1. Controller
The data controller is Eduardo Alberto Coto Astacio, an individual resident in Costa Rica, who offers Zen under the trade name VELTRON.
Zen is a personal project, not a company. There is one person behind the service, and that person answers for how your data is handled.
Zen is a personal logging tool. It is not a medical device: it offers no diagnosis, treatment or medical, psychological, nutritional or financial advice.
2. Local and synced use
Without an account
You can use the app with “Continue without an account”. Data is stored on the device only and is never synced. It can be lost if you clear the app's data, uninstall it or change devices.
With a synced account
If you create an account, what you record is transmitted to Firebase Authentication and Cloud Firestore so you can sign in and sync across devices. That means your data leaves your device and travels to the United States, as explained in section 6.
3. Data we process
Sensitive information
Read this before you write. Several Zen modules collect information about your health, which the law protects more strictly:
Processing this data requires your express consent, which you give by using those modules. Nobody makes you: you can use Zen without touching any of them.
Data about other people
If you write about someone else, that information is stored too. That person cannot know about it or exercise their rights, because they are not a user of the service. Keep it in mind as you write.
What we never ask for
Zen does not request location, camera, microphone, contacts, SMS, phone, photos, videos or files from your device. We collect no payment data and no advertising identifiers.
4. Purposes
- Providing the features you ask for: storing what you record, showing it back to you and syncing it.
- Keeping you signed in.
- Sending the notifications you have enabled.
- Protecting the service: limiting abuse and detecting improper access.
5. Providers and third parties
We do not hand your data to anyone to use for their own purposes. Some third parties are involved technically:
Unsplash and Qwen receive nothing you record: they only see that a browser with your IP requested an image. It is still a disclosure to a third party that happens without you doing anything, which is why it is declared here.
More in the Firebase privacy and security information.
6. Where it is stored and how it is protected
Your data is stored in Cloud Firestore, in the nam5 multi-region, located in the United States. Firebase Authentication is also processed in US data centres.
Security
Passwords are handled by Firebase Authentication: we neither store them nor can we see them. Database rules prevent one user from reading another's data. Traffic is encrypted in transit, and Zen disables unencrypted traffic and Android's automatic app backups.
The controller's access
We would rather say this plainly: the person responsible for the service can technically access stored data, including your health records and your free text, through the platform's administrative credentials. That access is used only to operate the service, investigate a security problem or comply with a legal obligation. If that is not enough for what you were planning to record, use local mode.
If a breach happens
If a breach affects your data, we will tell you by email within 72 hours of becoming aware of it, explaining what happened, which data was affected and what you can do.
7. Retention
Local data stays on the device until you delete it, clear the app's data or uninstall Zen.
| Data | How long it is kept |
|---|---|
| What you record in the app | For as long as your account exists |
| Inactive accounts | Deleted after 24 months without a sign-in, with 30 days' notice by email |
| Audit log and security events | 12 months |
| Notification log | 7 days |
| Rate-limiting data (includes IP) | 1 hour |
| Backups | 30 days |
| Messages sent through “Contact the creator” | 24 months after the reply, or until you delete your account |
8. Delete your account and data
Option 1 — From the app
Settings → Delete account and data- Open Zen and sign in to the account you want to delete.
- Go to Settings.
- Tap Delete account and data.
- Confirm the permanent deletion.
What survives, and why
If your account produced a security event, that record is kept with your identifier replaced by an irreversible code: it still helps defend the service against a pattern of abuse, and no longer says who you were.
| What remains | How long | Why |
|---|---|---|
| Audit log | 12 months | It is a signed chain where each entry validates the previous one. Altering it would make it look tampered with, which is exactly what it exists to detect. It is kept whole and expires on schedule; once your account is deleted, the identifier it holds no longer corresponds to anything |
| Your IP in rate-limiting data | 1 hour | Protection against abuse |
| Backups | 30 days | Recovery from failures |
| Google Cloud technical logs | Per Google's retention | They no longer contain your identifier in the clear, only the same irreversible code |
Option 2 — Without installing or opening the app
If you cannot reach the app or would rather not reinstall it, you can request deletion by email:
Write from the same address linked to your account (or state it in the message) so we can verify ownership. We process these requests within 30 days and confirm by the same channel once the account and its data have been deleted.
9. Your rights
Costa Rica's Law No. 8968 on the Protection of Individuals with regard to the Processing of their Personal Data grants you the right to informational self-determination. You can:
- Access the data we hold about you.
- Correct it if it is wrong, and update it.
- Delete it, by deleting your account.
- Object to certain processing and ask that it be restricted.
- Take it with you: use Settings → Export backup to download all your content. That is your right to portability and you do not need to ask us.
- Withdraw your consent for the sensitive modules at any time, by ceasing to use them and deleting what you recorded.
To exercise any of these, write to contact@veltron.cc. We reply within 5 working days at most.
If you believe we did not handle your request properly, you can turn to the Agencia de Protección de Datos de los Habitantes (PRODHAB), part of Costa Rica's Ministry of Justice and Peace.
10. Minors
Zen requires you to be 16 or older. It is not designed to process data from anyone younger, and if we find such an account we delete it along with its data.
If you are a parent or guardian and believe someone under 16 created an account, write to contact@veltron.cc.
11. Changes to this policy
If we change anything substantial, we will give at least 30 days' notice inside the app. Every version carries a number and an effective date.
The authoritative text of this policy lives in the Zen repository, in PRIVACY_POLICY.md, and this page is generated from it.
12. Contact
For any privacy question or help deleting your data, write to contact@veltron.cc or use Contact the creator inside Zen. Requests about accounts need reasonable verification to prevent unauthorised deletions.