Skip to content
Zync

Privacy

Privacy, in plain language.

This policy explains how the Zync desktop app, optional connected services, and this website handle information.

Last updated: September 20, 2026

At a glance

Three separate surfaces.

Desktop app

Local workspace data

Hosts, terminal content, and vault data stay on your machine. Limited pseudonymous usage analytics can be disabled in Settings.

Optional services

You choose the connection

Drive Sync, Public URLs, and cloud AI send specific data only when you configure or use them.

This website

Clarity analytics

The production site uses Microsoft Clarity to understand website use. It never receives credentials from the desktop app.

The policy

What happens to your data.

Desktop application

Zync is a local desktop application. Saved hosts, folders, tunnels, snippets, settings, and session state are stored in the app data directory on your device.

Authentication material is resolved on your device and used to connect to the host you selected. The core SSH workspace does not require a Zync account.

  • Pseudonymous usage analytics. When Share anonymous usage is enabled, Zync sends a random installation ID, UTC day, app version, operating system, architecture, and daily feature-use counts to the Zync analytics service.
  • Enabled by default. You can stop future usage submissions at any time under Settings -> General -> Share anonymous usage.
  • Sensitive data excluded. Usage submissions do not contain IP addresses in the payload, hostnames, paths, commands, credentials, vault contents, terminal output, or advertising identifiers.
  • Local settings. Connection configuration, workspace state, and interface preferences remain in local app storage unless included in an optional encrypted backup.
  • OS credential store. Device-bound vault unlock material and service tokens may be stored in Windows Credential Manager, macOS Keychain, or the Linux secret service.

Vault and credentials

The Local Vault is optional. It encrypts stored SSH passwords, private keys, and supported provider credentials on-device using Argon2id key derivation and authenticated encryption.

Your vault passphrase and recovery key are not uploaded by Zync. Store the recovery key offline. Losing both unlock methods means the local vault cannot be decrypted.

  • Existing key files. SSH key files stored on disk continue to work without moving them into the vault.
  • Remember on device. If enabled, Zync stores device-bound unlock material in the operating system credential store.
  • Credential history. Rotated vault credentials can keep encrypted revision snapshots so an earlier revision can be restored.
  • Plaintext migration. Credentials in older local connection records can be moved into the vault through normal app workflows.
  • AI provider keys. Provider API keys are encrypted in the Local Vault, remain local, and are excluded from credential sync and full Vault backup exports.

Google Drive Sync and Backup

Drive Sync is optional. Zync uses Google installed-app OAuth after you grant consent. It requests access to the hidden Drive app-data folder and the connected account email.

Backup and sync collections are encrypted before upload using a separate sync passphrase. Zync does not scan normal visible Drive files and does not host a copy of your encrypted collection.

  • Drive scope. The drive.appdata permission allows Zync to read and write its hidden app-specific folder only.
  • Account email. The email scope identifies which Google account is connected in the app.
  • OAuth tokens. Google tokens are stored locally, including in the operating system credential store where supported.
  • Desktop OAuth client. Release builds contain desktop OAuth client identifiers. They do not grant access to a Google account without that user granting consent.
  • Separate sign-in. Drive Sync OAuth is separate from the GitHub or Google account used for Public URLs.

Public URLs Beta

Public URLs is an optional sharing service and is not SSH port forwarding. It uses a separate Zync share account, a localhost-only desktop agent, and Zync-operated API and relay hosts.

GitHub sign-in requests profile and email access. Google sign-in requests OpenID, email, and profile access. The service stores the provider identity, email when available, profile image, account record, and share configuration.

While a share is active, the relay forwards HTTP, WebSocket, or TCP traffic for the localhost port you selected. The service is designed not to log request or response bodies.

  • Operational audit data. Security records can include account ID, action, share slug, IP address, metadata, and time.
  • Link access. Anyone with the URL can reach the selected service while it is active unless you set an optional password.
  • Share lifetime. A share remains available while the desktop share agent is running. Stopping an SSH session does not stop the share.
  • Local session tokens. Share access and refresh material is stored in the operating system credential store. Signing out clears the local session.
  • Ending a share. Stop or delete a share, or sign out, when you no longer want the public route active.

AI features

AI features are optional. Cloud AI requests go directly from your device to the provider you configure. Ollama can run locally.

Depending on the feature, a request may contain your prompt, limited terminal context, agent messages, command output, file listings, or tool results needed for the current task. Review the selected provider and context before using AI with sensitive systems.

  • Provider policies. The AI provider applies its own privacy, retention, and training policies to data you send.
  • Local provider. Prompts stay on your machine when you use a local Ollama instance.
  • Stored keys. Cloud provider API keys are encrypted in the Local Vault and excluded from sync and full Vault backup exports.
  • Active work. Locking the vault blocks future key resolution but does not cancel an AI request that already resolved its key.

