Zas

Privacy policy

Effective August 21, 2026

Zas is a service for sending text and files with encryption on the device. This page explains what data it handles, what encryption protects, and what metadata the service needs. Questions: support@zas.red

Who operates Zas

Zas is operated by Sebastian Fernandez Quezada in Argentina. The privacy contact is the email address at the top of this page.

Your account, or none

There are two ways to use Zas, and one exists only on the website. An anonymous session asks for no email address, name, or password. The server gives it an internal ID. The link holding its code is the only normal way back. If you lose it, Zas provides no reset or recovery. The other way uses an account: you sign in through Google or Apple with Firebase Authentication. We receive your email address, name, and profile photo to identify you and show your channels. If you use Hide My Email, we receive the forwarding address that Apple creates. The iPhone, iPad, and Android apps always use an account. They have no anonymous sessions. Zas does not keep a separate password.

Your content

Everything you send is encrypted on your device before it leaves. The database and object storage do not receive open filenames, titles, content, or previews. If you request an external-link preview, the server receives that address, as explained below. A separate key service derives the account key from a verified identity. An operator who controls that service and has account identifiers could reconstruct keys. Zas therefore does not call this design end-to-end encryption. For a public link, the key is in the fragment after #. A normal web request does not send that fragment to the server.

Local data on your device

To resume an interrupted file, the site keeps a queue in IndexedDB. It can hold the original file and encrypted parts with their keys until the send completes or you cancel it. The apps keep the session, keys, settings, transfer queue, and files needed to finish a transfer or open an item. Analytics does not receive that content. Signing out clears account-bound app state. Clearing site or app data clears normal local storage. It does not delete a copy that you saved outside Zas or a copy retained by the operating system.

What the server does see

  • Your account or session, profile details received at sign-in, the channels you own or follow, their members, and the notification tokens for your devices.
  • For each item: its channel, sender account, date, size, expiry, and state. For a stored file, the server also links the account, upload session, and a random storage object ID. The object holds encrypted bytes, not the open file.
  • For each public link, how many times it was opened, copied, and downloaded. Zas analytics does not identify the person who opens it. If you ask for a preview of an external link, the server receives that address. If you report a link, we store the reason and the link and account IDs. To limit automated reports, we briefly use a protected digest of the IP address.
  • Infrastructure can process the IP address, device or browser type, and connection data in security and operating logs. The Direct relay sees network data for both ends, but not the content. The legacy file system can also recognize that an encrypted chunk repeats.

This data supports authentication, delivery, synchronization, abuse limits, and fault diagnosis. It is not a readable list of your content.

Where it is stored

We use Google Firebase for authentication, database, hosting, and notifications; DigitalOcean Spaces for files stored as encrypted chunks; Cloudflare for the Direct relay and temporary encrypted copies; and PostHog and Google Analytics for the analytics described below. Apple and Google also process data needed to distribute the apps and deliver notifications. These providers can process data outside Argentina. When they process personal data for Zas, they must provide protection consistent with this policy and applicable law. We do not sell data or share it for advertising.

Retention

Zas is a corridor, not a warehouse. In an anonymous session each stored item lasts 2 days; with an account, 5. A temporary copy created to deliver a failed Direct transfer lasts no more than 24 hours and is deleted sooner when the receiver finishes downloading it. A session left empty deletes itself after half an hour. The one exception is you: a pinned item does not expire until you release or delete it. That is your decision, not ours. We keep an open abuse report until we review it. We delete a resolved report after 90 days.

Analytics and ads

The website uses Google Analytics and PostHog on normal routes. The iPhone, iPad, and Android apps use PostHog for selected product and reliability events. Zas can send the internal account ID, technical device or session IDs, app and system version, plan, language, total storage use, and numbers such as size, duration, and result. It does not send text, file or channel names, MIME type, profile photo, email address, name, content IDs, secret links, or full addresses. There is no autocapture, screen or session recording, advertising, or cross-app tracking. The site does not load analytics on public links, invitations, or anonymous sessions. The Apple share extension and widget do not load it either. The server sends PostHog a small set of invitation and public-link results without identifying the person who opens the link. Google Analytics uses a cookie. PostHog uses local or device storage. Write to us to also delete analytics data.

Deleting your data

You can delete any item or channel from the app, at any time. To delete everything at once: Settings → “Delete my account”, which removes your account or your session with everything in it. An anonymous session also expires on its own.

Deletion can continue in the background after the server accepts the request. For a legacy file that the browser cannot open, the server cannot safely identify its encrypted shared chunks. It removes the item record, and unpinned chunks keep their existing expiry. A historical pinned chunk can remain because deleting it could affect another user. Providers can also retain backups and security logs for their normal retention periods.

You can also request deletion by writing to support@zas.red.

Your data rights

You can ask for access to your personal data, correction or updates, deletion, and withdrawal of consent when processing depends on consent. We may ask you to confirm that the account is yours. Where Argentina's Law 25,326 applies, we answer an access request within 10 calendar days and a correction, update, or deletion request within 5 business days.

If we do not answer, or the answer is insufficient, you can complain to Argentina's data protection authority, the AAIP. How to exercise your rights.

Children

Zas is not directed at children under 13. Signing in with an account requires a Google or Apple account; an anonymous session asks for nothing, so we do not verify age — doing so would mean asking for exactly the data this policy says we do not ask for.

Changes

If this policy changes, this page and its effective date are updated.

Back to Zas