# Privacy and security

> What Zeptap stores, what it sends, who can reach the MCP server, and how the passcode is protected.

Source: https://zeptap.com/docs/reference/privacy



Zeptap runs entirely on your Mac. There is no Zeptap account and no Zeptap cloud.

| Topic        | How it works                                                                                                                                             |
| ------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
| iPhone       | Nothing is installed on it. Zeptap uses the USB connection and a Bluetooth pairing                                                                       |
| Screen       | Captured over USB and processed on the Mac. OCR runs on-device with Apple's Vision framework                                                             |
| MCP server   | Listens on `127.0.0.1:47801` only, so other machines on the network can't connect. Any process on this Mac can                                           |
| Agents       | Screenshots and OCR text go to the agent you connect, and from there to that agent's model provider under your agreement with them                       |
| Passcode     | In the login Keychain, non-synchronizable (never in iCloud). Read only while unlocking; never logged, never given to agents, never sent over the network |
| Agent unlock | Allowed or blocked per iPhone with **Let agents unlock this iPhone**                                                                                     |
| Config files | Before its first edit, Zeptap backs up each agent config as `<file>.zeptap-backup`                                                                       |
| Updates      | Checked once a day against a signed feed on GitHub; updates are EdDSA-signed and the app is notarized by Apple                                           |

## USB access [#usb-access]

Over USB Zeptap talks to the iPhone's lockdown service through Apple's `MobileDevice.framework`, the same framework Finder uses. It uses it to ask for Trust, read the device name, model and Bluetooth address, turn AssistiveTouch on, and lock the screen.
