Zado

Privacy Policy

Last updated: July 29, 2026

This Privacy Policy explains what personal data Zado ("we", "us", "our") collects, how we use it, and the choices you have. It applies to the Zado app and related services (the "Service").

Who we are. Zado is operated by an individual based in Türkiye and made available globally, acting as the data controller. Privacy contact: privacy@zadomessenger.com (general support: support@zadomessenger.com). We honor rights under the EU/EEA GDPR, Türkiye's KVKK, California's CCPA/CPRA, and other applicable laws. Translations are provided for convenience; if there is any conflict between a translated version and this English version, the English version prevails.

1. Data We Collect

CategoryExamples
AccountMobile phone number, display name, username, optional "about", optional profile photo.
Messages & mediaText, photos, videos, documents, voice messages and related metadata (sender, timestamps, delivery/read status), stored temporarily to deliver them (see Retention).
Calls & captionsIf you start a video call, call media is routed in real time; if you enable live captions, call audio is processed to produce translated subtitles.
LocationOnly when you choose to send a location or start live location sharing: the coordinates you send, and a lookup against Google Geocoding to turn them into a place name. Zado never tracks your location in the background.
Status updatesIf you post a Status: its content, your audience settings, and who viewed it.
Chat backupsOptional. If you start a backup, a copy of your chat history is stored on our servers so you can restore it on a new device (see Retention).
SubscriptionIf you buy a subscription: the store receipt, your subscription status and expiry date. Payment is handled entirely by Apple or Google — we never see your card details.
Device & usageDevice/app information, push notification token, presence (online/last-seen), and diagnostics/crash data. We do not run an analytics product — no behavioural analytics SDK is included in the app.

We do not sell your personal data. We do not run ads.

2. How & Why We Use Data

3. AI & Caption Processing

Several features send content to our processors so they can produce a result. This happens only while you are using the feature:

The processors involved are:

These features are optional and run only when you enable/use them. Your translation voice is entirely optional: it can only be recorded inside the app by reading the prompts aloud, is used solely to speak your translations, and can be permanently deleted at any time together with all language variants derived from it. This processing is based on your explicit consent, which you can withdraw at any time by deleting your translation voice. Call audio is processed only while translation or captions are on and is not retained after the translation is produced.

4. Who We Share Data With (Sub-processors)

We share data only with service providers that process it on our behalf to operate the Service:

ProviderPurpose
Google / FirebaseAuthentication, database, file storage, push messaging, crash reporting and performance diagnostics, Cloud Speech-to-Text (captions and Interpreter Mode), Cloud Text-to-Speech (speaking translations in Interpreter Mode), and Geocoding (turning a shared location into a place name).
OpenAIMessage translation, voice/caption processing, Interpreter Mode translation, and the Zado Assistant. We send every request with storage switched off, so OpenAI keeps no copy of the results. Your content is never used to train their models. OpenAI may keep short-lived abuse-monitoring logs for up to 30 days, accessible only to a limited number of authorised staff investigating misuse.
TwilioSending SMS one-time verification codes.
AgoraReal-time video/voice call delivery.
CartesiaSpeech synthesis for call translation; creation and storage of optional personal translation voices.
ElevenLabsSecond speech-synthesis provider (fallback for translated speech); also receives your voice recording and stores a personal translation voice when you create one.

Maps in the web version. When you open Zado in a browser and a location message is shown, your browser loads map tiles directly from OpenStreetMap's servers. Those servers therefore see your IP address and the coordinates being displayed. We do not send them anything ourselves, and this does not happen in the iOS or Android apps, which draw maps using the operating system's own map component.

We may also disclose data where required by law, to enforce our Terms, or to protect the rights, safety and security of users and the public.

5. Data Retention

DataRetention
Text messagesDeleted from our servers about 2 minutes after they are delivered.
Media (photos, videos, documents, voice)Up to 7 days after upload, then automatically deleted.
Chat backups (only if you turn them on)A backup is a stored copy of your chat history, so it is not covered by the 2-minute and 7-day rules above. We keep your 3 most recent backups and delete older ones automatically. Backups belonging to a device that has been inactive for 14 days are removed. You can delete a backup yourself at any time in the app, and all backups are deleted when you delete your account.
Location messagesStored as part of the message and deleted on the same schedule. Live location sharing stops at the time you set, or when you end it.
Status updatesDeleted automatically when they expire.
Account & profileKept while your account is active. When you delete your account, everything tied to it is erased — your profile, messages, media, chat backups, status posts, scheduled messages, subscription records, push tokens, and your personal translation voice at both Cartesia and ElevenLabs. Two things survive, deliberately and briefly: a deletion marker (your user ID and a one-way hash of your phone number — never the number itself), kept 7 days so a deleted identity cannot be silently restored; and abuse reports, which we keep to enforce our Terms and defend against misuse.
Assistant conversationsDeleted automatically 7 days after they are created.
Diagnostics & crash reportsRetained for a limited period per our providers' settings.

6. Our Security & Privacy Model

We protect your data with:

Zado does not use end-to-end encryption — and this includes chat backups, which are stored encrypted at rest on our infrastructure but are not end-to-end encrypted. To provide features you use (e.g., translation, captions), message content may be accessed by our systems and the service providers listed above. Please don't share information that requires end-to-end encryption.

7. Your Rights

Depending on where you live, you may have the right to:

You can edit your profile and delete your account in the app — see how to delete your account and data for step-by-step instructions and exactly what is removed. To exercise other rights, contact privacy@zadomessenger.com. EU/EEA users may lodge a complaint with their local Data Protection Authority; Türkiye users may apply to the KVKK Authority (KVKK Kurumu).

8. Children

Zado is not intended for anyone under 16. We do not knowingly collect data from children under 16. If you believe a child has provided us data, contact us and we will delete it.

9. International Transfers

Zado is offered globally and our providers operate worldwide, so your data may be processed in countries other than yours (including the EU and the United States). Where required, transfers rely on appropriate safeguards — such as EU Standard Contractual Clauses or an adequacy mechanism — under our data processing agreements with these providers. We are progressively putting such an agreement in place with every provider listed above.

10. Changes to This Policy

We may update this Policy from time to time. We will update the "Last updated" date and, for material changes, provide reasonable notice (e.g., in-app).

11. Contact

Privacy questions or requests: privacy@zadomessenger.com


See also our Terms of Service.