Legal

Privacy Policy

Effective date: 27 July 2026 · Last updated: 27 July 2026

Applies to: zidaan.app and site.zidaan.app · Operated by Zidaan

The short version: Your project data never leaves your own cloud storage. Zidaan's servers handle only your account identity: email, name, encrypted password hash. We cannot read your tasks, projects, expenses, or documents. By design. This is not a marketing claim; it is the technical architecture.

1. Who We Are

Zidaan is a project management platform. Our contact email is security@zidaan.app. When we refer to "Zidaan", "we", "us", or "our" in this policy, we mean the Zidaan service and those operating it.

2. The Architecture That Protects Your Data

Zidaan is built on a zero-vendor-data architecture. Understanding this is essential to understanding your rights.

What lives on Zidaan's servers (Railway/PostgreSQL)

What never touches Zidaan's servers

All project data is stored in your browser's IndexedDB (a local database on your device) and synchronised to your own cloud storage backend: Google Drive, Dropbox, OneDrive, SharePoint, AWS S3, Azure Blob, WebDAV, SFTP, or a local folder you choose. Zidaan acts only as a relay for authentication and AI requests. It never persists your project content.

Project data is encrypted client-side using AES-256-GCM before it is stored or synced. The encryption key is derived from your password using PBKDF2 (SHA-256, 310,000 iterations) and is held in your browser's memory only. It is never sent to our servers.

3. Data We Collect and Why

Account information

We collect your email, name, and encrypted password to authenticate you and operate your account. Legal basis: performance of a contract (your account agreement with us).

Usage analytics

We use PostHog (EU-hosted) to collect anonymised analytics about how the application is used: which screens are visited, which features are used, and performance metrics. We do not collect the content of your work. You can opt out of analytics via the cookie consent banner. Legal basis: legitimate interest in improving the product, with opt-out provided.

Support communications

When you email us or submit a bug report, we store that correspondence to resolve your issue. Legal basis: legitimate interest.

Payment information

Payments are handled by LemonSqueezy. Zidaan receives only a subscription status and customer identifier. We never see or store your card details. LemonSqueezy's privacy policy governs payment data.

AI relay

When you use the Ask AI feature, your prompt is relayed through our backend to the AI provider (Cerebras, Groq, Gemini via Google, or Anthropic depending on your plan). We do not log the content of AI conversations. The AI providers' data processing terms apply to the relay.

4. Regulatory Compliance

UAE Personal Data Protection Law (PDPL)

Zidaan is designed to support UAE PDPL compliance. Your project data never leaves your chosen storage backend. Zidaan processes only the minimum identity data required to operate the service. You have the right to access, correct, and delete your account data by contacting security@zidaan.app.

Saudi Arabia Personal Data Protection Law (PDPL)

We apply the same data minimisation principles for Saudi-based users. The zero-vendor-data architecture means your organisation's project data remains within your control at all times.

Canada: PIPEDA and Provincial Laws

For Canadian users, we comply with the Personal Information Protection and Electronic Documents Act (PIPEDA). You have the right to access personal information we hold about you and to request correction. Contact our privacy officer at security@zidaan.app.

5. Data Retention

Account data is retained while your account is active. If you delete your account, we delete your email, name, password hash, and session tokens within 30 days. PBKDF2 salt values are deleted at the same time.

Your project data is stored exclusively in your own cloud storage backend. Deleting your Zidaan account does not delete data from your Google Drive, Dropbox, or other storage. You control that directly.

Anonymised analytics events are retained for 24 months in PostHog.

6. Your Rights

Depending on your jurisdiction, you have the right to:

To exercise any of these rights, email security@zidaan.app. We will respond within 30 days.

7. Data Processing Agreement (DPA)

For enterprise customers requiring a formal Data Processing Agreement to meet their internal compliance obligations (UAE PDPL, Saudi PDPL, PIPEDA, or GDPR), please contact security@zidaan.app. We will provide a DPA tailored to your regulatory requirements.

8. Cookies

We use a small number of cookies and local storage values. See our Cookie Policy for the full list and how to manage them.

9. Third-Party Services

Zidaan uses the following third-party services. Each has its own privacy policy:

Your cloud storage backend (Google Drive, Dropbox, OneDrive, etc.) is governed entirely by its own provider's terms. Zidaan does not control or access data stored in your cloud backends.

10. Security

We implement industry-standard security measures including AES-256-GCM client-side encryption, bcrypt password hashing, HTTPS on all connections, and rate limiting on authentication endpoints. For security concerns or vulnerability disclosures, contact security@zidaan.app.

11. Children

Zidaan is not directed at children under 18. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us immediately.

12. Changes to This Policy

We will notify registered users by email of material changes to this policy at least 14 days before they take effect. Continued use of Zidaan after that date constitutes acceptance of the updated policy.

13. Contact

Privacy questions: security@zidaan.app
Security disclosures: security@zidaan.app
General: admin@zidaan.app