Privacy policy
In force since 3 October 2026
Who handles your data
The data controller is ZapLive Limited. For any request: [email protected].
What data we collect
- Account: email address, username, display name, and whatever you add to your profile (bio, pronouns, link, photo).
- Date of birth and country: we ask for your date of birth when you sign up, and after you log in if you already had an account; when you sign up we also store the country you're connecting from, worked out from the connection, because the minimum age varies from country to country. We don't show them to anyone and we don't give them to Google: we use them to check the minimum age, to apply the rules for anyone under 18 and to choose which ads to show you.
- Content: the videos and photos you post, the thumbnails and audio your phone extracts from them, the captions, the labels and the comments. We store direct messages only end-to-end encrypted: we can't read them.
- Interactions: likes, saves, follows, views and shares.
- App usage: for each video you watch, for how long, whether you finish it, rewatch it or skip it, along with the app version. This data is linked to your account, and we use it to choose the videos in For You.
- Country of posts: for each post we store the country it was published from, worked out from the connection, for the sound charts by country. It isn't shown on the post.
- Devices: for each device you sign in on, an identifier created by the app, the public keys for end-to-end encryption, the operating system (iOS or Android) and the last time you used it; if you turn on notifications, also the code Apple or Google use to deliver them, the language to write them in and the phone's time zone, which we use to avoid sending notifications at night to anyone under 18.
- Reports and appeals: what you send us when you report something or appeal a decision («Moderation and reports» section).
We don't collect your precise location and we don't read your contacts. For advertising, Google collects some data from the app: you'll find it in the «Advertising» section.
Why we process them
To let you use the app (performance of the contract), to keep the platform safe and moderate abuse (legal obligation and legitimate interest), to check the minimum age and protect minors (legal obligation and legitimate interest), to order the feed sensibly (legitimate interest), and to show ads (legitimate interest, and your consent where the law requires it).
Where they're kept
On Supabase, in a European Union data centre (Ireland, eu-west-1). We never see passwords: the authentication system keeps them encrypted. Videos, photos, sounds and profile pictures open only in the app, after you log in: someone who only has the link can't open them.
Our providers
To make Zap Live work we use a few providers, who process data on our behalf and only as far as needed:
- Supabase, for the database, account login and files, in a data centre in Ireland;
- Amazon Web Services, for the automatic check of posts and for connecting calls, in the Frankfurt region, in Germany;
- Apple and Google, to deliver notifications on iPhone and Android;
- Cloudflare, for the Zap Live website.
Google also provides the ads, but as an independent data controller: the «Advertising» section explains this.
Some of these providers are US companies, or belong to US groups, and some data, such as notifications, may pass outside the European Union. When that happens, the transfer takes place with the safeguards provided for by the GDPR: the European Commission's adequacy decision for companies that participate in the EU-US Data Privacy Framework, or the standard contractual clauses approved by the Commission.
For age verification, when we ask for it, we also use Yoti: the «Age verification» section explains this.
Logins and technical logs
For each phone you've logged in on, Supabase's login system keeps a session with the IP address and the app's technical data: it stays until you log out of the account on that phone, and it's deleted with the account. Every request the app sends to our servers also leaves a technical log with the IP address it comes from: it's used to make the service work, to find faults and to protect the service from abuse, and Supabase deletes it automatically after 7 days at most. Visits to the website also go through Cloudflare, which processes the IP address to serve the pages and protect them: we receive nothing from those logs, and the website doesn't use cookies or analytics.
For how long
As long as you keep the account. When you delete it, profile, date of birth, videos, files, comments, messages and interactions are removed straight away. The record of moderation decisions about you remains, to protect the platform and its users and to respond to the authorities («Moderation and reports» section).
Direct messages don't stay forever: they disappear once everyone has seen them and left the chat, or 24 hours after viewing if the chat is set that way, and in any case within 30 days of being sent (within 24 hours for text messages and posts in groups). Only what someone saves in the chat stays, until they remove it from the saved items.
The viewing data the app sends us is deleted after 90 days, even if you delete your account in the meantime; how much you watched each video, which For You uses to choose, is deleted one year after the last time you watched it, or straight away if you delete your account. The frames from the automatic check are deleted as soon as the check is finished, and messages attached to a report 90 days after the decision.
