5. Product disclosure: ZERO ONE Desktop and local ZSEC scans
Local desktop data and automatic startup
ZERO ONE Desktop stores user-chosen ZMail, ZeroThink, OpenZero, and CallChat service URLs, the configured OpenZero model, the CallChat media preference, and the launch-at-login preference in the operating system's application-data directory. The configured OpenZero endpoint can be a loopback address or an allowed public origin; model requests, prompts, and responses therefore are not always local. An OpenZero API token is stored only when secure operating-system encryption is available; the reviewed app refuses insecure Linux basic-text credential storage.
“Launch ZERO ONE when I sign in” is a user-controlled operating-system login item. When enabled, the operating system starts ZERO ONE automatically at sign-in. The setting can be turned off in the app, and the Clear desktop data control also disables it.
Automatic reachability checks
When ZERO ONE starts, and every 30 seconds while it remains open, it sends an HTTP GET reachability request to each configured ZMail, ZeroThink, OpenZero, and CallChat URL. The request follows HTTP redirects and has a bounded timeout. The configured service, and any followed redirect destination, receives the user's network IP address and the ZERO-ONE/<version> user agent as part of the connection. These probes do not attach the OpenZero API token, prompts, messages, mailbox content, or a diagnostics file.
User-initiated diagnostics export
Diagnostics export runs only when the user requests it and chooses a local save location. The JSON file contains its generation time, app version and platform, operating-system release, logical-core count, total RAM, origin-only service destinations, reachability state, HTTP status and latency, media and launch-at-login preferences, and a yes/no value showing whether an OpenZero token is configured.
The export excludes the computer hostname, API-token value, cookies, email, documents, notes, chat or call content, prompts, and model responses. Service destinations are reduced to origins: URL user information (userinfo), paths, queries, and fragments are not included. The saved file remains at the user-chosen location until the user moves, shares, or deletes it; uninstalling ZERO ONE or using Clear desktop data does not remove saved diagnostics files.
Remote service boundaries
ZMail, ZeroThink, OpenZero, and CallChat are remote-capable services displayed in separate persistent, isolated webview partitions. Requests, authentication, cookies, settings, and content used in those views are handled at the selected service boundary. The reviewed ZERO ONE Desktop preview does not merge their credentials or silently transfer content between those services. Server-side collection and retention can differ by service and must be read with the applicable service disclosure; this section does not claim that remote services collect no data.
Removing the reviewed Windows binary does not itself clear the operating-system application-data directory. ZERO ONE settings and persistent embedded-workspace cookies and storage can therefore remain after uninstall. Users who want to remove that local app data should use the in-app Clear desktop data control before uninstalling.
After confirmation, Clear desktop data removes ZERO ONE settings and the encrypted OpenZero token, clears embedded cookies, storage, caches, and authentication state for ZMail, ZeroThink, OpenZero, and CallChat, disables automatic startup, and restarts the app with defaults. It does not delete accounts, messages, files, or other data held by the connected services, and it does not delete diagnostics files previously saved by the user.
CallChat camera and microphone
Camera and microphone access is disabled by default. If the user enables CallChat media, access is restricted to the exact CallChat HTTPS origin and remains subject to operating-system permission controls.
Selected-folder ZSEC Shield scan
In the reviewed Windows x64 preview, the user must press the scan button and choose exactly one folder through the operating-system picker. The desktop invokes its bundled ZSEC Shield runtime with that selected path and bounded arguments. It does not start a background scan, automatic deletion, or automatic quarantine.
The reviewed desktop bridge does not upload file names, paths, hashes, samples, or reports. The app receives aggregate counts and a bounded scan outcome. Local command-line reports may contain paths, hashes, configured-rule matches, and operational errors. The separate command-line tool supports opt-in recoverable quarantine, but the desktop scan button does not request quarantine.
This selected-folder description is limited to the reviewed Windows x64 preview. It is not a claim about unverified platform packages, real-time protection, cloud reputation, telemetry, crash reporting, or sample submission.
Reporting
To report concerning AI output, use the AI output reporting page. Do not include passwords, API tokens, session cookies, private keys, recovery codes, unnecessary personal data, confidential files, or live malware samples.
Store-readiness boundary
This disclosure describes reviewed source behavior. It does not mean a Microsoft Store submission, publisher signing, exact final-binary verification, clean-machine testing, or review of every connected service's live privacy practice is complete.