Legal and privacy
Four documents: the privacy policy, the terms of service, a plain-language summary of what is stored, and the legal notice.
Privacy Policy
Version: 1.4 · Effective: 31 July 2026 · Last updated: 8 September 2026 (Stand: 2026-09-08)
1. Controller
Gian-Luca Luongo, Dorfstrasse 77, 5430 Wettingen, Switzerland [email protected]
The controller is a natural person, not a company. There is no Data Protection Officer; the controller answers data protection requests personally at the address above.
2. About the name
ZeroLog means the service is built not to need your identity: no email address, no phone number, no real name, and no IP address anywhere in the database or attached to your account.
That last one is deliberately narrower than "no stored IP addresses", because that would not be true. IP addresses reach short-lived security logs (failed logins, abuse events) which are kept for weeks (§3.4, §8). Weeks is storage. What does not happen is an IP being written into your account, your chats, or your history.
One caveat belongs up front: paying identifies you. Registration collects no name, but card and Google Pay payments carry your name and billing address to Stripe, and the operator can see them there. If you pay, you are identifiable: by the operator, by Stripe and by your bank. Only never-paying accounts stay unnamed, and even those are not untraceable.
It does not mean nothing is written down. Ordinary chats are stored so your history is there when you return. Usage is recorded so you can be billed accurately. Security events are logged so the service can defend itself. This policy states plainly what exists.
If you want content the operator genuinely cannot read, use anonymous chats (§6).
3. What is processed
3.1 Account
- Username, password hash (bcrypt), registration timestamp, permission flags.
- An email address is optional and empty by default. You may add one; you may remove it again. Without one there is no password reset and no way for us to notify you — that is the trade, and leaving it blank stays a fully supported choice.
- No phone number, no real name. There is no field for either.
3.2 Chats, messages and files
- Chat titles, messages, attachments, generated images, and files inside your containers, stored in a SQLite database and on disk on the server in Switzerland.
- Prompts you send are transmitted to the inference provider you selected (§5) to produce a reply. This is the core of the service and cannot be switched off while using a model.
3.3 Usage and billing
- Per-request: model used, token counts, cost, timestamp, and which chat it belonged to. This is what your ledger and spend limits are computed from.
- Payment records: Stripe's transaction and customer identifiers, amount, currency, status. Card numbers never reach this server: Stripe handles them.
3.4 Technical and security data
- Session records (session identifier, creation and last-use time) so you stay logged in.
- Sign-in events: time, outcome, browser identification, and a one-way check value derived from the source address. The address itself is not stored — the check value is an HMAC and cannot be turned back into an address; it exists so we can tell a sign-in from a familiar source from an unfamiliar one, and warn you about the latter. Visible to you under Settings, kept 90 days.
- Rate-limiting and abuse counters keyed on IP in memory and in short-lived server logs. IP addresses are not stored in the database as part of your account or your history.
- Server logs (errors, security events such as failed logins, container lifecycle). These can contain an IP address transiently and are rotated by the system journal.
- Container and agent activity: commands run, exit codes, tool calls, needed to show you what an agent did and to investigate abuse.
3.5 What is deliberately NOT collected
- No advertising or analytics trackers, no tracking pixels, no third-party cookies.
- No profiling, no automated decision-making with legal effect, no sale of data.
- No behavioural advertising of any kind.
4. Why, and on what legal basis
| Purpose | Legal basis (GDPR) | FADP |
|---|---|---|
| Providing the service (chats, containers, agents) | Art. 6(1)(b) contract | Contract performance |
| SSH access to your containers and VMs (public keys you register) | Art. 6(1)(b) contract | Contract performance |
| Billing, credit, fraud prevention | Art. 6(1)(b), 6(1)(c) | Legal obligation |
| Security, abuse prevention, rate limiting | Art. 6(1)(f) legitimate interest | Overriding private interest |
| Complying with lawful orders | Art. 6(1)(c) | Legal obligation |
| Optional connectors you switch on | Art. 6(1)(a) consent | Consent |
5. Who else sees anything (recipients and sub-processors)
Using ZeroLog necessarily involves these third parties:
| Recipient | What it receives | State | Why | Transfer basis |
|---|---|---|---|---|
| DeepInfra, Inc. | Your prompts and the resulting completions | USA | Model inference for the pool models (the ones without a provider prefix in their name) — this is the AI itself | Art. 17(1)(b) FADP |
| Stripe (Stripe Payments Europe Ltd; Stripe, LLC) | Payment and billing identifiers, amount, status | Ireland and USA | Payment processing | Art. 16(1) FADP |
| Cloudflare, Inc. | Traffic metadata, IP address, TLS termination | USA (corporate seat). Requests are terminated at the Cloudflare edge location nearest you: for visitors from Switzerland normally Zurich or Geneva, otherwise a location in the country or region you connect from | Reaching the site; DDoS protection | Art. 16(1) FADP |
| IONOS SE | Outbound traffic from containers | Germany | Egress gateway for container network access | Art. 16(1) FADP |
