Privacy & local-first
Last updated 17 September 2026.
Zoran watches your coding sessions on your machine. The cloud exists for one reason: so your phone can ring. It relays events, calls, and decisions — it never receives your source code.
What stays local
- Your source code and files
- Session transcripts — read locally and on demand only, never persisted, never synced
- Your device secret and configuration (
~/.zoran/, owner-only permissions)
What goes to the cloud
- Device identity: a random id, a hashed secret, your phone number, your preferences
- Session metadata: project folder name, event type, tool name, and a tool preview truncated to 80 characters with obvious secrets redacted before it leaves your machine
- The decision log: what rang, what you answered, when — this is what your dashboard shows
- The credit ledger: top-ups and per-call/SMS charges
- When you ask a question by voice or SMS: a short, redacted context summary built locally by the daemon. It is ephemeral — used to answer you, then deleted (minutes, not days)
Who controls this data
Polymerix Labs Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, is the data controller for Zoran. For anything in this policy, write to support@polymerix.io. A person reads it, not a form.
What we collect, and why
- Device id, phone number, preferences — running the service you signed up for: calling the right phone, in the right voice (contract)
- Session metadata and decision log — the product itself: pending decisions, activity feed, audit of what was allowed or denied (contract)
- Credit ledger — prepaid billing; card details are Stripe's, not ours (contract)
- Support messages you send us — answering you (legitimate interest)
We never sell data, and we never train a model on anything the daemon observes. The ephemeral Q&A context leaves your machine only to answer your own question.
Who else sees it
We use a small set of processors to run the service. Each sees only what its job requires; none may use it for their own purposes:
- Scaleway — hosting, in the EU (France); this is where device data and the decision log are stored
- Twilio — places the calls and sends the SMS; sees your phone number and the spoken/texted content
- Stripe — billing; they hold your card details, we hold a customer reference
- Anthropic — answers voice and SMS questions when the assistant is enabled; receives the redacted, ephemeral context, never your source
Some of these process data outside the UK/EEA. Where that happens, it is under that provider's own standard contractual safeguards for international transfer. Ask us for details at support@polymerix.io.
How long we keep it
Device data and the decision log: for as long as your device is active. You can ask us to purge everything at any time. Voice and SMS question context: minutes — deleted when the call ends or shortly after. Billing records are kept as long as required by tax law.
Cookies
The site sets no cookies. The dashboard keeps your device token in your browser's local storage, read only by the dashboard itself. No analytics, no advertising trackers.
Your rights
Under UK/EU data protection law you can ask us to: send you a copy of your data, correct it, delete it, restrict how we use it, or move it elsewhere. Write to support@polymerix.io and we'll act within a month. If you think we got something wrong, you can also complain to the UK Information Commissioner's Office (ico.org.uk) or your local EU data protection authority.
Children
Zoran is a developer tool, not directed at anyone under 16.
Changes to this policy
If this changes in a way that matters, we'll notify you before it takes effect. The date at the top of this page is always the true version.
Zoran is a product of Polymerix Labs Ltd · Terms