Privacy Policy

Last updated: 2026-08-25

ZeniCash is a personal finance, cashflow and invoice-tracking application used by individuals, freelancers and small businesses, published by Manor Systems, Unipessoal Lda (NIPC 519 377 753), Rua da Figueira 126, 4820-645 São Clemente, Fafe, Portugal ("we", "us"). This policy describes what data we process, why, where it is stored, and the rights you have over it.

1. Summary

2. What we collect, and when

2.1 Always — none

A user who installs the app and never signs in produces no data on our servers. The app's local SQLite database is protected by the operating system's per-app isolation and by your device PIN / biometric / app lock.

2.2 When you sign in (optional)

Sign-in is required only if you choose to enable Cloud Sync. We authenticate you through Google Sign-In or Apple Sign-In, and Firebase Authentication returns:

These are used to partition your data in Cloud Firestore under users/{uid}/… so that your devices recognise each other on sync.

2.3 When you enable Cloud Sync (optional)

The financial records you create — accounts, transactions, budgets, categories, invoices, advances, recurring transactions and similar — are copied to your private Firestore namespace, encrypted in transit (TLS) and at rest (Firebase). Only your authenticated session can read or write to your namespace; we do not access it.

From version 1.5.0, alongside the records, the documents you attached to entries — receipt photos and invoice PDFs — are copied too. They live in a private area readable only by your authenticated session, at users/{uid}/receipts/. Files larger than 10 MB are not copied and remain only on the device they were attached from. Documents are uploaded when the entry is saved and are downloaded only when you open them.

2.3b When you join a shared space (optional)

A shared space lets several people keep one book together. You are never placed in one: you either create a space yourself, or type an invitation code somebody gave you.

While you are in a space, what Cloud Sync would otherwise keep private to you is visible to every member of it — accounts, transactions, budgets, categories, projects, recurring transactions, cash-flow events, manual exchange rates and entities, including any tax number you recorded for a client or a supplier. Your name and email address, as they appear on the account you signed in with, are visible to the other members too, so the app can show whose each account is.

Records belonging to different members are never merged: two accounts with the same name stay two accounts. If you leave a space, your own book is restored on your device, but what you brought in stays with the members who remain — leaving does not withdraw it.

If your records describe other people — a client's name and tax number, for instance — sharing them with the other members is your decision, and you are responsible for having a lawful basis to do it.

2.4 When you subscribe to Premium (optional)

In-app subscriptions are processed by Google Play Billing (Android) or App Store In-App Purchase (iOS). The store handles your payment details; we receive only your subscription state (active / cancelled / expired) so the app can unlock Premium features. We never see card numbers.

2.5 Exchange rates

To convert balances across currencies the app calls public, free-of-charge exchange-rate APIs, in this order:

These requests carry only a base-currency code (e.g. EUR) — no identifier, no account or transaction data. Results are cached locally for 6 hours so subsequent conversions need no network call.

2.6 Receipt OCR — on device by default

By default, receipt scanning runs entirely on your device. When you photograph a receipt, the app uses Google ML Kit's on-device text recognition to extract the vendor, amount, date and document number. The image is processed locally; nothing is uploaded to us or to anyone else for OCR purposes.

AI receipt scanning — optional, off by default. Some receipts, faded thermal till rolls in particular, cannot be read reliably on the device. For those you can turn on AI receipt scanning in Settings. This is a Premium feature: beyond your consent, an active Premium subscription is required, and without Premium the receipt photo stays on the device even when the setting is switched on. While that setting is on and Premium is active, the photo of the receipt is sent to Google's Gemini API, which reads it and returns the extracted fields. We ask you to confirm before it is switched on, and you can switch it off at any time — with it off, no receipt photo ever leaves your device.

The photo is sent solely to perform that scan. Under Google's paid-tier API terms, content sent to the Gemini API is not used to train Google's models. ZeniCash does not store the photo on its servers: it is passed through, processed, and discarded. The extracted text is then stored on the device (and synced via Cloud Firestore if Sync is enabled, exactly like any other transaction note you typed yourself).

Legal basis: your consent (Art. 6(1)(a) GDPR), given by turning the setting on. You may withdraw it at any time by turning it off, with no effect on anything scanned before.

