Pre-launch draft. A few values are still to be confirmed and are marked to be confirmed in the text. This document is published for review and is not yet in force. See what is outstanding.
Status: DRAFT — not reviewed by a lawyer. See README.md before publishing.
Version 0.1 · Drafted 2026-08-12 · Effective 16 August 2026
Language: English. The English text is the authoritative version; see README.md on
translations.
The rest of this policy is the detail behind those statements.
The controller of your personal data is:
Moshe Zaudi, an individual sole trader (עוסק פטור) registered in Israel
Rafiah Yam 24, Netivot, Israel
Company number to be confirmed
Privacy contact: support@zakiapp.art
Zaki is operated from Israel and the service is offered in Israel only. No GDPR Article 27 representative and no DSA Article 13 legal representative are appointed, because the service is not offered in the European Union. If that changes, both appointments must be made before the first user in a member state signs up — they are separate appointments and one does not satisfy the other.
This policy is written to the standard of the EU General Data Protection Regulation (GDPR). Poland is in the EU, and rather than run three different privacy regimes we apply the strictest one to every user, in every market.
| Data | Where it comes from | Why |
|---|---|---|
| Email address | Apple or Google sign-in | To identify your account, send service and billing notices, let you recover access, and — only if you turn "Offers and news" on — send you occasional offers |
| Authentication ID | Apple or Google sign-in | The stable identifier that links you to your account and enforces one free trial per person |
| Locale and market | Your device settings, your choice in-app | To show the app in your language and price in your currency |
| Age confirmation | You, at signup | To enforce the 17+ requirement |
| Notification preferences | The two switches under Settings → Notifications | To decide whether to tell you a video is ready, and whether to send offers. They are stored on your device, not on our servers |
That is the whole of what we hold about you as a person. We do not ask for your name, phone number, address, date of birth, gender or photograph. If you use Apple's "Hide My Email", we only ever see the relay address, and that is fine.
| Data | Retention |
|---|---|
| Prompts — the text you write, plus the translated and expanded English version generated from it | Stored with the generation record; deleted with the video or with your account |
| Uploaded images — photos or images you attach to a generation | Kept for to be confirmed after the generation completes, then deleted; deleted immediately on request |
| Generated videos | Minimum 12 months, and in practice for as long as your account is active. Changeable on 30 days' notice. Deleted within 30 days of account deletion |
| Generation metadata — model used, duration, resolution, aspect ratio, credit cost, timestamps, success or failure | With the generation record |
When a request is screened we record the decision, the reason category, and the detected language of the input — and nothing else. The moderation record does not contain your prompt. It is what lets us count block rates per language and check that we are not wrongly refusing legitimate Hebrew, Arabic or Polish requests, which is the failure that would otherwise be invisible. See the AI Content Policy.
The text of a refused request lives on the generation record for that request, like any other prompt, and is deleted with it — see section 8. The moderation record is attached to your account and is deleted when your account is.
Reports you submit about a video are kept for as long as the video and your account exist; they are deleted with the account.
A prompt reaches OpenRouter before it is screened. Enhancement runs first, so your prompt is sent to OpenRouter in the United States to be translated and expanded, and only then does our classifier read the result. This means a prompt we go on to refuse has already left the EU. Nothing further is done with it, no video is generated, and you are not charged — but "blocked" does not mean "never sent". See sections 6 and 7.
We record your subscription status, purchases, top-ups, and every credit movement in an append-only ledger. We never see or store your card details — payment is handled entirely by Apple or Google, and we receive only a purchase confirmation and a subscription status through RevenueCat.
| Data | Why |
|---|---|
| Device type, OS version, app version, coarse country from IP | To debug and to price correctly |
| IP address, request logs and server error logs | Security, fraud and abuse prevention, and diagnosing failures. Retained for to be confirmed |
There is no analytics SDK and no crash-reporting SDK in the app. We do not run product analytics, we do not track screens you view, and nothing is sent to an analytics or crash-reporting provider — because none is integrated. What we have is the server-side request log above. If that changes we will say so here first, and where analytics needs your consent we will ask for it before collecting anything.
Because we do not track you across other companies' apps and websites, iOS App Tracking Transparency does not apply and the app does not show that prompt. We intend to keep it that way.
