Skip to content
enshevron
checkmarkEnglish
Українська
Polski

Privacy Policy

Zelvo is a personal finance service: budgeting, investment tracking and an AI assistant in one place. That means you trust us with information about your money, and this Privacy Policy explains — in plain language wherever we can — what Zelvo Corporation (the “Company”, “we”, “us”, “our”) collects, how we use it, who we share it with, and the choices and rights you have.

This Privacy Policy covers our marketing website at https://www.zelvo.io (the “Site”), the Zelvo web application at https://app.zelvo.io, and the Zelvo mobile application (together, the “Service”). “You” refers to you, as a visitor to our Site or a user of our Service.

By accessing our Site or our Service, you accept this Privacy Policy and our Terms of Use (found here: https://www.zelvo.io/terms-and-conditions), and you consent to our collection, storage, use and disclosure of your Personal Information as described in this Privacy Policy.

I. INFORMATION WE COLLECT

We collect only what the Service needs to work. A guiding principle of how Zelvo is built: the most sensitive things — raw statement files, exchange API keys, wallet seed phrases — are designed to either stay on your device or be unreadable to us.

  1. Account information

    When you create an account we collect your email address and a password. We store the password only as a one-way cryptographic hash (argon2) — we never store and cannot see the password itself. You can optionally add a first and last name and an avatar image, and set preferences such as language and currency. If you sign in with Google or Apple instead, we receive your email address (and basic profile information such as your name) from that provider. If you sign in with a crypto wallet, you prove control of the wallet by signing a message (Sign-In with Ethereum) and we store the public wallet address — never a private key. We also process one-time verification codes sent to your email for email verification, password reset and email changes.

  2. Financial data you enter

    The core of the Service is the financial picture you build in it: budgets, accounts and balances, transactions, income sources, goals, plans, recurring rules, and investments you track. You (and people you invite to a shared budget) enter this data; we store it to run the Service for you. We do not connect to your bank, and we never ask for your bank credentials.

  3. Files you import

    Zelvo is import-first, and imports are built to minimise what leaves your device:

    • Bank statements (CSV/XLSX) are parsed on your device. Only the structured transaction rows you review and confirm are sent to our servers — the raw statement file is never uploaded.
    • Brokerage statements (CSV/XLSX) work the same way: parsed on your device, and only the holdings you confirm are sent to us.
    • PDF statements and images are processed only when you explicitly attach them in a chat with the AI assistant (see Section IV).
    • Exchange (CEX) imports: if you import balances from a supported exchange (Kraken, Binance, Coinbase), the read-only API keys you provide are used in memory for a single balance fetch and then discarded — they are never stored, logged, or sent back to you.
  4. Crypto wallet data

    If you connect a watch-only wallet, we store its public address and fetch its balances through third-party APIs (Section V). Public addresses only — connecting a watch-only wallet never involves a private key or a signature that moves funds. If you generate a wallet inside Zelvo, the seed phrase is shown to you exactly once and stored only in encrypted form (AES-256-GCM), with the encryption key derived from your own password. We cannot decrypt it. If you lose the password, neither you nor we can recover the seed phrase.

  5. AI conversations, voice and memories

    When you talk to the AI assistant we store your messages and the assistant’s replies so you can revisit conversations. If you use voice input, the audio is transcribed to text and the text is what the assistant works with. The assistant can save small “memories” about your preferences and situation — you can view and delete every memory, and delete whole conversations, inside the app. The Service also learns from your own categorisation habits (for example, which category you give a merchant) to make imports and suggestions better; that learning is private to your account.

  6. Waitlist

    If you join the waitlist on the Site, we collect your email address and language preference, and use them to confirm your signup and to contact you about access to Zelvo.

  7. Technical data and cookies

    Like most services we process basic technical information — IP address, browser and device type, and error reports — to keep the Service secure and working. We use first-party cookies that are necessary for the Service: an authentication cookie that keeps you signed in, your cookie-consent choice, and preferences such as language and theme. Analytics runs only if you accept it in the cookie banner — see Section VI. If you enable push notifications, we store your push subscription and the browser it belongs to so we can deliver them.

  8. Children’s privacy

    Zelvo is a financial product for adults. The Site and the Service are not directed to anyone under the age of 18, and we do not knowingly collect personal information from anyone under 18. If you believe we have collected such information, please contact us at info@zelvo.io and we will delete it.

