Zara Privacy Policy
1. Introduction and About This Policy
This Privacy Policy explains how Zara ("Zara", "Zara AI", "we", "us" or "our") collects, uses, shares, stores and protects your personal information when you use the Zara personal AI assistant. Zara is a WhatsApp-native personal AI assistant for South Africa that you can reach over WhatsApp on the number +27 83 200 2127 and through our web application at https://zaraai.digital.
Zara is operated by MOOVE DIGITAL (PTY) LTD, a private company registered in South Africa with the Companies and Intellectual Property Commission (CIPC), trading as "Zara AI". MOOVE DIGITAL (PTY) LTD is the "responsible party" under the Protection of Personal Information Act, 2013 (POPIA) and the "data controller" under the EU General Data Protection Regulation (GDPR) for the personal information described in this Policy.
We have written this Policy to be thorough and plainly worded so that you, and where relevant a regulator, can understand exactly what happens to your information. Because Zara does not only answer questions but takes real actions on your behalf, this Policy pays particular attention to what happens to your data when Zara makes phone calls, sends messages, manages your connected accounts and builds a long-term memory of your life. Please read it carefully alongside our Terms of Service and our Cookie Policy.
If there is anything in this Policy you do not understand, or you would like a copy in another format, please contact us at privacy@zaraai.digital before you continue using the service.
- Service: Zara AI, a WhatsApp-native and web-based personal AI assistant.
- Responsible party / data controller: MOOVE DIGITAL (PTY) LTD, trading as Zara AI.
- Company registration number: 2024/675781/07.
- Registered office: [Registered address — to be inserted].
- WhatsApp: +27 83 200 2127 | Web: https://zaraai.digital
- Privacy contact: privacy@zaraai.digital
2. Scope of This Policy
This Policy applies to all personal information we process when you create a Zara account, link your WhatsApp number, connect third-party services, chat with Zara by text or voice, use the web app, or allow Zara to take actions on your behalf. It applies whether you interact with Zara over WhatsApp or through the web application.
This Policy does not cover the privacy practices of third parties whose services you connect to Zara (for example Google, Meta/WhatsApp, Spotify or LinkedIn) or businesses that Zara contacts on your behalf. When Zara acts through one of those services, that third party processes your information under its own privacy policy as well. We encourage you to review the privacy policies of any service you connect.
Where we refer to "personal information" we mean personal information as defined in POPIA and personal data as defined in the GDPR — broadly, any information relating to an identifiable living person (and, under POPIA, an identifiable existing legal entity).
- Covers: your Zara account, WhatsApp interactions, web app use, connected services and actions taken on your behalf.
- Does not cover: the independent privacy practices of third-party services you connect, or businesses Zara contacts for you.
- "Personal information" is used in the broad sense given by POPIA and the GDPR.
3. Summary — The Short Version
This summary is a quick overview only and does not replace the full Policy below. The detailed sections govern in the event of any difference.
- What Zara is: a personal assistant that not only answers you but takes real actions — placing outbound phone calls to businesses, making bookings, drafting and sending WhatsApp messages, and managing your connected Google and other accounts, always behind a confirmation/approval gate (for example replying "YES" or "SEND IT").
- What we collect: your account details, WhatsApp number and linked message content, the suburb/city you enter, your preferences, what Zara learns about your life (your "digital twin"), data from services you connect via OAuth, your chats and voice transcripts, and usage logs.
- Why we use it: to run the assistant, carry out the actions you authorise, personalise and remember context, send you proactive nudges and briefings, keep the service secure, and meet our legal obligations.
- AI processing: to generate replies and decide on actions, relevant parts of your messages and context may be sent to AI providers (Anthropic/Claude, OpenAI and Google Gemini).
- Where it lives: our servers are hosted in the European Union (Hetzner Cloud, Germany); some processing involves providers in other countries.
- Your control: you can access, correct, export (digital-twin JSON) and delete your data, opt out of nudges, lock digital-twin categories, disconnect any service, and delete your account at any time.
