Privacy policy
Last updated 12 September 2026
Zadi puts every credit card you own in one place, which means you are trusting us with a picture of your money. This page says what we hold, where it sits, who else can see it, and how to take it back.
The short version
- We never ask for your full card number, CVV, PIN, bank password or OTP, so we cannot store them.
- Your records are readable only by your own account. Every table in our database enforces that rule in the database itself.
- The copy Zadi keeps on your phone for offline use is encrypted, with the key held in your device's keychain.
- We do not sell your data and we do not run advertising against it.
- Settings has one button that exports everything as a file and one that deletes it.
Where Zadi is today. Zadi is in closed testing with invited users. Card and transaction details are entered by hand: the app holds no live connection to any bank, and it does not hold or move money.
This policy describes the app as it works now. When bank connections or payments arrive, they will need our own licensing to be in place first, this page will be updated before they are switched on, and nothing new starts without your consent.
Who we are
Zadi is a credit card app built in the United Arab Emirates by Hussein Tawfik and Mostafa Asseel. For anything on this page, write to privacy@zadi.ae and one of us will answer.
What we hold
Everything below is either something you typed into the app or something the app needs to run.
- Your account. The email address you sign in with, a display name if you set one, and your language, currency and appearance settings.
- Your cards. The bank, the nickname you give the card, the last four digits, the credit limit, and the statement and due dates you enter.
- Your money. Transactions and the categories you put them in, income you record, a monthly spending cap if you set one, and the card balances and payments you enter.
- What you send us. Feedback and support messages, and the email you send them from.
- Technical records. App version, platform, and the error reports described under who else sees it.
What we never hold
Full card numbers, CVV codes, card PINs, bank passwords and one-time codes. The app has nowhere to type them, so there is nothing to leak.
What we do with it
- Show your spending across every card in one view, in the currency you chose.
- Track statement and due dates, and remind you before a payment is due.
- Work out which of your cards earns most on a given purchase. These answers are worked out from your own numbers, they are informational, and they are not regulated financial advice.
- Keep the app working when your phone is offline.
- Understand how the app is used and fix it when it breaks.
We do not profile you for advertisers, and we do not make automated decisions that carry a legal effect for you.
Where it lives, and how it is protected
- On our servers. Your records sit in a Postgres database run by Supabase, our hosting provider. Row level security is switched on for every table, so a request carrying your account can read your rows and nobody else's, enforced by the database rather than by the app asking nicely.
- In transit. Every connection between the app and our servers is encrypted with TLS.
- On your phone. Zadi keeps a copy of your latest data so the app opens without a signal. That copy is encrypted with XChaCha20-Poly1305 under a random 256-bit key stored in the iOS Keychain or the Android Keystore, and it is unreadable to anything else on the device.
- Behind a lock, if you want one. You can require Face ID, Touch ID or a PIN every time Zadi opens. That check happens on the device.
Who else sees it
Four companies process data on our behalf. Each one is contracted to handle it only for us.
| Who | What they receive | Why |
|---|---|---|
| Supabase | Your account and everything listed under what we hold | Runs our database, sign-in and file storage |
| Sentry | Crash and error reports: the fault, the screen it happened on, the app version and the device type | Tells us the app broke before you have to |
| PostHog | Which screens are opened and which features are used, tied to an app identifier | Shows us what people actually use. Card numbers, amounts, merchants and names are not sent with these events |
| Apple and Google | A push token for your device, and the text of the reminder itself | Delivers due date reminders. Turning notifications off in your phone's settings ends this |
Beyond that, we share your information only when the law or a UAE regulator requires it, and only as far as the request reaches. We do not sell it, and it is not part of any advertising exchange.
Bank connections
Today there are none. You type your cards and transactions in yourself, which is why the app can say so plainly.
The UAE's open finance framework, run by the Central Bank through Al Tareq, is the route we intend to take for reading card data directly. It would work like this: you approve the connection at your own bank, your login details stay with your bank and never reach us, we receive only the card data covered by that approval, and you can revoke it at your bank whenever you like. None of it happens until we hold the licensing it requires, and this page will say so before it does.
Payments
Zadi does not hold, custody or move your money, and it has no access to any account you can pay from. The Settle screen records a payment you have already made through your own bank, so your balances stay accurate.
Payment initiation, once we are licensed for it, would send an instruction to your bank that you approve at your bank. Money would move from your account to your card issuer, and never through Zadi.
Your choices
- See it. Everything Zadi stores about you is visible in the app.
- Take it. Settings has an export button that writes the lot to a JSON file you can keep.
- Correct it. Every record you entered can be edited or deleted in the app.
- Delete it. Settings has a delete button that removes your cards, transactions, income and connections for good. Tell us at privacy@zadi.ae if you want the account itself closed with it.
- Object or ask. Write to us about any of this, including a copy in another format, and we will answer within 30 days.
How long we keep it
While your account is open, because the app is only useful with your history in it. When you delete your data it goes from the live database immediately, and from our provider's encrypted backups within 30 days as those backups roll over. Error reports expire after 90 days. Anonymous usage counts may be kept as totals that cannot be traced back to a person.
Children
Zadi is built for adults who hold credit cards and is not intended for anyone under 18. If a child's data reaches us, write to privacy@zadi.ae and we will remove it.
Changes to this policy
When it changes, the date at the top changes with it. Anything that materially affects what we hold or who sees it will be flagged in the app before it takes effect.
Contact
Questions, requests and complaints all go to privacy@zadi.ae. If we cannot resolve something between us, UAE residents can raise it with the UAE Data Office.
Zadi