Data that stays on your device
Zenmo processes launchable apps, selected limits, foreground-app events and usage totals, website rules and local DNS matches, gate attempts, passes, budgets, schedules, progress, and settings locally.
Your complete installed-app inventory, raw activity history, browsing history, messages, keystrokes, screenshots, contacts, precise location, and the contents of other apps are not uploaded to Zenmo. A selected app name and summary can leave the device only when you explicitly enable that Circle category for a specific supervisor.
Account and avatar data
Current connected builds use Zenmo's Cloudflare-hosted service for accounts. It can process an email and password verifier or an Apple/Google identity token; a Zenmo account ID, public handle and share code; session and security records; and the emoji or profile image you choose. Avatar images are validated by the Worker and stored in a private Cloudflare R2 bucket, then served through a versioned public profile URL.
Optional Circle data
Payment-free Circle is available to signed-in adults. It stores public handles and avatars, Karma, supervisor relationships, commitments, personal-consequence status, confirmations, check-ins, and only the aggregate progress categories you choose to share.
Karma has no cash value and cannot be purchased, transferred, redeemed, or paid out. Real-money commitments, deposits, stakes, payouts, and payment processing are disabled in the current release.
Learning integrations
If you connect the verified WaniKani beta, its personal API token remains in Android Keystore-backed storage or iOS Keychain. Zenmo contacts only WaniKani's official API, records a local baseline and high-water mark, and applies a 15-minute daily earning cap. User-defined endpoints are cosmetic and cannot grant unlock minutes.
Optional analytics
Pseudonymous product analytics are off by default. If you opt in, Zenmo sends defined interaction events to PostHog to improve reliability and usability. Automatic screen capture, session replay, deep-link capture, and lifecycle autocapture are disabled. Turning analytics off stops sending and clears the pending local outbox. Zenmo does not sell personal data.
Permissions and platform controls
- Android Usage Access identifies when a selected app is in the foreground.
- Android display over other apps shows the exercise gate you chose.
- Notifications and foreground services keep protection status and recovery actions visible.
- Android package visibility fills the on-device picker with launchable apps.
- Android local VPN optionally matches only the website rules you enter; allowed DNS requests use encrypted DNS-over-TLS.
- iOS Family Controls, Device Activity, and Managed Settings let Apple's Screen Time system select apps, monitor schedules, and show shields.
Permissions can be revoked in system settings. Protection becomes limited when critical access is off, while saved configuration remains on the device.
Retention, security, and processors
Local data remains until you remove it, clear app data, or uninstall Zenmo. Account data remains while the account exists and is deleted with the account, except for narrowly required security or legal records. Network traffic uses HTTPS; Android DNS forwarding uses certificate-verified DNS-over-TLS without plaintext fallback.
Cloudflare provides Workers, D1, R2, and DNS infrastructure; Google or Apple verifies federated sign-in; PostHog processes optional analytics after opt-in; and WaniKani processes requests only when you connect that integration.
Delete your account and data
Open Settings → Account & profile → Delete account and confirm. Zenmo revokes sessions and deletes the backend account, profile, avatar reference, Circle relationships, and dependent server records, then clears the local sign-in session.
Account deletion does not erase on-device budgets, schedules, usage history, or settings. Clear app data or uninstall Zenmo to remove those local records. Uninstalling alone does not delete a server account.
Zenmo is intended for adults 18 and over and is not enrolled in Google Play's Families program.
Changes
Material changes update the effective date and, when required, trigger a renewed in-app disclosure. The public policy, store privacy forms, and final release configuration are reviewed together for every release.