Your work stays yours.
Zeus servers do not receive your source code, prompts, diffs, or transcripts. Connected model providers receive the context you choose under your accounts and their terms.
EFFECTIVE AUG 23, 2026 · WRITTEN IN PLAIN ENGLISHThe short version: Zeus coordinates work on your Mac and does not proxy model traffic through Zeus servers. We keep the minimum account, licensing, security, and aggregate site data needed to run the product.
01What stays on your Mac
- Your repositories, diffs, model outputs, and local run history.
- Your API keys and CLI credentials, stored in a local permission-restricted file.
- The run ledger, stored in a local SQLite database with an append-only event chain.
02Connected model providers
When you ask a connected model to work, Zeus sends the prompt and context you choose directly to that provider. Your provider account, privacy terms, retention rules, and charges apply to that request.
03What Zeus stores on its servers
- Sign-in events: success or failure records, never raw Apple, Firebase, or Zeus service tokens.
- Your account: a pseudonymous Apple subject, verified email and verification state, plus a display name when Apple provides one.
- Licensing: your license, device slots, key thumbprints, and the events needed for activation and renewal.
- Aggregate site analytics: page views, fixed-category control clicks, and successful downloads by time period, path, and referrer hostname. Reports contain no account or visitor identifier.
- Authenticated product counters: successful app launches, Build selections, query and objective counts, Apply completions, failures, parks, council-seat counts, recovery actions, and content-free run timing by UTC day and month. Timing covers successful end-to-end runs, time waiting for a decision, and fixed build stages. Coarse hardware buckets record only architecture class, memory range, and logical-CPU range. These records use server-derived account and device pseudonyms so retries can be counted correctly without storing work content.
- Authenticated update delivery: the installed Zeus version and build last reported by each signed-in account, the number of update archives fetched, and the last fetched target version, build, and time. These account-linked fields help us operate staged updates, diagnose failed rollouts, and confirm which release a user has installed. They contain no source code, prompts, local paths, or device name.
- Feedback you choose to send: feature-request text or bug-report text. Bug reports also require one Zeus Doctor
.tar.gzarchive, which can contain diagnostic system and application information. If you open Doctor from the feedback page, Zeus shows a separate disclosure and does not collect or upload the archive until you approve it in the app. Manual upload remains available. Feedback is used only for product and support work, not advertising, and is not sold.
04What Zeus does not store
- Your source code, prompts, diffs, model outputs, or transcripts on Zeus servers.
- Product counters and coarse hardware buckets never include query or objective text, task or run identifiers, local paths, provider or agent names, council content, or reviewer identities. The product-usage records do not contain your email, name, raw account ID, license ID, or device ID.
- Raw identity tokens or model-provider credentials.
- Aggregate analytics do not store visitor identifiers, analytics cookies, IP addresses, user agents, query strings, full referrer URLs, raw link URLs or href values, or typed content. Clicks are reduced to a fixed list of product actions. To avoid counting repeated installer requests, a separate dedupe record stores only a cryptographic hash derived from the authenticated download-session token; it is marked for deletion after 24 hours and is never included in or joined to reports. A separate, short-lived abuse-control record stores a pseudonymous cryptographic hash derived from the request IP; it is also never joined to analytics reports. Security and licensing event logs may include request metadata such as IP address and user agent.
- Payment details. Billing is not available yet; if it launches, card data will go to the payment processor rather than Zeus.
05Where account data lives
Account, license, aggregate site analytics, and pseudonymous product-counter data use Firebase Authentication and Firestore on Google Cloud, encrypted at rest and sent over TLS. Firestore access is server-only.
The authorized owner dashboard can show a verified Apple email or private-relay address, Apple-provided display name, license state, installed Zeus version and build, and content-free update-fetch counts. It does not show the raw Apple subject or device names.
Feedback records use a dedicated server-only Firebase Firestore database. Zeus Doctor archives use a dedicated private Firebase Storage bucket. The browser receives a short-lived, exact-object upload capability only after its encrypted cleanup record is durable; it never receives general Firestore or Storage access.
Feature feedback is removed from product and triage access at its two-year retention deadline. Accepted Doctor archives become inaccessible at 30 days and are then deleted by a scheduled worker and Storage lifecycle backstop. Abandoned uploads are normally removed within 24 hours; an ambiguous provider upload can require the provider-expiry safety window before deletion can be proven.
06Your controls
Review your license, deactivate a Mac, send feedback, or request deletion of feedback data from your account page. Feedback deletion is non-cancellable after acceptance and pauses new feedback until active deletion completes.
Active feedback content is removed from product and triage systems first. Restricted continuity metadata and bounded recovery copies can remain temporarily to prevent deleted content or live upload capabilities from reappearing; the account control shows the recovery horizon when it is available.