Legal

Privacy Policy

Benchday shows you the terminal sessions running on your own computers. To do that, some of what is on those screens has to travel through our servers. This page explains exactly what travels, what we keep, who else sees it, and what you can switch off.

Last updated 2026-08-17 Zigzag Technologies, Inc. Terms of Service →

The short version

  • We relay your terminal, we don't mine it. While you are connected, live terminal content passes through our hub so it can appear on your phone or browser. That relay is never used for model training.
  • Model training is off unless you turn it on. New accounts start with it off. It is one switch, in Settings → Privacy & data, and you can turn it back off at any time.
  • Your machines stay yours. The Benchday daemon runs on your computer, opens no inbound ports, and the transcripts your coding agents write stay on that machine. Deleting your Benchday data does not reach into them.
  • Support cannot look at your content on a whim. Reading account content for debugging requires a grant you approve, scoped and time-limited, and every read is logged.
  • You can erase what we hold. "Delete my data" wipes the content the hub holds for your account while leaving you signed in.

This summary is here to be readable. The sections below are the operative terms, and they win if the two ever disagree.

01Who we are and what this covers

Benchday is a product of Zigzag Technologies, Inc., a company incorporated in Canada. In this policy, "Benchday", "we", "us" and "our" mean Zigzag Technologies, Inc.; "you" means the person using Benchday.

This policy covers the Benchday mobile apps, the desktop and web clients at benchday.zztech.io, the benchday command-line tool, the Benchday daemon you install on your own machines, and the hub service they connect to. It does not cover the coding agents you run (Claude Code, Codex, OpenCode, Aider and others), the terminal programs you launch, or any third-party service you reach from inside your own sessions — those are governed by their own terms and privacy policies.

Benchday is currently in private testing. Features, defaults and the details described here may change as it develops; material changes are handled under section 13.

02How Benchday works, in data terms

It helps to know the shape of the system, because it determines what we can and cannot see.

  • Your machines run a daemon. You install the Benchday daemon on computers you control. It manages tmux sessions locally and connects outbound to our hub, so you do not have to open any inbound port.
  • The hub relays. Our hub is the meeting point between your phone, browser or CLI and your machines. When you are attached to a session, terminal output travels from your machine through the hub to your client, and your keystrokes travel back the same way.
  • Some things are also stored. Features like session titles, read-aloud narration, search and "resume where I left off" need the hub to keep some content rather than just pass it along. That storage is described in section 3 and is subject to the controls in section 9.
  • Direct connections skip us. When your client and your machine can reach each other on the same network or over your own VPN, Benchday may connect them directly. In that case the terminal stream does not pass through our hub at all.

Benchday is not end-to-end encrypted. Terminal content is protected in transit, but our hub processes it in the clear in order to relay it and to run the features you ask for. If you would not want a service provider to be technically capable of seeing something on your screen, do not put it on a screen you attach to Benchday.

03What we collect

Account and identity information

To create and secure your account we hold a username, a password verifier (we store a cryptographic hash, never your password), and — if you sign in with GitHub or Google, or add one — an email address and the basic profile the provider returns, such as a display name and avatar. We record the devices registered to your account (a device identifier, a device name, app version) and the machines you enroll, so that we can route you to the right computer and so you can revoke access to any of them.

Terminal and session content

While you are attached to a session, live terminal content is relayed through our hub so that it can appear on your device, along with the input you send. This is the core of what the product does and it cannot be switched off while you are using the product to view a session.

Depending on the features you use and your privacy settings, the hub may also store derived or captured content: session and pane titles, summaries and digests, text used for search and for resuming past work, conversation context from coding agents running on your machines, and records of pane activity. Whether agent conversation context is stored on the hub is controlled by the AI context on hub setting.

Voice input

If you dictate, your audio is streamed to a speech-recognition engine to be turned into text — either an engine Benchday operates or one you configure yourself.

Voice audio retention is on by default. Recorded clips are kept on our server for 7 days so the feature can replay them, then deleted. You can turn this off at any time in Settings, under Privacy & data; with it off, dictation still works — your audio is transcribed and then discarded rather than stored. See also the retention rules in section 8.

Files you move

If you upload a file to one of your machines or download one from it through Benchday, the file passes through the hub in the same way terminal content does.