II. HOW WE USE YOUR INFORMATION

We use the information above to:

  • provide and operate the Service — storing your budgets and transactions, doing the balance and forecasting math, converting currencies, and rendering your financial picture;
  • power the AI assistant and related features, as described in Section IV;
  • keep accounts secure — authentication, session management, rate limiting and abuse prevention, and error monitoring so we can fix what breaks;
  • process subscription payments through Stripe (we never see your full card number — Stripe handles the card);
  • send service communications: verification codes, budget invitations, waitlist and beta-access emails, and the reminders and digests you choose in your notification preferences (email and push notifications can each be turned off per type);
  • understand product usage in aggregate, using the consent-gated analytics described in Section VI.

We do not sell your personal information, we do not share it with advertisers, and we do not use the contents of your financial data or your AI conversations for advertising.

We may share information with outside parties if we have a good-faith belief that access, use, preservation or disclosure is reasonably necessary to comply with legal process or an enforceable governmental request; to enforce our Terms of Use, including investigation of potential violations; to address fraud, security or technical concerns; or to protect against harm to the rights, property or safety of our users or the public as required or permitted by law. If we undergo a business transaction such as a merger, acquisition or sale of assets, your information may be among the assets transferred; the acquirer would remain bound by commitments at least as protective as this Privacy Policy, and we would notify you as described in Section XII.

III. WHERE YOUR DATA LIVES

Zelvo runs on cloud infrastructure: the Service is hosted on Vercel and your data is stored in a PostgreSQL database operated by Neon. Data is encrypted in transit. Providers we use to process your data are listed in Section V.

IV. THE AI ASSISTANT AND YOUR DATA

The AI assistant is a core part of Zelvo, so we want to be precise about what it processes:

  • Chat. When you send a message, your message (and any attachment you added, such as a PDF statement or receipt photo) together with relevant context from your budgets is sent to Anthropic, whose Claude models generate the reply. Anthropic processes this data on our behalf to provide the feature.
  • Search and recall. Short text descriptions of your transactions are converted into numerical embeddings using OpenAI’s embedding API so the assistant can find relevant history (“how much did I spend on groceries like this?”). The embeddings are stored in our own database, not OpenAI’s products.
  • Voice. Voice input is transcribed by OpenAI’s Whisper API; the audio is used for transcription and the resulting text powers your request.
  • Actions. When the assistant proposes a change to your data (adding a transaction, moving money between categories), the change runs through exactly the same permission checks as the buttons and forms in the app, you approve it before it executes, and you get a receipt with undo.
  • Memories. You can view and delete the assistant’s saved memories and your conversation history in the app at any time; deleting your account deletes all of it (Section VII).

Anthropic and OpenAI act as processors for these features through their business APIs. No other use of your data is made by them on Zelvo’s behalf.

V. WHO WE SHARE INFORMATION WITH

We share personal information only with service providers that help us run Zelvo, each limited to what its job requires:

  • Vercel (US) — hosting and infrastructure for the Site and the Service, and consent-gated web analytics.
  • Neon — the PostgreSQL database where your account and financial data are stored.
  • Anthropic — AI assistant replies (chat messages, attachments and budget context), as described in Section IV.
  • OpenAI — transaction-text embeddings and voice transcription, as described in Section IV.
  • Stripe — subscription payments. Your card details go directly to Stripe; we store subscription status, not card numbers.
  • Resend — delivery of the emails we send (verification codes, invitations, notifications, waitlist emails).
  • Sentry — error monitoring, so we learn about crashes and bugs. Session replay (a visual recording of your own session used for diagnosing bugs) is enabled only with your analytics consent, and even then all text is masked and media is blocked in the recording.
  • Google Tag Manager — analytics tags on the marketing Site only, and only after you accept the cookie banner.

Some providers receive no personal information at all — they supply market data we show you, or look up balances for wallet addresses:

  • OpenExchangeRates — currency exchange rates. No personal data is sent.
  • Zerion and public blockchain APIs (such as TronGrid and toncenter) — used to fetch balances for the wallets you track. They receive wallet addresses only. Wallet addresses are public information on their blockchains by design.
  • Market-data sources (CoinGecko, DefiLlama, DeFi venue APIs, Alpha Vantage for equity prices) — prices, yields and protocol statistics. No personal data is sent.

VI. COOKIES, ANALYTICS AND YOUR CONSENT

By default, we use only first-party cookies that are strictly necessary: keeping you signed in (an HttpOnly authentication cookie), remembering your cookie-consent choice, and remembering preferences such as language and theme. These do not track you across other websites.

