Privacy Policy
Effective 30 August 2026 · Last updated 30 August 2026
Enagach, operated by Zufan LLC, helps groups in Ethiopia split shared expenses and settle up. This policy explains exactly what we collect, why, who we share it with, and the control you have. We have tried to write it plainly rather than defensively.
Contents
- Who we are
- What we collect
- Your phone contacts
- What we never collect
- Why we use your information
- Who we share it with
- What other people in your groups can see
- Where your data is stored
- How long we keep it
- Your rights and choices
- How we protect your information
- Age requirement
- Changes to this policy
- Contact us
1. Who we are
Enagach is built and operated by Zufan LLC ("we", "us"), a limited liability company formed in Texas, United States. Zufan LLC is the controller responsible for your information.
Two names, one company. You downloaded an app called Enagach; the company behind it is Zufan LLC. Enagach is our product name. Wherever this policy says "we", it means Zufan LLC.
This policy covers the Enagach mobile app and the Enagach backend service. Contact us any time at info@enagach.com.
2. What we collect
Information you give us
| What | Why we need it | Required? |
|---|---|---|
| Phone number | How you sign in — we send a one-time code by SMS | Required, unless you register with an email address |
| Display name | So other people in your groups can recognise you | Required |
| Email address | How you sign in if you register with email, or a second way to sign in if you add one later — we send a one-time code to it | Required if you have no phone number on the account |
| Profile photo and short bio | Shown to people you share groups with | Optional |
| Preferred language | To show the app in English, Amharic, Afaan Oromo or Tigrinya | Required (defaults to English) |
Information you create by using Enagach
- Groups — names, descriptions, cover photos, and who is a member. For a member you add by name only (someone without an Enagach account), we store the name you entered — and, if you choose to link one, the phone number or email address you provide, which we keep so their membership connects to them automatically when they sign up with it (see section 3).
- Expenses — amounts, descriptions, categories, dates, who paid, how it was split, and any comments.
- Receipt photos — images you choose to attach to an expense.
- Settlements — records that someone paid someone else: the amount, the method (cash, bank transfer or Telebirr), an optional payment reference you type in, and an optional note.
- Problem reports — anything you send us through "Report a problem".
Information collected automatically
- Device and app details — platform (iOS/Android), device name, and app version.
- Push notification token — an identifier from Apple or Google so we can send you notifications. Only if you allow notifications.
- IP address — used to rate-limit sign-in attempts and prevent abuse of our SMS costs.
- Service logs — each request is logged with a request identifier, your user identifier, the endpoint, and the response status, so we can diagnose faults.
- Product analytics — which screens are opened and which features are used, along with a session identifier, platform and app version. These records reference accounts and groups by internal identifier only; they never contain names, phone numbers, expense descriptions or amounts.
- Crash reports — if the app crashes, we receive the error, a stack trace, and your device and OS version, tagged with your user identifier. Crash reporting is configured not to attach personal information.
3. Your phone contacts
We never upload your contact list, and we never store it. If you turn on contact matching, your phone converts each contact's number into an irreversible cryptographic hash (SHA-256) on your device. Only those hashes leave your phone. Our server compares them against hashes of registered numbers, tells your app which ones matched, and discards them — we keep only a count of how many hashes were checked, to enforce rate limits.
For matching, your contacts' names and phone numbers never reach us. If a contact of yours is not an Enagach user, matching tells us nothing about them at all.
Contact matching is optional. You can turn it off at any time in Settings → Security → Contact matching, which also clears the matches stored on your device. Names you have saved for people in your own phone are shown only to you and are not sent to us by matching.
Adding someone to a group is different from matching. When you add a person from your contacts to a group — or link a number or email to a name-only member — you are choosing to send us that person's name and the number or email you picked, because the group record needs it: it is what lets them join the group automatically when they sign up. That information is stored with the group until they join (at which point it is replaced by their own account) or the member is removed.
4. What we never collect
- Your location. The app does not request or use location data.
- Bank credentials, card numbers, or payment passwords. Enagach records that a payment happened; it never asks for the credentials to make one.
- Advertising identifiers. There is no advertising in Enagach and no third-party ad or marketing tracker in the app.
We do not sell your personal information, and we do not share it for advertising or cross-context behavioural profiling.
5. Why we use your information
- To run the service — create your account, keep group balances correct, and show who owes whom. Basis: performance of our contract with you.
- To sign you in securely — sending one-time codes and detecting abuse. Basis: contract and our legitimate interest in security.
- To notify you — when someone records a payment to you, adds an expense, or needs your confirmation. Basis: contract; push notifications also require your device permission.
- To keep an accurate financial record — money-affecting actions are written to an audit log so disputes can be resolved. Basis: legitimate interest in the integrity of shared financial records.
