Skip to content
Zolash is here — bot-less, on-device meeting notes. Start your free trial →
Security & data handling

Security at Zolash

Zolash keeps meeting content on your device, so the most sensitive data never leaves your control. There's no cloud copy of your recordings, transcripts, or summaries — because they're never uploaded to us. This page lays out how data is handled at rest, in transit, and under strict IT, in terms a reviewer can verify.

Available for macOS, Windows, and Linux. Works offline. Nothing uploaded.

At a glance, for reviewers

  • Meeting content never leaves the device
  • No server-side store of your recordings or transcripts
  • Three disclosed network paths, all over TLS, none with content
  • No cloud inference; no training on your data
  • Runs fully offline for locked-down environments

We keep our claims precise. Zolash makes architectural guarantees about where your data goes — not certifications or regulatory attestations. Below is what we can state plainly and stand behind, so you can map it to the requirements that apply to your work.

Data at rest

Your meeting data lives on your machine — and only your machine.

Recordings, transcripts, and summaries are stored as local files on the device that made them. There is no Zolash server holding a copy, because your content is never sent to one. Where the files live is a location you control, and deleting a meeting means deleting the file — the data is gone, with no cloud backup to reconcile.

  • Local files on the user’s device, in open, readable formats
  • No server-side store of meeting content to breach, subpoena, or audit
  • Deletion is entirely in the user’s hands

Data in transit

Only three narrow paths ever leave the device — none carry meeting content.

Zolash is built to keep meeting content local, so the network is used only for a small, fixed set of functions. Each of those connections uses standard transport encryption (TLS). Everything else — audio, transcripts, summaries, and the AI processing behind them — never leaves the device.

  • License & billing check — sends your license key and account status only
  • Calendar sync (opt-in) — reads event titles and times if you connect it; revocable
  • Exports & integrations — send only the note you choose to push, only when you trigger it

Consent & recording

Recording responsibly is on you — and we help you do it right.

Recording laws differ by region, and it’s the operator’s responsibility to follow the rules that apply. Our guidance is simple and consistent: tell participants the meeting is being recorded, and record only where you’re permitted to. Because Zolash captures from your own device rather than sending a bot into the call, you stay in control of when recording starts and stops.

  • Inform participants that the meeting is being recorded
  • Follow the consent rules that apply in your jurisdiction
  • You start and stop capture from your own device

Confidentiality by architecture

The most sensitive data is protected by never leaving your control.

Because meeting content stays on the device and never reaches Zolash or any third party, the usual exposure of a cloud notetaker simply isn’t present: there’s no vendor copy to be accessed, mishandled, or used to train a model. This is an architectural guarantee about where data goes — not a certification. We state plainly what we can guarantee and leave you to map it to your own requirements.

  • No cloud copy of meeting content exists on our side
  • Nothing is used to train a model or reviewed by staff
  • You map these guarantees to your own policies and obligations

Deployment under strict IT

Works in locked-down environments — no meeting-content egress.

Zolash records, transcribes, and summarizes with no internet connection, which suits air-gapped or network-restricted environments. Since no meeting content is transmitted, there’s no data-egress path for your security team to gate — the license check and any opt-in connections are the only outbound traffic, and you decide whether to allow them.

  • Fully functional offline — no server dependency for core features
  • No meeting-content egress to allow-list or block
  • Optional connections are opt-in and can be disabled

The model & no training

One shared model, running locally, that never learns from your meetings.

The meeting-tuned model runs on the device and is the same for every user. Your conversations don’t tune it and are never sent anywhere to do so. There is no cloud inference step, so producing a summary or answering a question involves no upload — the work happens where your data already is.

  • On-device inference — no transcript is sent to a server to be summarized
  • No training on user data; the model is identical for all users
  • No per-meeting metering or AI credits, because there’s no cloud compute to bill

Diligence questions, answered.

Where is my meeting data stored?

On your own device, as local files in open, readable formats. Zolash keeps no server-side copy of your recordings, transcripts, or summaries, because your content is never uploaded to us.

What data leaves my device, and is it encrypted?

Only three paths ever use the network: a license/billing check, opt-in calendar sync, and exports you trigger yourself. Each uses standard transport encryption (TLS). None of them carries your meeting audio, transcript, or summary.

Does Zolash meet my industry’s compliance or regulatory requirements?

We don't make certification or regulatory-compliance claims. What we can state plainly is architectural: meeting content stays on your device and never reaches us or any third party. Many teams with strict confidentiality needs use that guarantee as the basis for their own assessment against whatever frameworks apply to their work.

Can Zolash run in an air-gapped or network-restricted environment?

Yes. Recording, transcription, and summaries all work fully offline, so Zolash fits environments where the network is locked down. The only outbound traffic is the license check and any connections you opt into — which your IT team can allow or block.

Do you or your model ever see or train on my conversations?

No. There is no cloud inference and no training on your data. The model runs locally and is the same for everyone; your meetings are never transmitted, reviewed, or used to improve it.

What happens to my data if I stop using Zolash?

Your meetings are local files you own, so they stay on your device until you delete them. There is no cloud account holding your content, and nothing on our side to retain or purge.

Want the exact data-flow breakdown? Read the privacy architecture →

The strongest security posture is no cloud copy at all.

Start your free trial and keep every meeting on your own device — nothing to configure, nothing to upload.

Available for macOS, Windows, and Linux. Nothing uploaded.