usezend.app

Privacy Policy

Your data, handled honestly.

This policy covers usezend.app, the early-access waitlist, and the Zend! app. It says what we collect, why, who else sees it, how long we keep it, and what you can ask us to do about it. Where a claim would be aspirational, we say so instead of saying it.

Effective September 2, 2026Last updated September 2, 2026

00Overview

Who we are and what this covers

Zend! (“Zend”, “we”, “us”) builds a way to send money as easily as sending a message. This policy applies to the usezend.app website, the early-access waitlist, the Zend! mobile and web apps, and the APIs behind them. For that data, Zend is the controller — the party that decides why and how it is processed.

Two things shape everything below. First, we are a money product, so some data we must collect and keep by law, and some of it has to go to licensed partners. Second, Zend! is built so that the most sensitive material — your keys, your PIN, your direct messages — is encrypted on your device before it reaches us, which means there are things about you we deliberately cannot see.

01What we collect

What we collect

When you join the waitlist

Your email address, and — only if you give them — your name, a reserved zendtag, and your country. Our server also records the IP address the request came from and your browser’s user-agent string, which we use to prevent abuse and to understand where interest is coming from. We check that the email address is deliverable and not disposable before we save it.

When you use the app

Account and profile
Phone number, email address, display name, zendtag, avatar image, notification preferences, privacy settings, and sign-in timestamps.
Verification
Identity verification for bank rails runs on our partner’s hosted flow. Your documents and details go to the partner; on our side we store the verification status, the partner’s customer reference, and links to the flow — not your ID images.
Money movement
Wallet addresses, transaction amounts and currencies, on-chain transaction signatures, fees, exchange rates, counterparties, payment links and requests, savings pockets and locks, pool contributions, and order status.
Bank details
For Nigerian naira transfers, the bank, account number, and account name you save. For international transfers, the partner’s account reference plus the bank name, account-holder name, and last four digits.
Keys and secrets
Encrypted backups of your wallet keys (ciphertext only — we do not hold the PIN or passphrase that opens them), your public keys, and, for sign-in-with-Google identity on Sui, an encrypted salt. Sign-in codes are stored only as hashes and expire in minutes. PINs are stored as Argon2 hashes, never in the clear.
Messages and social
Direct messages as end-to-end encrypted ciphertext we cannot read, plus the metadata needed to deliver them. Pool messages and voice notes, reactions, comments, activity items and the connections between them, streaks, and what you have chosen to make public.
Device and technical
Push-notification tokens, platform and app version, IP address, user agent, an approximate country derived from your IP, and server logs of requests and errors.
Support
Messages you send us, and the account context needed to answer them.

Contacts

If you let the app find people you know, it sends phone numbers and email addresses from your device to our server to check which ones already have a Zend! account. We answer with the matches and do not keep the list you sent. We are working on doing this match in a way that never exposes the non-matching entries; today it is a straight lookup, so if that trade-off does not sit well with you, skip contact matching.

What we do not collect

  • Card numbers or CVVs — Zend! does not process cards.
  • Your PIN, your recovery phrase, or any private key in a form we can read.
  • The contents of your direct messages.
  • Behavioural advertising profiles. We do not sell or rent your data, and we do not use it to target ads.
  • Third-party analytics on this website. usezend.app loads no analytics scripts and sets no cookies of its own.

02Why we use it

Why we use it, and on what basis

We use your data for these purposes, and only these:

To run the Service
Create your account, sign you in, move money, show balances and history, deliver messages, send receipts and notifications, and answer support requests. Legal basis: performance of our contract with you.
To keep it safe
Detect and stop fraud, account takeover, spam, and abuse; rate-limit and monitor our systems; investigate incidents. Legal basis: our legitimate interest in a secure service, and yours.
To meet legal duties
Identity verification, anti-money-laundering and counter-terrorist-financing checks, sanctions screening, record-keeping, and responding to lawful requests. Legal basis: compliance with legal obligations.
To improve the product
Understand which flows fail, fix bugs, and decide what to build next — using aggregate and diagnostic data wherever that is enough. Legal basis: legitimate interests.
To talk to you about Zend!
Waitlist updates, launch news, and product announcements. Legal basis: your consent, which you can withdraw from any email we send.

We do not make decisions about you by automated means alone that have a legal or similarly significant effect, other than automated risk and sanctions screening — where a transaction is blocked by screening, you can ask a human to look at it.

03Who sees it

Who we share it with

We share the minimum each provider needs to do its job. The ones actually in the path today:

Bridge
Identity verification for individuals, and international bank rails (ACH, Faster Payments, SEPA, SPEI, and others). Receives your verification details and documents directly, plus the details of transfers it settles.
PAJ Cash
Nigerian naira cash-in and cash-out. Receives the bank account details and amounts for those transfers.
Dextopus and Jupiter
Cross-chain routing, swaps, and liquidity. Receive transaction and address data, not your identity.
Lit Protocol
Distributed key management for parts of our signing infrastructure. Receives encrypted key material and authorisation data.
Google
If you use sign-in with Google for Sui identity, Google authenticates you. We keep a fingerprint of the identifier, not the raw token.
Firebase Cloud Messaging
Push notifications. Receives your device token and the notification content.
Resend, SendGrid, and Mailgun
Sending and receiving transactional email — sign-in codes, receipts, waitlist mail, and email-based payment intents.
Cloudflare
Object storage for avatars and voice notes, plus content delivery and protection for our sites and APIs.
Telegram
Only if you use the Zend! bot or mini-app. Telegram sees the interaction as its own platform does.
Infrastructure providers
Cloud hosting, managed databases and caches, error monitoring, and an IP-geolocation lookup used to guess your country. Bound by contract to process data only on our instructions.