2.7 Bank statement imports

You can import a CSV, XLSX or OFX bank statement to populate transactions. The file is parsed locally and discarded; only the transactions you confirm end up in the app (and in Cloud Firestore if Sync is enabled).

2b. Crash reports and optional analytics

Two things measure the app itself rather than your finances. They are deliberately treated differently, because they are not the same kind of data.

Crash reporting — always on

When the app crashes, Firebase Crashlytics sends us the failure so we can fix it. Not knowing that the app broke on your phone helps nobody, least of all you. A crash report contains the stack trace and timestamp of the failure, the app version, your device model, CPU architecture, operating system version, and the amount of RAM and disk space free at the time, together with an installation identifier. It contains none of your financial data — no accounts, no transactions, no invoices, no receipts.

Product analytics — only if you allow it

Google Analytics for Firebase is installed but collects nothing until you agree. The app asks once; if you decline, it never asks again and nothing is sent. You can change your mind in either direction under Settings → Security.

With your consent it records how the app is used — how often it is opened, session length, app version, device model and operating system, and an approximate country derived from your IP address — under an app-instance identifier. It does not record what you type, what you earn or spend, who your clients are, or anything else from your books.

3. What we do NOT collect

4. Lawful basis for processing (GDPR / LGPD)

Under Article 6 of the GDPR — and the analogous provisions of the Brazilian LGPD — our lawful bases are:

5. No profiling, no automated decision-making

We do not apply any automated decision-making or profiling within the meaning of GDPR Article 22 to your data. We do not credit-score, risk-rate, target, segment or otherwise analyse your financial data to make decisions that produce legal or similarly significant effects for you. The app's local features (budget alerts, cashflow projections, account-limit notifications) are deterministic calculations performed on data you yourself entered; they are not profiling.

6. Where your data lives

7. Subprocessors

We rely on the following processors and sub-processors. We have a Data Processing Addendum or equivalent contractual protection in place with each.

Calls to the exchange-rate providers (open.er-api.com, jsDelivr, Cloudflare) carry only a 3-letter base-currency code — no user identifier and no financial data.

We notify users when we materially change this list, before the new sub-processor begins processing data.

8. How long we keep it

9. Sharing

We do not sell, rent, or share your personal or financial data with third parties for advertising. Sharing inside a shared space happens only where you have asked for it, and is described in Section 2.3b. We use the processors listed in Section 7 to provide the infrastructure described above. We may disclose data where we are legally compelled to do so (e.g. a binding court order) and will, where lawful, notify you of such a request.

10. Security and breach notification

Connections to Firebase and the exchange-rate APIs use TLS. Cloud Firestore encrypts data at rest. On the device, the SQLite database is protected by the operating system's per-app storage isolation, and you can additionally enable an in-app PIN / biometric lock in Settings > Security. The PIN itself is hashed (salted SHA-256) before being stored.

If we become aware of a personal-data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority (in Portugal, the CNPD) within 72 hours of becoming aware, as required by GDPR Article 33. If the breach is likely to result in a high risk to affected users, we will also notify them without undue delay (Article 34).

11. Your rights

If you reside in the EU/EEA (GDPR) or the UK, you have the right to access, rectify, port, restrict or object to processing of your data, and to lodge a complaint with a supervisory authority. In Portugal the authority is the CNPD. If you reside in Brazil (LGPD), you have analogous rights under that framework.

You can exercise most of these directly inside the app:

For any request we cannot fulfil in-app, email privacy@zenicash.com. We respond within 30 days.

12. Children

ZeniCash is a tool for adults and professional users. We do not direct the product at users under 16, and we do not knowingly collect data from them. If you believe a minor has signed in, email privacy@zenicash.com and we will erase the account.

13. Changes

We may update this policy when the app changes. Material changes will be surfaced in-app and on this page at least 30 days before they take effect. The "Last updated" date above always reflects the current version; older versions can be requested by email.

14. Contact

Controller: Manor Systems, Unipessoal Lda — NIPC 519 377 753.
Privacy and data-protection requests: privacy@zenicash.com.
General support: support@zenicash.com.

Get the app