- Contact: privacy@zaraai.digital for any privacy question or request.
4. The Personal Information We Collect
We collect the categories of personal information set out below. We only collect what we need to provide and improve the assistant and to carry out the actions you ask of it. The exact information collected depends on which features you use and which services you connect.
- Account information: your name, email address, your password (which we never store in readable form — it is kept only as a salted PBKDF2-SHA256 hash), and your preferred language.
- WhatsApp information: your mobile number, the one-time SMS/WhatsApp verification codes used to confirm it is you, and the content of messages from the WhatsApp chats you link to Zara.
- Location information: the suburb and city you enter during onboarding. This is text you type — Zara does not perform GPS or background location tracking.
- Preferences and interests: preference settings and interest tags you give us or that you allow Zara to infer, so it can tailor results to you.
- Digital-twin learnings: the longer-term context Zara builds about you, only within the categories you allow — for example routines, goals, relationships, career, and health — together with timeline events and channel metadata. This is your persistent "digital twin" or life graph.
- Connected-service data (via OAuth consent): depending on what you connect, this can include Gmail threads, Google Calendar events, Google Drive files, Google Contacts, YouTube data, and Google Tasks; your LinkedIn profile and posts; your Spotify activity; and Meta Page insights.
- Voice and chat content: your text messages to Zara, transcripts of your voice messages, and — only if you use it in the web app — optional screen-share frames you choose to share.
- Usage and technical information: authentication events (sign-ins), connector sync logs, and records of proactive nudge delivery, used to operate, secure and troubleshoot the service.
5. Sensitive Information and a Note on Categories You Control
Some of the information Zara can hold may be sensitive — for example health-related learnings in your digital twin, or personal details revealed in your messages and connected accounts. Under POPIA, certain information (such as health and religious or political beliefs) is "special personal information", and under the GDPR it is a "special category" of data that attracts extra protection.
Zara only records digital-twin learnings in a given category (such as health) where you have allowed that category. You can lock any category at any time, which stops further learning in it, and you can delete what has already been learned. Because you control which categories are active, you control whether and how this more sensitive information is collected.
Please be thoughtful about the information you choose to share with Zara or expose through connected accounts. Avoid sharing other people's sensitive information, or information you are not comfortable being processed as described in this Policy.
- Health and similarly sensitive learnings are only collected if you allow that digital-twin category.
- You can lock a category to stop further learning and delete what was learned.
- Sensitive details may also appear in your messages or connected accounts — share with care.
6. How We Collect Your Information
We collect information in three main ways: directly from you, automatically as you use the service, and from third-party services you choose to connect.
Most information comes directly from you — when you register, verify your WhatsApp number, type your suburb and city, set preferences, chat with Zara by text or voice, or approve an action. Some information is generated automatically as you use Zara, such as authentication events, sync logs and nudge delivery records, and the learnings Zara forms from your interactions. Other information reaches us from services you connect through OAuth consent, where the provider (such as Google, Meta, Spotify or LinkedIn) shares data with Zara according to the permissions you grant.
- Directly from you: registration details, verification codes, your suburb/city, preferences, chats, voice messages, optional screen-share, and action approvals.
- Automatically: authentication events, connector sync logs, nudge delivery records, and digital-twin learnings inferred from your use.
- From connected services: data shared by Google, Meta/WhatsApp, Spotify, LinkedIn and others under the OAuth permissions you grant — only after you consent.
7. How and Why We Use Your Information
We use your personal information to provide the Zara assistant, to carry out the actions you authorise, to personalise the experience, to keep the service safe, and to meet our legal duties. The specific purposes are set out below.
A defining feature of Zara is that it acts on your behalf. To do this responsibly, Zara routes actions through confirmation/approval gates — for example asking you to reply "YES" or "SEND IT" before it places a call or sends a message. We use your information to prepare, present and execute those actions once you approve them.
