ZAP is built around anonymity. We process the strict minimum of data needed to run the service and protect the community. Here is exactly what.
01Data we process
Email address: for sign-in and account verification.
Password: stored only as a hash (bcrypt), never in plain text.
Generated anonymous identity: pseudo, avatar and color gradient.
Vibe and interests: generic tags chosen at onboarding.
Age band: the category you declare at sign-up, used to check that you are at least 18. Never your exact birth date, never shown to others.
Minimal technical data: security and moderation logs.
02What we don't collect
No real name, no profile photo, no phone number, no precise location, no access to your contacts. Your real identity never enters ZAP.
03Messages
Messages are relayed in real time between participants.
They are kept for 30 days maximum, after which the sender's identifier is anonymized.
04Moderation
Every text message is automatically analyzed before being relayed.
Report contexts are masked before storage: numbers, emails and handles are replaced with placeholders.
05Data sharing
We don't sell any data. The AI partner's API key stays server-side and is never sent to the app.
Our processors (hosting, database, push notifications) are bound by contract and access data only to provide the service.
06Your rights
You can request access to, correction of, or deletion of your data.
Deleting your account anonymizes all your messages and erases your profile, friends, badges and strikes.
07Retention
Messages: 30 days. Moderation logs: 1 year maximum. Account: as long as active, then deleted on request.