Privacy Policy

Last updated: October 5, 2026

Introduction

This Privacy Policy explains how Zest (the "Service") collects, uses, and protects information when you use our products, including our Chrome browser extension, VS Code extension, Claude Desktop extension, web application, and websites.

Information We Collect

General Data Collection

  • Account information: such as your name, email address, and workspace details.
  • Usage data: interactions with the Service, device information, diagnostics, and logs.
  • Content: data you provide through the Service (e.g., text, files) as necessary to operate features.
  • Cookies and similar technologies: to remember preferences and analyze usage.

Chrome Extension Specific Data Collection

When you use the Zest Chrome Extension, we collect additional information to provide extension functionality:

  • Browser tab information: We collect URLs and metadata of active tabs you interact with to provide context-aware code snippet capture and development session tracking. This helps us understand which development tools and AI services you're working with.
  • Authentication tokens: We store authentication tokens locally in your browser using Chrome's storage API to maintain your logged-in session with your Zest workspace.
  • Website content: When you explicitly capture code snippets or interact with AI coding assistants, we collect the content you choose to save for app building assistance and session management.
  • Extension preferences: Settings and preferences are stored locally in your browser to customize your experience.

The Chrome Extension uses the following permissions:

  • activeTab: To capture code snippets and interact with the current webpage where you're building apps
  • tabs: To track which development tools and AI services you're working with for context-aware assistance
  • identity: To authenticate you with your Zest workspace using Google OAuth
  • storage: To save your preferences, authentication tokens, and extension settings locally
  • host_permissions (all URLs): To provide code assistance and snippet capture across all websites and development tools you work with

Deprecated Claude Cowork Plugin Data

The Zest Claude Desktop extension (MCPB) is deprecated and is no longer distributed or supported. Legacy installations may still contain data collected while the plugin was in use. The following describes how those versions handled data.

  • Session data: Legacy versions tracked only new sessions started after login. They extracted messages, tool uses, and session metadata such as start time, duration, and session title from Claude Desktop's local audit log files (audit.jsonl). This data was used to generate standup summaries and track coding activity. No historical or pre-existing chat data was accessed.
  • Local storage: Session data, sync queue, extraction state, logs, and legacy user settings from the deprecated Claude Cowork plugin are stored locally in ~/.claude-mcpb-zest/ on your machine.
  • Authentication tokens: Legacy versions stored authentication session data locally to maintain the logged-in session with your Zest workspace.
  • Analytics events: Legacy versions collected anonymized usage events (e.g., extension install and errors) via PostHog. Analytics were non-blocking and could be disabled.

Privacy redaction: Before any data was queued for remote sync, the extension automatically scans for and redacts sensitive information such as API keys, tokens, passwords, and secrets. You can configure the redaction strategy (detection, encryption, or hybrid) and enable aggressive mode for broader pattern matching.

User controls: You have full control over what data is synced:

  • Remote sync toggle: Disable remote sync entirely to keep all data local — no data leaves your machine.
  • Session ignore: Exclude specific sessions from sync and standup analysis.
  • Custom exclusion patterns: Add glob patterns (e.g., *.env, *.secret.js) to exclude matching content from collection.
  • .gitignore support: Optionally respect your project's .gitignore patterns for file exclusion.

How We Use Information

  • To provide, maintain, and improve the Service.
  • To personalize experiences and develop new features.
  • To communicate with you, including service updates and security alerts.
  • To ensure security, prevent abuse, and comply with legal obligations.

Legal Bases for Processing

Where applicable, we process personal data under legal bases such as performance of a contract, legitimate interests, consent, and compliance with legal obligations.

Sharing of Information

We may share information with trusted service providers who assist in operating the Service, subject to contractual safeguards. We do not sell personal data.

Third-Party Services

  • Cloudflare: We use Cloudflare for application hosting and edge compute — our web application and APIs run on its infrastructure.
  • Supabase (hosted on AWS): We use Supabase for authentication, data storage, and backend services, including encrypted storage of secrets such as integration tokens. Data is processed in accordance with Supabase's privacy practices.
  • OpenRouter: We use OpenRouter, with Vercel AI Gateway as a fallback route, to reach the large language models that generate summaries and reports from your coding activity.
  • Anthropic, OpenAI: Model providers reached through the gateways above. Your data is not used to train their models.
  • Resend: We use Resend to send transactional email, such as account, report, and notification messages.
  • PostHog: We use PostHog for analytics to understand how users interact with our Service and improve functionality. Analytics data is aggregated and used solely for product improvement.
  • Stripe: We use Stripe for billing and payment processing.

These service providers have access only to information necessary to perform their functions and are obligated to maintain confidentiality and security. The current list, including which providers process data originating from Slack, is maintained on our Sub-processors page.

Data Retention

We retain information for as long as necessary to provide the Service and for legitimate business or legal purposes. Retention periods vary based on the type of data and purposes of processing.

Your Rights and Choices

  • Access, correct, or delete your personal information.
  • Object to or restrict processing in certain circumstances.
  • Withdraw consent where processing is based on consent.
  • Portability of certain data, where applicable.

Security

We implement appropriate technical and organizational measures to protect information, recognizing that no system is completely secure.

International Transfers

Information may be processed in countries other than your own. Where required, we use appropriate safeguards for cross-border data transfers.

Children’s Privacy

The Service is not directed to children under the age where parental consent is required by law. We do not knowingly collect personal information from such children.

Changes to This Policy

We may update this Privacy Policy from time to time. If changes materially affect your rights, we will provide notice where required. Your continued use after changes take effect constitutes acceptance.

Contact

For privacy questions or requests, contact hi@winding.ai.