Privacy summary
Zagens runs locally on your PC. This page summarizes product behavior; the legal text is on Privacy Policy.
What stays on your machine
- API keys and
config.tomlunder your user profile - Chat threads, workspace files, symbol index cache
- Usage statistics shown in the usage dashboard
- Office deliverables in your chosen workspace folders
What leaves your machine
- LLM requests to the provider you configure (DeepSeek, NIM, OpenRouter, self-hosted, …)
- Web tools when enabled — URLs and search queries per network policy
- Vision images when you use
describe_image - In-app updates — version check to
zagens.com(no chat content)
What we do not do
- No Zagens cloud account required for core chat
- No uploading your repo to zagens.com by default
Your controls
- Disable web search and shell in execution policy
- Complete the Windows sandbox wizard (elevated blocks out-of-workspace writes and sensitive profile reads)
- Use
read-onlywith elevated sandbox for untrusted workspaces - Pick providers and regions via API settings
Note: Unelevated sandbox does not isolate profile reads; use Elevated for read isolation. Network-enabled tools use the online sandbox user with unrestricted outbound (separate from file sandbox rules).
Full terms: Privacy Policy · Terms