| Leonardo Interactive Pty Ltd | Image prompts — only if you switch it on | Australia | Optional image generation connector | Art. 17(1)(a) FADP — your explicit consent |
| Google LLC | Your prompt, if you pick a Gemini model; separately, an account identifier if you link Google sign-in | USA | Model inference for Gemini models; optional sign-in | Art. 16(1) FADP |
| Anthropic, PBC | Your prompt and the file content the tool reads — only if you run Claude Code in a container | USA | The CLI talks to its own vendor | Art. 17(1)(a) FADP — you start the tool |
| OpenAI, L.L.C. | Your prompt and the file content the tool reads — if you run Codex in a container, or pick an OpenAI model | USA | The CLI talks to its own vendor; OpenAI model inference | Art. 17(1)(a) FADP — you start the tool |
| OpenRouter, Inc. | Your prompts and completions — the fallback inference pool and for routed models | USA | Fallback inference pool; model routing | Art. 17(1)(b) FADP |
| Mistral AI SAS | Your prompts and completions — only if you pick a Mistral model | France (EU, adequate) | Model inference (direct provider) | Art. 16(1) FADP |
| Groq, Inc. / Cerebras Systems, Inc. / SambaNova Systems, Inc. / NVIDIA Corporation / Fireworks AI, Inc. / Together Computer, Inc. / Ofox | Your prompts and completions — only if you pick one of their models | USA | Fast inference (direct provider pool) | Art. 17(1)(b) FADP |
| Requesty B.V. | Your prompts and completions — only if you pick a Requesty-routed model | Netherlands (EU, adequate) | Model routing (direct provider) | Art. 16(1) FADP |
| SiliconFlow Technology | Your prompts and completions — only if you pick a SiliconFlow model | China | Model inference (direct provider) | Art. 17(1)(b) FADP — serving the model you picked; China has no adequacy finding, see below |
| Replicate, Inc. / Features and Labels, Inc. (fal.ai) | Your prompts and image inputs — only if you pick one of their image/video models | USA | Image/video generation | Art. 17(1)(b) FADP — serving the model you picked |
Router / Auto model and fallbacks. When you pick "Auto" or a model becomes unavailable, your request may be processed by a different provider than the one you selected, always a provider from the list above. A visible notice names the provider that actually served the turn.
Zero data retention: what is true today. An earlier version of this section said a rerouted request always inherits the same zero-data-retention (ZDR) routing. That was an overstatement and it is corrected here. Zero-retention routing is a field understood by one provider on the list (OpenRouter) and is requested only for chats that carry credentials from the secrets vault. The primary inference pool currently in use is a different provider, for which no such guarantee is enforced. Assume every request is retained under the policy of whichever provider answers it, and read that provider's own terms if retention matters for what you are about to send. The named provider is shown with every turn, so you can always tell which policy applied.
Vision proxy. If you send an image to a text-only model, an additional vision provider (from the list above, by default a Google/Gemini-class model) is asked to describe it; a badge tells you which provider produced the description.
Memory engine. Your long-term memories are encrypted at rest with keys held in your browser: the server stores only ciphertext, wrapped keys and (in the default mode) plaintext similarity vectors. When a memory is injected into a prompt its text is unavoidably in that prompt; zero-knowledge applies to storage at rest, and losing both your passphrase and your recovery code means the memories are unrecoverable.
Browser extension (Chrome and Firefox) and browser AI bridge, both off by default. With the extension on, the page content, screenshots and console output of tabs you act on are sent to ZeroLog and to the model provider you selected; a short-lived token is stored in the extension. With the browser AI bridge on, you use your own third-party AI account through an ephemeral session. ZeroLog stores no credentials, the provider's terms and any account-ban risk are yours, and the feature shows a consent screen naming that risk before it runs.
WebHook AI. If you configure a webhook, the third-party URL you name receives event data about your runs. You choose the endpoint and are responsible for it.
Security processing. For abuse and fraud prevention ZeroLog processes your IP address, user agent and request metadata (legal basis: overriding/legitimate interest, Art. 6(1)(f) GDPR / Art. 31(1) revDSG). These security logs are kept 30 days (aggregates 12 months). The egress denylist is compiled from public hostname lists that contain no personal data.
Art. 19 para. 4 FADP requires that the state be named, not a region, which is why no row above says "global" or "worldwide". Cloudflare is the awkward case: a CDN terminates your request wherever you happen to be, so the honest statement is the rule that decides it (nearest edge location to you) rather than a list of every country Cloudflare operates in. Cloudflare, Inc. holds an active Swiss–US certification, so Art. 16 para. 1 covers the transfer to the company itself; the operator has not separately concluded standard data protection clauses under Art. 16 para. 2 lit. d, and does not claim to have.
Where the bases come from. Under Art. 16 para. 1 FADP a transfer needs no further safeguard if the Federal Council has found the destination adequate. The list is Annex 1 to the Data Protection Ordinance (DPO, SR 235.11, per Art. 8 para. 1 DPO). Germany and Ireland are on it, so IONOS and Stripe's European entity are covered outright. The USA is on it only for organisations certified under the Swiss–US Data Privacy Framework: adequacy there is per organisation, never country-wide.
