← Zeki
Privacy Policy
Effective: July 5, 2026
The short version: Zeki is designed so we see as little of your data as possible.
• With your own API key, your messages go directly from your device to your AI provider — never through our servers.
• Your API keys live in the Apple Keychain on your device. We never receive them.
• Your chat history stays on your device.
• Zeki contains no ads, no trackers, and no analytics.
Who we are
Zeki is an independent app for Safari on macOS, iOS and iPadOS. For any privacy question or request, contact us at [email protected].
What Zeki does
Zeki adds an AI assistant sidebar to Safari. To answer your questions it sends the messages you write — and, when you use page-related features, text extracted from the page you are viewing — to an AI model. How that data travels depends on which mode you use.
Bring-your-own-key (BYOK) mode
- Your requests (messages, page excerpts, attachments) are sent directly from your device to the AI provider you chose (Anthropic, OpenAI, Google, OpenRouter, Groq or Mistral), using your own API key.
- We operate no server in this path. We cannot see, store or log your conversations.
- Chat history stays on your device. If you enable iCloud sync (off by default), conversations are stored in your private iCloud database, readable only by your devices — never by us.
- Your use of the provider is governed by that provider's own privacy policy and terms.
Subscription (managed) mode
- If you use Zeki without your own API key, your messages are relayed through our proxy service (hosted on Cloudflare) to Google's Gemini API and the reply is streamed back to your device.
- We do not store the content of your messages or the AI's replies. Message content passes through the relay and is not written to any database.
- For abuse prevention and rate limiting, the relay processes: a random per-install identifier generated by the app (not tied to your identity), your IP address (as part of normal HTTPS traffic), and request counts. Operational logs record technical metadata (timestamps, response codes, model tier) — not message content.
- Free usage without a key is limited per day; these counters are keyed to the random install identifier.
Your API keys
- Keys are stored in the Apple Keychain on your device, encrypted at rest by the operating system.
- Keys are never synced off the device by Zeki, never sent to our servers, and never included in logs or diagnostics.
- The only network use of a key is authenticating your direct requests to the provider you chose.
Chat history and settings
- Conversations, prompts and settings are stored locally on your device.
- If you enable iCloud sync for settings/prompts, that data is stored in your personal iCloud account under Apple's protections; we have no access to it.
- You can delete any conversation, or all history, at any time from within Zeki.
Web search and page fetching
When the assistant searches the web or opens a linked page to answer you, those pages are fetched by your browser on your device (search queries go to DuckDuckGo). Our servers do not fetch pages on your behalf and do not see your browsing.
Diagnostics
Zeki sends no automatic crash reports or telemetry. If you choose to report a problem, you can copy a diagnostics report to your clipboard and send it to us yourself. It contains version information and recent error messages only — never your chats, page contents, browsing history or keys — and you can read exactly what it contains before sending it.
Purchases
Subscriptions are processed by Apple through the App Store. We receive subscription status (for example, "active subscriber") but never your payment details. Receipt validation is performed against Apple's servers.
What we never do
- No ads, no ad identifiers, no cross-app tracking.
- No sale or sharing of personal data with third parties.
- No reading of your browsing history, cookies, bookmarks or passwords.
- No analytics SDKs inside the app or extension.
Data retention and deletion
Because your conversations live on your device, deleting them in Zeki deletes them — there is no server copy. Managed-mode rate-limit counters expire automatically within 24 hours. Operational logs of the relay are retained briefly for reliability and abuse prevention and contain no message content. To reset the random install identifier, uninstall and reinstall the app.
Children
Zeki is not directed at children under 13 (or the equivalent minimum age in your jurisdiction) and we do not knowingly collect data from them.
Changes
If this policy changes, the updated version will be posted here with a new effective date. Material changes will be noted in the app's release notes.
Contact
[email protected]