LEGAL
Privacy Policy
ZeroWrite is a security product. Trust is the product, so this policy is written to be read, not to be survived.
LAST UPDATED — 4 AUGUST 2026
The short version
Your files never leave your computer. ZeroWrite analyses executables locally. It does not upload file contents, documents, or anything it scans. The only things that can be sent are cryptographic hashes and URLs, and only when you have left the relevant setting enabled.
We collect the minimum needed to run an account and a licence: your name and email if you create one, and standard technical data such as IP address. We do not sell data, and we do not run advertising or cross-site tracking.
Who we are
ZeroWrite.ai provides the ZeroWrite desktop application and this website. For privacy questions, contact us at privacy@zerowrite.ai.
The desktop application
What stays on your machine, always
- The contents of every file analysed.
- File paths, file names, and directory structure.
- Your username, hostname, and local account details.
- Quarantined items and the local event history, which are stored in a database on your own disk.
Behavioural analysis, intent scoring and rule matching all run on your computer. Protection does not depend on a network connection.
What may be sent, and when
The first-run setup asks about three categories separately. Each can be changed later in Settings.
| Category | Default | What it contains |
|---|---|---|
| Crash reports | On | Stack traces and application version when ZeroWrite crashes. No file contents. |
| Operational telemetry | On | Application version, OS build, rule-pack version, detection counts by severity only, verdict latency, update success or failure. |
| Threat-data sharing | Off | For blocked items only: the SHA-256 hash, the rule name, and the risk score. Never the file itself. |
Telemetry is tied to a random install identifier generated on first run. It is not linked to your name, email, or licence unless you tell support about it.
Machine identifiers
Licence seats are counted using a random identifier created once per installation. It is deliberately not derived from your hardware — no motherboard IDs, disk serials, or MAC addresses are read or hashed. Reinstalling produces a new identifier.
Accounts on this website
If you create an account, we store:
- Your name and email address.
- A password hash, if you use a password. The password itself is never stored or logged.
- Your identifier at Google or Microsoft, if you sign in with one of them.
- Two-factor secrets and passkey public keys, if you enable them.
- Security events — sign-ins, password changes, device revocations — with the IP address and browser user agent, kept so that you and we can investigate suspicious activity.
When you choose a password we check it against known breach corpora using k-anonymity: only the first five characters of its hash are sent, which is not enough to identify the password or you.
Payments
Payments are handled entirely by Stripe using their hosted checkout and billing portal. Card numbers never reach our servers. We receive confirmation of a subscription, its status, and the billing email.
Who else processes your data
| Provider | Purpose |
|---|---|
| Vercel | Website hosting |
| Supabase | Account database |
| Stripe | Payments and billing |
| Resend | Transactional email |
| Cloudflare | Proxy and protection for our API |
| GitHub | Release and update distribution |
| Sentry | Crash reporting |
How long we keep things
- Account data — for as long as your account exists.
- Security event logs — retained for a limited period for abuse investigation, then deleted.
- Billing records — for as long as tax and accounting law requires.
- Telemetry — aggregated; the raw events are not kept indefinitely.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to processing, and to complain to a supervisory authority. Contact privacy@zerowrite.ai and we will respond within the period the applicable law requires.
Deleting your website account does not disable ZeroWrite on your computer — the application keeps protecting you using the licence already installed.
Children
ZeroWrite is not directed at children and we do not knowingly collect data from anyone under 16.
Changes
If we change this policy in a way that materially affects you, we will say so on this page and, where the change is significant, by email.
Related: Security & vulnerability disclosure · Terms of Service