Checked against the official participant list on 31 July 2026: Cloudflare, Inc. (record 5666), Google LLC (record 5780) and Stripe, LLC (record 10014) each hold an active Swiss–US certification. Those three transfers therefore rest on Art. 16 para. 1.
DeepInfra does not appear on that list at all: not active, not lapsed, not withdrawn. So the Data Privacy Framework cannot be claimed for the single largest transfer this service makes, and claiming it would be worse than naming the real basis. That basis is Art. 17 para. 1 lit. b FADP: the disclosure is directly connected with performing the contract between you and the operator. Sending your question to a model is the service. There is no version of it that answers you without a model reading what you asked. No separate consent is collected for it, because consent that cannot be refused without losing the product is not consent.
Australia has no Swiss adequacy finding, and the Data Privacy Framework is open only to US organisations, so an Australian company cannot join it even in principle. Image generation through Leonardo therefore runs on Art. 17 para. 1 lit. a FADP, your explicit consent, which is exactly what the switch in Settings collects. It is off until you turn it on, turning it on is the consent, and turning it off withdraws it for the future.
The command-line tools talk to their own vendors. Claude Code, Codex and the Gemini CLI run inside your container and, when you sign them in with your own account, they contact Anthropic, OpenAI and Google directly. Your prompt and whatever files the tool reads go to that vendor, not through the model pool, and the operator does not see the exchange. Those hosts are on the egress allow-list precisely so the tools work. Starting such a tool and signing it in is the consent this rests on (Art. 17 para. 1 lit. a); if you would rather not send anything to them, do not run them.
Failover is routine, not hypothetical. The model pool runs on DeepInfra, and when a pool request fails (the provider is out of funds, down, or refuses the request), the service retries the same model at another provider from the table above (in practice most often OpenRouter, Inc. (USA) or Requesty B.V. (Netherlands)) rather than showing you an error. This happens as a matter of course, and the reply is billed at the price of whoever actually served it, never more than the price you were shown. A failover never routes to a provider in a country without an adequacy finding or a listed derogation basis: in particular, no request reaches SiliconFlow (China) unless you picked a SiliconFlow model yourself. That exclusion is enforced in the routing code, not just promised here.
A limit worth stating. A Data Privacy Framework certification must be renewed annually, and a lapse removes the Art. 16 para. 1 basis for that recipient. The certifications above run to 13 September 2026 (Google), 23 September 2026 (Cloudflare) and 11 May 2027 (Stripe). The operator re-checks the list at renewal; if one lapses, this policy is corrected rather than left standing.
China, stated plainly. SiliconFlow models run in China, which has no Swiss adequacy finding. There is no separate consent screen: the model's name carries the provider (“(SiliconFlow)”), and this policy names the country. The transfer rests on Art. 17 para. 1 lit. b FADP, because serving the model you picked is performing the contract. Nothing routes there on its own: no auto-routing, no failover, only your own pick. If a transfer to China is unacceptable to you, do not pick a SiliconFlow model.
The routers forward. OpenRouter and Requesty are routing services: a prompt sent to a openrouter/… or requesty/… model goes to the router, which passes it to the model's operator under the router's own terms. The router is the recipient this policy can name, and the onward hop is governed by its published sub-processor terms. Zero-retention routing is requested only for chats that carry credentials from the secrets vault, and only towards OpenRouter, which is the one provider on this list that understands the field.
Assume that anything you type into a prompt leaves Switzerland. If that is not acceptable for a particular piece of information, do not put it in a prompt, and consider an anonymous chat, which keeps the stored copy unreadable here even though the model still has to see the question.
No data is sold, rented, or shared for advertising.
6. Anonymous chats (zero-knowledge)
Anonymous chats are encrypted in your browser before they reach the server. The server stores only ciphertext plus the billing counters (tokens and cost) needed to charge you.
Consequences, stated plainly:
- The operator cannot read them, and cannot be compelled to produce their content, because the key never reaches the server.
- The operator cannot recover them. Lose the passphrase and the content is permanently gone.
- They cannot be moderated. Prohibited use is still prohibited (Terms §4). It simply cannot be detected there, and enforcement rests on other signals.
- Prompt content is still sent to the inference provider to get an answer. Encryption protects storage on this server, not the fact that a model must see the prompt.
7. Cookies
Three. None of them is used for tracking or advertising, and none needs a consent banner.
| Cookie | What it is for | How long it lasts |
|---|---|---|
__Host-mh_session | keeps you logged in. Set at sign-in, never before | 30 days, or until you sign out |
__Host-mh_oauth | ties one Google sign-in attempt to the browser that started it, so a link opened somewhere else cannot finish it for you | that one sign-in, then deleted |
__Host-mh_ref | set only if you arrive through a link the operator posted somewhere public. It holds a short name for the link, not for you: everyone who follows the same link gets the same value | at most 30 days |
All three set HttpOnly, Secure and SameSite=Lax, and the __Host- prefix means a browser accepts them only from this exact origin over HTTPS. The plain-language summary further down this page says exactly what the third one records and what it deliberately does not.
