ZeptapDocs

Privacy and security

What Zeptap stores, what it sends, who can reach the MCP server, and how the passcode is protected.

Zeptap runs entirely on your Mac. There is no Zeptap account and no Zeptap cloud.

TopicHow it works
iPhoneNothing is installed on it. Zeptap uses the USB connection and a Bluetooth pairing
ScreenCaptured over USB and processed on the Mac. OCR runs on-device with Apple's Vision framework
MCP serverListens on 127.0.0.1:47801 only, so other machines on the network can't connect. Any process on this Mac can
AgentsScreenshots and OCR text go to the agent you connect, and from there to that agent's model provider under your agreement with them
PasscodeIn the login Keychain, non-synchronizable (never in iCloud). Read only while unlocking; never logged, never given to agents, never sent over the network
Agent unlockAllowed or blocked per iPhone with Let agents unlock this iPhone
Config filesBefore its first edit, Zeptap backs up each agent config as <file>.zeptap-backup
UpdatesChecked once a day against a signed feed on GitHub; updates are EdDSA-signed and the app is notarized by Apple

USB access

Over USB Zeptap talks to the iPhone's lockdown service through Apple's MobileDevice.framework, the same framework Finder uses. It uses it to ask for Trust, read the device name, model and Bluetooth address, turn AssistiveTouch on, and lock the screen.

On this page