Privacy Policy
Your data, handled honestly.
This policy covers usezend.app, the early-access waitlist, and the Zend! app. It says what we collect, why, who else sees it, how long we keep it, and what you can ask us to do about it. Where a claim would be aspirational, we say so instead of saying it.
Effective September 2, 2026Last updated September 2, 2026
00Overview
Who we are and what this covers
Zend! (“Zend”, “we”, “us”) builds a way to send money as easily as sending a message. This policy applies to the usezend.app website, the early-access waitlist, the Zend! mobile and web apps, and the APIs behind them. For that data, Zend is the controller — the party that decides why and how it is processed.
Two things shape everything below. First, we are a money product, so some data we must collect and keep by law, and some of it has to go to licensed partners. Second, Zend! is built so that the most sensitive material — your keys, your PIN, your direct messages — is encrypted on your device before it reaches us, which means there are things about you we deliberately cannot see.
01What we collect
What we collect
When you join the waitlist
Your email address, and — only if you give them — your name, a reserved zendtag, and your country. Our server also records the IP address the request came from and your browser’s user-agent string, which we use to prevent abuse and to understand where interest is coming from. We check that the email address is deliverable and not disposable before we save it.
When you use the app
- Account and profile
- Phone number, email address, display name, zendtag, avatar image, notification preferences, privacy settings, and sign-in timestamps.
- Verification
- Identity verification for bank rails runs on our partner’s hosted flow. Your documents and details go to the partner; on our side we store the verification status, the partner’s customer reference, and links to the flow — not your ID images.
- Money movement
- Wallet addresses, transaction amounts and currencies, on-chain transaction signatures, fees, exchange rates, counterparties, payment links and requests, savings pockets and locks, pool contributions, and order status.
- Bank details
- For Nigerian naira transfers, the bank, account number, and account name you save. For international transfers, the partner’s account reference plus the bank name, account-holder name, and last four digits.
- Keys and secrets
- Encrypted backups of your wallet keys (ciphertext only — we do not hold the PIN or passphrase that opens them), your public keys, and, for sign-in-with-Google identity on Sui, an encrypted salt. Sign-in codes are stored only as hashes and expire in minutes. PINs are stored as Argon2 hashes, never in the clear.
- Messages and social
- Direct messages as end-to-end encrypted ciphertext we cannot read, plus the metadata needed to deliver them. Pool messages and voice notes, reactions, comments, activity items and the connections between them, streaks, and what you have chosen to make public.
- Device and technical
- Push-notification tokens, platform and app version, IP address, user agent, an approximate country derived from your IP, and server logs of requests and errors.
- Support
- Messages you send us, and the account context needed to answer them.
Contacts
If you let the app find people you know, it sends phone numbers and email addresses from your device to our server to check which ones already have a Zend! account. We answer with the matches and do not keep the list you sent. We are working on doing this match in a way that never exposes the non-matching entries; today it is a straight lookup, so if that trade-off does not sit well with you, skip contact matching.
What we do not collect
- Card numbers or CVVs — Zend! does not process cards.
- Your PIN, your recovery phrase, or any private key in a form we can read.
- The contents of your direct messages.
- Behavioural advertising profiles. We do not sell or rent your data, and we do not use it to target ads.
- Third-party analytics on this website. usezend.app loads no analytics scripts and sets no cookies of its own.
02Why we use it
Why we use it, and on what basis
We use your data for these purposes, and only these:
- To run the Service
- Create your account, sign you in, move money, show balances and history, deliver messages, send receipts and notifications, and answer support requests. Legal basis: performance of our contract with you.
- To keep it safe
- Detect and stop fraud, account takeover, spam, and abuse; rate-limit and monitor our systems; investigate incidents. Legal basis: our legitimate interest in a secure service, and yours.
- To meet legal duties
- Identity verification, anti-money-laundering and counter-terrorist-financing checks, sanctions screening, record-keeping, and responding to lawful requests. Legal basis: compliance with legal obligations.
- To improve the product
- Understand which flows fail, fix bugs, and decide what to build next — using aggregate and diagnostic data wherever that is enough. Legal basis: legitimate interests.