Local storage in your browser holds interface preferences (theme, language, layout) and, for anonymous chats, key material that never leaves your device.
8. How long data is kept
| Data | Retention |
|---|---|
| Account | Until you delete it |
| Chats, messages, files | Until you delete them, or with the account |
| Container contents | Until you delete the container |
| Usage and billing records | 10 years — Swiss accounting law (Art. 958f CO) |
| Payment records at Stripe | Per Stripe's own retention |
| Session records | Expiry or logout |
| Security / abuse logs | 30 days by default (aggregates 12 months); longer where an incident is under investigation |
| Sign-in events | 90 days, then deleted |
| Backups | Rolling; deleted content disappears from backups within the backup cycle |
On account deletion, personal data is deleted or anonymised, except where retention is legally required (billing records above) or an abuse investigation is open.
9. Your rights
Under the FADP and, where applicable, the GDPR, you may request:
- Access: a copy of your data
- Rectification: correction of inaccurate data
- Erasure: deletion (subject to legal retention)
- Restriction and objection: including objection to processing based on legitimate interest
- Portability: your data in a machine-readable form
- Withdrawal of consent: for anything you consented to, with future effect
Write to [email protected]. A response follows within 30 days.
An honest limitation: most accounts carry no email address, and where none is on file identity cannot be verified by email. Requests are honoured by proving control of the account (logging in). If you cannot log in, the operator cannot safely identify you as the account holder and may have to refuse. Refusing is the privacy-preserving answer, since the alternative is handing your data to whoever asks.
Complaints. Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Bern. EU/EEA: your national supervisory authority.
10. Security
Passwords are hashed with bcrypt and never stored in clear. Traffic is TLS-encrypted. Containers run in a sandbox (gVisor) with a restricted syscall profile and a network egress allow-list. Access to the server is limited to the operator.
Stated plainly: this is a service run by one person on self-hosted hardware. Reasonable measures are taken, but no absolute security can be promised, and you should not store data here whose exposure you could not tolerate.
11. Children
The service is not directed at children under 16 and accounts require the user to be 16 or older (Terms §3.1). No data is knowingly processed from children under that age.
12. Changes
This policy may be updated. The version and date at the top always reflect the current text. Material changes are announced in the app.
Terms of Service
Version 1.2, in force. Accepting these is required to create an account. Section 4 is the Acceptable Use Policy.
1. What this is
These Terms govern your use of ZeroLog (zerolog.ch and its subdomains), a self-hosted AI workspace that gives you chat access to third-party AI models, real Linux containers, public network ports, and autonomous agents that can run commands on your behalf.
By creating an account or using the service you accept these Terms. If you do not accept them, do not use the service.
The service is operated by a single natural person in Switzerland, not a company. It is provided in the operator's own name and on the operator's own hardware.
2. The service, described honestly
ZeroLog gives you:
- AI chat against models hosted by third-party inference providers. The pool models run on DeepInfra; Gemini models run on Google; a model whose name carries a provider prefix (
openrouter/…,requesty/…,groq/…and others) is served by that provider, and the two routers among them (OpenRouter and Requesty) forward the prompt onward to the model's operator under their own terms. If the provider serving your model fails mid-request, the same model may be served by another provider from the Privacy Policy's list so your request completes. Your prompts leave this server and are processed by whichever provider serves the model you picked; the model picker names it, and the Privacy Policy lists every provider with its country. - Linux containers running under a sandbox (gVisor). You get root inside your own container.
- Public ports: you may expose a service on a
*.zerolog.chhostname. Anything you publish there is reachable by the public internet and is published in the operator's name and from the operator's IP addresses. - Autonomous agents (
/goal, scheduled tasks) that continue to run commands without you watching, on instructions you gave. - Outbound network access via an egress gateway, which may route through infrastructure in other countries.
This is a hobby-scale service run by one person. There is no uptime guarantee, no support guarantee, and no guarantee that your data survives. See §9 and §10.
3. Account and eligibility
3.1 You must be at least 16 years old. If you are under 18, you may only use the service with the consent of a parent or legal guardian.
3.2 Registration requires a username and a password. No email address is collected. This has a consequence you must accept: there is no password reset. If you lose your password, you lose your account and its contents.
3.3 You are responsible for everything that happens under your account, including actions taken by agents you started and by anyone you share a container or workspace with.
3.4 One person may not operate accounts to evade a suspension, a quota, or a spend limit.
4. Acceptable Use Policy
This section is the core of these Terms. It exists because the operator's name, hardware, IP addresses and legal identity stand behind everything you do here.
You must not use ZeroLog, its containers, its agents, its network or its models to:
4.1 Attack, disrupt or overload anyone
- Denial-of-service or distributed-denial-of-service attacks of any kind, including tests, simulations, demonstrations, stress tests and "load tests" against systems you do not own.
- Traffic floods, amplification or reflection attacks, or any traffic intended to exhaust another party's bandwidth, connections, CPU or memory.
- Operating, hosting or controlling a botnet, command-and-control server, stresser/booter service, or a proxy or relay used to conceal attack traffic.
