Skip to content
Zirraw
How it worksVoicePrivacySupportBack to home
Legal

Privacy Policy

Last updated October 3, 2026. This policy explains what Zirraw stores on your phone, what Cloud AI sends when you add an entry or ask a question, and the controls you have.

On-device dataCloud AICloud AI connectionProblem reportsProvidersPermissionsAds & analyticsDeletionRetentionSecurityChildrenContact

Zirraw is a local-first personal money journal published under the name Zirraw Labs. This policy applies to the Zirraw mobile app and the Zirraw website.

Short version: your saved entries, totals and notes stay on your phone. Cloud AI is optional: during first-run setup you can choose Turn on Cloud AI or Keep it local. When Cloud AI is on, Zirraw sends only the request being processed and the limited context described below; it does not upload your complete journal. You can change the choice anytime in Settings → Privacy & deletion. Zirraw does not need an email/password account.

Information stored on your device

Zirraw stores transactions, notes, budgets, recurring items, money-event context and app settings in a local SQLite database on your device. The live SQLite database is protected by the device/app sandbox but is not encrypted with SQLCipher at the database-file level.

If you enable App Lock, a PIN or supported biometric check controls access to the app interface. Zirraw can also create internal recovery snapshots in private app storage. New recovery snapshots are encrypted with AES-GCM using a device-bound key stored through SecureStore; snapshots created by an earlier build may remain readable until they are rotated or deleted. Password-protected .mnbak backups are encrypted before sharing. Readable exports such as CSV or JSON are not encrypted by Zirraw after you export them.

The Android app is configured to opt out of Android platform automatic backup for Zirraw app data so the local ledger is not silently copied into Android backup storage by Zirraw. Files you intentionally export to another destination are outside this protection.

Cloud AI

Cloud AI improves how Zirraw understands voice and everyday sentences, and it is optional. The first time you open Zirraw, setup explains what Cloud AI sends and gives you two choices: Turn on Cloud AI or Keep it local. Nothing is sent to Cloud AI unless you turn it on. You can change the choice anytime in Settings → Privacy & deletion → Cloud AI. While it is off, no text or audio is sent to Zirraw's Cloud AI services and the local parser still understands short entries such as “Lunch 500”.

While Cloud AI is on, Zirraw may send through the Zirraw backend to an AI provider: text you type that the on-device parser cannot understand, questions you ask in Ask, and the limited context needed to answer them (your currency, country, time zone and today's date). Zirraw does not upload your saved entries, totals, notes or complete journal.

While Cloud AI is on and you are online, Zirraw sends the short audio clip you intentionally record through the Zirraw backend to Groq for transcription. To spell names correctly, the request can also include up to 40 merchant and people names that Zirraw learned on your phone from entries you confirmed. Zirraw's backend does not store the audio, transcript or these names. If your device already has compatible on-device speech recognition installed, Zirraw can instead use that local capability without sending the recording to Zirraw or Groq. Zirraw does not download its own speech model and does not continuously record audio in the background.

If neither cloud transcription nor compatible on-device recognition is available, you can keep the short recording encrypted in Voice Inbox on your device and choose to transcribe it later. Queued recordings are not included in Zirraw backups and are deleted after successful transcription or when you delete them.

Personal learning: Zirraw can learn low-risk merchant, wording and category associations from entries you explicitly confirm. This personalization stays in the local ledger and can be cleared from Settings. Zirraw does not learn likely transaction amounts, balances, security credentials or raw voice recordings as personalization rules.

Anonymous Cloud AI connection and usage records

Cloud AI uses an anonymous Supabase Auth identity so requests can be authenticated and rate-limited without requiring a Zirraw email/password account. For abuse prevention and quota enforcement, the Zirraw backend stores the anonymous identifier, which AI feature was used, the request time, a request count, and whether the anonymous identity was created in the last 24 hours (so new devices can be limited during abuse). These usage records do not contain entry text, notes, amounts, audio, transcripts or AI responses.

Service providers

  • Supabase — anonymous authentication, the database that holds AI usage records, and the server functions that run Cloud AI requests. Supabase Privacy Policy.
  • Groq — processes Cloud AI language requests and voice transcription. Groq Privacy Policy.
  • Expo and device-platform services — tooling and device capabilities used to build and run the installed app.

These providers may process data on servers outside Pakistan, including in the United States. Provider-level processing and log retention are governed by the applicable service terms, account configuration and provider policies. Zirraw Labs reviews these settings as part of production operations and when providers or configurations materially change.

Microphone, biometrics and notifications

Zirraw requests microphone access only for user-initiated voice capture. Supported biometric APIs may be used for App Lock when you enable them. Notification permission may be requested for optional Quick Voice and recurring-item reminders. Recurring reminder previews are designed not to include amounts, merchants, descriptions, categories or note contents.

Problem reports

If something goes wrong in the app, Zirraw keeps the last 25 error messages on your phone, with numbers and email addresses removed. They contain no entries, notes or amounts. They are only sent if you choose Settings → Help → Share a problem report, and you choose the app or address they go to. Erase local data also deletes them.

Advertising, analytics and sale of data

The current Zirraw release does not intentionally include an advertising SDK or third-party analytics SDK. Zirraw Labs does not sell personal ledger data. If advertising, analytics or a materially different data practice is introduced in a future release, this policy and the relevant app-store disclosures will be updated before that version is released.

Data deletion

Inside Zirraw, Settings → Privacy & deletion provides controls to turn off Cloud AI, to Erase local data from this phone, and to Delete Cloud AI connection, which deletes the anonymous identity and its usage records.

Files you previously exported or saved outside the app's private storage are controlled by the location or app where you saved them and are not automatically deleted by Zirraw. See Data Deletion for step-by-step instructions.

Retention

Local journal data remains on the device until you delete it, clear the app's data, uninstall the app in a way that removes local storage, or replace it through a restore operation. Exported copies remain wherever you saved them until you delete those copies.

Anonymous AI usage records are kept for abuse prevention and operations for up to 30 days. A scheduled database cleanup runs daily to delete older quota records, and the records associated with your anonymous identity are also deleted when you successfully use Delete Cloud AI connection in Settings. Provider-side logs or request data may be retained according to the provider's applicable terms and configured service settings.

Security

Zirraw uses device sandboxing, optional App Lock (which can also hide Zirraw in the recent-apps screen), SecureStore for sensitive app-lock/auth state, device-bound encryption for new internal recovery snapshots, an Android automatic-backup opt-out, server-side provider keys, authenticated Edge Functions, request validation, rate limits and encrypted transport for designed cloud flows. No security measure can guarantee absolute protection.

Children's privacy

Zirraw is intended for adults age 18 and over for its initial public launch. It is not designed as a child-directed financial service.

Changes to this policy

We may update this policy when Zirraw, its service providers or applicable requirements change. The updated date at the top of this page will change when the policy is revised.

Contact

Zirraw Labs
Pakistan
privacy@zirraw.app
support@zirraw.app

© Zirraw Labs.Home · Privacy · Support · Delete Data · Terms