Privacy policy

Zero Backlog LLC · v1.0.0 · last updated June 16, 2026

This Privacy Policy describes how Zero Backlog LLC ("Zero Backlog," "0switch," "we," "us," or "our") handles information in connection with the 0switch desktop application, the website at 0switch.com, and related services (together, the "Services"). By using the Services, you agree to this Policy. It works alongside our Terms of Service.

0switch is built local-first and privacy-by-default. The app runs on your device, your content stays on your device, and nothing is sent to us or to any third party except the specific data needed for a cloud feature you choose to turn on. This Policy covers the 0switch desktop application and the 0switch.com website; the website does not use cookies, analytics, or tracking technologies.

1. How your data is processed

0switch can run in different ways, each with different privacy implications:

  • On-device (default). Core features (dictation, transcription, text cleanup, document parsing and structuring, OCR, and chat) are configured to run on local models on your device first. When a feature runs on-device, your inputs and outputs never leave your machine and we never receive them.
  • Local-only mode. You can enable Local-only mode to force every capability to run on-device and disable all cloud processing (both the 0switch cloud and any third-party keys). The only network activity that remains is optional software/model downloads and app-update checks, which never include your content.
  • Bring your own keys (BYOK). If you add your own third-party provider API key, your key is stored in your operating system's keychain on your device and is never transmitted to or stored by us. Content you send through your own key goes directly from your device to that provider and does not pass through our servers; it is governed by your relationship with that provider and its privacy policy.
  • 0switch cloud (optional). If you sign in and use the 0switch cloud service, requests are routed through a proxy server we operate. See Sections 2 and 4 for what this does and does not retain. Note that more demanding features (deep reasoning, image understanding, and agent workflows) are configured to use the 0switch cloud by default when you are signed in; use Local-only mode if you want a guarantee that nothing leaves your device.

2. Information we collect

What we collect depends entirely on which features you use.

Stored only on your device (we have no access):

  • Your content (dictations, transcripts, meeting transcripts, runs, chat threads, templates, dictionary terms, and snippets) in a local SQLite database and local files.
  • App settings: interface, audio, language, and shortcut preferences in a local configuration file. These contain no personal or device identifiers.
  • Local app state: a small amount of local web-storage holding your theme, the floating widget's screen position, and (only if you sign in) your cloud session token.
  • Third-party API keys: kept in your operating system's secure keychain, never on disk in plaintext and never exposed back to the app interface.

Collected only if you create an account to use the optional 0switch cloud:

  • Account information: handled through our authentication provider when you create an account. Your email address and, if you provide them, your name and profile image, plus your plan and email-verification status. Sign-in is passwordless (one-time email code); we do not collect or store a password.
  • Session: a session token that keeps you signed in. We do not store your IP address or device/browser user-agent as part of your account.
  • Payment information: if we offer paid plans, billing is handled by a third-party payment processor; we do not store your full payment-card details.

This account and authentication data is the only information we hold on our servers. We store no content and keep no record of your individual activity.

Other:

  • Support communications: information you provide when you contact us for support or feedback.

We do not collect: behavioral or usage analytics, advertising or tracking cookies, tracking pixels, or any third-party analytics/telemetry SDK. The app contains none. We do not transmit your content for analytics, and we do not use your content to train any AI model. Optional crash reporting, where offered, is off by default, sends only anonymized diagnostics (never your content), and runs only if you opt in.

3. Device access and capture

Depending on the features you turn on, 0switch may access the following on your device. Most context-capture features are off until you enable them; the app requests the relevant operating-system permission first.

  • Microphone: for dictation and recording features.
  • System audio (which may include other people). 0switch includes features that can record system audio, which may capture the voices of other people (for example, other participants on a call). You are solely responsible for complying with the laws that apply to recording others, including obtaining any consent required in your jurisdiction.
  • Screen: manual screenshots, and full-screen capture for context (full-screen capture is off by default).
  • Active application: the name and basic metadata of your foreground app, captured only on runs you explicitly arm.
  • Clipboard: read into a run's context only when you enable it; a lightweight watcher otherwise tracks only a change signal, not content.
  • Files: files you attach, read into a run's context; off by default.
  • Calendar: read-only access to your Google Calendar, only if you connect it, to detect meetings.

Most of these are off until you enable them. This data is processed on your device, recordings are not retained unless you choose to save them, and data only leaves your device if a run uses a cloud feature, as described in Section 4.

Transcription, not voice identification. 0switch converts speech to text. It does not generate voiceprints, perform voice or speaker biometric identification, or use anyone's voice to identify, authenticate, or track them. Meeting transcripts label who spoke only by audio source (your microphone vs. system audio), not by analyzing the characteristics of any voice. We do not create or store biometric identifiers as defined by laws such as the Illinois BIPA, the Texas CUBI Act, or Washington law.

