ZSEC Browser 0.3.25 · Browser Shields 0.5.2

Privacy should be a testable contract.

ZSEC Browser uses a separate local profile, bounded local bookmarks/history/settings data, a separate user-operated encrypted password vault and local request controls. Browser Shields evaluates 49,505 packaged network rules, optional High-Risk Browsing and site-pause choices inside the browser. The Community packages have no ZSEC analytics, advertising, account, crash-upload, cloud-reputation, spyware-verdict, vault-sync or remote-control endpoint.

Effective and last reviewed: . This policy covers the accepted unsigned ZSEC Browser Community 0.3.25 Windows package and the separately distributed Browser Shields Community 0.5.2 Manifest V3 package. The 4,265,007-byte Windows archive has SHA-256 ecd59e8fb86560f0f2a4b5c645f956ef59e9140debcbbb25d6f3d3bd571ee548 at source revision cd0fff58072403dddaf3810aacbdb2288a01139d; its 2,123-byte metadata JSON has SHA-256 67f230dcbad5c04c023285691bfe487f270162ce2f9ab49b596b46d558705857.

What the extension uses

  • Forty packaged declarative ad, tracker and link-cleaning rules.
  • The global protection on/off setting.
  • The user's High-Risk Browsing on/off choice.
  • Domain names the user explicitly pauses during normal protection.
  • Two browser-managed High-Risk request rules when that profile is active.
  • Exact-host player-data fields and page-interface signals used for bounded YouTube protection when enabled.

These operations happen inside the browser. The current extension sends no report about them to TalkToAI. The High-Risk preference is one local setting; it is not a targeting assessment or infection verdict.

What we do not receive

  • Browsing history, full URLs, searches or page text.
  • Cookies, form fields, credentials or payment details.
  • Files, downloads or clipboard contents.
  • Advertising identifiers, analytics events or crash reports.
  • Affiliate-attribution replacements or shopping-link rewrites.
  • Which requests High-Risk Browsing blocked.
  • Whether the user enabled High-Risk Browsing.
  • Any inference that the user is being targeted.
  • A malicious, safe, infected or clean verdict for any site or device.

Why broad site access exists

A network blocker must be able to evaluate requests across websites, and the interface-cleanup script must run on the sites it supports. That access is not permission to build a browsing profile or transmit page contents. The extension uses Manifest V3 packaged code and rules; it does not download or execute remote code.

The network engine contains 49,464 EasyList rules pinned to the disclosed upstream release, 39 focused ZSEC privacy rules and two tracking-link cleaners. Acceptable Ads is not bundled or enabled. EasyList attribution, retained source, provenance, exact hashes and its GPL-3.0-or-later or CC-BY-SA-3.0-or-later licence are included in the package.

Page-requested windows are blocked by default. If the user adds a revocable exact HTTPS origin under Settings > Permissions, a request must still be reported by WebView2 as user initiated, target an accepted HTTPS URL, stay within the tab limit and pass the popup-burst guard. Accepted requests open as independent tabs without a usable opener relationship. ZSEC stores only the allowed origin and bounded local reason counters, not the requested popup URLs; this control does not bypass certificate, download, request-filtering or tab-limit protections and cannot guarantee protection from every malicious site.

High-Risk Browsing uses Chromium Manifest V3's declarativeNetRequest mechanism to apply two fixed local request rules. It does not decrypt TLS, inspect response bodies, upload full URLs, classify a request as spyware or produce a forensic request log. A blocked request means only that it matched one of the disclosed local rules.

The global protection choice, High-Risk Browsing choice and paused domains remain in the browser extension's local storage. Paused domains may remain stored while High-Risk Browsing is active, but the pause control cannot override the stricter rules. Removing the extension removes its local settings through the browser's normal extension lifecycle. Community 0.5.2 creates no ZSEC server-side account record to delete.

A separate local profile, with no ZSEC telemetry.

ZSEC Browser Community 0.3.25 stores cookies, cache, permissions and other engine state under the user's dedicated LocalAppData\TalkToAI\ZSEC Browser profile. A separate bounded browser-data.json stores bookmarks, app history and Community settings atomically for this Windows account. Repeat history is consolidated, explicitly typed addresses can influence local suggestions, and the chosen search provider is stored locally. History recording can be disabled, cleared immediately or cleared on a clean exit. ZSEC does not reuse Chrome, Edge or Brave profiles and adds no ZSEC analytics, account, history upload or remote-control endpoint.