- To talk to you about Zend!
- Waitlist updates, launch news, and product announcements. Legal basis: your consent, which you can withdraw from any email we send.
We do not make decisions about you by automated means alone that have a legal or similarly significant effect, other than automated risk and sanctions screening — where a transaction is blocked by screening, you can ask a human to look at it.
04On-chain data
The part that is public forever
Transactions on Solana, Sui, and other public blockchains are recorded on a ledger that anyone can read and that nobody can edit — including us. Addresses, amounts, timing, and the links between addresses are public by design.
We cannot delete, correct, or hide on-chain data at your request, and someone who knows one of your addresses may be able to infer other activity from it. Inside Zend!, activity is private unless you choose to make it public; on-chain, treat it as permanently visible.
05Where it goes
International transfers
Zend! is used across borders and our providers sit in several countries, mostly the United States and the European Union. That means your data may be processed outside the country you live in, where privacy laws differ.
When we move data across borders we rely on the mechanisms available to us — standard contractual clauses, adequacy findings, or your explicit consent for a specific transfer — and we require providers to protect the data to the standard described in this policy.
06How long
How long we keep it
- Waitlist entries
- Until you are invited and become a user, or until you ask us to remove you, or until we stop running the waitlist.
- Account and profile data
- For as long as your account is open.
- Transaction and verification records
- At least five years after the relationship ends, where financial and anti-money-laundering rules require it. We cannot delete these on request within that window.
- Sign-in codes
- Hashed, and invalid within minutes of being issued.
- Messages and media
- Until deleted by you or by the room’s participants, then removed from live systems and aged out of backups on their normal cycle.
- Encrypted key backups
- Until you delete the backup or close your account. We cannot read them at any point.
- Server and security logs
- Short retention — long enough to investigate incidents, not longer.
Being straight with you: automated deletion tooling is still being built. Today, deletion and export requests are handled by a person, and we commit to completing them within 30 days of verifying who you are.
07Security
How we protect it
- TLS on everything in transit.
- AES-256-GCM envelope encryption for keys, key shares, and other sensitive material at rest.
- Argon2 hashing for PINs and passwords; SHA-256 hashing for one-time codes, which are never stored in the clear.
- End-to-end encryption for direct messages, with keys that stay on your devices.
- Device-level protection you control: PIN, biometrics, passkeys, and a per-payment confirmation option.
- Least-privilege internal access with audit logging, rate limiting, signed and replay-protected webhooks, and continuous monitoring.
No system is perfectly secure. If a breach affects your personal data, we will tell you and the relevant regulator as quickly as the law requires and as clearly as we can. To report a vulnerability, email security@usezend.app.
08Your rights
Your rights
Wherever you live, you can ask us to:
- Show you the personal data we hold about you, and where it came from.
- Correct anything inaccurate or incomplete.
- Delete your data and close your account.
- Give you a copy in a portable format.
- Restrict or object to a particular use, including profiling for risk where the law gives you that right.
- Stop sending you marketing, at any time, with no reason needed.
Email privacy@usezend.app to exercise any of these. We may need to verify your identity first — we are protecting your account by doing so. We will respond within 30 days and tell you if we need longer.
Three honest limits:
- Records we must keep for financial-crime and accounting rules cannot be deleted early.
- On-chain data cannot be deleted or altered by anyone.
- We cannot hand over the contents of your end-to-end encrypted messages, because we cannot read them.
You can also complain to your data-protection authority — in Nigeria, the Nigeria Data Protection Commission; in the UK, the Information Commissioner’s Office; in the EU, your national authority. We would rather you came to us first, but the right is yours.
09Children
Children
Zend! is for adults. It is not directed at anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us data, email privacy@usezend.app and we will delete it.
11Changes
Changes to this policy
As Zend! changes, this policy will change with it. We will update the “last updated” date, and for material changes we will notify you by email or in the app before they take effect. Old versions are available on request.
12Contact
Contact us
- Privacy and data requests
- privacy@usezend.app
- Security and vulnerability reports
- security@usezend.app
- Everything else
- support@usezend.app
We read every message that arrives at these addresses, and a person answers.