4. How your content reaches third parties

Your content is sent off your device only when you use a cloud feature:

  • BYOK providers: sent directly from your device to the provider whose key you supplied; it does not pass through our servers.
  • 0switch cloud: the content needed for a request (for example, the text, audio, or image to process, or the chat you send) passes through our proxy to an upstream AI provider that fulfils it, and the result is streamed back to your device. Our proxy relays this content to complete your request and does not store or log the content of your requests. Upstream providers we may route to include, for example, Groq and AWS; cloud transcription, language, OCR, and agent web-search features may use providers such as OpenAI, Anthropic, Mistral, Deepgram, AssemblyAI, AWS, and search providers (Brave, Tavily, Serper, or DuckDuckGo), depending on your settings.
  • Connected services: if you connect Google Calendar, calendar data is exchanged with Google under its terms.

In all cases, content you send to a third-party provider is also processed by that provider under its own terms. We do not sell your personal information and do not use it for advertising.

International transfers. We are based in the United States, and the providers that handle account data or cloud requests (such as Cloudflare and our upstream AI providers) may process data in the United States and other countries. Where we transfer personal data out of the EEA or UK, we rely on an adequacy decision where one applies, or otherwise on the European Commission's Standard Contractual Clauses (and the UK Addendum).

5. How we use information

We use the limited information we collect to: provide and operate the Services; authenticate your account and secure the cloud service; process payments and send related notices; respond to support requests; detect and prevent fraud or abuse; and comply with legal obligations.

Legal bases (EEA/UK users). We rely on these lawful bases under the GDPR: performance of a contract, to create and operate your account and process the cloud requests you send; legitimate interests, to keep the cloud service secure and prevent fraud and abuse; consent, for anything you opt into, such as crash reporting (you can withdraw it at any time); and legal obligation, to retain limited information where the law requires it.

6. How we share information

We do not sell your personal information. We share information only with:

  • Service providers that operate the Services on our behalf: our cloud host (Cloudflare), our authentication provider, the upstream AI and search providers described in Section 4, and, for paid plans, our payment processor. They access data only to perform their function.
  • Legal and safety: when required by law, regulation, or legal process, or to enforce our terms and protect the rights, property, or safety of anyone.
  • Business transfers: in connection with a merger, acquisition, or sale of assets.

7. Other network connections

The app makes a few connections that do not carry your content: on launch it checks our release channel (GitHub) for updates, and when you choose to install a model or engine it downloads the file from sources such as Hugging Face or GitHub over HTTPS. These remain available even in Local-only mode because they are needed to obtain and update on-device software.

8. Data storage, retention, and security

  • Local by default. Your content is stored only on your device. We do not back up or synchronize your local database to the cloud; the only backup feature is a local file you export and import yourself (limited to your dictionary terms and snippets). Because your data is local and not backed up by us, you are responsible for your own backups.
  • No cloud storage of content. We do not store the content of your requests on our servers. The only data we hold on our servers is the account and authentication data for accounts you create, retained while your account is active; we keep no content and no log of your individual activity.
  • Encryption at rest. The app does not encrypt the local database itself; at-rest protection is provided by your operating system and device (for example, full-disk encryption such as FileVault or BitLocker). We recommend enabling it. API keys are stored in your OS keychain, and your cloud session token is held only in memory while the app runs.
  • Security. We use commercially reasonable measures to protect information, but no method of storage or transmission is completely secure, and we cannot guarantee absolute security.
  • Breach notification. If a security breach affects personal data we hold, we will notify affected users and any authority required by law without undue delay.
  • Legal retention. We may retain limited information as necessary to comply with law, resolve disputes, and enforce our agreements.

9. Your choices and rights

  • Stay local. Enable Local-only mode at any time to keep all processing on your device.
  • Control local data. Your content lives on your device; you can view, export, or delete it directly, including by removing local files or the app.
  • Account. You can sign out or delete your account at any time; deleting your account removes the account and session data held by our authentication provider, subject to any retention required by law.
  • Provider keys. You can add or remove your own provider keys at any time; they are stored only on your device.
  • Your rights. For the limited account data we hold, you can ask us to access, correct, delete, export, restrict, or object to our processing of it, and to withdraw any consent at any time. EEA/UK users have these rights under the GDPR. Contact us (Section 12); we will respond within the period the law requires, at no charge, and will not treat you differently for asking.
  • Complaints (EEA/UK users). If you believe we have mishandled your data, you may lodge a complaint with your local data-protection supervisory authority (in the UK, the Information Commissioner's Office).

10. Children's privacy

The Services are intended for adults and are not directed to children. You must meet the minimum age in our Terms (at least 13, or the minimum age of digital consent in your country if higher). We do not knowingly collect personal information from children below that age; if you believe a child has provided us data, contact us and we will delete it.

11. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will update the "Last updated" date above. Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy.

12. Governing law and contact

This Policy is governed by the laws of the State of Wyoming, without regard to its conflict-of-law principles, and any dispute is subject to the exclusive jurisdiction of the courts located in Wyoming. The data controller is Zero Backlog LLC, 28 Geary St STE 650 Suite #514, San Francisco, California 94108, United States. Questions about this Policy? Contact us at support@0switch.com.