a registration or a purchase happened, and that it came from one of our ads.

This happens only if you allow trackingwhen iOS shows Apple's App Tracking Transparency prompt, which Brixa shows you once, shortly after you first open it. If you choose "Ask App Not to Track", nothing is sent to Meta at all, not even an anonymous count, and nothing else about the app changes.

When you allow it, Meta receives:

  • Your device's advertising identifier, which Apple provides for this purpose.
  • That the app was installed and opened, that an account was created, and that a subscription or trial started.

Meta never receives your transactions, balances, account numbers, merchant names, bank credentials or the contents of anything you keep in Brixa. Your financial data is not used for advertising, by us or by anyone else, and we do not sell it.

You can change your mind at any time in iOS Settings, under Privacy & Security, Tracking. Turning Brixa off there stops any further data reaching Meta.

4. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. You may delete your account, after which we will delete or anonymize your personal data except where retention is required by law.

5. Your Rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to withdraw consent for bank connections at any time. To exercise these rights, contact us at the address below.

Deleting your data

You can delete your account and everything in it yourself, from inside the app. You do not need to ask us and you do not need a reason.

  1. Open Brixa and go to Settings.
  2. Scroll to the Account section and tap Advanced.
  3. Tap Delete account and confirm.

Deleting the account does all of the following, immediately and permanently:

  • Withdraws your open-banking consents with Enable Banking, so no further data can be retrieved from your banks.
  • Deletes your transactions, accounts, balances, categories, rules, budgets, goals and sharing invitations.
  • Deletes your profile: your name, email address and authentication records.

It cannot be undone, and we cannot restore a deleted account. Your subscription is billed by Apple rather than by us, so if you have one, cancel it separately in Settings, Apple ID, Subscriptions on your device; deleting your Brixa account does not cancel an Apple subscription.

If you cannot reach the app, for example because you have already removed it or cannot sign in, email andrew@usebrixa.com from the address on the account and we will delete it for you. We may keep a minimal record of the deletion itself, and anonymous, non-identifying usage counts that can no longer be linked to you, where we are required or permitted to do so by law.

6. Security

We use technical and organizational measures to protect your data, including encryption in transit and access controls. No method of transmission or storage is completely secure, but we work to safeguard your information.

7. Changes

We may update this Privacy Policy from time to time. Material changes will be communicated through the Service.

8. Contact

For privacy questions or requests, contact ZATECH at andrew@usebrixa.com.