We also disclose data where the law requires it — to regulators, law enforcement, or a court — or where it is needed to establish or defend a legal claim, or to protect someone from harm. If Zend is ever part of a merger, acquisition, or reorganisation, data may transfer with the business, and this policy will continue to apply until you are told otherwise.

We do not sell your personal data, and we never have.

04On-chain data

The part that is public forever

Transactions on Solana, Sui, and other public blockchains are recorded on a ledger that anyone can read and that nobody can edit — including us. Addresses, amounts, timing, and the links between addresses are public by design.

We cannot delete, correct, or hide on-chain data at your request, and someone who knows one of your addresses may be able to infer other activity from it. Inside Zend!, activity is private unless you choose to make it public; on-chain, treat it as permanently visible.

05Where it goes

International transfers

Zend! is used across borders and our providers sit in several countries, mostly the United States and the European Union. That means your data may be processed outside the country you live in, where privacy laws differ.

When we move data across borders we rely on the mechanisms available to us — standard contractual clauses, adequacy findings, or your explicit consent for a specific transfer — and we require providers to protect the data to the standard described in this policy.

06How long

How long we keep it

Waitlist entries
Until you are invited and become a user, or until you ask us to remove you, or until we stop running the waitlist.
Account and profile data
For as long as your account is open.
Transaction and verification records
At least five years after the relationship ends, where financial and anti-money-laundering rules require it. We cannot delete these on request within that window.
Sign-in codes
Hashed, and invalid within minutes of being issued.
Messages and media
Until deleted by you or by the room’s participants, then removed from live systems and aged out of backups on their normal cycle.
Encrypted key backups
Until you delete the backup or close your account. We cannot read them at any point.
Server and security logs
Short retention — long enough to investigate incidents, not longer.

Being straight with you: automated deletion tooling is still being built. Today, deletion and export requests are handled by a person, and we commit to completing them within 30 days of verifying who you are.

07Security

How we protect it

  • TLS on everything in transit.
  • AES-256-GCM envelope encryption for keys, key shares, and other sensitive material at rest.
  • Argon2 hashing for PINs and passwords; SHA-256 hashing for one-time codes, which are never stored in the clear.
  • End-to-end encryption for direct messages, with keys that stay on your devices.
  • Device-level protection you control: PIN, biometrics, passkeys, and a per-payment confirmation option.
  • Least-privilege internal access with audit logging, rate limiting, signed and replay-protected webhooks, and continuous monitoring.

No system is perfectly secure. If a breach affects your personal data, we will tell you and the relevant regulator as quickly as the law requires and as clearly as we can. To report a vulnerability, email security@usezend.app.

08Your rights

Your rights

Wherever you live, you can ask us to:

  • Show you the personal data we hold about you, and where it came from.
  • Correct anything inaccurate or incomplete.
  • Delete your data and close your account.
  • Give you a copy in a portable format.
  • Restrict or object to a particular use, including profiling for risk where the law gives you that right.
  • Stop sending you marketing, at any time, with no reason needed.

Email privacy@usezend.app to exercise any of these. We may need to verify your identity first — we are protecting your account by doing so. We will respond within 30 days and tell you if we need longer.

Three honest limits:

  • Records we must keep for financial-crime and accounting rules cannot be deleted early.
  • On-chain data cannot be deleted or altered by anyone.
  • We cannot hand over the contents of your end-to-end encrypted messages, because we cannot read them.

You can also complain to your data-protection authority — in Nigeria, the Nigeria Data Protection Commission; in the UK, the Information Commissioner’s Office; in the EU, your national authority. We would rather you came to us first, but the right is yours.

09Children

Children

Zend! is for adults. It is not directed at anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us data, email privacy@usezend.app and we will delete it.

10Cookies

Cookies and local storage

This website sets no cookies and runs no analytics or advertising scripts. Fonts and assets are served from our own origin, so browsing usezend.app does not hand your visit to a third party.

The app uses your device’s secure storage to hold your session token, your encrypted keys, and your preferences. That is what keeps you signed in — it is not used to track you across other apps or sites.

11Changes

Changes to this policy

As Zend! changes, this policy will change with it. We will update the “last updated” date, and for material changes we will notify you by email or in the app before they take effect. Old versions are available on request.

12Contact

Contact us

Privacy and data requests
privacy@usezend.app
Security and vulnerability reports
security@usezend.app
Everything else
support@usezend.app

We read every message that arrives at these addresses, and a person answers.