Local-first by design

Privacy Policy

This policy explains what Zap processes on your device, what information reaches our services, why we use it, and the choices available to you.

Effective October 1, 2026Version 3.1
The short version: Drip Type composition and typing run locally. When you choose to use Zap AI, your submitted text and attached screenshots are sent through Zap to Anthropic. Online services also process account, billing, licensing, support, security, update, and AI usage information.

1. Who we are

This policy covers Zap and the tryzap.net website ("Zap," "we," "us," or "our"). For privacy questions or requests, use the private support form.

2. Scope

This policy applies to the Zap macOS and Windows applications, tryzap.net pages for Zap, subscription activation, software updates, and related support. It does not govern third-party websites, applications into which you choose to type, or Stripe-hosted pages governed by their own notices.

3. The local-first boundary

Drip Type drafts remain in application memory. Zap does not automatically collect drafts or monitor clipboard history. When you submit text to Zap AI, it is processed as described below. Existing data from retired Templates, Pro Studio, Profiles, and Clipboard features remains on your device; the current app does not read or edit that data. Information you deliberately submit in the support form is sent to Zap as support content.

Zap does not send keystroke logs, browser history, contact lists, microphone recordings, camera recordings, or precise location to Zap. The operating system may expose limited interface access after you grant Accessibility or Automation permission, but Zap uses that permission to enter the text you direct it to type, not to build a record of your activity.

Optional Zap AI: when you select Ask Zap, your prompt, selected context, and any screenshots you attached are sent to Zap’s authenticated service and then to Anthropic for inference. Screen capture is initiated by you and can be previewed and cropped before submission. Responses and AI history remain in app memory until cleared or the app closes. The service records subscription usage counts and keyed, non-plaintext identifiers for IP- and account-based request counters to enforce usage limits; it does not save prompt or response content to its account or quota stores. Zap does not use submitted AI content to train its own models. This is not a promise of zero retention or no model improvement by a provider. Anthropic processes content under its Commercial Terms of Service, which govern how it may retain and use API inputs and outputs. Hosted AI requires a verified active subscription and available credits. We record request identifiers, reserved and reconciled costs, and billing-period credit balances to enforce allowances; these ledger records do not contain your prompts or generated responses. Do not submit passwords, API keys, payment-card details, health records, confidential material, or personal data about others to hosted AI. Review Anthropic’s Privacy Policy and Commercial Terms of Service.

4. Information we collect and why

CategoryExamples and sourcePurpose
Account and authentication informationYour email address, account identifier, subscription identifier, authentication status, session information, and security events. Supabase Auth securely manages passwords and email verification for current accounts. Legacy installations may retain a one-way activation-code hash; older accounts may also retain a salted password hash and recovery-code hash. Zap does not store plaintext passwords or send them to Stripe.Create and secure your account, verify your email, connect website purchases to the app, let you sign in with email and password, and prevent accidental duplicate subscriptions.
Contact, support, and billing informationName, reply email, issue category, platform, optional app version, subject, issue description, billing address, country, and related correspondence supplied by you or returned by Stripe after checkout.Process subscriptions, provide receipts, receive and respond to support tickets, reproduce and fix reported issues, prevent fraud, and meet tax, accounting, and legal duties.
Commercial informationPlan, price, subscription status, purchase and renewal dates, invoice, customer, and checkout identifiers from Stripe.Complete checkout, activate paid features, manage plans, provide the Customer Portal, and maintain transaction records.
Product feedbackAn AI model name and optional reason that you submit through the model-request form. The saved request contains a request identifier and submission time, without an account identifier, email address, or IP address.Review suggestions privately and prioritize model support and product improvements.
Device and license informationA randomly generated app device identifier, derived device hash, entitlement and refresh-credential hashes, app version, plan, and feature claims. We do not use a hardware serial number for activation.Bind entitlements to authorized devices, secure subscription and admin activation, refresh access, prevent abuse, and deliver compatible updates.
Internet and service activityIP address, request time, requested route, browser or user-agent information, response status, and security events generated when you visit the site or call billing and update services.Deliver and secure the service, rate-limit abuse, diagnose failures, and maintain availability.
AI input and outputText, custom instructions, selected prior answers, attached screenshots, and generated responses. Screenshots may include information about other people.Fulfill the AI request you initiate. Input passes through Zap’s hosted service to the inference provider; output returns to your app. These contents are not written into Zap’s account, support, or quota records unless you separately submit them for support.
Local app informationDrip Type drafts, typing settings, and AI preferences supplied in the app.Provide the local feature you selected. This information stays on your device unless you choose to submit it to Zap AI.