If you upload a photo containing an identifiable person, that photo is their personal data as well as yours, and we process it on your instruction.
| What | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and running your account, generating and storing your videos, credits and billing | Contract — Art. 6(1)(b) |
| Translating and expanding your prompt before generation — the enhancement step, on by default and switchable off per request | Contract — Art. 6(1)(b): it is part of producing the video you asked for |
| Moderation, fraud and abuse prevention, security and error logging, spend limits | Legitimate interests — Art. 6(1)(f): keeping the Service lawful, safe and financially viable |
| Sending you offers and news by email or push | Consent — Art. 6(1)(a). Off unless you turn on "Offers and news" in Settings → Notifications, and turning it off withdraws it |
| Keeping financial records | Legal obligation — Art. 6(1)(c): tax and accounting law |
| Responding to a lawful order | Legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interests, you can object — see section 9.6. Where we rely on consent, you can withdraw it at any time — for offers, with the switch that gave it — without affecting processing that already happened.
Uploaded images of identifiable people are processed on your instruction and on the consent you are required to hold from that person.
We use a small number of providers. Each acts as a processor under a data processing agreement, and each is used for one clear purpose.
| Provider | What it does | Where |
|---|---|---|
| Supabase | Database, authentication, background jobs. Your account record, prompts, credit ledger | EU — Frankfurt, Germany |
| Cloudflare R2 | Stores your generated videos and uploaded images | to be confirmed — configured for EU storage |
| OpenRouter | Two things. First, it translates and expands your prompt into English — every non-English prompt is sent to it for that, before our moderation classifier reads anything. Then it routes the generation request to the AI model you selected | United States |
| RevenueCat | Validates App Store and Google Play receipts, tracks subscription status | United States |
| Apple / Google | Sign-in, payment processing, push notifications | Global. They are independent controllers for the sign-in and payment they provide |
The AI model providers — for example Google, ByteDance, MiniMax, Kuaishou, xAI, Black Forest Labs — receive your prompt, and your uploaded image where you attach one, in order to generate your video. They are reached through OpenRouter and they operate under their own terms. What each provider may do with material submitted to it is governed by that provider's terms, which we surface alongside each model. See Terms of Service section 8.
We do not sell personal data, and we do not share it with advertisers or data brokers.
We may disclose data where we are legally required to — a valid court order, a lawful request from a competent authority, or a legal obligation to report specific illegal material — and to establish or defend legal claims. If we are acquired, data may transfer to the acquirer under this policy; we will tell you first.
Your account data, prompts and credit ledger are stored in the European Union. Videos and uploads are stored in EU-configured object storage.
Two processors are based in the United States: OpenRouter and RevenueCat. Transfers to them rely on the European Commission's Standard Contractual Clauses, together with the EU–US Data Privacy Framework where the provider is certified, plus transfer risk assessments. Copies of the relevant safeguards are available on request at support@zakiapp.art.
Every prompt is transferred to OpenRouter, including one that our own moderation then refuses — the enhancement step runs before the classifier, so the transfer has already happened by the time a request is blocked. Where you attach an image, it goes to the model provider with the generation request. See section 3.3.
For users in Israel and the United Arab Emirates, data is likewise stored in the EU and handled under this policy.
| Data | Retention |
|---|---|
| Account record | While your account exists |
| Generated videos | Minimum 12 months; in practice while your account is active. Deleted within 30 days of account deletion, subject to the hold in 9.4 |
| Prompts and generation metadata, including the prompt text of a refused request | With the generation record: deleted when you delete that video, and with your account |
| Uploaded images | to be confirmed after generation |
| Credit ledger | While your account exists, then anonymised — see 9.4 |
| Moderation records — decision, reason category, detected language; no prompt text | While your account exists; deleted with it |
| Reports | While the reported video and your account exist; deleted with the account |
| Security, request and error logs | to be confirmed. These survive account deletion for the rest of that period — see 9.4 |
| Anonymised financial records | seven (7) years, as tax and accounting law requires — see 9.4 |
| Backups | Overwritten on a rolling to be confirmed cycle |
Deletion from live systems is immediate; deletion from backups happens as those backups roll over, and until then the data is not accessible for normal use.
Two entries above are deliberately tied to your account rather than given a period of their own. Moderation records and reports are the evidence of a refusal or a complaint, and today they are deleted when the account is — which means a user who deletes their account also removes that history. Whether abuse evidence should outlive the account, and on what basis, is flagged in README.md as a question for legal review; if that changes, this table and section 9.4 change with it, on notice.
Under the GDPR you have the rights below. They are free of charge, and we answer within one month. To exercise any of them, write to support@zakiapp.art — or use Settings → Data, where "Export my data" and "Delete account" open a pre-filled message to that same address. They are a request to us, not a self-service button: nothing is exported or deleted at the moment you tap, and we do the work when the message reaches us.
