Veltron Zen
ESEN
Privacy and control

Your information stays under your control.

This policy explains what data Zen uses, where it is stored, who else sees it, how long it is kept and how to delete it. It is written so you can decide what to record before you record it.

Version 2.0 — effective 27 August 2026Controller: Eduardo Alberto Coto AstacioCosta Rica
Local firstYou can use Zen without an account. In that mode your records never leave the device.
No ads, no data sellingWe do not sell data, there is no advertising, and your content does not train AI models.
Stored in the United StatesWith a synced account, your data travels to Google servers in the US.

1. Controller

The data controller is Eduardo Alberto Coto Astacio, an individual resident in Costa Rica, who offers Zen under the trade name VELTRON.

Zen is a personal project, not a company. There is one person behind the service, and that person answers for how your data is handled.

Zen is a personal logging tool. It is not a medical device: it offers no diagnosis, treatment or medical, psychological, nutritional or financial advice.

2. Local and synced use

Without an account

You can use the app with “Continue without an account”. Data is stored on the device only and is never synced. It can be lost if you clear the app's data, uninstall it or change devices.

With a synced account

If you create an account, what you record is transmitted to Firebase Authentication and Cloud Firestore so you can sign in and sync across devices. That means your data leaves your device and travels to the United States, as explained in section 6.

3. Data we process

AccountEmail address, display name, username, internal identifier and the provider you sign in with.
TechnicalIP address for abuse limiting, and a browser identifier if you enable notifications.
ProductivityTasks, goals, events, progress and preferences.
Personal financesBudget and savings you choose to record.

Sensitive information

Read this before you write. Several Zen modules collect information about your health, which the law protects more strictly:

Health, Sleep, Movement, Hydration, EnergyRecords about your physical state, rest and activity.
Mood and MindYour emotional state over time, which can reveal mental health.
NutritionA food diary, which can also reveal religious or philosophical beliefs.
Journal, Notes, Purpose and RelationshipsEntirely free text. It can contain any category of information, including information about other people.

Processing this data requires your express consent, which you give by using those modules. Nobody makes you: you can use Zen without touching any of them.

Data about other people

If you write about someone else, that information is stored too. That person cannot know about it or exercise their rights, because they are not a user of the service. Keep it in mind as you write.

What we never ask for

Zen does not request location, camera, microphone, contacts, SMS, phone, photos, videos or files from your device. We collect no payment data and no advertising identifiers.

4. Purposes

  • Providing the features you ask for: storing what you record, showing it back to you and syncing it.
  • Keeping you signed in.
  • Sending the notifications you have enabled.
  • Protecting the service: limiting abuse and detecting improper access.
What we do not do: we do not sell personal data, we show no advertising, we do not profile you commercially, and we do not use your content to train artificial intelligence models.

5. Providers and third parties

We do not hand your data to anyone to use for their own purposes. Some third parties are involved technically:

Google (Firebase)Hosts the database, authentication and server functions. Processes all your account data on the controller's behalf.
UnsplashSixteen of the background images load from their servers, so they receive your IP address and browser details.
Qwen (Alibaba)One background image loads from image.qwenlm.ai, which means a connection to infrastructure in China and your IP being sent there.

Unsplash and Qwen receive nothing you record: they only see that a browser with your IP requested an image. It is still a disclosure to a third party that happens without you doing anything, which is why it is declared here.

More in the Firebase privacy and security information.

6. Where it is stored and how it is protected

Your data is stored in Cloud Firestore, in the nam5 multi-region, located in the United States. Firebase Authentication is also processed in US data centres.

International transfer. If you live outside the United States, using a synced account transfers your data there, including the sensitive data in section 3. If you would rather avoid that, use Zen in local mode: nothing leaves your device.

Security

Passwords are handled by Firebase Authentication: we neither store them nor can we see them. Database rules prevent one user from reading another's data. Traffic is encrypted in transit, and Zen disables unencrypted traffic and Android's automatic app backups.

The controller's access

We would rather say this plainly: the person responsible for the service can technically access stored data, including your health records and your free text, through the platform's administrative credentials. That access is used only to operate the service, investigate a security problem or comply with a legal obligation. If that is not enough for what you were planning to record, use local mode.

If a breach happens

If a breach affects your data, we will tell you by email within 72 hours of becoming aware of it, explaining what happened, which data was affected and what you can do.

7. Retention

Local data stays on the device until you delete it, clear the app's data or uninstall Zen.

DataHow long it is kept
What you record in the appFor as long as your account exists
Inactive accountsDeleted after 24 months without a sign-in, with 30 days' notice by email
Audit log and security events12 months
Notification log7 days
Rate-limiting data (includes IP)1 hour
Backups30 days
Messages sent through “Contact the creator”24 months after the reply, or until you delete your account
Data control

8. Delete your account and data

Option 1 — From the app

Settings → Delete account and data
  1. Open Zen and sign in to the account you want to delete.
  2. Go to Settings.
  3. Tap Delete account and data.
  4. Confirm the permanent deletion.
Deleted immediately: your sign-in account, everything you recorded in the modules, your username reservation, any messages you sent through “Contact the creator” — with your name and email inside them — your notification log, and your suspension record if there was one. In local mode, the data stored on that device is cleared.

What survives, and why

If your account produced a security event, that record is kept with your identifier replaced by an irreversible code: it still helps defend the service against a pattern of abuse, and no longer says who you were.

What remainsHow longWhy
Audit log12 monthsIt is a signed chain where each entry validates the previous one. Altering it would make it look tampered with, which is exactly what it exists to detect. It is kept whole and expires on schedule; once your account is deleted, the identifier it holds no longer corresponds to anything
Your IP in rate-limiting data1 hourProtection against abuse
Backups30 daysRecovery from failures
Google Cloud technical logsPer Google's retentionThey no longer contain your identifier in the clear, only the same irreversible code

Option 2 — Without installing or opening the app

If you cannot reach the app or would rather not reinstall it, you can request deletion by email:

✉ Request deletion by email

Write from the same address linked to your account (or state it in the message) so we can verify ownership. We process these requests within 30 days and confirm by the same channel once the account and its data have been deleted.

9. Your rights

Costa Rica's Law No. 8968 on the Protection of Individuals with regard to the Processing of their Personal Data grants you the right to informational self-determination. You can:

  • Access the data we hold about you.
  • Correct it if it is wrong, and update it.
  • Delete it, by deleting your account.
  • Object to certain processing and ask that it be restricted.
  • Take it with you: use Settings → Export backup to download all your content. That is your right to portability and you do not need to ask us.
  • Withdraw your consent for the sensitive modules at any time, by ceasing to use them and deleting what you recorded.

To exercise any of these, write to contact@veltron.cc. We reply within 5 working days at most.

If you believe we did not handle your request properly, you can turn to the Agencia de Protección de Datos de los Habitantes (PRODHAB), part of Costa Rica's Ministry of Justice and Peace.

10. Minors

Zen requires you to be 16 or older. It is not designed to process data from anyone younger, and if we find such an account we delete it along with its data.

If you are a parent or guardian and believe someone under 16 created an account, write to contact@veltron.cc.

11. Changes to this policy

If we change anything substantial, we will give at least 30 days' notice inside the app. Every version carries a number and an effective date.

The authoritative text of this policy lives in the Zen repository, in PRIVACY_POLICY.md, and this page is generated from it.

12. Contact

For any privacy question or help deleting your data, write to contact@veltron.cc or use Contact the creator inside Zen. Requests about accounts need reasonable verification to prevent unauthorised deletions.