Privacy policy
What Zesam knows about you
Nothing. Zesam has no server, no account, no audience measurement. This page states exactly what the app keeps, where, and the only three occasions when anything leaves your device.
Effective 25 August 2026.
Who is responsible
Zesam is published by an independent developer based in France. For any question about this policy, write to privacy@zesamapp.fr.
What the app keeps, and where
No secret is ever written to disk in the clear, not even briefly: no temporary file, no cache, no log, no error message. That is a rule the code is written to, not an intention.
| Data | Where it lives | Who can read it |
|---|---|---|
| Two-factor secrets, backup codes | The system keychain, and iCloud Keychain if you have it on | You alone. Apple encrypts iCloud Keychain end to end and does not hold the key. |
| Account names, issuers, folders, tags, logos | The local database, and your private iCloud database if sync is on | You alone, through your iCloud account. |
| Browser extension access log | Local preferences on the Mac. Never synced. | You alone, on that device. |
The only three connections
1. iCloud sync
Between your own devices, through your iCloud account, in your private database. It runs on Apple's infrastructure; Zesam's publisher has no access to it and operates no server. You can turn it off in your iCloud settings.
2. Reference time
A two-factor code depends on the time. When a device's clock drifts, codes are refused with no explanation. Zesam therefore queries public time servers now and then to measure that gap: first time.cloudflare.com, time.apple.com, time.google.com and time.windows.com, then, if they do not answer, the volunteer servers of the pool.ntp.org project nearest your region. These servers see your IP address and the time of the request, nothing else: no account data reaches them, and nothing sets them apart from an ordinary computer clock.
The request contains nothing: no identifier, no account, no usage data. Like any network connection it exposes your IP address to the server queried. That is unavoidable, and that is all.
3. Fetching a logo
Only when you ask, for one account. Zesam then contacts that service's own site to take its icon. Nothing about you is sent, and nothing happens automatically.
What never happens
- No analytics, no telemetry, no automatic crash reporting, no “anonymised data”.
- No advertising, no trackers, no ad networks.
- No account to create, so no email address collected.
- No selling, no sharing, no transfer to third parties: there is nothing to transfer.
- No third-party library is bundled into the app.
Permissions the app asks for
| Permission | Why |
|---|---|
| Camera | To read an enrolment QR code. The image feeds the system detector directly: no intermediate file, no cache, nothing kept. |
| Photos | To import a QR code from a screenshot, or pick a service logo. Zesam reads the image you point at, and nothing else. |
| Face ID / Touch ID | To unlock the app and its extensions. The system performs the check; Zesam only receives a yes or a no. |
| Network (Mac) | Local listening, for the Chrome and Firefox extensions. Off by default, switched on in settings, and closed to any connection that does not come from your Mac. |
The clipboard
A code is copied only when you ask for it. The clipboard is readable by every installed app and syncs to your other devices: putting a code there without a gesture from you would be a silent leak, and Zesam does not do it.
The browser extensions
They never hold a secret: they ask the app for an already-computed code, valid for a few dozen seconds. They read the host name of the tab you click in (never the path, never the history) and contact no server.
On Chrome and Firefox the exchange goes through a local address (127.0.0.1), which means your own computer and does not leave the machine. Every code served and every refusal is written to a log you can inspect.
Your rights
European law gives you rights of access, rectification, erasure, restriction, objection and portability. Here they are exercised without writing to us, because we hold nothing:
- Access and portability: the encrypted export, in settings, produces a file containing everything Zesam keeps.
- Erasure: deleting the app removes its local data and its keychain entries. To erase the iCloud copy, use Settings › your name › iCloud › Manage Storage.
- Objection: there is no processing to object to.
Children
Zesam is not directed at children in particular, and collects no data whatever the age of the person using it.
Changes to this policy
Any substantive change will be announced in the app's release notes, and the effective date above updated.