Privacy Policy
Zirova
Privacy Policy
Effective 8 August 2026
This Privacy Policy explains how Zirova Limited, a company registered in Masdar City, Abu Dhabi, United Arab Emirates (Licence No. MC 14798) (“Zirova”, “we”, “us”, “our”) handles information in connection with the Zirova mobile application (the “App”) and the Zirova Wallet. It is written to describe what actually happens in our system — which, for the information most people worry about, is that it never reaches us at all.
The short version. Zirova reads activity and wellbeing signals from your device and any wearable you pair, and scores them on your device. Your health and fitness readings are never transmitted to Zirova, never stored on our servers, and never shared with any institution, advertiser, data broker or other third party. What can reach our servers is a verified tier, reward figures, and a cryptographic proof — nothing that contains or can be reversed into a health measurement. If you turn on optional cloud backup, an encrypted copy of your data is stored in your own cloud storage account — never with us. We never use health or fitness data for advertising, marketing or data mining, and we never sell it. The App contains no advertising or analytics SDKs.
1. Information processed on your device only
With your explicit permission, and only for the categories you allow, the App reads the following from Apple HealthKit on iOS, from Google Health Connect on Android, or directly from a paired Zirova wearable band over Bluetooth, depending on what your device and wearable make available:
Heart-rate variability (HRV) — where your device or wearable provides it.
Resting heart rate — read alongside HRV as an indicator of recovery relative to your own recent range.
Activity — steps, active energy, exercise minutes and workout sessions.
Sleep — sleep duration and, where your device provides them, sleep stages.
Basic characteristics — your age band and, where available, biological sex, used only to calibrate scoring.
Every category is optional. If you do not grant a permission, or your wearable does not produce a particular measure, the App adapts and scores you on the signals that are available — it does not substitute an invented value for a reading you did not produce, and it does not treat a missing signal as a poor one.
This information is used for one purpose: to calculate your daily Zirova score and your resulting reward tier, on your device. It is processed locally and is not transmitted to Zirova. Our servers do not receive it, cannot request it, and have no technical means of reconstructing it. Where you allow background access, your device may deliver new readings to the App in the background so your score stays current; those readings are handled in exactly the same way — on the device.
You may grant or revoke access to each category at any time in your device's Health or Health Connect settings, or in the App's settings. Revoking access stops new readings being available to the App; it does not delete a score already calculated on your device.
In accordance with Apple's requirements, health and fitness information read through HealthKit is not stored in iCloud, is not used for advertising or marketing, is not used for use-based data mining, and is not sold or disclosed to data brokers — by us or by anyone acting on our behalf. The App reads from your health store; it never writes anything into it.
2. Information that does leave your device
Only the following may be transmitted from the App to Zirova's servers, and only where necessary to operate the service:
Your verified tier and reward figures — a graded result (for example, a tier letter) and your reward figures. Neither contains, nor can be reversed into, any underlying health measurement.
A confidence value — an indication of how complete the underlying measurement was, expressed as a number. It contains no measurements.
A cryptographic proof — which allows a receiving party to confirm the credential is genuine, without revealing anything about how it was produced, together with standard platform integrity checks confirming the request comes from a genuine copy of the App. Neither contains personal or health information.
Account information — the details you provide when you create or update an account, such as your name, email address, phone number, date of birth, sex and nationality, and, where an institution requires it for enrolment, a participant reference supplied by that institution.
Identity verification — where a feature requires your identity to be verified, the details of your Emirates ID (number and expiry) and photographs of the document, and, if you choose to add one, a profile photo. Document scanning and text recognition happen on your device; only the resulting images and extracted details are uploaded to Zirova, solely to verify your identity. They are never shared except as described in Section 3, with your explicit consent.
Device and technical information — a device identifier, identifiers of wearables you pair, the type of health data source you use (HealthKit, Health Connect or Zirova band — the type only, never its readings), your push-notification token, device model, operating-system version, app version, and crash and diagnostic reports. Crash reports are associated with your account so we can investigate faults, are scrubbed of personal text before they leave the device, and never include health or fitness data. We use all of this to operate and secure the service and to detect fraud, not to profile you.
Wallet records — your Zi balance and transaction history, maintained on our servers so your wallet works across devices.
3. Sharing with institutions
Where you choose to connect the App to a participating institution — for example a bank, insurer or employer running a rewards programme — that institution may receive:
your verified tier;
the specific amount of Zi you are redeeming in a transaction you have initiated;
a cryptographic proof confirming the credential is genuine; and
where that institution's enrolment requires it and only with your explicit consent given at the moment of enrolment: the enrolment details you submit, and your Emirates ID details if you choose to share them. The App asks you separately before anything identity-related is shared, and you can decline.
