← Back to Zuse

Subprocessors & third-party services

Effective September 9, 2026

This page identifies the service providers currently verified in Zuse's application and infrastructure configuration, and the independent services you may choose to connect. It is a feature-scoped description, not a promise that every provider is enabled for every account or environment.

Zuse service providers

These providers process information on Zuse's behalf or provide a platform component that Zuse operates. The cards describe categories at a high level; a provider receives data only when the relevant feature is used.

WorkOS

Account authentication

Data categories
Account identifiers, verified email and profile details returned by the sign-in flow, and session or access-token material needed to authenticate requests.
When it applies
Signed-in desktop, mobile, remote, and Cloud Workspace features. Not required for the ordinary local desktop workspace.
Your choice
Do not create or use an account for local-only work; sign out when you do not need account features.

PostHog

Product analytics

Data categories
A pseudonymous installation or account-derived analytics identity; approved event names and limited properties such as screens, feature use, normalized provider/model choices, aggregate usage, performance, and sanitized reliability outcomes.
When it applies
Optional desktop and mobile analytics. Analytics can run while signed out.
Your choice
Turn off “Share usage analytics” in desktop or mobile Settings.

Cloudflare

API, edge routing, storage, and database connectivity

Data categories
Account and workspace lifecycle metadata, connection tickets, encrypted command envelopes and results, and encrypted transcript checkpoints. Cloudflare also handles network and routing information needed for requests. The API uses Workers, Durable Objects, R2, and Hyperdrive; managed tunnels are an optional remote-connectivity path.
When it applies
Signed-in API, remote connectivity, and Cloud Workspace features. Local desktop data does not pass through this service just to run a local workspace.
Your choice
Use local, LAN, SSH, or another user-managed environment instead of Cloud Workspace or managed remote connectivity.

E2B

Isolated Cloud Workspace compute and paused workspace storage

Data categories
Cloud Workspace repository contents, files, terminals, provider processes, and runtime state needed to execute an accepted task. Zuse sends scoped runtime credentials and receives lifecycle signals and usage information.
When it applies
The Cloud Workspace public beta, when you create or resume a Cloud Workspace. It is not used for local, paired, SSH, or user-managed remote environments.
Your choice
Do not create a Cloud Workspace; use a local or user-managed environment.

Polar

Cloud Workspace billing and usage metering

Data categories
Billing account and subscription identifiers, selected product, payment status, and usage totals needed for checkout, entitlement, and overage reconciliation. Payment details are handled in Polar's checkout flow rather than entered into the Zuse app.
When it applies
Signed-in users who use a paid or metered Cloud Workspace offer. Checkout and billing enforcement are rollout-controlled and may be disabled for a cohort.
Your choice
Do not start a paid Cloud Workspace offer. Manage billing through the provider's checkout or customer-portal flow when it is presented.

Expo push service

Mobile push-notification delivery

Data categories
A device push token and a small notification payload, such as an activity kind, target, and optional title, so the mobile app can alert you.
When it applies
Mobile only, after you sign in, register a device, and grant notification permission. It is not used for desktop notifications.
Your choice
Decline or revoke notification permission, or turn notifications off in mobile and device settings.

GitHub

Cloud Workspace repository connection

Data categories
When you install the Zuse GitHub App, GitHub account and installation metadata, repository selection, repository metadata, and short-lived scoped installation credentials. A selected repository's contents may then be copied into the E2B workspace you request.
When it applies
Only for the optional Cloud Workspace GitHub connection. Zuse does not need GitHub for local repositories or other remote environments.
Your choice
Do not install the Zuse GitHub App, select only repositories you are authorized to use, and revoke the installation in GitHub when finished.

Website hosting and waitlist destination

Public-site delivery and optional signup handling

Data categories
Network request information needed to deliver the site. If you submit the waitlist form, the deployment-configured destination receives the email address, submission time, and form source.
When it applies
Website visitors and people who choose to submit the public waitlist form. The exact deployment provider is configuration-dependent and is not identified in this repository.
Your choice
You can browse without joining the waitlist. Do not submit the form if you do not want its configured destination to receive the entered email address.

Independent services you select

The services below are not Zuse subprocessors. You decide whether to connect them, and they process information under their own terms and privacy notices. Zuse may provide an adapter or user interface, but does not control the provider's systems or policies.

Model and coding-agent providers

The provider you choose runs the requested model or coding agent

Data categories
Prompts, responses, attachments, files, commands, credentials, and other content you deliberately make available to that provider, plus provider account and usage data under its own controls.
When it applies
Any local, remote, or Cloud Workspace session where you connect or select a provider. Supported providers and models vary by release and configuration.
Your choice
Choose whether to connect a provider, which model to use, and what content or permissions to provide. Review that provider's terms and privacy notice.

Source-control, package, browser, and other integrations

Independent services you direct Zuse or an agent to use

Data categories
The requests, repository or package data, browser data, credentials, and outputs involved in the integration you enable. Zuse does not control the service's processing, retention, or availability.
When it applies
Only when you connect or use the relevant service. A local workspace has no automatic upload to these services.
Your choice
Connect only services you trust and are authorized to use; revoke credentials and integrations when you no longer need them.

Locations and international transfers

A provider may process information in a country different from where you live. This page does not list regions, hosting addresses, transfer mechanisms, retention periods, certifications, or contractual terms that are not verified in Zuse's current configuration and documentation. The applicable location and safeguards can vary by provider, account, plan, and feature.

For more context about the local-first default, Cloud Workspaces, and provider boundaries, read the Privacy Policy. A provider's own notice governs information it receives directly from you or from a connected client.

Your choices and provider changes

You can keep work local, choose whether to sign in, disable product analytics, decline mobile notifications, avoid Cloud Workspaces, choose which repositories and model providers to connect, and revoke access in the relevant provider. Removing a connection does not necessarily delete information already held by that provider; use its controls for that request.

Zuse may add, remove, or replace a provider as the product changes. We will update this page and its effective date. If a change materially affects how Zuse handles personal information, we may also provide notice in the app or through another appropriate channel, consistent with the Privacy Policy. Release availability and beta configuration can change before a provider is enabled for you.

Scope notes

  • Local SQLite, operating-system credential stores, local files, and user-managed servers are not Zuse subprocessors.
  • A feature marked optional, configurable, or private beta may be absent, disabled, or limited for your account or release.
  • We do not list speculative vendors, disabled infrastructure adapters, or a provider merely because its software is bundled as a dependency.