Zhipu AI deletes data and compensates users after coding tool controversy
Zhipu AI has completed technical remediation for its ZCode AI coding tool and announced a compensation plan for users. All involved cloud data has been deleted and verified by third parties.

Zhipu AI has announced the completion of technical remediation for its ZCode AI coding tool following a data upload controversy. The company confirmed on Monday that all cloud data associated with the incident has been deleted. The deletion process was verified by two independent third-party organizations, the China Academy of Information and Communications Technology and NSFOCUS.
In addition to the technical fixes, Zhipu AI has introduced a compensation plan for all users of the ZCode tool. This plan includes free Token credits. The data security incident, which surfaced in the developer community on September 18, lasted over ten days and prompted product changes, the release of the tool's source code, and external security checks.
The controversy began when a developer discovered an encrypted 313MB file in ZCode's local data directory, which reverse engineering indicated contained the user's entire workspace, including project source code and Git history. It was revealed that earlier versions of the tool had an automatic data upload feature enabled by default, without a clear user-facing option to disable it. Some developers reported that background processes continued to attempt data uploads even after privacy settings were turned off.
In response to the backlash, Zhipu AI implemented several changes. The company issued an apology, acknowledging the inadequate disclosure of the upload mechanism. In its latest announcement, Zhipu confirmed the deletion of all data objects and the bucket itself from Alibaba Cloud's storage. Going forward, ZCode will adopt a "no upload unless initiated by the user" policy, ensuring that code and project files remain on local devices unless actively uploaded by the user.
This incident highlights broader security concerns surrounding AI-powered coding tools. As AI becomes more integrated into software development, transparency regarding code location and handling is critical. Developers and companies need assurance that their source code is protected, especially when dealing with sensitive proprietary information.