SSH, SFTP, and remote servers

SSH connections originate from your device and terminate at the server you choose. SFTP moves files between your device and that server.

Remote server operators, jump hosts, DNS providers, internet providers, and network paths may process connection metadata or session activity under their own policies. Zync does not control remote server logging.

  • Host authentication. Passwords, key files, agents, or vault-resolved credentials are used locally to complete the SSH handshake.
  • Remote content. Commands, terminal output, and transferred files necessarily pass between your device and the connected server.

Plugins and extensions

Zync can install themes, editor providers, icon packs, and other extensions. Community extensions are third-party software unless they are identified as official.

Marketplace plugins do not receive raw vault secrets by design. A plugin may process local data or make network requests when allowed by its capabilities and the action you take.

  • Review the source. Check the publisher, source, requested capabilities, and update history before installing an extension.
  • Third-party services. Network destinations used by a community plugin have their own terms and privacy practices.

Updates, downloads, and feedback

Zync contacts public GitHub endpoints for release checks, downloads, release notes, and contributor information. The extension marketplace also uses public GitHub-hosted metadata and files.

Installer buttons on this site link to GitHub Releases or official Zync package repositories. Those services receive normal request information when you access them.

  • No credentials in update requests. Release and marketplace requests do not include vault contents or SSH credentials.
  • Optional feedback. When used, in-app feedback is sent to a Zync-operated survey API. It does not include vault secrets, SSH keys, or terminal content.
  • Remote icons. Optional connection icons can be requested from the public URL configured for that icon.

This website

zync.thesudoer.in is a marketing and documentation site. It is separate from the desktop app and does not receive SSH credentials, vault data, or terminal content from the app.

The production site uses Microsoft Clarity for behavioral analytics, including heatmaps and session recordings. Microsoft and the hosting provider may process routine browser, device, network, request, and usage information for analytics, delivery, reliability, and security.

  • Microsoft Clarity. Clarity helps the project understand how visitors use the site. Microsoft applies its own privacy practices to information processed by the service.
  • Fonts. Pages load font files from Google Fonts, so your browser connects to Google when loading them.
  • Video posters. Homepage demo posters load from YouTube image servers.
  • Video playback. A privacy-enhanced YouTube iframe loads only after you open a demo.
  • Browser storage. The site may use localStorage to remember a visual theme preference. It is not used for advertising.
  • Downloads. Installer links send you directly to GitHub Releases or the Zync package repositories.

Sharing and sale of data

The Zync project does not sell, rent, or trade personal information. Information is disclosed to another service only when needed for a feature you request, a destination you choose, or service security and operation.

  • Remote systems. SSH and SFTP data goes to the servers and network path you choose.
  • Connected providers. Google Drive, AI providers, OAuth providers, GitHub, YouTube, fonts, hosting, and plugin services receive data described in their relevant sections.
  • Public shares. Visitors with a Public URL can access the selected localhost service while that share is active.

Your choices and controls

Most Zync data remains under your control because it is stored locally or in services you connect.

  • Stay local. Do not enable Drive Sync, Public URLs, cloud AI, remote icons, or third-party plugins if you do not want those connections.
  • Usage analytics. Turn off Share anonymous usage under Settings -> General to stop future desktop usage submissions.
  • Google. Disconnect Drive Sync in Zync and revoke its access from Google Account permissions.
  • Public URLs. Stop or delete individual shares and sign out to clear the local share session.
  • AI. Use local Ollama, remove provider keys, or leave AI disabled.
  • Extensions. Uninstall plugins and review their own services for separate deletion controls.
  • Local deletion. Remove Zync app data using the appropriate in-app reset flow or delete the application data directory after closing Zync.

Retention and deletion

Local app data remains on your device until you remove it. Uninstalling Zync may not remove the app data directory automatically.

Encrypted Drive collections remain in your Google account until you remove them or delete the associated app data. Provider tokens remain until disconnected, revoked, expired, or removed under the provider flow.

Deleting a Public URL removes that share record. Public URLs account and operational audit records may be retained as needed to operate and protect the Beta service. Hosting and third-party providers apply their own retention policies.

  • Account or privacy request. Use the public repository contact below for a privacy question or deletion request. Do not include passwords, keys, or other secrets in a public issue.
  • Security report. Use the private disclosure link for vulnerabilities or sensitive security details.

Children

Zync is a developer tool and is not directed to children under 13, or the minimum age required in their jurisdiction. The project does not knowingly seek personal information from children.

Changes to this policy

This policy may change when the desktop app, optional services, website, or legal requirements change. The last-updated date at the top identifies the current version.

Material product changes that affect privacy will be reflected in this policy and relevant release or security documentation.

Questions and requests

Talk to the maintainers.

Use the public repository for privacy questions, corrections, or deletion requests. Never include credentials or sensitive personal data in a public issue. Report vulnerabilities privately.