Analytics is opt-in. When you first visit, a banner asks whether you accept analytics. If you decline, nothing analytics-related loads — the Site and the Service remain fully functional. If you accept, we enable: Google Tag Manager (marketing Site only), Vercel Analytics and Speed Insights, and Sentry session replay (with text masked). Product usage events we record are deliberately minimal — the type of action and a count, never amounts, merchant names, notes, or any other content of your financial data.

Your consent choice is stored for one year, after which we ask again. You can change your mind at any time by deleting the “zelvo_consent” cookie in your browser — the banner will ask again on your next visit.

VII. DATA RETENTION AND DELETION

We keep your data for as long as your account exists, because the product is your financial history. Two specifics worth knowing:

  • Deleting your account deletes your data. You can delete your account from the app’s settings. Deletion is a hard delete, not a deactivation: your budgets, transactions, investments, chat conversations, AI memories, transaction embeddings, learned categorisation memory, sessions and telemetry rows are all removed, and any active subscription is cancelled. If a budget you own is shared with other people, we ask you to resolve that (transfer or remove members) first, so we never silently destroy someone else’s data. If you funded a transaction in another person’s budget, that budget keeps its own ledger history, with your side detached.
  • Rolling windows. Daily DeFi position snapshots (used for earnings charts) are kept for about 400 days and then pruned. Expired sign-in sessions, one-time codes and similar short-lived records are purged automatically.

Waitlist entries are kept while we run the waitlist; email us to be removed. Records we are legally required to keep (for example, billing records processed by Stripe) are retained as required by law.

VIII. YOUR RIGHTS

If you are in the European Union, the United Kingdom, Ukraine, Poland or another jurisdiction with similar data-protection law, you have the right to:

  • access the personal data we hold about you;
  • correct inaccurate data (most of it you can edit directly in the app);
  • erase your data (the in-app account deletion described in Section VII does this immediately; you can also email us);
  • receive a copy of your data in a portable format — the app includes a budget export that downloads your full budget history, and you can request a broader copy from us;
  • object to or restrict certain processing;
  • withdraw consent where processing is based on consent (for example analytics — Section VI) without affecting the Service;
  • complain to your local data-protection supervisory authority.

Our lawful bases are: performance of our contract with you (running the Service you signed up for, including its AI features), legitimate interests (keeping the Service secure and working, including error monitoring), and consent (analytics cookies and session replay). To exercise any right, use the in-app controls or email info@zelvo.io; we will need to verify that you control the account.

You can opt out of non-essential emails using the unsubscribe link in the email or your notification preferences in the app; we may still send administrative emails such as verification codes or notices about changes to this Privacy Policy.

IX. HOW WE PROTECT INFORMATION

We implement security measures designed to protect your information: encryption in transit (TLS), one-way password hashing (argon2), wallet seed phrases encrypted with keys derived from your own password (which means we cannot read them), HttpOnly authentication cookies, role-based access control on shared budgets, and rate limiting on credential endpoints. Secrets such as wallet passwords and seed phrases are deliberately kept out of the layers of the system that persist activity.

No security measure is perfect, and we cannot guarantee that your information will never be accessed, disclosed, altered or destroyed by a breach. Help us protect you: use a strong, unique password, and never share your password or a seed phrase with anyone — we will never ask for them.

X. INTERNATIONAL TRANSFERS

We serve users in Europe and beyond, and the providers listed in Section V operate largely in the United States. This means your personal data may be transferred to and processed in countries other than your own, including the US. Where such transfers are subject to European data-protection law, we work with providers under their data-processing agreements and applicable transfer safeguards.

XI. LINKS TO OTHER WEBSITES

The Service contains links to third-party websites — for example, DeFi protocols or exchanges we show information about. We are not responsible for the privacy practices of those websites, and this Privacy Policy does not apply to them. When you follow a link out of Zelvo (for instance, to interact with a DeFi protocol), that party’s privacy policy applies. We encourage you to read the privacy statements of other websites before using them.

XII. CHANGES TO OUR PRIVACY POLICY

The Company reserves the right to change this policy and our Terms of Use at any time. We will notify you of significant changes by sending a notice to the primary email address specified in your account or by placing a prominent notice on our Site. Significant changes will go into effect 30 days following such notification. Non-material changes or clarifications will take effect immediately. You should periodically check the Site and this privacy page for updates.

XIII. CONTACT US

If you have any questions about this Privacy Policy, your data, or your rights, contact us at info@zelvo.io or by mail at Zelvo Corporation, 1111B S Governors Ave, STE 39751, Dover, Delaware 19904, USA.

This Privacy Policy was last updated on 14 August 2026.