Ziora Privacy Policy

Last Updated: June 6, 2026

This Privacy Policy explains how we collect, use, store, and share information in connection with the Ziora mobile application, related websites, and related services (collectively, the "Service").

1. Scope

This Policy applies to information processed in connection with the Service. By using the Service, you acknowledge the practices described here.

2. Information We Collect

2.1 Account and Authentication Information

  • an anonymous account identifier created automatically when you first use the app;
  • your Firebase authentication identifier;
  • if you link your account, information provided by Google Sign-In or Sign in with Apple, such as your email address, name, and provider-specific identifiers; and
  • anti-abuse account metadata, such as a device-linked identifier used to help detect ban evasion or account abuse.

2.2 Photos and Related Metadata

  • the image you upload;
  • the storage path for that image and generated thumbnails;
  • country, region, city, neighborhood, latitude, longitude, or other place data associated with the post;
  • posting and expiration timestamps;
  • language, like counts, and impression counts associated with the post; and
  • safety and moderation metadata, such as automated screening scores, moderation status, and moderation logs.

2.3 Activity and Settings Information

  • likes, blocks, reports, and notification preferences;
  • notification timing preferences and language preference;
  • support inquiries, export requests, and deletion requests; and
  • account creation and last-active timestamps.

2.4 Device, App, and Diagnostic Information

  • Firebase Cloud Messaging token(s) used for push notifications;
  • app version and operating system version included with support inquiries;
  • crash logs, diagnostics, and non-fatal error information;
  • App Check or similar security tokens used to protect backend resources; and
  • advertising-related permissions or status, including App Tracking Transparency where applicable.

2.5 Information Stored Locally on Your Device

  • lists of photos you have already seen to reduce duplicates;
  • liked-photo records and locally cached image files or thumbnails;
  • language and notification preferences;
  • cached place-name data; and
  • temporary tokens awaiting sync after sign-in.

3. How We Use Information

  • provide, operate, and maintain the Service;
  • authenticate users and manage accounts;
  • store, display, and expire posted photos;
  • attach, translate, and display place labels;
  • deliver notifications about new photos, likes, and reminders;
  • respond to support requests;
  • perform moderation, safety review, abuse prevention, and fraud detection;
  • process subscription status;
  • improve reliability, investigate issues, comply with law, and enforce our Terms.

4. How Information Is Shared

4.1 Shared with Other Users

  • Posted photos, place labels, and some engagement information may be visible to other users.
  • Your internal account identifier is generally not shown as a profile identity in the normal app experience, but content you choose to post may still identify you.

4.2 Shared with Service Providers

We use the following third-party services.

ServiceProviderPurpose
Firebase AuthenticationGoogle LLCAuthentication
Cloud FirestoreGoogle LLCApplication database
Firebase Cloud StorageGoogle LLCPhoto and asset storage
Firebase Cloud MessagingGoogle LLCPush notifications
Cloud Functions for FirebaseGoogle LLCBackend processing and moderation
Firebase CrashlyticsGoogle LLCCrash and diagnostics reporting
Google Analytics for FirebaseGoogle LLCUsage analytics and performance measurement
Firebase Remote ConfigGoogle LLCFeature and regional configuration
Firebase App CheckGoogle LLCAbuse prevention and backend protection
Google Cloud Translation APIGoogle LLCPlace-name translation
Google Cloud Vision APIGoogle LLCAutomated content safety screening
Google AdMobGoogle LLCAdvertising and ad mediation
Meta Audience NetworkMeta Platforms, Inc.Advertising delivered through AdMob mediation
Sign in with AppleApple Inc.Authentication
App Store / StoreKitApple Inc.Subscription and purchase processing

4.3 Shared for Support, Moderation, and Legal Reasons

Support inquiries may be stored in our backend and forwarded to our support mailbox. Reports may include report details, internal identifiers, and moderation links in our safety workflows. We may also disclose information where reasonably necessary to comply with law, enforce our Terms, or protect users, us, or others.

5. Advertising and Tracking

Unless you have an active ad-free subscription, the Service may display advertisements through Google AdMob. AdMob uses mediation to fill ad inventory, which may include third-party advertising networks such as Meta Audience Network (Meta Platforms, Inc.). These advertising partners may process device and usage information, including advertising identifiers, under their own privacy policies.

On Apple platforms, we request permission through App Tracking Transparency (ATT) before tracking is enabled for advertising. Whether you see personalized or non-personalized advertising depends on your ATT choice and, where applicable, other consent signals: if you do not allow tracking, advertising is intended to be limited to non-personalized advertising where supported by our partners. You can change advertising and tracking permissions at any time through your device settings.

