Z.ai Open-Sources ZCode After Data Uploading Scandal

Z.ai said that it has open-sourced its coding tool, ZCode, after the Chinese AI firm faced intense backlash from developers who found out that their data was being uploaded to cloud servers without their consent.
“In response to the ZCode product security issues reported by the community, we have completed the necessary remediation and sincerely apologize to all our users,” ZCode’s official X account said in a post on Monday.
“With respect to the code data referenced by the community, we confirm that no such data is retained and that it has never been used for model training,” Beijing-based Z.ai, whose shares are listed in Hong Kong, said in the post.
On Friday, a tech blogger known as Ferstar published an analysis of ZCode, revealing that the desktop coding app automatically bundles, encrypts and uploads users’ local repository data—including the entire timeline of the project and stored files—directly to Z.ai’s cloud servers without asking for user consent. Ferstar’s X post about ZCode has amassed 1.6 million views.
The discovery triggered widespread outrage from developers on social media and shook users’ trust in Z.ai. Earlier this year, xAI’s Grok Build faced similar controversies when a security researcher discovered that the coding tool was uploading users’ code repositories to cloud servers without user consent. In response to users’ backlash, xAI open-sourced Grok Build, just like Z.ai did with ZCode this time.