Windows Community client
A separate local profile, with no ZSEC telemetry.
ZSEC Browser Community 0.3.25 stores cookies, cache, permissions and other engine state under the user's dedicated LocalAppData\TalkToAI\ZSEC Browser profile. A separate bounded browser-data.json stores bookmarks, app history and Community settings atomically for this Windows account. Repeat history is consolidated, explicitly typed addresses can influence local suggestions, and the chosen search provider is stored locally. History recording can be disabled, cleared immediately or cleared on a clean exit. ZSEC does not reuse Chrome, Edge or Brave profiles and adds no ZSEC analytics, account, history upload or remote-control endpoint.
The optional password manager stores website origins, usernames, passwords and notes under a separate password-vault directory for the current Windows account. Windows DPAPI CurrentUser protects a random device key; an independently random vault master key and per-record keys protect authenticated encrypted records. Passwords stay concealed in the manager list; a deliberate reveal ends after at most 15 seconds or immediately on focus loss. The vault locks after five idle minutes, and a copied username or password is cleared after 30 seconds if the clipboard still contains that exact copied value.
Password migration operates only on a CSV explicitly exported and selected by the user. It accepts recognised Chrome, Edge, Brave or Firefox password-export columns, strict UTF-8, bounded files and HTTPS origins; previews counts; skips exact-origin username duplicates without overwriting; and rolls back entries created by a failed import. An optional post-import deletion requires a separate confirmation and re-verifies the selected file's length and SHA-256. ZSEC does not inspect another browser's credential database and does not import cookies, authenticated sessions, passkeys, TOTP secrets or history.
The local Migration centre may read the current Windows account's supported browser bookmark files after the user opens it. Brave, Chrome and Edge bookmark JSON is previewed and deduplicated locally. Firefox is offered only when a bounded plain-JSON backup or recovery file is readable. URL-only tab restoration never transfers cookies, account tokens, form state, storage or other authenticated session material.
The separate Sign-in Setup Assistant does not use the source profile selected in Migration centre. It builds a bounded review list only from exact HTTPS origins already stored in local ZSEC bookmarks/history and a built-in catalog. Every item starts unselected; paths, queries and fragments are removed; obvious local-address forms are rejected; and the exact origins are confirmed before any tab opens. It does not read, decrypt, copy or transmit another browser's cookies, authenticated sessions, tokens, passwords, form data or profile. If a site is already signed in, that state came from the existing ZSEC WebView2 profile; otherwise the user signs in directly to the site inside ZSEC.
Local automation is absent during ordinary launches. An automation host must explicitly start ZSEC with --enable-local-automation, securely capture the fresh per-process token and connect through the current-user-only Windows named pipe. Its fixed command allowlist can ping, return version/tab-count/visibility state, activate the window, or open an HTTP(S) URL/tab. It cannot read page content, URLs, titles, passwords, cookies, history, bookmarks, storage, downloads or files, and exposes no TCP, WebSocket, DevTools or arbitrary-script interface.
Password saving and filling are independent opt-in settings and remain off by default. When saving is enabled, a top-level login submission can trigger a native Save, Update, Not now or Never for this site choice; ZSEC never silently saves. When filling is enabled, it matches the exact HTTPS scheme, host and port, uses a native picker when several usernames exist, and never submits the form. It does not operate on HTTP, internal pages, frames, cross-origin content, subdomains or other ports. Microsoft WebView2 password autosave and general autofill remain disabled. The vault never uploads or synchronises entries and cannot protect against malware running as the unlocked Windows user, keylogging, page compromise, a stolen interactive session or browser-process memory access. ZMath supplies a domain-separated commitment label only; it is not the vault cipher or a security proof.
Clearing the app-history list does not delete WebView2 cookies, cache, IndexedDB, service workers, permissions, DNS/operating-system records or logs held by sites, networks or other providers. The Journalist preset is therefore not an ephemeral or “nothing retained” mode.