- Port scanning, vulnerability scanning, fuzzing, brute-force or credential-stuffing attacks against systems you do not own and do not have written authorisation to test.
4.2 Create or distribute malicious software
- Writing, compiling, building, packing, obfuscating, testing, hosting or distributing malware, including ransomware, wipers, worms, trojans, rootkits, bootkits, keyloggers, info-stealers, banking trojans, RATs, droppers, loaders and exploit kits.
- Developing or weaponising exploits for vulnerabilities in systems you do not own.
- Building tooling whose primary purpose is to defeat antivirus, EDR, sandbox detection or other security controls.
- Hosting or distributing stolen credentials, stolen data, card data, or dumps.
On security research: defensive security work, CTF challenges, malware analysis in an isolated container, and testing of systems you demonstrably own or are contracted to test are permitted. The line is authorisation and intent, not subject matter. If you are doing security work, be prepared to evidence your authorisation on request. Automated scanning may flag your activity; if it does, the burden is on you to show the work was authorised.
4.3 Gain or attempt unauthorised access
- Accessing or attempting to access any account, container, workspace, network, database or system that is not yours.
- Escaping or attempting to escape the container sandbox, the hypervisor, or the egress controls.
- Circumventing quotas, spend limits, rate limits, the egress allow-list, or any access control of this service.
- Intercepting, sniffing or altering traffic that is not yours.
4.4 Commit crimes or infringe rights
- Any activity unlawful under Swiss law or the law that applies to you.
- Fraud, phishing, identity theft, social engineering, or impersonating a person or organisation.
- Producing fake identity documents, forged records, counterfeit goods, or deceptive material intended to pass as genuine.
- Infringing copyright, trademarks, patents, trade secrets, or personality rights, including hosting or distributing pirated media or software.
- Unsolicited bulk messaging (spam) of any kind, and harvesting contact data for that purpose.
4.5 Produce or handle prohibited content
- Child sexual abuse material: created, stored, transmitted, processed or generated. This is reported to the authorities without notice to you.
- Content that incites, promotes, organises or provides operational assistance to terrorism, violent extremism or serious violence against people.
- Instructions for producing weapons, explosives, or chemical, biological, radiological or nuclear agents intended to cause harm.
- Non-consensual intimate imagery, including synthetic imagery of real people.
- Targeted harassment, stalking, doxxing or threats against a person.
- Racial, ethnic, religious or sexual-orientation hatred and discrimination, and the denial or gross trivialisation of genocide or other crimes against humanity (Art. 261bis of the Swiss Criminal Code). Published from this service, that content makes the operator its publisher, which is why it is named here rather than left to the general prohibition above.
4.6 Abuse the models
- Attempting to circumvent the safety controls of a model or of this service in order to obtain output that is otherwise prohibited by this section ("jailbreaking").
- Reselling or redistributing model access, or operating the service as an inference proxy for third parties, unless expressly agreed in writing.
- Automated scraping or bulk extraction of model output for the purpose of training a competing model, where the upstream provider's terms forbid it.
4.7 Abuse the resources
- Cryptocurrency mining, coin-hashing, or proof-of-work computation of any kind.
- Deliberately wasteful workloads whose purpose is to consume capacity rather than to produce a result.
- Using the egress gateway to anonymise activity that would breach this section.
4.8 Sanctions and export control
The operator supplies compute, model access and cross-border network egress. You must not use the service if you are subject to Swiss, EU, UK or US sanctions, nor make it available to a person or entity that is, nor use it in or for the benefit of a comprehensively sanctioned territory. You are responsible for any export-control obligation that attaches to what you build or transmit here.
4.9 Public ports carry extra duties
Anything you expose on a *.zerolog.ch hostname is published in the operator's name. You must not publish there: malware distribution points, phishing pages, illegal marketplaces, CSAM, or infringing content. Abuse complaints about a published port land with the operator, and will result in immediate closure of that port.
5. You are responsible for your agents
ZeroLog can run agents that continue working autonomously for hours on a goal you set.
An agent's actions are your actions. You accept full responsibility for everything an agent does under your account, including outcomes you did not specifically foresee. "The AI did it" is not a defence, and the operator does not accept it as one. If you cannot supervise an agent, do not start it.
The same applies to anyone you invite to a container or workspace: their actions under your resources are your responsibility toward the operator.
6. Enforcement
6.1 Investigation. The operator may investigate suspected breaches of §4, including inspecting container contents, network flows and logs where technically possible. Anonymous (client-side encrypted) chats cannot be inspected. See the Privacy Policy.
6.2 Immediate suspension. The operator may suspend or terminate your account, stop your containers, close your ports and cut your network access immediately and without prior notice where there is a reasonable suspicion of a breach of §4, or where your use creates a security risk, a legal risk, or a risk to the service or other users. There is no obligation to warn first.
6.3 Preservation and disclosure. Where required by Swiss law or by a lawful order from a Swiss authority, the operator will preserve and disclose data. In cases involving CSAM or an imminent threat to life, the operator will report to the authorities proactively.
