Zhipu AI Resolves ZCode Data Upload Controversy
  • News
  • Asia

Zhipu AI Resolves ZCode Data Upload Controversy

Cloud data deleted and verified as ZCode shifts to user-initiated uploads and compensates all users

9/29/2026
•Ghita Khalfaoui
Back to News

Zhipu AI has moved to close a contentious chapter for its AI coding tool ZCode by announcing verified data deletion, a revised upload policy, and a user compensation package. The company said all cloud data tied to a September 18 upload controversy has been removed, with deletion verified by two third-party organizations. The announcement follows more than 10 days of developer scrutiny, product changes, source code publication, and third-party security reviews.


Incident Origin

The controversy began when developer ferstar discovered an encrypted file of around 313MB in ZCode's local data directory on September 18. Reverse engineering suggested the file packaged the user's entire workspace while logged in, including project source code, Git history, LFS file caches, and global development configurations. Developers reported that the upload feature was enabled by default in earlier versions, and some background processes continued trying to upload data even after privacy and indexing settings were turned off.

Enterprise Security Concerns

For enterprise developers, the issue went beyond product functionality and raised concerns over code assets and data security. Some companies reportedly stopped using the tool and began checking whether their code had been exposed. The episode demonstrated how quickly developer trust can be affected when data handling practices are unclear.

Zhipu AI's Response

Within 72 hours of the incident, Zhipu AI issued an apology and acknowledged that the upload mechanism had not been adequately disclosed when the feature launched. On September 19, ZCode released version 3.14.0, removing the Repo Wiki entry and the relevant paths for generating and uploading repository snapshots. On September 21, the company open-sourced ZCode's source code and released initial third-party security findings, stating that affected code data had not been retained or used for model training.

Verified Data Deletion

In its latest update, Zhipu AI confirmed that all data objects in the affected Alibaba Cloud OSS bucket, along with the bucket itself, had been deleted. The deletion was verified by the China Academy of Information and Communications Technology and NSFOCUS. The company also said ZCode will adopt a policy of no upload unless initiated by the user, and the open-source version has been updated to version 3.14.3 on GitHub under the Apache-2.0 license.

User Compensation

Zhipu AI also announced a compensation plan for all users. Paid users will receive four weekly quota reset cards and four five-hour quota reset cards, each valid for one month. Between September 28 and October 7, ZCode will distribute 100,000 free Token packages, with each package containing 100 million Tokens.

Industry Implications

The incident highlights a broader challenge for AI coding tools as they become embedded in enterprise development environments. Users and organizations increasingly need clear distinctions between data uploaded at their request and data transferred automatically in the background. Transparent data collection mechanisms and verifiable controls are becoming just as important as model capabilities.


Zhipu AI's remediation announcement signals the likely end of the immediate ZCode dispute, but the underlying concerns around code security and data governance are unlikely to fade quickly. The company's shift to user-initiated uploads, verified cloud deletion, and open-source publication may help restore some developer trust. For the broader industry, the episode underscores that balancing AI productivity with code security will remain a long-term responsibility.