Advertising
Zap Live is free and shows ads. In Home, between posts, full-screen ads labelled «Sponsored» appear. Google provides them, through the AdMob service, and the app receives them directly from Google's servers. We don't store anything about the ads you see, and from Google we only receive overall figures, such as how many ads were shown.
To show the ads, measure their results and fight fraud, Google collects from the app: the IP address, from which it can estimate the area you're in, not your precise location; technical information about the phone and the app, such as performance and errors; when you open the app, the ads you see and what you do with them, for example whether you tap them or watch their video; an identifier linked to the app and, in the cases described below, the phone's advertising identifier. To do this it may also store data on the phone and read it back, as cookies do on websites. Google processes this data as an independent data controller, under its own rules, including outside the European Union with the safeguards provided for by the GDPR. We don't give Google your date of birth, nor your username, your email or your content.
If you've told us your date of birth and you're at least 18, ads may be personalised, that is, also chosen based on what Google knows about your interests. Where the law requires consent, as in the European Union, the United Kingdom and Switzerland, Google asks you for it the first time with a form of its own: if you don't give it, you still see ads, but not personalised ones. You can change or withdraw your consent whenever you like from Settings → Ad preferences, and it applies from then on. On iPhone there is also Apple's request about tracking: unless you say yes, Google doesn't receive the iPhone's advertising identifier, and you can change your mind in the iPhone's settings, under Privacy & Security → Tracking. On Android, the advertising identifier can be deleted or reset in the phone's settings.
If you're under 18, or you haven't told us your date of birth, you see only non-personalised ads, without the phone's advertising identifier and without third-party measurement, chosen from those suitable for minors. We don't ask you for consent, and all we tell Google is to treat your ad requests as those of a minor.
The icon in the corner of every ad opens the Google page that says who paid for it and why you're seeing it, and from there you can also report it. How Google processes data: https://business.safety.google/privacy/. How it uses data from the apps that show its ads: https://policies.google.com/technologies/partner-sites.
End-to-end encryption
Direct messages and calls on Zap Live are protected by end-to-end encryption. Content is encrypted on your device before it leaves, and only the devices of the people taking part in the conversation can decrypt it: the keys to do so stay on those devices. Neither Zap Live nor the providers hosting our servers can read your messages or listen to your calls.
Protected:
- the text of messages, emoji included;
- photos and videos in Snaps;
- posts you share in a chat;
- the audio and video of calls and video calls.
We use public, well-reviewed standards: HPKE (RFC 9180) with X25519 to deliver the message key to each device, ChaCha20-Poly1305 to encrypt the content and Ed25519 to sign it. The signature lets the receiving device discard a message that has been tampered with or doesn't come from the sender. In calls, the two devices recognise each other with the same keys as soon as the connection opens, and on every reconnection they check it is still the same one: if the check fails, the call ends.
Keys and devices
Every device you sign in on creates its own keys. Private keys stay on the device and never move to another phone, not even when a backup is restored; we only store public keys, so that others can write to you. You can use Zap Live on up to five active devices: beyond that, the one unused for the longest stops receiving messages, as does a device where the app hasn't been opened for 60 days.
A new device has new keys and can't read messages that arrived before; in the same way, someone who joins a group only sees messages sent after they joined. When you log out, the device deletes its keys and stops receiving messages; its public key stays on record, marked as withdrawn, to verify messages already sent, and is deleted together with the account.
The public keys of other devices are provided by our servers. The app remembers the ones it has already received and doesn't accept them changing, and in every one-to-one chat it shows a security code, as numbers and as a QR code, to compare with the one on the other person's phone: if they match, no one has got in between. The code changes when either of you changes phone, adds one or logs out of one, and the app points it out in the chat. The phones work it out, and only yours knows whether you've verified it.
What we see of messages
To make the chat work, we process some information that isn't encrypted: who writes to whom and when, the type of message (text, Snap or post), whether it has been read, opened, replayed, saved or captured with a screenshot, and when it expires; for Snaps, also the format, the size and for how many seconds they can be viewed. Group names and members, chat settings and the notices written by the app, such as “Missed call” or who joined a group, aren't encrypted either. When you share a post in a chat, its share count goes up, and the device of the person receiving it asks us for the post's card in order to show it, as with any post being watched.