Diagnostics and usage

We collect operational telemetry needed to run the service: connection events, errors, performance measurements, network usage counters, app and daemon versions, and the coarse identifiers needed to attribute them to an account and device. The app also keeps a local "flight recorder" of what happened in the app; by default those recordings stay on your device and are not uploaded. Diagnostic logs reach us only when you push them, or under a support grant you approve (section 10).

Payment information

Paid plans are billed through Stripe. Stripe collects and processes your card details directly; we never receive your full card number. What we store is the reference identifiers Stripe gives us for your customer and subscription records, your plan tier, and its status and renewal date.

What we deliberately do not collect

  • Your SSH private keys and stored passwords. Those are held by the app on your own device and are not sent to us.
  • The contents of your machines at large. Benchday reads what you attach to and what you explicitly browse — it does not index your disks.
  • Advertising identifiers. We do not run ads and we do not sell or share personal information for advertising purposes.

04How we use it

  • To run the service — authenticate you, route you to the right machine, relay terminal content and input, move files, and keep sessions in sync across your devices.
  • To provide the features you invoke — titles, summaries, digests, narration, search, work items, and resuming past work.
  • To keep it working — diagnose faults, measure performance, prevent abuse, and protect the security and integrity of the service and of your account.
  • To bill you, if you are on a paid plan, and to support you when you contact us.
  • To improve models, only if you have turned that on — see section 5.
  • To comply with law, or to respond to a valid legal request.

We do not sell your personal information, and we do not use your terminal content to build a profile of you for marketing.

05AI features and model training

Two different things are easy to confuse here, so we separate them.

AI features you invoke

Benchday uses large language models to generate session titles, summaries, digests, read-aloud narration, suggested actions and search results. To do this, the relevant content is sent to a model provider on our behalf and a result comes back (see section 6). This happens because you are using the feature — it is not training.

Model training is opt-in

Using your session content to train or improve models is off by default. New accounts start with it off, you are shown the choice before you connect your first computer, and you can change it at any time in Settings → Privacy & data. Relayed terminal content is never used for model training.

If you do turn it on, understand that it cannot be fully undone. Content used to improve a shared model becomes part of that model. Turning the setting off later stops future use, and deleting your data removes it from our stores — but neither removes what a model has already learned. We tell you this in the app before you consent, and we are repeating it here for the same reason.

Turn it on only for sessions whose content you are actually allowed to share. If your work is under an employer's or client's confidentiality obligation, that is your call to make, not ours.

06Who else sees your data

We share data with service providers who process it on our behalf, for the purposes below and no other. We do not sell personal information.

WhoWhat they receive, and why
Model providers
SiliconFlow · OpenRouter
The content needed to fulfil an AI feature you invoked — for example the terminal text being titled, summarised or narrated. OpenRouter in turn routes requests to the model vendor that serves them.
Speech services Dictation audio, to transcribe it. This may be an engine Benchday operates or, if you configure one, an engine of your choosing.
Stripe Payment and subscription processing. Stripe takes your card details directly and is an independent controller of that data under its own privacy policy.
Infrastructure providers Hosting, storage, networking and object storage for the hub and update servers.
App distribution Apple and Google receive the information inherent in distributing and installing an app through their stores, under their own terms.

We may also disclose data where we are legally required to, where it is necessary to investigate abuse or protect the rights and safety of users or the public, or to a successor in the event of a merger, acquisition or sale of assets — in which case we will say so before your data becomes subject to a different policy.

07Where data is processed

Zigzag Technologies, Inc. is a Canadian company and also operates an affiliated entity in China. Our hub and the service providers listed above operate in a number of countries, and SiliconFlow is based in China. Using Benchday therefore involves your data being transferred to and processed in countries other than the one you live in, including countries whose data-protection laws differ from your own and where authorities may have rights of access under local law.

If that matters to your work, note that the AI features are the surface that sends content to model providers, and they can be limited through the settings described in section 9.

08How long we keep it

We keep data only as long as we need it, and the hub runs an automated age-based sweep that deletes stored content once it passes its retention window. Different classes of content have different windows: conversation and transcript text, session recordings, voice audio, activity records and suggestion-feedback records each expire on their own schedule, and voice audio has the shortest one.

