Privacy
What leaves your Mac, where it goes, and the one switch that stops it.
Two kinds of thing can leave your Mac, and it is worth keeping them apart.
Your words — what you say and what you type — go only to the provider you picked to handle them. Choose one that runs on your Mac and they never leave it.
Anonymous diagnostics go to us, to help make Zeph better. They are on by default, and one switch in Settings turns them off. They carry no account and none of your words.
Everything else stays on your machine.
Where your voice goes
A spoken phrase, from the microphone to your cursor
The companion sends your audio straight to the provider you picked, with your own key on the request. Pick one that runs on your Mac and the audio never leaves it. Pick a cloud one and it goes to that company — and only that company. Which providers run where is on What runs locally.
These are the cloud providers that see your audio or your text, if you choose one:
- Providers
- 13
- Run locally
- 6
- Free
- 6
- Metered
- 1
| Provider | What it does | Runs | Cost |
|---|---|---|---|
| Anthropicanthropic | modelsClaude models for agent and summarization features. | Cloudapi_key | Not stated |
| Deepgramdeepgram | sttttsStreaming speech-to-text with live partial transcripts, plus Aura text-to-speech on the same key. | Cloudapi_key | Metered |
| Google Geminigemini | modelsGoogle's Gemini models (1.5 Pro, Flash, and newer) power the assistant, agent workflows, and tool use over the Gemini API. Connect with an API key from Google AI Studio. | Cloudapi_key | Not stated |
| Groqgroq | modelsGroq serves open models (Llama, Qwen, and more) on its LPU inference hardware behind an OpenAI-compatible chat-completions API for very low latency. | Cloudapi_key | Not stated |
| OpenAIopenai | modelssttttsOpenAI's GPT models (GPT-4o, o-series, and newer) power the assistant, agent workflows, and tool use over the Chat Completions API. The same key also drives Whisper speech-to-text (/v1/audio/transcriptions) and text-to-speech (/v1/audio/speech). Connect with an API key from platform.openai.com. | Cloudapi_key | Not stated |
| OpenRouteropenrouter | modelsOpenRouter is an OpenAI-compatible model gateway: a single API key routes chat completions to 400+ models (Anthropic, OpenAI, Meta, Mistral, and more) behind one endpoint. | Cloudapi_key | Not stated |
| Vercel AI Gatewayvercel-ai-gateway | modelssttembeddingsVercel AI Gateway is an OpenAI-compatible model gateway: a single API key routes chat completions to hundreds of models across providers (Anthropic, OpenAI, Google, xAI, and more) with unified billing, fallbacks, and observability. | Cloudapi_key | Not stated |
Cost is what the provider’s manifest states. Most cloud vendors state nothing, and an unstated cost is not a free one — those rows say so rather than guess.
Your keys stay on your Mac
A provider key lives in your Mac's keychain — one entry per provider, so you can remove one without touching the rest. It is never written into Zeph's own settings files, and it never reaches the device. macOS asks once so Zeph can use it; click Always Allow. Prefer no prompts? In Settings → Privacy, turn off Store provider keys in the keychain and Zeph keeps them in a plain file on your Mac instead.
Diagnostics
To catch bugs and see what needs work, the companion sends anonymous diagnostics: how features get used, and a report when something crashes. They are on by default, and a single switch in Settings → Privacy turns them off.
Neither one is tied to an account — there are no Zeph accounts today — and neither carries your recordings or the words you dictate. Usage is keyed to a random ID made on your own machine, not to you. Crash reports start from the very first launch, so a crash during setup is still caught, and carry only what crashed and the version of the app.
Report a problem
The Report a problem button is a path you drive yourself. Pressing it sends your description, your email if you filled that field in, and a short slice of the most recent log — and only when you press it.
This one works even with diagnostics off
Report a problem is how you reach us when the diagnostics switch is off, so it still sends when you press it — carrying your description, that recent slice of log, and your email if you added one. Pressing the button is the consent, once, for that one report.
Turning it off
Open Settings → Privacy and switch off Share diagnostics & usage data. One switch covers both background paths — usage and crash reports — and it takes effect immediately, with no restart. Report a problem keeps working, because you press it.
That screen also shows your anonymous ID — the random value your usage is keyed to — with a button to copy it. That is the value to quote if you ask us to find or delete what is tied to it.
What stays on your machine
Recordings are saved in a Zeph folder inside your Music folder, on your own disk. The assistant's conversation history is a file on your Mac. The companion's logs are on disk too, and are cleared after a few days.
The full legal text is at Privacy Policy.