- Operate the assistant: understand your requests, generate replies, and run the WhatsApp and web experiences.
- Take authorised actions: place outbound phone calls to businesses, make bookings and appointments, and draft and send WhatsApp messages — after your confirmation.
- Manage connected services: read and act within your Google services (Gmail, Calendar, Drive, Contacts, YouTube, Tasks) and other connected accounts as you direct.
- Personalise and remember: build and maintain your digital twin so Zara understands your context, routines and goals over time.
- Be proactive: run automations, send daily briefings, and deliver proactive nudges based on your preferences (which you can switch off).
- Compare and research: compare prices and deals and run web research to answer your questions and complete tasks.
- Secure the service: authenticate you, detect and prevent fraud and abuse, and keep accounts isolated.
- Support and improve: respond to your support requests and diagnose and fix problems.
- Comply with law: meet obligations under POPIA, ECTA, RICA where relevant, the Consumer Protection Act, and other applicable laws.
8. Our Legal Bases for Processing (POPIA and GDPR)
We only process your personal information where the law allows. Under POPIA, processing must meet a lawful justification (such as consent, performance of a contract, compliance with a legal obligation, or our legitimate interests properly balanced against your rights). Under the GDPR, we rely on a corresponding lawful basis for each purpose. The main bases we rely on are set out below.
Where we rely on your consent — for example to link WhatsApp chats, to connect a third-party account via OAuth, or to enable a sensitive digital-twin category — you may withdraw that consent at any time, and we explain how in the section on your rights. Withdrawing consent does not affect processing that already happened, and may mean a feature can no longer work.
- Consent: linking WhatsApp chats, connecting OAuth services, enabling specific (including sensitive) digital-twin categories, and sending optional proactive nudges.
- Performance of a contract: creating and running your account, processing your requests, and carrying out the actions you authorise — so we can deliver the service you signed up for.
- Legitimate interests (balanced against your rights): keeping the service secure, preventing fraud and abuse, maintaining authentication logs, and improving and troubleshooting the assistant.
- Legal obligation: retaining certain records and responding to lawful requests under POPIA, ECTA, RICA and other applicable laws.
- You can withdraw consent at any time; some features depend on it and will stop working if you do.
9. How Zara Uses AI — and What That Means for Your Data
Zara is powered by artificial intelligence. To understand your messages, generate replies, build your digital twin and decide how to carry out a task, relevant parts of your input and context are sent to AI providers that run large language models. These providers are Anthropic (Claude), OpenAI and Google Gemini. This means the content of your prompts, and surrounding context Zara assembles to do the job well, may be transmitted to and processed by these providers to generate a response.
The context sent to an AI provider can include the substance of your request, relevant digital-twin learnings, and information drawn from your messages or connected services where that is needed to complete the task. We aim to send only what is needed for the task at hand. We use these providers as our processors / sub-processors and rely on our agreements with them to govern how they may handle your data.
AI can make mistakes. Zara's responses and suggested actions may be inaccurate, incomplete or out of date, and Zara is not a substitute for professional legal, medical or financial advice. You remain responsible for any action you confirm and authorise Zara to take. Please review important outputs and confirmations before approving them.
- AI providers used for inference: Anthropic (Claude), OpenAI, and Google Gemini.
- What may be sent: your prompt content plus relevant context (which can include digital-twin learnings and connected-service data needed for the task).
- These providers act as our processors / sub-processors under contract.
- AI can be wrong and is not professional advice — review outputs and you remain responsible for actions you authorise.
10. When Zara Acts on Your Behalf — Calls and Messages
Zara is built to take real actions in the real world. When you ask it to, and after you confirm, Zara can place outbound phone calls to businesses, make bookings and appointments, draft and send WhatsApp messages, and act within your connected accounts. These actions involve processing and sometimes disclosing your information so the action can be completed.
