Privacy Policy
Last updated: 2026-07-24
In short: we collect the minimum information needed to run ZenWitGo, and we never sell your personal data. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have. It applies to the ZenWitGo mobile app and any associated websites operated by ZenWitGo (“we”, “us”, “our”).
Information we collect
We collect the following categories of information:
- Account & authentication. Your email address and a password (we store only a salted hash of it, never the password itself) — or, if you sign in with Apple or Google, the account identifier those providers give us so we can recognise you on future visits.
- Learning data. The missions and exercises you complete, the answers you submit, and the progress that results from them — your XP, streaks, rank, and any badges you earn.
- Device & usage data. App and session events (for example, when a mission starts or ends), your device model and operating system, your device’s IANA time zone (used to schedule reminders and reset daily streaks at the right local time), and a push-notification token if you turn notifications on.
- Purchase data. Your subscription or entitlement status, as reported to us by Apple In-App Purchase or Stripe when you subscribe. We do not receive or store your full card number or other payment credentials — Apple and Stripe handle your payment details directly, not us.
- Support enquiries. The name, email address, and message you send us through the in-app or website support form.
How we use it
We use the information above to:
- run your account and keep you signed in;
- deliver your daily missions and track your progress, streaks, ranks, and badges;
- send reminders and notifications you have opted into;
- process subscription purchases and keep your entitlements up to date;
- respond to support requests you send us; and
- improve our content and detect abuse or misuse of the service.
Legal bases for processing (GDPR)
If you are located in the European Economic Area or United Kingdom, we rely on the following legal bases under the GDPR:
- Contract — most of our processing (running your account, delivering missions, tracking progress) is necessary to provide the service you signed up for.
- Consent — for optional features such as push notifications and any marketing communications, which you can withdraw at any time.
- Legitimate interests — for security, fraud prevention, and improving our product, balanced against your rights and interests.
Sharing & processors
We do not sell your personal data, and we do not share it with third parties for their own marketing purposes. We share information only with the service providers (“processors”) who help us run ZenWitGo, acting on our instructions and only to the extent needed for them to perform that function:
- AWS (Amazon Web Services) — hosting and infrastructure for our backend and database.
- Apple and Stripe — payment processing for subscriptions; they handle your card details directly.
- Firebase Cloud Messaging and Apple Push Notification service (APNs) — delivery of push notifications you have enabled.
- Our email provider — delivery of transactional emails, such as account or support correspondence.
We may also disclose information where required by law, to protect our rights, or in connection with a merger, acquisition, or sale of assets — in which case this policy would continue to apply to your data.
Data retention
We keep your information for as long as your account is active and it is reasonably necessary to provide the service. If you delete your account — which you can do directly in the app, under Profile — we delete your personal data, subject to a limited period during which we may retain certain records where the law requires it, for example financial or payment records that Apple or Stripe require to be kept for tax, accounting, or fraud-prevention purposes.
Security
We use industry-standard safeguards to protect your information, including encryption of data in transit, hashed (never plaintext) password storage, and least-privilege access controls that limit who inside ZenWitGo can reach production data. No method of transmission or storage is 100% secure, and we can’t guarantee absolute security.
International transfers
We and our service providers may process your information in countries other than the one you live in. Where that happens, we rely on appropriate safeguards — such as standard contractual clauses — to protect data that is transferred internationally.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we’ll revise the “Last updated” date at the top of this page, and if a change is material we’ll let you know inside the app.
Contact
Questions, requests, or concerns about this policy or your personal data can be sent to privacy@zenwitgo.com.
This policy is provided in good faith and should be reviewed by legal counsel before public launch.