You can see what we hold about you. Ask at support@zakiapp.art, or through Settings → Data → Export my data, and within one month we send you a copy of your account record, your prompts, your generation history and your credit ledger. (Art. 15.)
We provide that copy in a structured, commonly used, machine-readable format, and you can download your videos individually from the app at any time. (Art. 20.)
Your email comes from Apple or Google, so correct it there and it will update here. Anything else that is wrong, tell us and we will fix it. (Art. 16.)
Settings → Data → Delete account, or write to support@zakiapp.art. Either way it is a request that reaches a person, and we act on it within one month. It is a real deletion, not a hidden deactivation.
Deleted within 30 days of us acting on your request:
Four things survive, and we would rather list all four than let you discover them.
1. An anonymised financial record. We are legally obliged to keep accounting records of money received — that is tax and company law, not a choice. So we keep the date, the amount, the currency, the store it came through, the VAT treatment, and an opaque internal reference.
That record contains no email address, no name, no authentication ID, no device identifier, no prompt, and no link back to you. The identifiers are destroyed, not hidden — the row cannot be re-associated with you by us or by anyone else, which is what makes it anonymous rather than merely pseudonymous.
This is expressly permitted by GDPR Article 17(3)(b), which disapplies the right to erasure where processing is necessary for compliance with a legal obligation. It is kept for seven (7) years as required by the Income Tax Ordinance [New Version], 5721–1961, and the Income Tax Regulations (Bookkeeping), 5733–1973, and it is used for accounting and audit only.
2. Security, request and error logs, which contain your IP address. They are kept for the rest of their to be confirmed window and then deleted on their own schedule, not yours. We rely on Article 17(3)(e) — establishment, exercise or defence of legal claims — and on our legitimate interest in being able to investigate fraud and abuse after the account behind it is gone.
3. Backups, until they roll. Deletion from live systems happens first; backups are overwritten on a rolling to be confirmed cycle, and until then the data is not available for normal use and is not restored except to recover the whole system.
4. A video that is under report. If a video of yours has been reported and the review has not closed, that one video and its report are held until it does, and then deleted. This is the same hold described in Terms of Service section 11, and it exists because deleting the subject of a live complaint destroys the evidence the review needs. It is a hold of days, not a second retention period.
Nothing else about you is kept.
Note that deleting your account does not cancel a subscription purchased through Apple or Google. Cancel that in the store, or you will continue to be billed for an account that no longer exists.
You can ask us to stop processing your data while a dispute about its accuracy or our legal basis is resolved. (Art. 18.)
You can object to processing based on legitimate interests. (Art. 21.) Tell us at support@zakiapp.art and we will weigh it. Be aware of the limit: we cannot stop the security, moderation and fraud-prevention processing that keeps the Service lawful and continue to provide it to you.
The only thing we ask consent for is offers and news. Turn "Offers and news" off under Settings → Notifications and it stops. Everything else in the app works exactly the same either way.
You can complain to a supervisory authority. If you are in Poland that is the Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw. If you are in Israel, the Privacy Protection Authority. If you are in the UAE, the UAE Data Office. We would rather you told us first at support@zakiapp.art, but it is your right either way.
Two things happen automatically:
Neither produces a legal effect on you, but both can affect your use of the Service, so: you can ask for a human to review any refusal or restriction, and challenge it, by writing to support@zakiapp.art. What we have to tell you when we refuse or restrict something is set out in the AI Content Policy section 6. We record refusals partly so that we can find and fix systematic errors — for example a classifier that misreads Hebrew or Arabic and blocks legitimate requests. (Art. 22.)
We do not profile you for advertising, and we do not make automated decisions about pricing based on your behaviour.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours and tell affected users without undue delay, as GDPR Articles 33 and 34 require.
The Service is 17+. We do not knowingly collect data from anyone below that age. If we learn that we have, we delete the account and its data. If you believe a child is using the Service, tell us at support@zakiapp.art.
We may update this policy. For material changes we give at least 30 days' notice in the app and by email before they take effect, and we keep previous versions available at https://zakiapp.art/legal/archive. The version number and date at the top of this document tell you which version you are reading.
Privacy questions, rights requests, and requests about an image of you that someone else uploaded:
Moshe Zaudi
Rafiah Yam 24, Netivot, Israel
support@zakiapp.art