6. Data Retention

  • Posted photos and generated assets: intended to expire automatically about 7 days after upload, unless removed sooner or retained longer for safety, investigation, legal, or operational reasons.
  • Account profile and settings data: generally retained until account deletion, unless we need to keep certain data longer for fraud prevention, dispute handling, or legal compliance.
  • Support inquiries: retained for support and operational follow-up.
  • Reports and moderation records: retained as needed to review abuse and maintain safety, and some records may be anonymized rather than fully deleted.
  • Anti-abuse device identifiers: a device-linked identifier associated with banned or abusive devices may be retained, including after account deletion, in order to enforce bans and prevent ban evasion.
  • Crash and diagnostics information: retained according to service provider retention practices.
  • Local device data: retained on your device until you delete it, clear app data, or remove the app.

7. Account Deletion and Data Export

7.1 Account Deletion

If you use the in-app account deletion flow, we currently attempt to delete or remove:

  • your authentication record;
  • your user document and saved notification settings;
  • photos you uploaded and associated stored image assets;
  • likes you created;
  • notification records, blocked-user records, and reports you created; and
  • support inquiries associated with your user ID.

Some data may be retained or transformed instead of fully deleted, such as moderation logs kept in anonymized form for safety audit purposes, or crash, operational, security, and fraud-prevention records that must be retained. In particular, if your device has been associated with a ban, a device-linked identifier may be retained even after account deletion to enforce the ban and prevent ban evasion. Reports submitted by other users about your content may also be retained for safety purposes. For non-anonymous accounts, recent re-authentication may be required before deletion.

7.2 Data Export

Where available, you may request an export of certain account data through the app. Exported data may include settings, uploaded-photo metadata, likes you gave, blocked users, reports, and support inquiry history.

8. Your Choices

  • choose whether to link your account with Google or Apple;
  • revoke location permission through device settings;
  • disable or adjust push notifications through the app or device settings;
  • manage ad tracking permissions through device settings;
  • delete local app data by removing the app or clearing device data where supported; and
  • contact us about access, correction, deletion, or other privacy-related requests.

9. International Transfers

Your information may be processed in countries other than your own, including where our service providers operate infrastructure. Those countries may have different data protection laws than your place of residence.

10. Regional Privacy Disclosures

10.1 European Economic Area, United Kingdom, and Switzerland

If you are located in the EEA, the UK, or Switzerland, the controller of your personal data is Ziora, which you can reach at ziora.app.contact@gmail.com. We process personal data on the following legal bases:

  • Performance of a contract — to create and operate your account and provide the core features of the Service;
  • Legitimate interests — to keep the Service secure, prevent abuse and fraud, perform content moderation, and improve reliability, in a way balanced against your rights;
  • Consent — for personalized advertising and tracking where required, which you can withdraw at any time through your device settings; and
  • Legal obligation — where we must process data to comply with applicable law.

Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, the right to data portability, and the right to withdraw consent. You also have the right to lodge a complaint with your local data protection supervisory authority. To exercise these rights, contact us at ziora.app.contact@gmail.com. Where your data is transferred outside your region, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, where required.

10.2 California

If you are a California resident, you have rights under the California Consumer Privacy Act, as amended ("CCPA/CPRA"). In the preceding 12 months, we may have collected the following categories of personal information: identifiers (such as account and device identifiers), commercial information (such as subscription status), internet or network activity (such as app usage and interactions), geolocation data, photos and their metadata that you choose to upload, and inferences drawn for advertising. We collect this information for the business and commercial purposes described in this Policy.

We do not sell your personal information for money. However, our use of advertising partners may involve "sharing" of identifiers for cross-context behavioral advertising as defined under California law. You can opt out of such sharing by declining tracking through App Tracking Transparency or your device settings. California residents have the right to know, access, correct, and delete personal information, the right to opt out of sale or sharing, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising these rights. To exercise these rights, contact us at ziora.app.contact@gmail.com.

11. Children's Privacy

The Service is not directed to children under 13, or the minimum age required in the relevant jurisdiction. If you believe a child has provided personal information to us, contact us so we can review and take appropriate action.

12. Security

We use administrative, technical, and organizational measures designed to protect information, including secure transport, access controls, backend security tooling, abuse prevention systems, and authentication controls. No method of transmission or storage is completely secure.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we may notify you by updating the in-app legal pages or by other reasonable means. The updated version becomes effective when posted unless otherwise stated.

14. Contact

If you have privacy questions or requests, contact us at:

ziora.app.contact@gmail.com