The optional password manager stores website origins, usernames, passwords and notes under a separate password-vault directory for the current Windows account. Windows DPAPI CurrentUser protects a random device key; an independently random vault master key and per-record keys protect authenticated encrypted records. Passwords stay concealed in the manager list; a deliberate reveal ends after at most 15 seconds or immediately on focus loss. The vault locks after five idle minutes, and a copied username or password is cleared after 30 seconds if the clipboard still contains that exact copied value.

Password migration operates only on a CSV explicitly exported and selected by the user. It accepts recognised Chrome, Edge, Brave or Firefox password-export columns, strict UTF-8, bounded files and HTTPS origins; previews counts; skips exact-origin username duplicates without overwriting; and rolls back entries created by a failed import. An optional post-import deletion requires a separate confirmation and re-verifies the selected file's length and SHA-256. ZSEC does not inspect another browser's credential database and does not import cookies, authenticated sessions, passkeys, TOTP secrets or history.

The local Migration centre may read the current Windows account's supported browser bookmark files after the user opens it. Brave, Chrome and Edge bookmark JSON is previewed and deduplicated locally. Firefox is offered only when a bounded plain-JSON backup or recovery file is readable. URL-only tab restoration never transfers cookies, account tokens, form state, storage or other authenticated session material.

The separate Sign-in Setup Assistant does not use the source profile selected in Migration centre. It builds a bounded review list only from exact HTTPS origins already stored in local ZSEC bookmarks/history and a built-in catalog. Every item starts unselected; paths, queries and fragments are removed; obvious local-address forms are rejected; and the exact origins are confirmed before any tab opens. It does not read, decrypt, copy or transmit another browser's cookies, authenticated sessions, tokens, passwords, form data or profile. If a site is already signed in, that state came from the existing ZSEC WebView2 profile; otherwise the user signs in directly to the site inside ZSEC.

Local automation is absent during ordinary launches. An automation host must explicitly start ZSEC with --enable-local-automation, securely capture the fresh per-process token and connect through the current-user-only Windows named pipe. Its fixed command allowlist can ping, return version/tab-count/visibility state, activate the window, or open an HTTP(S) URL/tab. It cannot read page content, URLs, titles, passwords, cookies, history, bookmarks, storage, downloads or files, and exposes no TCP, WebSocket, DevTools or arbitrary-script interface.

Password saving and filling are independent opt-in settings and remain off by default. When saving is enabled, a top-level login submission can trigger a native Save, Update, Not now or Never for this site choice; ZSEC never silently saves. When filling is enabled, it matches the exact HTTPS scheme, host and port, uses a native picker when several usernames exist, and never submits the form. It does not operate on HTTP, internal pages, frames, cross-origin content, subdomains or other ports. Microsoft WebView2 password autosave and general autofill remain disabled. The vault never uploads or synchronises entries and cannot protect against malware running as the unlocked Windows user, keylogging, page compromise, a stolen interactive session or browser-process memory access. ZMath supplies a domain-separated commitment label only; it is not the vault cipher or a security proof.

Clearing the app-history list does not delete WebView2 cookies, cache, IndexedDB, service workers, permissions, DNS/operating-system records or logs held by sites, networks or other providers. The Journalist preset is therefore not an ephemeral or “nothing retained” mode.

WebView2 and SmartScreen are not ZSEC services.

Microsoft's Evergreen WebView2 runtime supplies the engine and updates. WebView2 diagnostics and SmartScreen may send information to Microsoft under Microsoft's terms and Windows diagnostic settings; see Microsoft's WebView2 data and privacy documentation. A selected search provider receives the query and ordinary network metadata; ZSEC does not proxy searches. The ZSEC Community application adds no ZSEC analytics, account, browsing-history upload or remote-control endpoint. It does not claim that all browser data is encrypted by ZMath or hidden from the engine or search provider.

No silent expansion.

Any future URL reputation, indicator feed, blocked-request reporting, diagnostics, content inspection, synchronisation or sample submission would materially change this privacy contract and requires a separately disclosed purpose, data set, destination, retention period and user control.

This policy describes data handling, not security efficacy. Local processing and no telemetry do not prove that a site or device is safe. Material policy changes require a new review date and release notes.

Security issues can be reported through the repository's security policy.

Return to ZSEC Browser