Effective August 21, 2026
Zas is a service for sending text and files with encryption on the device. This page explains what data it handles, what encryption protects, and what metadata the service needs. Questions: support@zas.red
Zas is operated by Sebastian Fernandez Quezada in Argentina. The privacy contact is the email address at the top of this page.
There are two ways to use Zas, and one exists only on the website. An anonymous session asks for no email address, name, or password. The server gives it an internal ID. The link holding its code is the only normal way back. If you lose it, Zas provides no reset or recovery. The other way uses an account: you sign in through Google or Apple with Firebase Authentication. We receive your email address, name, and profile photo to identify you and show your channels. If you use Hide My Email, we receive the forwarding address that Apple creates. The iPhone, iPad, and Android apps always use an account. They have no anonymous sessions. Zas does not keep a separate password.
Everything you send is encrypted on your device before it leaves. The database and object storage do not receive open filenames, titles, content, or previews. If you request an external-link preview, the server receives that address, as explained below. A separate key service derives the account key from a verified identity. An operator who controls that service and has account identifiers could reconstruct keys. Zas therefore does not call this design end-to-end encryption. For a public link, the key is in the fragment after #. A normal web request does not send that fragment to the server.
To resume an interrupted file, the site keeps a queue in IndexedDB. It can hold the original file and encrypted parts with their keys until the send completes or you cancel it. The apps keep the session, keys, settings, transfer queue, and files needed to finish a transfer or open an item. Analytics does not receive that content. Signing out clears account-bound app state. Clearing site or app data clears normal local storage. It does not delete a copy that you saved outside Zas or a copy retained by the operating system.
This data supports authentication, delivery, synchronization, abuse limits, and fault diagnosis. It is not a readable list of your content.
We use Google Firebase for authentication, database, hosting, and notifications; DigitalOcean Spaces for files stored as encrypted chunks; Cloudflare for the Direct relay and temporary encrypted copies; and PostHog and Google Analytics for the analytics described below. Apple and Google also process data needed to distribute the apps and deliver notifications. These providers can process data outside Argentina. When they process personal data for Zas, they must provide protection consistent with this policy and applicable law. We do not sell data or share it for advertising.
Zas is a corridor, not a warehouse. In an anonymous session each stored item lasts 2 days; with an account, 5. A temporary copy created to deliver a failed Direct transfer lasts no more than 24 hours and is deleted sooner when the receiver finishes downloading it. A session left empty deletes itself after half an hour. The one exception is you: a pinned item does not expire until you release or delete it. That is your decision, not ours. We keep an open abuse report until we review it. We delete a resolved report after 90 days.
The website uses Google Analytics and PostHog on normal routes. The iPhone, iPad, and Android apps use PostHog for selected product and reliability events. Zas can send the internal account ID, technical device or session IDs, app and system version, plan, language, total storage use, and numbers such as size, duration, and result. It does not send text, file or channel names, MIME type, profile photo, email address, name, content IDs, secret links, or full addresses. There is no autocapture, screen or session recording, advertising, or cross-app tracking. The site does not load analytics on public links, invitations, or anonymous sessions. The Apple share extension and widget do not load it either. The server sends PostHog a small set of invitation and public-link results without identifying the person who opens the link. Google Analytics uses a cookie. PostHog uses local or device storage. Write to us to also delete analytics data.
You can delete any item or channel from the app, at any time. To delete everything at once: Settings → “Delete my account”, which removes your account or your session with everything in it. An anonymous session also expires on its own.
Deletion can continue in the background after the server accepts the request. For a legacy file that the browser cannot open, the server cannot safely identify its encrypted shared chunks. It removes the item record, and unpinned chunks keep their existing expiry. A historical pinned chunk can remain because deleting it could affect another user. Providers can also retain backups and security logs for their normal retention periods.
You can also request deletion by writing to support@zas.red.
You can ask for access to your personal data, correction or updates, deletion, and withdrawal of consent when processing depends on consent. We may ask you to confirm that the account is yours. Where Argentina's Law 25,326 applies, we answer an access request within 10 calendar days and a correction, update, or deletion request within 5 business days.
If we do not answer, or the answer is insufficient, you can complain to Argentina's data protection authority, the AAIP. How to exercise your rights.
Zas is not directed at children under 13. Signing in with an account requires a Google or Apple account; an anonymous session asks for nothing, so we do not verify age — doing so would mean asking for exactly the data this policy says we do not ask for.
If this policy changes, this page and its effective date are updated.