6.4 Costs. Where your breach causes the operator direct costs (abuse handling, IP reputation damage, blocklisting, upstream provider penalties, legal fees), those costs are recoverable from you under §8.
6.5 Termination for breach. Subscription fees for the current period are not refunded where an account is terminated under §4. Unused prepaid credit is refunded less the operator's documented costs arising from the breach (abuse handling, upstream penalties, legal costs). Credit is not forfeited as a penalty: a Swiss court reduces an excessive contractual penalty in any case (Art. 163 para. 3 CO), so this states what the operator would actually be able to keep.
7. Payment, credit and refunds
7.1 Plans buy hardware capacity (container size, count, ports). Model usage is paid separately from credit, priced per §7.2.
7.2 Credit is prepaid, is consumed as you use models, and is not exchangeable for cash while your account is open: it pays for model usage and nothing else. On termination it is refunded under §12.3. Payments are processed by Stripe; the operator does not receive or store your card details. Topping up carries a 3% currency buffer and no service fee, applied to the conversion into credit and shown in the quote before you pay. Token prices are the inference provider's rate plus a service margin, currently 2%. The margin is already included in every price the app shows (the model picker, the catalogue, and the cost strip under each reply), so the price shown is the price charged. Usage billed against your own provider API key carries no margin, because that spend never passes through the operator.
7.3 Prices and model rates may change. Rate changes for models follow the upstream provider and can take effect without notice, because they are not the operator's prices.
7.4 You are responsible for spend you cause, including spend caused by an agent running autonomously. Spend limits are a convenience, not a guarantee; do not rely on them as your only control.
7.5 Statutory withdrawal rights, where they apply to you as a consumer, are unaffected.
8. Your indemnity to the operator
This clause is the reason these Terms exist.
You will defend, indemnify and hold harmless the operator against any claim, demand, proceeding, loss, damage, fine, penalty, and reasonable legal and abuse-handling costs arising out of or connected with:
(a) your use of the service, including anything done by an agent under your account or by any person you gave access to; (b) your breach of these Terms, and in particular of §4; (c) content you generate, store, publish or transmit through the service; (d) your infringement of a third party's rights; and (e) any claim by a third party that your activity harmed them, their systems or their data.
Limits on this indemnity. Where you are a consumer, this obligation is capped at the same amount that limits the operator's liability to you under §10.2. The two sides are deliberately symmetrical: a duty on you far larger than the operator's own ceiling is the imbalance Art. 8 UCA (UWG) exists to strike, and a clause that is struck protects nobody. It does not apply where the loss was caused by the operator's own intent or gross negligence, nor to the operator's own regulatory fines (Art. 20 CO: an agreement to shift somebody else's penalty onto you is void, and including it would put the rest of this clause at risk). It applies in full where you use the service in a professional or commercial capacity, where Art. 8 UCA does not apply.
This survives termination of your account.
9. No warranty
The service is provided "as is" and "as available", with no warranty of any kind, express or implied, including merchantability, fitness for a particular purpose, non-infringement, availability, or accuracy of model output.
Specifically not warranted:
- that the service will be available, uninterrupted, or performant;
- that your data, containers, files or chat history will survive, so keep your own backups;
- that model output is correct, lawful, safe, non-infringing or fit for any purpose;
- that a sandbox or an isolation boundary is impenetrable;
- that a third-party provider (inference, payment, network) will continue to be available.
AI output is not advice. Output from this service is not legal, medical, financial, tax or professional advice, and must not be relied on as such.
10. Limitation of liability
10.1 To the fullest extent permitted by Swiss law, the operator is not liable for indirect, incidental, consequential or special damage, lost profit, lost data, business interruption, or reputational harm.
10.2 The operator's aggregate liability arising from or connected with the service is limited to the total amount you paid in the twelve (12) months before the event giving rise to the claim, or CHF 50, whichever is greater.
10.3 What cannot be excluded. Nothing in these Terms excludes or limits liability for intent or gross negligence (Art. 100 CO), for personal injury or death, or any other liability that cannot be limited under mandatory Swiss law. Where you are a consumer, mandatory consumer protections of your country of residence are unaffected.
10.4 The operator is not liable for the acts of third-party providers (inference, payment, network, hosting), nor for what other users do.
11. Your content and data
11.1 Your content stays yours. You grant the operator only the technical licence needed to run the service: to store, transmit, process and display your content for the purpose of providing it to you, and to transmit prompts to the inference provider you selected.
11.2 The operator does not use your content to train models and does not sell it.
11.3 On account deletion, your data is deleted as described in the Privacy Policy. Backups and legally required records may persist for a limited period.
11.4 Anonymous chats are encrypted in your browser. The operator cannot read, recover, export or restore them. If you lose the passphrase, the content is gone permanently, and no support request can change that.
12. Availability, changes and termination
12.1 The operator may change, restrict or discontinue any feature at any time, including discontinuing the service entirely. Reasonable notice will be given where feasible; where a provider, a cost, or a legal obligation forces the operator's hand, it may not be.
