On September 18, 2026, a developer going by ferstar published a reverse-engineering walkthrough of ZCode, the AI coding desktop app from Z.ai, the Beijing-headquartered company behind the GLM family of open-weight models. The finding: whenever the app is logged in, it silently packages the user's entire workspace—complete .git history, LFS asset cache, reflogs, and global app configs—encrypts it, and uploads the archive to Aliyun OSS. One capture: a 313MB encrypted archive from a 345MB commercial workspace (42,411 files), with 564 failed upload attempts logged while investigating.
If you run GLM locally, the company that publishes the weights is not the same thing as the runtime a developer might use on top of them. Several commenters assumed ZCode was open source because GLM is. It is not. The weights are open; the harness is closed.
Envelope encryption with a server-only key
ZCode uses envelope encryption: the payload is encrypted with a symmetric key, and that key is wrapped with an RSA-OAEP public key delivered by the server during upload-credential negotiation. The corresponding private key lives only in Z.ai's cloud. ferstar's conclusion: "A key that only the server can use serves exactly one purpose: making sure the server can read your code whenever it wants."
What gets packed
In one 42,411-file snapshot, .git/lfs/ was 196.1 MB (56.8%), .git/objects/ 102.2 MB (29.6%), with source and docs only ~13.4%. The .git directory alone was 86.6% of the payload—years of lineage, not just open files.
The upload pipeline (from app.asar): credentials from zcode.z.ai → pack tar.gz → AES-256-CTR encrypt → form POST to Aliyun OSS → callback to Z.ai.
The toggles do not stop it
- "Optimize Experience" only controls training authorization; snapshot upload continues.
- "Repo Snapshot Indexing" only controls server indexing; local packaging and upload continue.
The capture sidecar starts unconditionally when a valid JWT is available. Session logs showed 62 capture events from a single session. OrcaPromptVault's captured ZCode system prompt shows checkpoint/rewind templates but zero snapshot/upload/telemetry tools—the pipeline is host-level, outside the agent tool loop.
Privacy policy gap
ZCode's privacy policy discloses conversational "text, files, and code submitted during conversations" but, per ferstar, does not mention packaging and uploading entire workspaces and git histories.
Defense that works
Deleting the pending archive does not stop re-packaging. Filesystem-level immutability on ~/.zcode/v2/checkpoints does:
Linux: chattr +i ~/.zcode/v2/checkpoints
macOS: chflags uchg ~/.zcode/v2/checkpoints
Trade-off: checkpoint rollback UI stops; chat and tools continue.
What it means for local AI
A locally-running model wrapped in a cloud-phoning harness is not local. Two checks for every harness: what does the runtime transmit when logged in, and who can decrypt what it stores.
Sources include ferstar's forensics post and X threads; see the original Tokenstead guide for full diagrams and citations.