Last updated: August 2026
The best security policy is not having your data in the first place.
Your code never leaves your machine. Your API keys never touch our servers. What we do collect is anonymous usage data: the kind that helps us understand what's working and what's broken.
You can opt out of everything by going to settings, so even anonymous usage data will not go to the server.
ZeroSphere is BYOK (Bring Your Own Keys). When you run the agent, your code goes directly to your model provider, whether Anthropic, OpenAI, or Google, using your API key. It never touches our servers.
ZeroSphere runs on your machine. The editor, the agent, the virtual display, and the build-run-fix loop are all entirely local.
We can't leak what we don't store.
We only collect data that helps us prioritize what to fix and what to build. This includes:
Which tools are called, token usage, and where the agent fails. All completely anonymous.
Error rates, latency, and failure patterns so we know when something breaks before you do.
Logged purely for security, abuse prevention, and rate-limiting. Not tied to identity.
Most AI tools that interact with UIs read the DOM or the accessibility tree. That's the text layer underneath what you see, and it's exactly where prompt injection attacks live. A malicious website, a compromised dependency, or a crafted UI element can write hidden text into the DOM that an AI reads and obeys.
AI reads the hidden DOM text and obeys the attack.
Hidden text doesn't render. The attack is eliminated.
A screenshot is taken by an internal capture tool and passed directly to the model as an image. No DOM. No accessibility API. No text layer. No hidden instructions. This isn't a security feature we bolted on. It's a natural consequence of how vision-based perception works, completely eliminating hidden structural injection attacks.
ZeroSphere's agent operates inside an isolated virtual display, which is a sandboxed screen separate from your desktop. It interacts with your app inside that boundary. You control which applications it can launch and interact with. Every action is visible in real time. Nothing runs hidden.
The agent asks before it acts outside its expected scope. You can grant permissions per action type, revoke them mid-session, and see a full log of everything it did.
If you find a vulnerability, tell us before anyone else.
We respond within 24 hours.
No legal threats. No runaround.