A leading product engineering company, creating adaptive software solutions to improve operations, providing businesses with expert development services from across domain.
A leading product engineering company, creating adaptive software solutions to improve operations, providing businesses with expert development services from across domain.
AI coding tool data privacy: a researcher found ZCode packaging whole workspaces, Git history included, for upload. What to check on your tools and vendors.

A developer clearing disk space found a 313MB encrypted file in the data folder of ZCode, the desktop coding agent from Chinese AI company Z.ai. It turned out to be most of a commercial project — including its full Git history — packaged for upload to cloud storage, encrypted to a key only the vendor holds. The report is a sharp reminder that AI coding tool data privacy is decided by what the software actually does on the developer's machine, not by what the privacy page says.
In a detailed reverse-engineering write-up published on 18 September, the developer, who goes by ferstar, describes finding a 313MB archive in ZCode's local data directory, with metadata recording 564 failed upload attempts. By unpacking the application, they reconstructed the flow:
node_modules but including the complete .git history, Git LFS cache and app configuration.Because the private key is held on the server, neither the user nor the ZCode client can decrypt the archive sitting on the user's own disk. The researcher reports that the "Optimize Experience" setting governs whether data is used for model training, not whether the upload happens, and that they found no mention of whole-workspace uploads in the privacy policy, FAQ or changelog.
RuntimeWire's account adds the payload breakdown: 42,411 files in a 345.5MB workspace, with the .git directory making up 86.6% of the archive. It also makes the important caveat: the test establishes the behaviour of one installation, not how widely the mechanism was deployed across versions, accounts or regions.
A working directory shows today's code. A Git object store holds everything the repository has ever contained. As RuntimeWire notes, that can include deleted credentials, old configuration files, unpushed branches, internal hostnames and unreleased work. A secret removed from the code two years ago is still in the history unless someone rewrote it. So a snapshot of .git is not a copy of the product; it is a copy of its whole lineage.
It can be, but only with tools whose data handling you have verified. Coding agents need broad access to a repository to be useful — that is exactly why they are powerful — and it is also why the desktop client, and who holds its keys, sit at the centre of the trust question. This is not a question about one vendor or one country. Any tool with repository access and a network connection can send more than it needs to.
For companies that write their own software, the practical questions are:
If an agency or outsourcing partner builds software for you, their tools touch your code too. Add these to your vendor due diligence, alongside the usual questions in our guide to choosing a software development partner:
A good partner will answer quickly, because they will have had to answer the same questions for themselves. We covered what else to ask in what CTOs should look for in a development partner.
AI coding tools are now part of how software gets built, including by us. The answer is not to ban them but to treat them like any other supplier with access to your most valuable asset. If you want an independent review of how AI tools touch your codebase — yours or your vendor's — our custom software development team can help set the policy and the controls.
AI coding tools can be safe on proprietary code when you have verified what they send off the machine, where it is stored, who holds the keys, and how long it is kept. Use business plans with contractual limits and monitor network egress from developer machines.
A developer found ZCode packaging a 345MB commercial workspace, including its full Git history, into an encrypted archive for upload to Alibaba Cloud storage, with 564 retry attempts. The encryption key was held by Z.ai's server, so the user could not decrypt it.
Git history contains everything a repository has ever held, including deleted credentials, old configuration, internal hostnames and unpushed work. Uploading the .git directory therefore exposes far more than the current code in the working directory.
Ask which AI coding tools touch your code and under which account type, whether they retain or train on your code, how secrets are kept out of them, for the tools' data processing terms, and to be told before any new tool is adopted.
Ready to take the first step towards unlocking opportunities, realizing goals, and embracing innovation? We're here and eager to connect.
11th Floor, O-Hub, Chandaka Industrial Estate, Infocity, Bhubaneswar, Odisha 751024
Level 4, 11 York Street Sydney Startup Hub Sydney, NSW – 2000
30 N. Đinh Nghệ, Phước Mỹ Sơn Trà, Đà Nẵng / Da Nang City – 550000
Level 25, AIDP Business Tower, Dubai Marina, United Arab Emirates
50 Beauchamp Street, Wellington, WGN 5028, New Zealand