To place a phone call or send an SMS within South Africa, Zara uses Africa's Talking. To synthesise the voice used on a call, Zara uses ElevenLabs, and for a photorealistic avatar in the web app it can use Simli. To deliver WhatsApp messages, Zara uses the Meta / WhatsApp Cloud API. To carry out an action, Zara may share the details needed for that specific task — for example your name, your booking details, the relevant phone number, or the content of a message you approved.
Actions pass through confirmation/approval gates. Zara will typically tell you what it intends to do and wait for you to reply (for example "YES" or "SEND IT") before acting. You should review what Zara proposes, because once you confirm, Zara will act, and the receiving business or contact will see the information necessary to complete the request. Calls and messages Zara makes for you may be received, recorded or logged by the other party under their own practices and applicable law.
- Outbound calls and SMS in South Africa: routed through Africa's Talking.
- Voice synthesis: ElevenLabs; photorealistic avatar in the web app: Simli.
- WhatsApp message delivery: Meta / WhatsApp Cloud API.
- Data shared for an action is limited to what that task needs (e.g. your name, booking details, the number to call, the message content you approved).
- Confirmation gates: Zara waits for your approval (e.g. "YES"/"SEND IT") before acting — review proposals carefully.
- The business or contact on the other side processes the interaction under their own policies and the law.
11. Sharing Your Information and Our Sub-Processors
We do not sell your personal information. We share it only as needed to run the service, carry out the actions you authorise, comply with the law, or protect rights and safety. The third parties below act as our operators (under POPIA) / processors and sub-processors (under the GDPR), processing your information on our instructions under contract.
Beyond the processors listed, we may disclose information to a connected service when you direct Zara to act there (for example sending an email through Gmail), to a business or contact when Zara completes an action for you, to professional advisers, to authorities or other parties where required by law or legal process, and to a successor entity in connection with a merger, acquisition or reorganisation (subject to this Policy).
- AI inference (prompt context may be processed): Anthropic (Claude), OpenAI, Google Gemini.
- Messaging delivery: Meta / WhatsApp Cloud API.
- Connected Google services: Google APIs (Gmail, Calendar, Drive, Contacts, YouTube, Tasks).
- Other connected platforms: Spotify; LinkedIn.
- Outbound voice calls and SMS in South Africa: Africa's Talking.
- Voice synthesis: ElevenLabs. Photorealistic avatar: Simli.
- Web research: Tavily.
- Also disclosed where you direct an action, to complete a task with a business/contact, to advisers, to authorities as legally required, and to a successor in a corporate transaction.
- We do not sell your personal information.
12. International Data Transfers
Our servers are hosted in the European Union (Hetzner Cloud, in Germany), so your account and stored data are primarily held in the EU. Because the EU benefits from strong data-protection law, this also supports protection for South African users' information.
Some of the processors we use to run the assistant operate, or process data, in other countries — for example AI providers and certain platform and communications providers. As a result, transmitting your information to deliver the service may involve a transfer of personal information across borders, including outside South Africa and outside the EU/EEA.
When we transfer personal information internationally, we take steps to ensure it remains protected. Under POPIA, we rely on lawful grounds for trans-border information flows, such as your consent, the necessity of the transfer to perform our contract with you, or contractual safeguards requiring an adequate level of protection. Under the GDPR, where we transfer data outside the EU/EEA we rely on an appropriate transfer mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with any additional measures needed.
- Primary hosting: European Union (Hetzner Cloud, Germany).
- Some processors (e.g. AI, messaging and communications providers) may process data in other countries.
- POPIA basis for cross-border flows: consent, contract necessity, or contractual safeguards ensuring adequate protection.
- GDPR basis for transfers outside the EU/EEA: adequacy decision or Standard Contractual Clauses, plus additional measures where needed.
- Whether a formal EU representative is appointed: [EU representative — to be inserted].
13. How Long We Keep Your Information
We keep personal information only as long as we need it for the purposes described in this Policy, or as required by law. In general, we keep your information for as long as your account is active, and you can delete most of it yourself at any time. The specific retention periods are set out below.