  • Account and identity records are kept for as long as your account exists, and afterwards only as long as needed for security, dispute resolution and legal obligations.
  • Billing records are retained as long as tax and accounting law requires, independently of your content settings.
  • Relayed terminal content that is only passing through is not retained as a stored copy of your session; what is retained is the derived and captured content described in section 3.
  • Deleted data may persist briefly in backups and logs before being overwritten in the ordinary course.

Some accounts used for our own product development are exempt from these windows so that we can analyse our own usage. That exemption applies only to the account it is set on and cannot reach another user's data.

09Your controls

The controls live in the app under Settings → Privacy & data. They are real switches on real behaviour, not preferences we consult when convenient.

ControlWhat it does
Local-only modeStops the app sending content to the hub beyond what is needed to connect you.
AI context on hubGoverns whether agent conversation context is stored on the hub for titles, narration, search and resuming work.
Voice audio retentionGoverns whether dictation audio clips are retained on the hub.
Adaptive-chips trainingThe model-training consent from section 5. Off unless you turn it on.
Session recordingPer-device. Controls the local flight recorder.
Push log nowPer-device, and deliberately manual — sends a diagnostic log to us when you decide to.
Delete my dataErases the content the hub holds for your account. See below.

What "Delete my data" actually does

It removes the content the hub stores for your account — recordings and their audio, activity records, pane journals, suggestion observations and feedback, and the agent conversation context, titles, search text, embeddings and inventories belonging to the machines you own. It keeps your identity — your account, devices, grants and sign-in — so that you stay logged in and can keep using Benchday. It does not touch the transcripts and files on your own machines, which were always yours and never ours to delete. As noted in section 5, it also cannot reverse the effect of content that was already used for model training.

Access, correction and complaints

You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete your account entirely rather than just its content. Write to contact@zztech.io and we will respond within a reasonable period. Depending on where you live you may also have the right to complain to a data-protection authority.

10Support access to your account

Sometimes diagnosing a problem needs someone at Benchday to look at data from your device or account. That is gated:

  • Access requires a grant you explicitly approve for a specific request. Without one, nothing is readable through this path.
  • The grant is scoped — a grant covering device diagnostics does not extend to your content.
  • It is time-limited, expiring 24 hours after you approve it, and you can revoke it before then.
  • Every read under a grant is logged, rate-limited, and returns only a bounded, recent sample. The content read this way is not copied into another store.

Separately, a small number of our staff can access production systems as part of operating them. Access is limited to what the role requires.

11Security

  • In transit, client-to-hub and daemon-to-hub connections use TLS. Daemons authenticate with per-machine keys, and self-update packages are signature-verified.
  • Passwords are stored as argon2id hashes, never in a recoverable form.
  • On your device, SSH keys and saved passwords are held in the platform's encrypted secure storage — Keychain on iOS and macOS, the Keystore-backed store on Android — optionally behind biometric authentication. In the browser version there is no such platform store: the same values are kept in ordinary browser storage, which is protected only by your browser and your operating system. If that matters to you, use the app rather than the web portal for machines whose credentials you store.
  • At rest, we are rolling out per-account envelope encryption for stored content, so that a stolen database, snapshot or backup does not by itself reveal it. Where it is enabled for your account, the app tells you so in Settings → Privacy & data. This is server-side encryption, not end-to-end: our services can decrypt content in order to provide features such as search and narration.

We hold no security certifications. Benchday has not been audited against SOC 2, ISO 27001, HIPAA or any comparable standard, and we make no such claim. No system is perfectly secure, and we cannot guarantee that yours will never be compromised.

12Children

Benchday is a developer tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, write to contact@zztech.io and we will delete it.

13Changes to this policy

We will update this policy when what the software does changes. The "Last updated" date at the top always reflects the current version. If a change materially reduces your privacy or expands how we use your data, we will give you notice in the app or by email before it takes effect, and where the law requires consent we will ask for it rather than assume it.

14Contact us

Questions about this policy, a request about your data, or a security report — one address reaches us for all of it.

Talk to a person

Privacy questions, data requests and security reports all go to the same place, and a human reads them.

contact@zztech.io

Zigzag Technologies, Inc.
Canada · zztech.io