Privacy
Z Privacy runs on your computer. There is no account, no server of ours, and nothing of your work reaches us. This site is a handful of static files that counts nobody. Below, every promise names the file where you can check it.
Who publishes this
Faruk AB publishes Z Privacy and this website, and is the controller of whatever personal data this site involves. Swedish law and the General Data Protection Regulation apply, and the supervisory authority is IMY, Integritetsskyddsmyndigheten. The company, its registration number and its registered address are in the footer of this page, and the address you can write to is zprivacy@mono-peak.com.
The app runs on your computer
- Your documents are opened on your device, and nothing of them is uploaded to us — because the product carries no address of ours at all. The only addresses in it are the six AI services you can choose and a loopback address for a model running on your own machine.Searching the product for our own domains finds nothing, and the same search finds all six providers it does speak to:
docs/THE_PROVIDERS.md,z_core/src/providers/http.rs - What leaves is what you were shown, character for character.
z_core/tests/wire_capture.rsrecords the request byte for byte on a server on your own machine, and proves the body is literally the text you reviewed and that no original value appears in it, in a header, or in the address. - Nothing leaves without your word.
z_core/src/payload.rs,z_core/tests/the_send_door_is_a_sessions_door.rs - The answer is restored on your device, from a store that never left it.
z_core/tests/round_trip.rs - What Z learns is kept in an encrypted vault on your machine, and the vault file names nobody.
z_core/src/vault/crypto.rs— ChaCha20-Poly1305 with Argon2id.z_core/tests/the_vault_file_says_nothing.rsreads the vault file’s own bytes looking for a client’s name, a second spelling of it, an account number and the passphrase: it finds none of them, and a control in the same test proves the search finds all five when they are plainly there. - The one file that is not encrypted is the settings file, and what may never enter it is tested.
z_core/tests/zcfg_leak.rs - The files are created private to your own account, and a symlink in their place is refused rather than followed.
scripts/check_storage_contracts.shnames six contracts and requires each one to be measured on the platform you are standing on.
What we do not promise
Z Privacy reduces what you send. It does not make you anonymous to the AI provider. If a protected text still describes the only factory of its kind in a small village, a model may still work out which company it is. What Z offers is data minimization and a replacement you can see and check before it leaves — not anonymity. That sentence is in the product’s own contract, docs/SECURITY_INVARIANTS.md, which requires it to be said on every page like this one.
Z does not come between you and the company whose model you use. It does not alter, evade or comment on any provider’s terms. You sign up in your own name, and your provider is entitled to know who its customer is and what they use it for. What it does not learn is whose names and accounts are in your documents: those people signed nothing with it — docs/THE_PROVIDERS.md.
A request has a time, a size and an address. Z protects what is in the document, not the fact that you asked. And once you copy protected or restored text out of the app, the clipboard is outside Z Privacy.
This site
A handful of static files. No script runs on it, it sets no cookie, it counts nobody, and it asks your browser for nothing from anywhere else: the fonts and the stylesheet are served from here. The browser is told to refuse the rest — the content security policy is default-src ‘none’, recorded in site/_headers, and scripts/check_site.sh refuses to call the site publishable if a request would leave it or a script appeared on a page.
Like any web server, the one that answers this page sees the request it answers. It is nginx, hosted on Hetzner servers in Finland — inside the EEA — with Cloudflare in front of it as the network. We add nothing to that: no analytics account, no tag, no pixel. There is no form on this site, so there is nothing here to send us with.
What we hold about you
Nothing of your work. If you write to zprivacy@mono-peak.com we have your message and the address it came from, because that is what an e-mail is, and it stays in that mailbox and nowhere else. There is no newsletter and no customer list. We cannot delete a document we never had — and for the same reason we cannot hand one to anybody who asks for it.
Your rights
Under the GDPR you may ask what we hold about you, have it corrected or erased, object to its use, ask for a copy, and complain to a supervisory authority. In practice the only thing we can hold is an e-mail you chose to send us, so one message to the same address settles all of them. For a Swedish company the authority is IMY, Integritetsskyddsmyndigheten, and you may also complain to the authority where you live.
Two blanks we name instead of filling them with words
- A Swedish version of this page. The company is Swedish and so is the authority; this page is in English, German and Arabic today.
- A measured retention period for the mailbox. Mail you send us stays until it is deleted by hand. No number is written here because none has been measured, and a number without a measurement behind it is the thing this product exists to refuse.
When this changed
Written on 9 October 2026. This page is a file in the product’s own repository under site/, one per language, so the promise and the page move in the same commit. Z Privacy is open source under the Apache License 2.0 — the source repository.