When you delete data, lock a digital-twin category, disconnect a service, or delete your account, we act on that request. For operational and security reasons, some information persists for a limited period after deletion, as described below, before it is fully removed.
- Account data: kept while your account is active.
- Chat and digital-twin learnings: kept until you delete them, lock the relevant categories, disconnect the related services, or delete your account.
- WhatsApp and Gmail import archives: kept until you delete them.
- Authentication logs: kept for up to 24 months, to support security and fraud prevention.
- Encrypted backups: may persist for up to 30 days after deletion, after which they are removed.
14. How We Protect Your Information
We take the security of your information seriously and apply technical and organisational measures designed to protect it against loss, misuse and unauthorised access. No system can be guaranteed completely secure, but the measures below are central to how we protect your data.
If a security compromise affecting your personal information occurs, we will respond in line with our legal obligations, which under POPIA can include notifying the Information Regulator and affected users where required.
- Encryption in transit: all traffic is protected with HTTPS/TLS.
- Password protection: passwords are hashed using PBKDF2-SHA256 with a salt and are never stored in readable form.
- API authentication: access is protected with bearer-token authentication.
- OAuth tokens: stored server-side and revoked when you disconnect a service.
- Tenant isolation: each user's data is isolated per-user within a multi-tenant database.
- Privacy locks: category-level locks let you control digital-twin learning.
- Breach response: we follow applicable notification obligations, including under POPIA, where required.
15. Your Privacy Rights and How to Exercise Them
You have rights over your personal information under POPIA and, where it applies, the GDPR. We have built controls into Zara so you can exercise many of these rights directly, and you can always contact us for help. We will respond to verified requests within the timeframes required by applicable law and will not charge a fee except where the law allows (for example for excessive or repetitive requests — [any fee — to be inserted]).
To make a request, or if you are unhappy with how we handle your information, email privacy@zaraai.digital. We may need to verify your identity before acting. If you are an EU/EEA data subject, additional GDPR rights apply as noted below.
- Access: ask what personal information we hold about you and how we use it.
- Correction: ask us to correct information that is inaccurate, out of date or incomplete.
- Deletion: delete your data — including chats and digital-twin learnings — or delete your whole account.
- Objection / restriction: opt out of proactive nudges and lock digital-twin categories to stop further learning; under the GDPR, object to or restrict certain processing.
- Data portability: export your digital twin as a JSON file.
- Withdraw consent: disconnect any OAuth-connected service (which revokes its tokens) or delete your account.
- Lodge a complaint: with the Information Regulator (South Africa), and, for EU/EEA data subjects, with your local supervisory authority.
16. The Digital Twin, Profiling and Automated Decisions
Zara builds a persistent "digital twin" — a life graph that remembers context about you over time, such as your routines, goals, relationships, career and (where you allow it) health, along with timeline events and channel metadata. This profiling lets Zara personalise its help, anticipate your needs, and act more usefully on your behalf.
Zara also uses automated processing to decide what to suggest, which proactive nudges to send, and how to prepare an action. Importantly, actions that affect the outside world — such as calls, bookings and messages — are placed behind confirmation/approval gates, so a human (you) approves them before they happen. This keeps you in control of consequential decisions.
You have meaningful control over profiling. You can lock any digital-twin category to stop further learning in it, delete learnings already held, opt out of proactive nudges, export your twin, and disconnect services or delete your account. Where the GDPR applies, you have rights in relation to decisions based solely on automated processing that produce legal or similarly significant effects, including the right to obtain human intervention — and Zara's confirmation gates are designed to keep a human in the loop for such actions.
- Profiling: the digital twin learns routines, goals, relationships, career and (if allowed) health, plus timeline events and channel metadata.
- Automated processing drives suggestions and nudges, but real-world actions require your confirmation.
- Your controls: lock categories, delete learnings, opt out of nudges, export your twin, disconnect services, or delete your account.
- GDPR: confirmation gates keep a human in the loop; you can request human intervention for significant automated decisions.
