← Back to Zado

Privacy Policy

Last updated: June 14, 2026

The Short Version

  • We collect only what we need to help you budget
  • We never sell your data. Ever.
  • Your bank credentials never touch our servers
  • You can export or delete all your data anytime
  • We don't train AI on your personal financial data
  • Agent access to your budget is always opt-in and revocable
  • SMS approval prompts are opt-in only, opt-out anytime

What We Collect

Account Information

When you sign up, we collect:

  • Email address - So you can log in and we can reach you about your account
  • Name - So your AI coach knows what to call you
  • Password - Stored encrypted (hashed), we can never see it

Financial Data

When you connect your bank, we receive:

  • Transaction history - Descriptions, amounts, dates, and categories
  • Account balances - So you can see your money in one place
  • Account names - To help you identify your accounts

Important: We never receive or store your bank login credentials. Bank connections are handled by Teller and Plaid, secure third-party financial-data services. Your username and password go directly to your bank, not to us.

Preferences & Settings

We store your choices, like:

  • Your coach's personality settings
  • Your neurotype preferences (if you choose to share)
  • Notification settings
  • Budget categories and allocations

App Usage

We may collect basic analytics:

  • Which features you use (to improve them)
  • Error reports (to fix bugs)
  • Device type and browser (to ensure compatibility)

How We Use Your Data

  • To run the app - Your transactions power your budget
  • To personalize your coach - Your preferences shape how it talks to you
  • To improve Zado - Anonymous, aggregated data helps us build better features
  • To contact you - Only for account-related stuff, never spam

What We Don't Do

  • Sell your data - Never have, never will
  • Share with advertisers - We don't have ads
  • Train AI models on your data - Your conversations stay yours
  • Store bank credentials - We literally can't access them

Bank Connection Security

We use Teller and Plaid for bank connections. Here's how it works:

  1. You log in to your bank directly through Teller's or Plaid's secure popup
  2. The provider gives us a token to fetch your transactions
  3. We never see your bank password
  4. You can disconnect your bank anytime from Settings

Both Teller and Plaid are regulated financial technology companies that follow strict security standards.

About Plaid

When you connect a bank through Plaid, Plaid processes your data under their own privacy policy. We don't control how Plaid handles your information. That relationship is between you and Plaid.

Read Plaid's policy here: Plaid End User Privacy Policy.

Plaid may collect more information about you than Zado uses. From the data Plaid makes available to us, Zado only requests and stores what we need to run your envelope budget: transaction history, account balances, and account names (as listed above under "Financial Data").

To revoke Plaid's access, you have two paths:

  • Disconnect the bank from Zado at Settings > Banks & Data. When you remove a connection, Plaid is designed to automatically delete the personal data tied to that connection from its systems.
  • Manage your Plaid connections directly through Plaid Portal at my.plaid.com.

You can also contact Plaid directly at privacy@plaid.com for data subject requests.

AI Coach Privacy

Your AI coach conversations are:

  • Private - Held on access-controlled servers, visible only to you
  • Not used for training - We don't train AI models on your data, and our AI provider (Anthropic) does not train on Zado data under our commercial terms
  • Deletable - You can clear your chat history anytime

The AI can see your transactions to help you make sense of your money, but this data stays within your account.

Where the data lives: Conversations and the financial data the coach references are stored in our database. Encryption at rest for these records is on our roadmap and not yet implemented. We're transparent about this and will update this policy as that work ships. In the meantime, access to production data is limited to essential personnel (currently the founder).

Agent Access

You can grant AI agents (like Claude or other assistants) limited access to your budget:

  • Opt-in only - You create each agent token manually
  • Scoped permissions - Read-only or spend, with per-transaction caps
  • Revocable - Freeze or delete any agent token from Settings
  • Audited - Every agent action is logged and visible in your dashboard
  • No data sharing - Agents see only what your spending endpoints return

SMS Communications & Consent

If you choose to receive SMS-based approval prompts for AI agent purchases, here's exactly what happens.