- To fix faults and improve the product — crash reports and product analytics. Basis: legitimate interest in a working, improving service.
6. Who we share it with
We share personal information only with the service providers below, only to the extent they need it to do their job, and never for their own purposes.
| Provider | What they receive | Purpose |
|---|---|---|
| Amazon Web Services | All service data (hosting and storage) | Running the Enagach service and storing photos |
| AfroMessage | Your phone number and the one-time code | Delivering sign-in codes by SMS in Ethiopia |
| Apple (APNs) and Google (FCM) | Your push token and the notification content | Delivering push notifications to your device |
| Sentry | Crash diagnostics and your user identifier | Diagnosing app crashes |
| Telebirr | Payment amount and reference — only if you choose in-app Telebirr payment | Processing a payment you initiate |
In-app Telebirr payment is not yet enabled. Until it is, Telebirr receives nothing from us — recording a "Telebirr" settlement in the app is just a note you write for your own group.
We may also disclose information if we are legally required to, or where necessary to establish, exercise or defend a legal claim. If Enagach is ever acquired or merged, your information may transfer as part of that transaction, and we will tell you before it becomes subject to a different policy.
7. What other people in your groups can see
Enagach is a shared app, so some of your information is visible to people you choose to share groups with:
- Members of a group see your display name, profile photo and bio, and every expense, comment and balance in that group.
- Someone you share a balance with can see your phone number, so they can reach you to settle up.
- Payments are private to the two people involved. A settlement between you and another member is visible only to the two of you — never to other members, and not even to the group's owner. Group balances still reflect confirmed payments, because that is the shared maths.
8. Where your data is stored
Enagach runs on Amazon Web Services in the United States (region us-east-1). If you use Enagach from Ethiopia or elsewhere, your information is transferred to and stored in the United States, which may have different data protection laws than your own country. We rely on our service providers' contractual data protection commitments to protect it in transit and at rest.
9. How long we keep it
- While your account is open, we keep your information for as long as it is necessary to provide the service.
- Sign-in codes are deleted automatically 48 hours after they are created.
- When you delete your account, we irreversibly remove your personal details: your name, phone number, email, bio and photo are erased, every session and push device is revoked, and your phone number is released so that signing up again creates a completely new account.
What survives account deletion, and why. The shared expenses and settlements in your groups remain, attributed to "Deleted user". Those records belong to the other members too — deleting them would silently change what everyone else is owed. Nothing in what remains identifies you.
You cannot delete your account while any group balance involving you is unresolved (whether you owe or are owed), while a payment is still pending, or while you are a group's only owner. Settle up or hand the group over first, so nobody is left with a balance they cannot resolve.
We do not commit to a fixed retention period for the remaining operational records, such as audit logs and analytics. We keep them for as long as necessary for the purposes described in this policy, and you may ask us at any time what we hold about you.
10. Your rights and choices
You can do most of this yourself, in the app:
- See and correct your information — Profile → Edit profile.
- Delete your account — Profile → Delete account. This is confirmed by a one-time code and cannot be undone.
- Turn off contact matching — Settings → Security → Contact matching.
- Control notifications — Settings → Notifications, including quiet hours, per-group muting, and settlement reminders. You can also revoke notification permission in your phone's system settings.
- Sign out of a device — Settings → Security, which lists your active devices.
Depending on where you live, you may also have the right to request a copy of your data, ask us to correct or erase it, object to or restrict how we use it, ask us to transfer it, or withdraw consent. Write to info@enagach.com and we will respond within 30 days. You will never receive worse service for exercising a privacy right.
11. How we protect your information
- All traffic between the app and our servers uses HTTPS, and our servers redirect any unencrypted connection to HTTPS.
- Our database is encrypted at rest, is not reachable from the public internet, and is backed up continuously.
- Sign-in is protected by rate limiting and automatic lockout after repeated wrong codes, and sessions can be revoked at any time.
- Staff access to user data is restricted and recorded in an audit log.
- You can add an app lock (Face ID, Touch ID or your device passcode) in Settings → Security.
No service can promise perfect security, but if a breach ever affects your personal information we will notify you and the relevant authorities as required by law.
12. Age requirement
Enagach is not intended for anyone under 16, and we do not knowingly collect information from children. If you believe a child has given us personal information, contact info@enagach.com and we will delete it.
13. Changes to this policy
If we change this policy we will update the date at the top. For changes that materially affect your rights, we will tell you in the app or by notification before they take effect. Continuing to use Enagach after a change means you accept the updated policy.
14. Contact us
Zufan LLC (operator of Enagach)
Texas, United States
Privacy enquiries: info@enagach.com
We aim to reply within 30 days. If you are in the European Economic Area or the United Kingdom, you also have the right to complain to your local data protection authority.