> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zas.red/llms.txt
> Use this file to discover all available pages before exploring further.

# What the server can see

> A plain list of what Zas records about your account, your items and your links, where that data sits, and how long it is kept.

Your content is encrypted on your device. The server still needs some data to deliver it. This page says exactly what that is.

<Note>
  The binding text is the [Zas privacy policy](https://zas.red/privacy). This page follows it and does not add to it.
</Note>

## What the server does see

**About you.** Your account or session, the profile details received at sign-in, the channels you own or follow, their members, and the notification tokens for your devices.

**About each item.** Its channel, sender account, date, size, expiry, and state. For a stored file the server also links the account, the upload session, and a random storage object ID. That object holds encrypted bytes, not the open file.

**About each public link.** How many times it was opened, copied, and downloaded. Zas analytics does not identify the person who opens it. If you ask for a preview of an external link, the server receives that address. If you report a link, Zas stores the reason and the link and account IDs.

**About the connection.** Infrastructure can process the IP address, device or browser type, and connection data in security and operating logs. The Direct relay sees network data for both ends, but not the content. The older file system can also recognize that an encrypted chunk repeats.

This data supports sign-in, delivery, synchronization, abuse limits, and fault diagnosis. It is not a readable list of your content.

## What the server does not receive

The database and object storage do not receive open filenames, titles, content, or previews.

## An agent does not change this

An item sent by a [coding agent](/en/agents/index) is encrypted on your machine by the same code the app uses. The server sees the same fields as for any other item, plus the agent's own identifier on the link, which is what draws the `>_` mark.

It still never receives a channel key, a channel name or item content. An agent cannot derive your account key either: the key-derivation service refuses it.

## Where it is stored

| Provider | What it holds |
| - | - |
| Google Firebase | Authentication, database, hosting, notifications |
| Cloudflare | Stored files as encrypted chunks (R2), the Direct relay, and temporary encrypted copies |
| PostHog, Google Analytics | The analytics described below |

These providers can process data outside Argentina. Zas does not sell data and does not share it for advertising.

## How long it is kept

* An item in an account: **5 days**. In an anonymous session: **2 days**.
* A temporary copy made to rescue a failed Direct transfer: **no more than 24 hours**, and sooner once the receiver finishes downloading it.
* A session left empty: **30 minutes**.
* A pinned item: until you release or delete it. That is your decision, not the product's.
* An open abuse report is kept until it is reviewed. A resolved report is deleted after 90 days.

## Analytics

Zas measures the product, not you.

**What can be sent:** the internal account ID, technical device or session IDs, app and system version, plan, language, total storage use, and numbers such as size, duration and result.

**What is never sent:** text, file or channel names, MIME type, profile photo, email address, name, content IDs, secret links, or full addresses.

**Where analytics does not load at all:** public links, anonymous sessions, and the Apple share extension and widget.

There is no autocapture, no screen or session recording, no advertising, and no cross-app tracking. Invitation pages record only closed stages and outcomes, such as viewed, signed in, accepted, failed or retried.

## Data kept on your device

To resume an interrupted upload, the website keeps a queue in IndexedDB. That queue can hold the original file and its encrypted parts with their keys until the send finishes or you cancel it.

The apps keep the session, keys, settings, transfer queue, and the files needed to finish a transfer or open an item. Analytics does not receive any of that.

Signing out clears account-bound app state. Clearing site or app data clears normal local storage.

## Deleting your data

You can delete any item or channel from the app at any time. To delete everything, use **Settings → Delete my account**.

<Warning>
  One honest exception. For a legacy file that your browser cannot open, the server cannot safely identify its encrypted shared chunks. It removes the item record, and unpinned chunks keep their existing expiry. A historical pinned chunk can remain, because deleting it could affect another person.

  Providers can also retain backups and security logs for their normal retention periods.
</Warning>

<Card title="Export and delete" icon="file-zipper" href="/en/using-zas/export">
  Take everything with you first.
</Card>

## Your rights

You can ask for access to your personal data, correction, deletion, and withdrawal of consent where processing depends on it. Zas may ask you to confirm the account is yours.

Where Argentina's Law 25,326 applies, Zas answers an access request within 10 calendar days, and a correction, update or deletion request within 5 business days. If the answer is missing or insufficient, you can complain to the AAIP, Argentina's data protection authority.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.