What you'll receive

We send text messages for two purposes only:

  • Purchase approval requests - When an AI agent connected to your Zado account tries to make a purchase above your configured approval threshold, you'll get a text like: "[Zado] Your agent Dottie wants to spend $87.00 on Groceries (Whole Foods). Reply YES to approve, NO to deny." You reply, and the agent only proceeds if you said YES.
  • Verification codes - When you add a new phone number to your account, we text you a one-time 6-digit code to confirm the number is really yours.

No marketing. No promotions. No surveys. No solicitations. Every text is triggered by a specific action you or your agent took.

How you opt in

  1. Go to Settings → Phones in the Zado app
  2. Enter your phone number
  3. We send a one-time code via text
  4. Enter the code in Zado to verify the number

By adding your phone and confirming the code, you explicitly consent to receive SMS messages from Zado for the purposes listed above.

How you opt out

  • Reply STOP to any Zado text message. We'll immediately stop sending you SMS. STOPALL, UNSUBSCRIBE, CANCEL, END, and QUIT also work.
  • Remove your phone from Settings → Phones. Same effect, instant.

You can reply START to reactivate if you've previously opted out, or just re-verify the phone in Settings.

How to get help

Reply HELP to any Zado text message. You'll receive a single response with support contact info: "Zado SMS. Reply STOP to opt out. Support: nicholas.smith@evolvingintelligence.ai or https://zadofi.ai."

The full SMS opt-in workflow (with screenshots) is at zadofi.ai/sms-opt-in.

How often

Volume scales with your own agent activity:

  • One SMS per agent purchase that requires your approval
  • Plus one SMS per phone-verification setup (one-time)
  • Plus an optional settlement confirmation when a transaction completes

Typical: a few SMS per day if your agents are active; zero if they're not.

Message and data rates

Standard message and data rates may apply per your wireless plan. Zado does not charge you for SMS.

How we handle your phone number

  • What we store - The phone number, an optional label you provide, and the timestamp of when you verified it.
  • Verification codes - Stored as a one-way bcrypt hash; we can't recover or read them. Hashes are deleted after successful verification.
  • Who else sees it - Only our SMS provider (Twilio), for the sole purpose of delivering messages you've asked to receive. Twilio's privacy policy covers their handling.
  • Marketing - We never use your number for marketing and never share it with marketers.
  • Deletion - Remove your phone from Settings → Phones anytime. The number is immediately deleted from our records and all SMS to that number stops.

Your Rights

You can always:

  • Export your data - Download everything in JSON or CSV format
  • Delete your account - Removes all your data from our systems
  • Disconnect your bank - Stop transaction syncing anytime
  • Update your info - Change your email, name, or preferences
  • Contact us - Ask questions about your data

To exercise these rights, go to Settings > Data & Privacy, or email us at nicholas.smith@evolvingintelligence.ai

Data Storage

Here's the honest picture of how your data is stored today:

  • Encryption in transit - All connections between the app and our servers use HTTPS
  • Encryption at rest for sensitive credentials - Bank access tokens are encrypted at rest using Fernet
  • Access controls - Only essential personnel (currently the founder) can reach the production database
  • Automatic backups - Our hosting provider maintains automatic backups of the database

What is not yet encrypted at rest: Transaction history, envelope balances, AI coach conversations, preferences, and audit logs are stored in the production database without an additional encryption layer at rest. The database itself is access-controlled and not publicly reachable, but we want you to know exactly what is and isn't cryptographically protected. Expanding encryption at rest to cover the full data surface is on our roadmap.

Formal security audits: We have not yet completed a formal third-party security audit. We follow standard security practices (parameterized queries, scoped tokens, access controls, secure providers for bank data) and will pursue a formal audit as the user base grows. We'll update this section when that work is underway.

Cookies

We use a few essential cookies to:

  • Keep you logged in
  • Remember your preferences
  • Protect against cross-site attacks

We don't use tracking cookies or third-party advertising cookies.

Changes to This Policy

If we make significant changes, we'll:

  • Update the "Last updated" date
  • Notify you via email or in-app message
  • Give you time to review before changes take effect

Contact Us

Questions about privacy? We're happy to help.

  • Email: nicholas.smith@evolvingintelligence.ai
Terms of Service Back to Zado