Trust & security

Your content, and who can see it

The short version

Everything you put in Zegazone is private until you decide otherwise. Sharing is something you do deliberately, one collection at a time, and you can undo it. When a collection is public, it is genuinely public — and nothing else is.

What “private” actually means here

Every time anyone asks for one of your files — a page load, a thumbnail, an agent reading through the API — our servers check whether that particular request is allowed, right then. There is no shortcut where something is trusted because it was trusted a moment ago.

If a request is unclear or something goes wrong, the answer is no. Private is the default the system falls back to, not a setting you have to remember to switch on.

One honest detail about revoking access: files are served using short-lived signed credentials, so someone who had a collection open at the moment you removed them may be able to keep loading its files for up to an hour, until the credential their browser is holding expires. New visitors are stopped immediately. We would rather tell you that than let you assume a revoke is instant everywhere.

Sharing, and taking it back

  • Privateonly you.
  • Shared with specific peopleonly those you invite, and only for that collection. You can remove someone at any time.
  • Publicanyone with the link, and search engines. This is the one that means what it says: a public collection's images and files are served openly, so that pages load quickly for everyone. Make a collection public only when you would be comfortable with a stranger seeing it.

Moving a collection back from public to private stops it being served to new visitors. As with anything on the internet, we cannot recall a copy someone already downloaded.

What we can see

We run an internal admin tool for keeping the service healthy — checking accounts, storage totals, sign-up dates, that sort of thing. It cannot open your files. It shows counts and account details, never the contents of your collections, never your images or documents, never the text of your private notes. That boundary is built into what the tool is able to do, not just a rule we ask ourselves to follow.

What we are not claiming

Zegazone is not end-to-end encrypted, and we would rather say so plainly than imply otherwise.

End-to-end encryption would mean our servers could never read your content — which sounds ideal until you notice it would break the things Zegazone is for. We could not generate thumbnails, could not show you a preview of a document, and could not let an AI agent you have authorised read a collection and act on it. That last one is the heart of the product.

So here is the honest position.

Your content is protected from other users by a check on every single request. It is protected from casual internal access by an admin tool built without the ability to read your files at all.

What is left is infrastructure access — the credentials that administer the servers and storage themselves. Those are held by Zegazone’s founder alone. They have never been issued to anyone else, and only he can issue them. There is no support team who can open a ticket and look inside your collections, no analytics team working from a copy of the database, no on-call engineer with standing access — not because we ask those people to behave, but because no such credentials have been handed out.

That is a smaller circle than at most services you use, where access is granted to entire teams as a matter of ordinary operation. It is not zero, and we will not pretend otherwise: a service that can generate your thumbnails is, by definition, a service that can read your files. What we can tell you is exactly who could, that it has never been widened, and that widening it would take a deliberate decision by one person.

If you have material where that trade-off is unacceptable, please do not upload it.

Where your content travels

  • Your files are stored with Cloudflare, and the site runs on Vercel — standard, reputable infrastructure providers.
  • Office documents are a specific exception worth knowing about. When you preview a Word, Excel or PowerPoint file, that preview is rendered by Microsoft’s viewer service, which means the document is sent to Microsoft’s servers to produce the preview. If that is not acceptable for a particular document, don’t preview it — downloading it works without involving them.
  • Image and video thumbnails are generated by a service we operate on Google’s cloud, so media passes through it briefly while being processed.

Found a security problem?

Please tell us: security@zegazone.com

Include enough detail to reproduce it if you can. There is no bug-bounty programme at the moment, but reports are read and acted on — the claims on this page only mean something if they hold up when someone tests them.