Zeraix

Legal · Privacy

Privacy Policy

Effective date: August 24, 2026 Last updated: August 24, 2026

Zeraix ("Zeraix," "we," "us") is an open-source, local-first AI workbench. This Privacy Policy explains what information Zeraix collects and how that information is used and stored — with particular focus on two features that involve your Google account: Google Sign-In for our official cloud models, and the Gmail plugin.

If you only use Zeraix's local core features (local models, local files, local terminal tools), Zeraix does not require you to create an account, and we do not send your prompts, conversations, or files to our servers. This policy primarily covers the optional features described below, which involve an account or third-party data.
01

Scope

This policy applies to the Zeraix desktop application (macOS and Windows) and the Zeraix website (zeraix.com). This policy does not apply to any third-party models, third-party MCP services, or third-party plugins you choose to connect — please review those third-party providers' own privacy policies separately.

02

Local-first by default

Zeraix's local core — local model inference, local conversations, local memory, local files, and the local execution sandbox — runs entirely on your own device. This part does not require an account and does not send data to Zeraix's servers. The rest of this policy explains the two features that do involve an account or third-party data.

03

Google Sign-In (for Zeraix's official cloud models)

3.1 Purpose

If you want to use Zeraix's officially hosted cloud models (as distinct from your own local models or custom endpoints), you need to sign in with your Google account. Sign-in is used to verify your Zeraix user identity and, on that basis, to issue you an API key / credential for calling the official cloud model service.

3.2 What we collect

When you use Google Sign-In, we obtain basic profile information from your Google account, limited to:

  • Your name
  • Your email address
  • Your avatar (if any)

We use this information only to create and identify your Zeraix account, to issue and manage your model-usage credentials, and to provide support if you contact us. This sign-in flow itself does not request access to your Gmail, Drive, Calendar, or any other Google service — it is used for authentication only.

3.3 What we don't do

We do not sell this information, and we do not use it for advertising. We do not access any of your other Google services through this sign-in flow.

04

Gmail plugin (Gmail OAuth in the plugin marketplace)

4.1 Purpose

Zeraix's plugin marketplace offers an optional Gmail plugin. If you choose to install and connect it, you'll be guided through Google's OAuth authorization page to complete authorization. Once connected, you can have Zeraix's AI agent help manage your Gmail — for example, reading and organizing email, or sending email on your behalf, depending on the scopes you've authorized.

This plugin is off by default and entirely optional; it is only enabled once you explicitly choose to add it and complete the Google authorization flow.

4.2 What data is involved

Depending on the scopes you authorize, this plugin may access email content, email headers, labels, and permission to send email on your behalf. Before you approve, the specific scopes being requested are clearly shown on Google's authorization page, and you may review or revoke these authorizations at any time.

4.3 Where your tokens and data are stored

This is the core privacy commitment of the Gmail plugin.

  • The OAuth access token and refresh token issued by Google are stored only on your local device — they are never uploaded, transmitted, or stored on Zeraix's servers.
  • Token refresh happens locally: your device communicates directly with Google's servers to refresh the token. Zeraix's servers are not involved in the refresh process and never see the refresh process itself or the resulting token.
  • Gmail content obtained through the plugin (for example, emails the AI reads to fulfill your request) is processed locally on your device as part of the agent's local workflow. If you've chosen a cloud model to process that request, the relevant content is sent directly from your device to that model provider to generate a response — handled the same way as any other content you choose to share with a cloud model. It does not pass through or get stored in some separate "Zeraix email storage service," because no such service exists.

4.4 Your controls

You can disconnect the Gmail plugin at any time within the Zeraix app, which deletes the locally stored tokens. You can also independently revoke Zeraix's authorization at any time directly from your Google Account third-party access page, separate from the Zeraix app.

4.5 Google API Services User Data Policy (Limited Use Disclosure)

Zeraix's use and transfer of information received from Google APIs (including via the Gmail plugin) adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:

  • Gmail data obtained through this plugin is used only to provide and improve user-facing features you have requested within Zeraix (i.e., allowing you to manage your own mailbox using natural language).
  • We do not use Gmail data for advertising purposes.
  • We do not allow humans to read Gmail data except: with your explicit consent for a specific email, for security purposes (such as investigating abuse), to comply with applicable legal requirements, or when the data has been aggregated and de-identified.
  • We do not transfer Gmail data to third parties except: as necessary to provide the feature you requested (such as sending your request to the cloud model you've chosen), to comply with legal requirements, as part of a merger or acquisition where this policy continues to apply, or with your explicit consent.
05

Cloud models and custom endpoints (general)

If you choose to use Zeraix's official cloud models, a custom OpenAI-compatible endpoint, or any other cloud model, the prompts and any attachments you send in that conversation will be sent to the corresponding model provider to generate a response. This applies whether the content was typed by you manually or came from a plugin such as Gmail. What this means for your privacy when the provider is not Zeraix itself is explained in Section 6.