Message notifications don't contain the text: they only say who wrote to you and, in groups, which group, and they go through Apple's and Google's notification services. Since we can't read messages, we don't monitor them. You can always block or report a person; when you report a chat you can choose to attach the last 5 text messages, which your phone decrypts and sends to us. This is the only way messages reach us in readable form, and it's the person reporting who decides («Moderation and reports» section).
Messages sent before 26 September 2026 weren't encrypted; none of them is still stored on our servers.
Calls and video calls
We don't record calls or listen to them. Audio and video travel from one phone to the other, encrypted; when the two networks can't connect directly, they pass, still encrypted, through an Amazon Web Services server in Frankfurt. To find each other, the two phones exchange their IP addresses through the same service: whoever is on a call with you receives yours.
For each call we store who called whom, when, whether it was a video call, how it ended and how long it lasted. We use this to make the phone ring, to show whether the other person is already on another call and to stop anyone calling too many times in a row, and it's deleted 30 days after the call. The call's line in the chat, such as “Missed call”, stays and follows the same rules as other messages.
Moderation and reports
For the automatic check of posts, Amazon Rekognition, an Amazon Web Services service, in the Frankfurt region, receives from us the post's thumbnail and, for videos, up to four frames that your phone extracts before posting. The frames are deleted as soon as the check is finished; the result remains, that is, whether the post passed, was blocked or is waiting for a person, and why. If the check blocks one of your posts, appealing the decision gets it reviewed by a person.
When you report something we keep who reported, what was reported, the reason, the note you write and the outcome, which we send to your Inbox. Someone reported from the app doesn't know who reported them. If you report a chat and choose to attach the last 5 messages, your phone decrypts them and sends them to us: only the text, five at most, with who wrote them and when. Only Zap Live's moderators read them, and they're deleted 90 days after the decision. For reports that arrive by email, we keep what you write to us and your contact details, to handle them and reply to you.
We keep a record of moderation decisions: what was decided, on which content or account, when and for what reason. We use it to show you the decisions and answer your appeals in Settings → Account status, to count violations and to respond to the authorities. Appeals are deleted with the account; the record remains even after that.
When the law requires it, we give data to the authorities, and only the data they request. We report child sexual abuse material to the Italian Polizia Postale and to NCMEC, the US National Center for Missing & Exploited Children, with the data needed to find whoever posted it.
Copyright reports
When we receive a copyright infringement report we process the reporter's data (name, contact details, the work claimed and the title on which they hold it), the identifier of the reported content and the outcome of the check. We tell whoever published the content the reason for its removal; if they reply, we pass the reply and their contact details on to the reporter, because a dispute over rights is settled between the two parties.
Established infringements stay recorded on the account so that the rule on repeated infringement can be applied: they are kept for 24 months from the last one, or for as long as the account exists if it was closed for this reason. The legal basis is legal obligation and the legitimate interest in defending the platform and rightsholders.
Support requests
If you open a ticket from Settings → Report a problem, we keep the category you choose, what you write and our replies, together with a few details that help us understand the problem: the system and its version, the app version, the phone model and the app language. The ticket is linked to your account, isn't end-to-end encrypted and is read only by the people who answer for Zap Live. A closed ticket is deleted after 12 months; if you delete your account, your tickets are deleted straight away.
Your rights
You can request access, rectification, erasure, restriction and portability of your data, and object to processing. You can carry out erasure yourself, right away, from Settings → Delete account. For anything else write to [email protected]. You may also lodge a complaint with the Irish Data Protection Commission, the lead supervisory authority for Zap Live, or with the data protection authority of the EU country where you live.
Minors
Zap Live is not for anyone under 14, or under the higher age required by the law of their country, as the terms of use say: when you sign up we ask for your date of birth, and if you are under the minimum age the account is not created. If we find out an account belongs to someone under the minimum age, we close it. More protective rules apply to anyone under 18, explained in the terms of use under «If you're under 18»: to apply them we use the date of birth and, to avoid sending notifications at night, the phone's time zone. Anyone under 18 sees only non-personalised ads, as the «Advertising» section explains. Your date of birth can't be changed in the app: if you got it wrong, ask support to correct it, from Settings → Report a problem or by writing to [email protected].
