Privacy Policy
Last updated: 13 August 2026
Ziora runs on your Mac. Your code and your canvases stay there — we never upload them. We don’t use analytics or tracking of any kind. The only things we hold are a random licence identifier that isn’t linked to you, and your email if you joined the waitlist.
1. Who we are
Ziora (“we”, “us”) provides the Ziora application for macOS and this website. We are the data controller for the information described below.
For any privacy question, or to exercise any of the rights in section 7, email hello@ziora.dev. We read and answer these ourselves.
2. What we collect
On our servers
| Record | What it contains |
|---|---|
licenses | install_id (a random UUID), licence code, tier, revoked flag, created date |
invites | Licence code, tier, which install claimed it, when, expiry, an internal note |
app_access | Global version gate — minimum supported build and access window. No personal data |
waitlist | Email address, the date you signed up, and where you signed up from |
We do not store names, and the licence system holds no email address at all. The only email address we hold is one somebody typed into the waitlist form themselves.
Your install identifier is a randomly generated UUID. It is created the first time you launch the app and kept in your macOS Keychain. It is not derived from your hardware, serial number, MAC address, Apple ID, or anything else about you or your machine. It cannot be used to identify you. Reinstalling produces a different one.
On your own Mac — never uploaded
- Canvases and settings, in
~/.ziora/ - Wallpapers, in
~/Movies/Ziora/ - A voice log at
~/.ziora/logs/voice.log— text transcripts only. No audio is ever recorded or stored. - Agent transcripts, wherever each coding tool already writes them
3. What we never collect
- No analytics, telemetry, tracking or crash-reporting of any kind is built into the app.
- Ziora uploads no source code. Agents run locally in your own checkout; whatever they send goes directly to that agent’s provider, under your own account.
- No audio recordings are stored, by us or on your machine.
- No advertising, no selling of data, no profiling.
- No account is required to use Ziora — a licence key, not a login.
4. Where your data goes
Ziora talks to the following services. Where an AI provider is listed, that is your own account under your own agreement with them — we are not a party to it and never see those keys.
| Destination | What is sent | When |
|---|---|---|
updates.ziora.dev | A request for the update feed and build download. Our server logs record IP address, user agent, app version and timestamp | On launch, and when you check for updates |
| Supabase | Your random install_id and the licence code being redeemed | On launch (at most once a minute) and when you enter a key |
| OpenAI | Live microphone audio and conversation | Only while Live Voice is switched on, and only with your own OpenAI key |
| xAI | Live microphone audio and conversation | Only while Live Voice is switched on, and only with your own xAI key |
| Hugging Face | Nothing about you — a model download of roughly 600 MB | The first time you enable on-device voice |
| Apple | Search terms you type into the player | When you search the Apple Music catalogue |
| Spotify | OAuth sign-in and search terms | Only if you connect Spotify |
YouTube, via player.maestro.orizu.dev | Standard YouTube embed traffic. This sets YouTube cookies | When you use a YouTube node |
| Your AI coding tools | Whatever those tools normally send — prompts and code context | When you run an agent. These are your own tools on your own accounts |
5. Legal basis for processing
- Contract — for verifying your licence, so we can provide the software you bought.
- Legitimate interests — for delivering updates and keeping the service secure.
- Consent — for the waitlist. You can withdraw it at any time by unsubscribing or emailing us.
6. How long we keep it
- Licence records: for the life of the licence, plus six years afterwards, which is the period HMRC requires business records to be kept.
- Waitlist entries: until you unsubscribe or ask us to remove you.
- Server logs: 30 days, then deleted.
7. Your rights
Under UK data protection law you have the right to access your data, to have it corrected or erased, to receive a portable copy, to object to processing, and to withdraw consent where we rely on it. To exercise any of these, email hello@ziora.dev.
If you are unhappy with how we have handled your information, you can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint.
8. International transfers
Our database is hosted by Supabase in the EU (Ireland), so the licence and waitlist records described above stay in the European Economic Area. Where you choose to use them, OpenAI, xAI, Apple and Spotify are United States based and process data under their own terms with you.
9. Cookies
This website sets no cookies, uses no analytics, and loads no third-party scripts or embeds. Note that the app itself sets YouTube cookies if you use a YouTube node, as described above.
10. Children
Ziora is not directed at anyone under 16.
11. Changes to this policy
If we change this policy we will update the date at the top of this page and, where the change is significant, tell you in the app or by email.