06

Third-party models, MCP services, and plugins (not covered by this policy)

Zeraix lets you connect your own local models, cloud model providers, custom OpenAI-compatible endpoints, MCP (Model Context Protocol) services, and marketplace plugins other than the built-in Gmail plugin described in Section 4. These are third-party services you choose to connect yourself, are not operated, reviewed, vetted, or controlled by Zeraix, and are not covered by this Privacy Policy.

When you connect a third-party model, MCP service, or plugin:

  • Any data you send through that connection (prompts, files, Gmail content, or other information) is transmitted directly to that third party and handled according to that third party's own infrastructure and data retention practices — not Zeraix's.
  • Zeraix cannot see, and has no control over, how that third party stores, processes, retains, or shares the data it receives.
  • The availability of a service, or the presence of a third party in Zeraix's plugin marketplace or MCP directory, does not mean Zeraix endorses that provider's privacy or security practices.
  • Before connecting, it is your responsibility to review that third party's own privacy policy and terms of service and to decide for yourself whether to trust them with your data.

This applies to (without limitation): any cloud model you choose other than Zeraix's official cloud models, any custom endpoint you configure, any MCP service you add, and any marketplace plugin other than Zeraix's official Gmail plugin.

07

AI-generated content and AI-performed actions

Zeraix allows AI models to generate content and, with your authorization, to perform actions on your behalf — such as drafting or sending email via the Gmail plugin, editing files, or executing terminal commands in Developer Mode. This section explains where our responsibility ends in that process.

  • AI-generated content can be wrong. Whether from a local model, Zeraix's official cloud models, or a third-party/custom endpoint model you've connected, the generated text, summaries, code, or suggested actions may be inaccurate, incomplete, or unsuitable for your specific situation. Treat AI-generated content as a draft or suggestion, not as verified fact or an instruction that's safe to execute without review.
  • Verification before execution is your responsibility. When Zeraix asks for your confirmation — such as a diff preview before a file change, a confirmation before running a command, or a confirmation before sending an email — that step exists to give you a chance to catch and stop mistakes. Please carefully review what's actually shown to you — the content, path, or command itself — rather than just the AI's description of it, before confirming.
  • Zeraix does not review AI-generated content or actions on your behalf. We do not monitor, review, or verify the content generated by models in your sessions, or the actions they perform. We are not responsible for the accuracy of AI-generated content, or for the consequences of any action performed by an AI model — regardless of whether you approved it — including but not limited to emails sent via the Gmail plugin, files created or modified, or commands executed.
  • This applies to all models. Whether Zeraix's official cloud models, your local models, or any third-party or custom endpoint model you've connected (see Section 6), this section applies equally.
  • For anything important that Developer Mode or a plugin might modify, we recommend keeping backups and using version control so you can recover from mistakes.

This section addresses AI-generated content and AI-performed actions from a privacy and responsibility standpoint; for the complete disclaimer and limitation-of-liability terms, please see our Terms of Service.

08

Data we do not collect

Zeraix does not collect or transmit:

  • Local conversation content when using local models
  • Files you open, edit, or run locally in Developer Mode
  • Terminal commands run locally, or their output
  • Gmail OAuth tokens (as described above, these always remain on your local device)
09

Data storage and cross-border transfer

Storage location: Your basic account information is stored on secure cloud servers located within mainland China. Gmail message data and OAuth tokens are stored only on your local device and are never uploaded to or stored on our servers (see Section 4.3).

Cross-border transfer: When you use Google Sign-In, an AI model API hosted outside mainland China, or access the Service from outside mainland China, necessary information may be transferred across borders for processing by the relevant service provider's region, protected in accordance with applicable law and industry-standard encryption.

10

Data retention

  • Account profile information obtained through Google Sign-In is retained for as long as your Zeraix account remains active. You may request deletion at any time (see Section 12).
  • Gmail OAuth tokens are retained on your local device until you disconnect the plugin, revoke authorization via your Google account, or uninstall Zeraix.
11

Security

For account information processed by our servers, we use industry-standard security measures to protect it. Locally stored tokens and data rely on the standard local storage protections provided by your operating system. As with all software systems, no method of storage or transmission can be guaranteed 100% secure, and we cannot make an absolute guarantee in this regard.

12

Your rights and choices

You may:

  • Disconnect the Gmail plugin at any time within the Zeraix app and delete the locally stored tokens.
  • Revoke Zeraix's access at any time from your Google Account permissions page.
  • Contact us (see email below) to request access to, correction of, or deletion of the account data we hold (name, email, avatar).
  • Skip creating an account entirely and avoid the features described in Sections 3–4, using only Zeraix's local core features.
13

Children's privacy

Zeraix is not directed at children under the age of 13 (or the minimum age required under the law applicable to you), and we do not knowingly collect personal information from them.

14

Changes to this policy

We may update this Privacy Policy from time to time. If there are material changes, we will update the "Last updated" date above and provide additional notice where required by law.

15

Contact us

If you have any questions about this Privacy Policy, or wish to exercise the rights described above, please contact us:

[fergus@zeraix.com]

This policy is part of the Zeraix open-source project. The source code implementing the behaviors described above (including local-only token storage) is publicly available at github.com/zeraix/zeraix.