Privacy Policy
Effective date: 27 July 2026 · Last updated: 27 July 2026
Applies to: zidaan.app and site.zidaan.app · Operated by Zidaan
The short version: Your project data never leaves your own cloud storage. Zidaan's servers handle only your account identity: email, name, encrypted password hash. We cannot read your tasks, projects, expenses, or documents. By design. This is not a marketing claim; it is the technical architecture.
1. Who We Are
Zidaan is a project management platform. Our contact email is security@zidaan.app. When we refer to "Zidaan", "we", "us", or "our" in this policy, we mean the Zidaan service and those operating it.
2. The Architecture That Protects Your Data
Zidaan is built on a zero-vendor-data architecture. Understanding this is essential to understanding your rights.
What lives on Zidaan's servers (Railway/PostgreSQL)
- Your email address and display name
- A bcrypt hash of your password (we cannot recover your original password)
- A PBKDF2 salt value used for client-side encryption key derivation (this is a public parameter; it does not give us access to your data)
- Your workspace membership and role
- Your plan status and subscription identifier
- Session tokens (rotated regularly, not stored long-term)
- AI usage counts (number of requests per day, not content)
What never touches Zidaan's servers
- Your tasks, projects, subtasks, and work packages
- Your expenses, budgets, and financial data
- Your stakeholder and risk registers
- Your audit trail entries and project history
- Your documents and file attachments
- Your CRDT operation log (the sync record of all changes)
- Your AI prompt content and responses
All project data is stored in your browser's IndexedDB (a local database on your device) and synchronised to your own cloud storage backend: Google Drive, Dropbox, OneDrive, SharePoint, AWS S3, Azure Blob, WebDAV, SFTP, or a local folder you choose. Zidaan acts only as a relay for authentication and AI requests. It never persists your project content.
Project data is encrypted client-side using AES-256-GCM before it is stored or synced. The encryption key is derived from your password using PBKDF2 (SHA-256, 310,000 iterations) and is held in your browser's memory only. It is never sent to our servers.
3. Data We Collect and Why
Account information
We collect your email, name, and encrypted password to authenticate you and operate your account. Legal basis: performance of a contract (your account agreement with us).
Usage analytics
We use PostHog (EU-hosted) to collect anonymised analytics about how the application is used: which screens are visited, which features are used, and performance metrics. We do not collect the content of your work. You can opt out of analytics via the cookie consent banner. Legal basis: legitimate interest in improving the product, with opt-out provided.
Support communications
When you email us or submit a bug report, we store that correspondence to resolve your issue. Legal basis: legitimate interest.
Payment information
Payments are handled by LemonSqueezy. Zidaan receives only a subscription status and customer identifier. We never see or store your card details. LemonSqueezy's privacy policy governs payment data.
AI relay
When you use the Ask AI feature, your prompt is relayed through our backend to the AI provider (Cerebras, Groq, Gemini via Google, or Anthropic depending on your plan). We do not log the content of AI conversations. The AI providers' data processing terms apply to the relay.
4. Regulatory Compliance
UAE Personal Data Protection Law (PDPL)
Zidaan is designed to support UAE PDPL compliance. Your project data never leaves your chosen storage backend. Zidaan processes only the minimum identity data required to operate the service. You have the right to access, correct, and delete your account data by contacting security@zidaan.app.
Saudi Arabia Personal Data Protection Law (PDPL)
We apply the same data minimisation principles for Saudi-based users. The zero-vendor-data architecture means your organisation's project data remains within your control at all times.
Canada: PIPEDA and Provincial Laws
For Canadian users, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). You have the right to access personal information we hold about you and to request correction. Contact our privacy officer at security@zidaan.app.
5. Data Retention
Account data is retained while your account is active. If you delete your account, we delete your email, name, password hash, and session tokens within 30 days. PBKDF2 salt values are deleted at the same time.
Your project data is stored exclusively in your own cloud storage backend. Deleting your Zidaan account does not delete data from your Google Drive, Dropbox, or other storage. You control that directly.
Anonymised analytics events are retained for 24 months in PostHog.
6. Your Rights
Depending on your jurisdiction, you have the right to:
- Access: request a copy of the personal data we hold about you
- Correction: request we correct inaccurate data
- Deletion: request we delete your account and associated identity data
- Portability: export your account data in a common format
- Objection: object to processing based on legitimate interest
- Withdraw consent: opt out of analytics at any time via the cookie settings
To exercise any of these rights, email security@zidaan.app. We will respond within 30 days.
7. Data Processing Agreement (DPA)
For enterprise customers requiring a formal Data Processing Agreement to meet their internal compliance obligations (UAE PDPL, Saudi PDPL, PIPEDA, or GDPR), please contact security@zidaan.app. We will provide a DPA tailored to your regulatory requirements.
8. Cookies
We use a small number of cookies and local storage values. See our Cookie Policy for the full list and how to manage them.
9. Third-Party Services
Zidaan uses the following third-party services. Each has its own privacy policy:
- Railway: backend hosting (identity data only)
- Vercel: frontend hosting (no user data stored)
- PostHog: anonymised analytics (EU-hosted, opt-out available)
- Resend: transactional email delivery (email address relayed)
- LemonSqueezy: payment processing (payment data only)
- Anthropic, Cerebras, Groq, Google (Gemini via OpenRouter): AI relay by plan tier (prompt content relayed to provider, not logged by Zidaan)
Your cloud storage backend (Google Drive, Dropbox, OneDrive, etc.) is governed entirely by its own provider's terms. Zidaan does not control or access data stored in your cloud backends.
10. Security
We implement industry-standard security measures including AES-256-GCM client-side encryption, bcrypt password hashing, HTTPS on all connections, and rate limiting on authentication endpoints. For security concerns or vulnerability disclosures, contact security@zidaan.app.
11. Children
Zidaan is not directed at children under 18. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us immediately.
12. Changes to This Policy
We will notify registered users by email of material changes to this policy at least 14 days before they take effect. Continued use of Zidaan after that date constitutes acceptance of the updated policy.
13. Contact
Privacy questions: security@zidaan.app
Security disclosures: security@zidaan.app
General: admin@zidaan.app