12.2 These Terms may be amended. Material changes are announced in the app or on the site at least 14 days before they take effect, and the version you accepted is recorded on your account. Continued use after the effective date is acceptance of the new version. If you do not accept, stop using the service and request deletion before that date; credit is refunded under §12.3.
12.3 You may terminate at any time by deleting your account. Unused prepaid credit is refunded on request; the operator may deduct amounts already owed. (§6.5 covers the different case of termination for breach.) Subscription fees for the current period are not refunded.
13. Governing law and venue
13.1 These Terms are governed by Swiss law, excluding its conflict-of-law rules and the CISG.
13.2 The place of jurisdiction is Baden, Canton of Aargau, Switzerland.
13.3 If you are a consumer, this does not bind you. Art. 32 of the Swiss Civil Procedure Code gives you the choice of the court at your own domicile or at the operator's, and Art. 35 para. 1 lit. a ZPO makes that right one you cannot waive in advance. If you live in the EU, Iceland or Norway, Art. 15-17 of the Lugano Convention give you the same protection. §13.2 therefore applies in full only where you use the service commercially.
13.4 The choice of law in §13.1 has the same limit. Where Art. 120 of the Swiss Private International Law Act (IPRG) applies to you as a consumer, the law of the state of your habitual residence governs instead, and a choice of law is excluded; where EU law applies to you, the mandatory consumer protections of your residence remain applicable notwithstanding §13.1 (Art. 6 para. 2 Rome I Regulation).
14. Miscellaneous
14.1 If a provision is invalid, the rest stays in force and the invalid provision is replaced by one closest to its economic intent.
14.2 No rights may be transferred by you without consent. The operator may transfer this agreement as part of a transfer of the service, with notice.
14.3 Failure to enforce a provision is not a waiver of it.
14.4 These Terms are published in English only, and the English text is the binding version. Other parts of this site are available in German; these Terms are not.
Report abuse: [email protected]. Include the hostname, IP, timestamp (with timezone) and evidence. Abuse reports about *.zerolog.ch are acted on.
Privacy at a glance
A plain-language summary of the Privacy Policy above, under the Swiss Federal Act on Data Protection (FADP). Where this summary and the full policy differ, the full policy governs. Last updated: 8 September 2026.
About the name. ZeroLog means we do not ask for more than the service needs: no email, no phone number, no name at registration, and no stored IP addresses. It does not mean you are anonymous, and it does not mean nothing is written down — ordinary chats are saved so your history survives, and anonymous chats are the mode where the server genuinely cannot read them. Both are described below, in those words.
Paying identifies you. Registration is name-free, but topping up credit is not: card payments and Google Pay carry your name and billing address to Stripe, and the operator can see them there. If you pay, you are identifiable — by us, by Stripe and by your bank. Only never-paying accounts stay unnamed, and even they are not untraceable.
Controller
Gian-Luca Luongo, Dorfstrasse 77, 5430 Wettingen, Switzerland · [email protected]
What is processed
- Account: a username, a password hash (bcrypt) and the time you registered. No email address is collected — there is no field for one, which also means there is no password-reset by mail.
- Chats and messages: stored in a SQLite database on this server, so your history is there when you come back. Anonymous chats are the exception: their content is encrypted in your browser and the server holds only the ciphertext and the billing counters. Nobody operating this service can open them, and losing the passphrase loses the history.
- Containers: the files you create live in a workspace directory on our hardware, and on the NAS while a container is paused. They are yours, they are not read as a matter of routine, and deleting a container deletes its workspace. The one exception is stated in the Terms and not hidden here: when a breach of §4 is being investigated, the operator may inspect container contents, network flows and logs. There is no technical barrier to that — only the undertaking not to do it otherwise.
- Vault: credentials you store are encrypted with AES-256-GCM and never written to logs in clear text.
- Usage and billing: per-request token counts and cost, plus the plan you are on. Needed to bill accurately and to show you what you spent.
- IP addresses are never written to the database. They are held in memory to rate-limit sign-ins and registrations. They do appear transiently in server logs — failed logins, security events — which the system journal rotates away. So "not stored" is true of your account and your history, and not true of the logs; saying it without that qualification would overclaim.
Who else sees anything
- DeepInfra (USA) runs the pool models — the ones
whose names carry no provider prefix. Models named with a prefix are served by that provider
instead: Gemini requests go to Google (USA),
openrouter/…models to OpenRouter (USA),requesty/…models to Requesty (Netherlands) — the full list with countries is in the policy above, and the model picker names which provider runs each one. This is unavoidable: inference happens on their machines, and it is the one transfer the service cannot work without. A chat that uses vault credentials still flips a zero-retention flag, but that flag is one provider's field and the pool answering requests today ignores it. Assume the prompt is retained by whoever answers it, the same as any other. - IONOS (Germany) carries the outbound traffic from your containers. It sees the connections a container makes, not the contents of your chats, and it exists so that traffic leaves from a stable address instead of ours.
- Leonardo (Australia) generates images — only if you switch that connector on. It receives the image prompt and nothing else.