If your phone and the store allow it, when you sign up and then at most once a day, we ask Apple or Google for the age range of your store account and, if you are a minor, whether a parent has approved Zap Live. We keep only the age range, how the store determined it, any approval and the date of the request: we use them only to apply the age rules, never for advertising or analytics, and they are deleted with the account. If the store doesn't respond, or you choose not to share it, only the date of birth applies.
Family Pairing
If an account is linked through Family Pairing, we process who is linked to whom and since when, the controls chosen by the parent or guardian, and the code used for linking, which is valid for 10 minutes. The parent or guardian sees the teen's username and profile picture and the controls they have set, but not the teen's messages, what they watch, what they search for, who they talk to or how much time they spend on Zap Live, which is counted on the phone. The teen sees the username and photo of the parent or guardian. The parent gets a notification when the link is created, the teen when the controls change, and each of them when the other removes the link.
The legal basis is the service you have chosen to use together, and the legitimate interest in protecting minors. The link and the controls remain until one of the two removes the link, and they are deleted with the account.
Age verification
If we ask you to confirm your age, the check is carried out on our behalf by Yoti Ltd, based in London, in the United Kingdom. With a selfie, Yoti estimates your age from your face and deletes the image as soon as the estimate is made: the estimate isn't used to recognise who you are, and nobody looks at it. With an ID document, Yoti reads its details and uses a selfie to check that the document is yours, then deletes the images and data as soon as it has worked out your age. With a credit card, you enter the card details on Stripe, Yoti's payment provider, and Yoti doesn't keep them. Only the result reaches Zap Live, that is, whether you meet the required age: no photos, no documents and no card details.
We keep the result, the attempts, the dates and the Yoti session ID for as long as the account exists; Yoti keeps only the result for us, for 6 months. Yoti carries out the checks in its own data centres in the United Kingdom or in Amazon Web Services regions in the United Kingdom, the European Union or the United States: when data leaves the European Union, it does so with the safeguards provided for by the GDPR. The legal basis is the same as for the date of birth: legal obligation and the legitimate interest in protecting minors.
If you live outside the European Union
We process everyone's data under the rules of this policy, wherever you live, and the data is kept in the same places. If the law of your country gives you additional rights over your data, you can exercise them by writing to [email protected].
Below is what changes in some countries. In the others, you can also contact your country's data protection authority.
Canada
You can ask us to show you your data and to correct it, and you can contact the Office of the Privacy Commissioner of Canada; in Québec, the Commission d'accès à l'information. The person in charge of the protection of personal information under Québec law is Sufyan Arif, at [email protected].
South Korea
You can ask us to show you your data, to correct or delete it, or to stop processing it, and you can contact the Personal Information Protection Commission. The person responsible for protecting personal information (Chief Privacy Officer) is Sufyan Arif, at [email protected].
Philippines
The Data Privacy Act gives you rights similar to those in this policy: you can exercise them by writing to [email protected], and you can contact the National Privacy Commission.
Japan
You can ask us to tell you what data we hold about you, to correct it or to stop using it, by writing to [email protected], and you can contact the Personal Information Protection Commission.
India
You can send a complaint about how we process your data to the Grievance Officer named in the terms of use, with the same time limits.
New Zealand
You can ask us to show you your data and to correct it by writing to [email protected], and you can contact the Privacy Commissioner.
United Kingdom
We also process your data under the UK GDPR and the Data Protection Act 2018, which give you the same rights as this policy. You can contact the Information Commissioner's Office (ICO), the UK's data protection authority.
United States
The Zap Live website doesn't use cookies or tracking tools, so your browser's «Do Not Track» signals make no difference. In the app, Google may show personalised ads to anyone who is at least 18, and to choose them it may use data collected in other apps and websites too: the «Advertising» section explains how to say no.
Thailand
Thailand's Personal Data Protection Act (PDPA) gives you rights similar to those in this policy: you can exercise them by writing to [email protected], and you can contact the Personal Data Protection Committee.