17. How to Delete Your Account and Data
You can delete your information in stages or all at once. To remove specific content, delete individual chats and digital-twin learnings, or lock categories to stop further learning. To stop a connected service from sharing data, disconnect it — this revokes the stored OAuth tokens. To remove everything, delete your account.
When you delete your account, we remove your personal information from active systems, subject to the limited retention described in this Policy: encrypted backups may persist for up to 30 days before removal, and authentication logs may be retained for up to 24 months for security and fraud-prevention purposes. If you need help, contact privacy@zaraai.digital.
- Delete chats and learnings, or lock categories, to remove or stop specific content.
- Disconnect a service to revoke its OAuth tokens and stop data sharing.
- Delete your account to remove your information from active systems.
- After deletion: encrypted backups may persist up to 30 days; authentication logs up to 24 months for security.
- Need help? Email privacy@zaraai.digital.
18. Children's Privacy
Zara is intended for adults and is not directed at children. We do not knowingly collect personal information from children without the consent of a competent person (such as a parent or guardian) where the law requires it. Under POPIA, the personal information of children is treated as a special category requiring additional protection.
If you are a parent or guardian and believe a child has provided us with personal information without appropriate consent, please contact us at privacy@zaraai.digital and we will take appropriate steps to delete it.
Minimum age to use Zara: 18 years.
- Zara is intended for adults and is not directed at children.
- We do not knowingly collect children's information without the required consent of a competent person.
- Contact privacy@zaraai.digital if a child has shared information without proper consent.
- Minimum age: 18 years.
19. Cookies and Similar Technologies
Our web app at https://zaraai.digital uses cookies and similar technologies to keep you signed in, remember your preferences, keep the service secure, and help us understand how it is used. Some of these are necessary for the app to work, while others are optional.
For full details of the cookies and similar technologies we use, their purposes and durations, and how to manage your choices, please see our separate Cookie Policy. You can also control cookies through your browser settings.
- We use cookies and similar technologies in the web app for sign-in, preferences, security and analytics.
- Necessary cookies keep the service working; other cookies are optional.
- See our separate Cookie Policy for full details and your choices.
- You can also manage cookies through your browser settings.
20. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our service, the third parties we use, or the law. When we make changes, we will update the date below and, where the changes are significant, we will take reasonable steps to let you know — for example by a notice in the app or a message over WhatsApp.
Your continued use of Zara after an updated Policy takes effect means you accept the updated Policy, so we encourage you to review it periodically.
- We may update this Policy as our service, providers or the law change.
- We will revise the effective date and give notice of significant changes.
- Continued use after an update means you accept the updated Policy.
- Effective date / last updated: 26 June 2026.
21. Contact Us and the Information Officer
If you have any questions about this Policy, want to exercise your rights, or wish to make a complaint about how we handle your personal information, please contact us. We will do our best to resolve any concern directly.
MOOVE DIGITAL (PTY) LTD has designated an Information Officer responsible for compliance with POPIA, as required by the Act. Privacy and data requests should be sent to privacy@zaraai.digital, and you can reach general support at support@zaraai.digital and partnership enquiries at partnerships@zaraai.digital.
If you are not satisfied with our response, you have the right to lodge a complaint with the Information Regulator (South Africa). EU/EEA data subjects may also complain to their local data-protection supervisory authority.
- Responsible party / controller: MOOVE DIGITAL (PTY) LTD, trading as Zara AI.
- Privacy and data requests: privacy@zaraai.digital
- General support: support@zaraai.digital | Partnerships: partnerships@zaraai.digital
- Information Officer: Malcolm Govender (Director, MOOVE DIGITAL (PTY) LTD) — privacy@zaraai.digital.
- Registered address: [Registered address — to be inserted].
- Regulator: the Information Regulator (South Africa); EU/EEA users may also contact their local supervisory authority.
Questions about this policy? Email privacy@zaraai.digital — we respond within 2 business days.