We obtain information directly from you, including when you create an account or submit the support form; automatically from the app or browser when it contacts our services; and from Stripe when you purchase or manage a subscription. We do not collect payment-card numbers; Stripe processes payment credentials on its hosted pages. Zap does not send your password or recovery code to Stripe. The support form does not accept attachments, and we ask you not to include passwords, recovery codes, full payment-card numbers, private clipboard content, or other sensitive information.

5. How we use information

Where data-protection law requires a legal basis, we rely on performance of our contract with you, compliance with legal obligations, and our legitimate interests in operating and securing a limited, local-first subscription service. Where consent is required, we will request it separately and you may withdraw it as permitted by law.

6. Cookies, local storage, and analytics

The account flow uses essential __Host-zap_access and __Host-zap_refresh cookies to keep you signed in and securely connect checkout, payment verification, and billing management. The access cookie lasts up to one hour; the refresh cookie lasts up to 90 days and can be renewed during use. Both are HttpOnly, Secure, and SameSite=Lax, so page scripts cannot read them. Signing out clears them. The old __Host-zap_purchase cookie is cleared when you sign in to the new account flow.

The Zap pages on tryzap.net do not run advertising pixels, cross-site tracking, or writing-content analytics. Optional first-party visit analytics run only after you choose Allow analytics, and respect Do Not Track and Global Privacy Control. We do not use third-party session replay, remote Google Fonts, or externally fetched profile avatars on these pages. The following storage is necessary to provide features you request:

These necessary technologies are not used to profile you or follow you across websites. Their notice is separate from optional analytics consent. If you opt in to visit analytics, we issue signed, anonymous browser and session identifiers in secure HttpOnly cookies: the browser identifier expires after 30 days and the session identifier after 30 minutes. The analytics service receives one-way keyed identifiers and the public page path; it does not receive your email, account ID, raw IP address, search parameters, referrer, prompts, or writing. We count consenting browsers, sessions, and page views to understand site usage. Analytics events older than 90 days are removed when the service next records a visit; cleanup can be delayed during inactivity or outages. These counts do not include people who opt out or use browser privacy signals. Use Analytics choices to change your preference at any time; declining clears the analytics cookies. Necessary billing records separately measure checkout starts and verified purchases. We do not join anonymous visit identifiers to accounts or purchases. Stripe-hosted checkout and Customer Portal pages may use cookies or similar technologies under Stripe's Privacy Policy. Hosting and security providers may process ordinary request data needed to deliver and protect the site.

7. When we disclose information

We disclose limited information only as needed to:

We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics about you.

8. Retention and deletion

Local drafts disappear when their in-memory session ends. Local preferences, device identifiers, and data from retired features remain until you remove the relevant application data. The subscription refresh credential is stored in macOS Keychain or encrypted using Windows Data Protection API (DPAPI) until it is replaced, access is revoked, or you remove the relevant application data.

Support tickets become eligible for deletion after 90 days. A scheduled daily cleanup and ticket access remove expired tickets from Zap’s active private support store; outages or failed cleanup jobs can delay removal. Account, billing, subscription, device-hash, security, and transaction records are retained for as long as reasonably necessary to provide account access, resolve disputes, prevent fraud, enforce agreements, and meet legal, tax, and accounting requirements. Hosting logs and payment records are also subject to the providers' retention practices. When information is no longer required, we delete or de-identify it where reasonably practicable.