- Google (USA) receives data in two separate cases, and it is worth keeping them apart. If you pick a Gemini model, your prompt goes to Google, exactly as it would to DeepInfra for a pool model. If you link Google sign-in, Google sees an account identifier and nothing else. Neither happens on its own: pick no Gemini model and link no Google account, and Google receives nothing.
- Anthropic, OpenAI and Google (all USA) receive whatever you type and whatever files the tool reads, if — and only if — you run Claude Code, Codex or the Gemini CLI inside a container and sign it in with your own account. Those tools talk to their own vendor directly, not through our model pool, and that exchange is not visible here. Starting one and signing it in is the consent it rests on; don't run them and nothing is sent.
- OpenRouter (USA) and Requesty (Netherlands) also serve as the fallback pool, and that fallback is routine, not hypothetical: when a pool request fails — provider out of funds, down, or refusing — the same model is retried at another provider from the list above and the reply is billed at the price of whoever served it, never more than the price you were shown. A failover never reaches a provider in a country without an adequacy finding or a stated derogation basis; in particular nothing is routed to SiliconFlow (China) unless you picked a SiliconFlow model yourself.
- Why this is allowed. For a transfer abroad the
FADP wants either adequate protection in the destination state (Art. 16 para. 1, the list is
Annex 1 to the Data Protection Ordinance) or an exception under Art. 17. Both apply here, but
not the same one to every recipient.
Adequate protection (Art. 16 para. 1). Germany and Ireland are on the list, so IONOS (container egress) and Stripe's European entity are covered outright. The USA is on it only for organisations certified under the Swiss–US Data Privacy Framework — adequacy there is per organisation, never country-wide. Checked on 31 July 2026: Cloudflare, Inc., Google LLC and Stripe, LLC each hold an active Swiss certification, so the transfer to each company rests on Art. 16 para. 1. The operator has not separately concluded standard data protection clauses with any of them and does not claim to have; requests from Switzerland are normally terminated at a Swiss Cloudflare edge in any case.
DeepInfra is not on that list — not active, not lapsed, not withdrawn. So the Framework cannot be claimed for the largest transfer this service makes. The basis is Art. 17 para. 1 lit. b FADP: the disclosure is directly connected with performing the contract between you and us. Answering you is sending your question to a model. Assume that anything you type into a prompt leaves Switzerland.
Leonardo runs on your consent. Australia has no Swiss adequacy finding, and an Australian company cannot join the Framework at all. Image generation therefore rests on Art. 17 para. 1 lit. a FADP — your explicit consent. It is off until you switch it on; switching it on is the consent and switching it off withdraws it for the future. Google sign-in is optional too, but rests on Art. 16 para. 1 because Google LLC is certified — optional does not automatically mean consent. - Stripe (Ireland and USA) handles payments. Card details never reach ZeroLog; we store the amount, the time and Stripe's reference.
- Cloudflare (USA — the company's seat; your request is terminated at the edge location nearest you, from Switzerland normally Zurich or Geneva) carries the connection as CDN and tunnel, so it sees request metadata in transit. The origin server's address is never exposed.
- No analytics, no trackers, no external fonts or scripts — including on this page, which loads only same-origin stylesheets and the language switcher and calls no API at all.
Cookies
One for signing in, and only once you sign in: __Host-mh_session (HttpOnly, Secure,
SameSite=Lax). It
holds a random session token, does nothing but keep you signed in, and expires after 30 days.
Signing out deletes the session on the server. This page sets no cookies at all.
One more, if you arrive through a link we posted. When the operator answers a
question in a public forum, the link he leaves carries a short name for that link, not for
you. Following it records three things on this server: which link it was, the time, and the
host of the page you came from — reddit.com, never the path or the query,
because those carry search terms and titles. No IP address is written down, and nothing about
your browser, so there is nothing here to build a profile from. The cookie that comes with it,
__Host-mh_ref (HttpOnly, Secure, SameSite=Lax), holds that link's name and nothing
else, expires after seven days and never lasts longer than 30, and identifies nobody — everyone arriving
through the same link gets the identical value. No third party is involved, and these records
are deleted on the same retention schedule as everything else in that tool, 30 days by
default.
How long
Account data, chats and workspaces are kept until you delete them or ask for the account to be removed. Billing records are kept as long as Swiss accounting law requires. Deleting a chat or a container deletes its content; aggregate usage totals are retained for accounting and are not linked to message content.
Your rights
Access, correction, deletion and a copy of your data — by email to the controller above. You can export your chats yourself at any time from the app, in Markdown, JSON, HTML or plain text.
Legal notice
Operator
Gian-Luca Luongo
Dorfstrasse 77
5430 Wettingen, Switzerland
[email protected]
Liability
ZeroLog provides access to third-party AI models and to computing environments you control. Model output can be wrong, and code an agent runs does what it does — check anything you intend to rely on. No warranty is given for the accuracy, completeness or availability of results, and responsibility for what you run in your containers rests with you.
Legal research is not legal advice
The legal research feature answers from official sources and cites them. It is automated research, not advice from a lawyer, and it creates no client relationship. For a binding answer in a specific matter, consult a qualified lawyer.