An institution never receives your health or fitness readings, and never receives your total balance or history. It receives only what you push to it, at the moment you push it. This is an architectural property of the system, not a policy commitment we could quietly change: we cannot disclose to an institution health information we do not hold.
Redemption itself takes place inside that institution's own rewards programme and is governed by that institution's terms and its own privacy policy. We encourage you to read them.
4. Optional cloud backup — your cloud, not ours
You can optionally back up the App's data so you can restore it on a new device. Backup is off until you turn it on, and you choose the destination: the private app folder of your own Google Drive or Microsoft OneDrive account.
The backup file contains your account settings, your score and reward history, and a limited recent history of the signals described in Section 1, which the App needs to rebuild your personal baseline on a new device. It is encrypted on your device before upload and is transmitted only to the cloud provider you chose, under your own account. It is never transmitted to Zirova, and our servers have no access to your cloud storage. You can turn backup off, or delete the backup file, at any time in the App's settings or directly in your cloud account.
5. Who else we share information with
We do not sell personal information. We do not share it with advertisers, advertising networks, or data brokers. We do not use it for behavioural advertising or audience profiling. The App contains no advertising or third-party analytics SDKs and does not access your device's advertising identifier.
We use a small number of service providers to operate the App — cloud hosting, sign-in, push notifications, crash reporting, remote configuration, and customer-support tooling. They act on our instructions, are bound by contract to protect the information they process, and receive only what is necessary for their function. They do not receive health or fitness data, because we do not hold it. If you sign in with Apple, Google or Microsoft, or back up to Google Drive or OneDrive, that provider's own privacy policy governs its part of the process.
We may disclose account or technical information where we are legally required to do so by a court, regulator or law-enforcement authority with valid jurisdiction. We cannot disclose health or fitness data in response to such a request, because it is not in our possession.
6. Legal basis and your rights
We process personal data in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, and, where applicable to you, other data-protection laws. Our legal bases are your consent (for device data access, cloud backup, and connecting to an institution), the performance of our contract with you (to operate your account and wallet, including identity verification where required), and our legitimate interests in securing the service and preventing fraud.
Subject to applicable law, you have the right to:
access the personal data we hold about you;
have inaccurate data corrected;
request deletion of your account and associated data;
withdraw consent at any time, including revoking device data access;
request a copy of your data in a portable format; and
object to or restrict certain processing.
To exercise any of these rights, contact us at info@zirova.ai. We will respond within the period required by applicable law.
7. Retention and deletion
Account and identity-verification information is retained while your account is active and for as long as we are required to retain it by law. Credential records — tiers, reward figures and proofs — are retained while your account is active and for a limited period afterwards where an institution's programme requires a redemption history to be reconcilable, or where we are required to retain records by law.
When you delete your account, we delete or irreversibly anonymise the information we hold about you within a reasonable period, subject to any legal retention obligation. Health and fitness data on your device is under your control and is removed by deleting the App or revoking its access in your device settings. A cloud backup, if you created one, lives in your own cloud storage account and is deleted by you — from the App's settings or directly in that account.
8. Security
All communication between the App and our servers uses encrypted transport. Credentials are cryptographically signed, and device integrity is verified using standard platform mechanisms. Backups are encrypted on your device before upload. Access to systems holding account information is restricted and logged. No system is perfectly secure — but the most meaningful security measure in our design is structural: the information most people worry about is never collected in the first place, and therefore cannot be breached, leaked or compelled from us.
9. Children
The App is intended for adults. It is not directed at children, and you must be at least 18 years old (or the age of majority in your jurisdiction, if higher) to create an account. We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us and we will delete it.
10. International transfers
We are established in the United Arab Emirates and our infrastructure may process account and technical information in other jurisdictions. Where we transfer personal data outside the UAE, we do so in accordance with UAE Federal Decree-Law No. 45 of 2021, including by using providers that offer an adequate level of protection or by putting appropriate contractual safeguards in place.
11. Changes to this policy
We may update this policy as the service develops. If we make a material change, we will notify you in the App or by email before it takes effect. The version in force is always the one published at this address, with its effective date shown above.
12. Contact
Questions, requests or complaints: info@zirova.ai. Postal address: Zirova Limited, Masdar City, Abu Dhabi, United Arab Emirates. If you are not satisfied with our response, you may lodge a complaint with the UAE Data Office.
Zirova — Privacy Policy | Effective 8 August 2026