Summary
- Zimam is a personal-finance tracker made by Onports Private Limited. It never connects to a bank and never moves money.
- What you enter (transactions, accounts, budgets, goals, receipts) is stored in your account so the app can work across your devices. We never sell it and never use it for advertising. There are no ads.
- AI capture sends receipt images, screenshots, pasted text and voice transcripts from our server to Anthropic's API to read the amount, payee and category. You confirm every result before it is saved.
- Analytics and crash reports never include amounts, balances, payees, notes or account names, and you can switch usage reporting off in Settings.
- You can delete your account and everything in it from inside the app, immediately and permanently.
Who we are
Zimam (the "app") is operated by Onports Private Limited ("Onports", "we", "us"). This policy explains what we collect when you use the app and this website, why we collect it, where it goes, and the choices you have.
Questions about this policy go to support@onports.in.
What we collect
An account is required to use Zimam. Everything below is collected only to provide the service you signed up for.
| Data | Why we collect it | Where it goes | | --------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Sign-in details: your email address, or the identity token from Sign in with Apple or Google Sign-In, and a password if you set one | To create and secure your account and let you sign in on another device | Supabase Auth (our authentication provider), encrypted in transit | | Ledger data: transactions (amounts, payees, notes, categories, dates, payment method), accounts and account names, budgets, goals and recurring rules | To store your ledger, sync it between your devices, and show budgets, insights and the widget | Supabase Postgres database, encrypted in transit | | Receipt photos and screenshots you attach or capture | To keep them with the matching transaction, and to parse them if you use AI capture | Supabase Storage; and, only when you trigger AI capture, Anthropic's API (see below) | | Bank statement PDFs and CSV files you import | To turn statement rows into transactions for you to review | CSV files are read on your device and are not uploaded. PDFs are sent to our server and to Anthropic's API for parsing, then discarded after the result is returned | | Voice input | To let you log an entry by speaking | Transcribed on your device by the operating system. The audio is never uploaded or stored. Only the resulting text is sent for parsing, and only if you use AI capture | | Purchase status for Zimam Pro | To unlock Pro features on all your devices | RevenueCat, our subscription manager, which gives us an app user ID and entitlement status. We never receive your card details | | Usage events and crash reports | To find bugs and understand which features are used | Firebase Analytics and Firebase Crashlytics (see below) | | Push notification token | To deliver the notifications you opted in to | Firebase Cloud Messaging | | Device information: model, operating system version, app version, language | Bundled with crash reports and support requests to reproduce problems | Firebase Crashlytics, and our support inbox if you email us |
We do not collect precise location, contacts, or advertising identifiers. We do not use any advertising SDK.
AI capture
AI capture is the feature that reads a receipt, a screenshot, a line of pasted text or a spoken sentence and proposes a transaction. It is included in Zimam Pro, and the free plan includes a limited number of captures each month.
When you use it, the image, text or transcript is sent from our server to Anthropic's API (Claude models), which returns a structured guess at the amount, payee and category. The result lands in your review inbox. Nothing is written to your ledger until you confirm it, and you can edit or discard any suggestion.
Bank statement PDFs uploaded for import are processed the same way, row by row.
Anthropic processes this data under its commercial API terms, which state that inputs and outputs submitted through the API are not used to train Anthropic's models. We do not send your name, email address or account identifiers alongside the content.
Voice is transcribed on your device by the operating system. The audio itself is not uploaded and is not stored anywhere by us.
Analytics and crash reports
We use Firebase Analytics and Firebase Crashlytics (Google) to understand how the app is used and to find crashes. They receive:
- screen views and event shapes, for example "transaction added, had a category" or "budget created";
- crash logs and stack traces;
- device model, operating system version and app version;
- a user identifier so that a crash can be matched to a support request.
They never receive amounts, balances, payees, notes, account names, receipt images or any content of your ledger. Analytics is switched off entirely in debug builds.
You can turn usage reporting off at any time at Settings → Privacy → Share usage data. The app works identically with it off.
Subscriptions
Zimam Pro is sold as an in-app subscription through the Apple App Store and Google Play, and managed on our side by RevenueCat. Apple or Google handles the payment, renewal and refunds under their own terms and privacy policies. We receive your subscription status and a RevenueCat app user ID. We never see your card number or billing address.
Notifications
If you opt in during onboarding, we send push notifications through Firebase Cloud Messaging for budget-cap alerts, recurring-entry reminders and "capture ready" messages. You can switch them off at any time in your phone's system settings. Notification content is generated on your device and on our server; it is not shared with any third party beyond the delivery service.
Security
- All traffic between the app, our server and our providers is encrypted in transit.
- Your data is stored in Supabase with access limited to your authenticated account.
- App lock uses Face ID, Touch ID or your passcode through the operating system. Biometric data is handled by your device and never reaches us.
- Entries made while offline are queued on your device and synced when a connection returns.
- CSV exports and PDF statements are generated for you, on your request, and delivered to you. We do not send them anywhere else.
No system is perfectly secure. If you believe your account has been accessed without permission, email us immediately.
Retention
We keep your data for as long as your account exists. When you delete your account, your data is deleted immediately from our live systems and purged from backups within 30 days. Analytics and crash data already sent to Firebase is not linked back to a deleted account and is kept under Google's retention settings, which we set to the shortest available period.
Your rights
Depending on where you live, you may have rights under laws such as the GDPR (European Economic Area and the United Kingdom), the CCPA/CPRA (California), or the data-protection law of REPLACE_JURISDICTION. Regardless of where you live, we give everyone the following:
- Access — see the data we hold about you. Your ledger is visible in the app; anything else, ask us.
- Correct — edit any entry, account, budget or goal in the app at any time.
- Export — generate a CSV export or PDF statement from the app.
- Delete — delete your account and all of its data from Settings → profile → Delete account, or by email if you have uninstalled the app. See how to delete your account.
- Withdraw consent — turn off usage reporting in Settings, turn off notifications in system settings, or stop using AI capture.
- Object or restrict — write to us and we will consider your request under the applicable law.
To exercise any of these rights, email support@onports.in from your account address. We respond within 30 days. If you are in the EEA or UK and are unhappy with our response, you may lodge a complaint with your local supervisory authority.
We do not sell personal information and do not share it for cross-context behavioural advertising.
Children
Zimam is intended for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a child has created an account, email us and we will delete it.
Changes
We may update this policy as the app changes. The date at the top of this page shows the latest revision. If a change materially affects how we handle your data, we will tell you in the app before it takes effect.
Contact
Onports Private Limited
Email: support@onports.in
Website: onports.com
This policy is governed by the laws of REPLACE_JURISDICTION.