DataStorage and retention
AI prompts, screenshots and answersHeld in app and request-processing memory for the feature; clear history or close the app to clear app history. Zap does not persist these in its account or quota stores. Provider retention and permitted uses are governed separately; we do not promise provider deletion at the end of a request.
Account and support recordsEncrypted in private hosted storage. Account records are maintained while needed for access and the legal, fraud-prevention, and dispute purposes above. Support records have the 90-day cleanup policy above.
Model requestsStored privately for product planning without a requester account or email. To request removal, contact support and include enough information to identify your suggestion. General hosting logs and separate hashed rate-limit counters may still record service activity.
Session, rate and usage recordsCurrent account access cookies last up to one hour and refresh cookies up to 90 days, with renewal during use; legacy website sessions may last up to seven days. Rate counters stop affecting requests after their short enforcement windows; stale counters are removed when their storage shard is next updated. AI quota records keep a daily count, with one rolling record per subscription. Expiry of a counter is not a promise of immediate physical deletion.
Checkout reservations and billing recordsA checkout reservation is valid for up to 35 minutes, then may be replaced on a later attempt. It stores billing identifiers and a one-way checkout proof, not card data. Stripe records, legal holds, and required financial records may remain after account deletion.

Account deletion requests are handled through support after proportionate identity verification. Clearing app history or signing out does not delete Stripe records or automatically cancel billing. Cancel renewal in the billing portal as well; tell support if you also want account deletion. If we retain information under a legal exception, we will explain that when responding to your request. Provider logs, backups, and records may have separate retention periods.

9. Security

We use measures designed for the information we process, including HTTPS, Supabase-managed password authentication and email verification, encrypted app session storage, Secure HttpOnly browser cookies, verified account access, server-side secret keys, rate limits, restricted admin access, and Stripe-hosted payment entry. We validate support requests to reduce accidental disclosure of credentials and payment-card data. macOS releases are signed and notarized, and published installers include checksums. No system is completely secure, so we cannot guarantee absolute security.

10. Your privacy rights

Depending on where you live and which law applies, you may have rights to know or access personal information, correct it, delete it, obtain a portable copy, restrict or object to processing, withdraw consent, or appeal a denied request. California residents may also have rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive equal service and pricing when exercising their rights. We do not sell or share information for cross-context behavioral advertising; a Global Privacy Control signal does not change those practices.

For California notice-at-collection purposes, the categories described above are identifiers and customer-record information, commercial information, internet or electronic activity, support communications, and content you voluntarily submit for AI processing. These categories are used and disclosed for the purposes and recipients described in Sections 4 through 7. We do not sell or share them for cross-context behavioral advertising.

Submit a request through the private support form with the summary "Privacy request." Tell us the right you want to exercise and the email associated with your subscription, if any. We may ask for information reasonably necessary to verify your identity and authority. An authorized agent may submit a request where permitted by law. We will respond within the period required by applicable law. You may also complain to your local data-protection regulator.

11. International processing

Zap is based in the United States, and our providers may process information in the United States and other countries. Processing outside your country may be subject to different laws. Applicable transfer safeguards and provider agreements must support the service concerned; this notice is not a certification that every provider or transfer is approved for regulated or sensitive data. Local writing content stays on your device unless you submit it to Zap AI as described in Section 3.

12. Children

Zap is not directed to children and is offered only to people who can form a binding contract and are at least 18 years old. Checkout requires confirmation that the purchaser is at least 18; we do not collect a full date of birth for this check. This self-declaration is not identity verification. We do not knowingly collect personal information from children through Zap. If you believe a child has provided information, contact us so we can review and delete it where appropriate.

13. Changes to this policy

We may update this policy when the product, providers, or law changes. We will post the revised version with a new effective date and provide additional notice when required. Material changes apply prospectively unless law permits otherwise.

14. Contact

Private support form
© 2026 Zap Pro.Legal center · Terms · Cancellation policy