PANews reported on Sept. 20 that Taiyuan Chengming Technology Co., Ltd. has sent a formal letter to Beijing Zhipu Huazhang Technology Co., Ltd., demanding explanations over allegations that the ZCode client uploaded the company’s data assets and trade secrets without authorization. Chengming said it is reserving the right to pursue legal liability.
Chengming says uploaded materials went far beyond disclosed collection scope
According to the report, Zhipu had previously issued a public apology over what it described as 「ZCode silently uploading users’ local repository data」 and said the issue had been fixed. Chengming said its own independent evidence collection found that the upload behavior was automatically triggered and occurred in batches, rather than being limited to 「code snippets」.
Chengming said the uploaded materials included full project source code, system architecture, version control history, database passwords, cloud service credentials, and employees’ personal information in complete archived files. It said that scope went well beyond what was described in the privacy policy.
Company questions whether the issue was actually fixed
Chengming also said that although the client had been updated to version 3.12.3 on Sept. 16, upload activity was still detected in the early hours of the day Zhipu issued its public apology. On that basis, it questioned the real-world effect of the company’s statement that the issue had already been fixed.
The letter also raised questions about responsibility and data location. Chengming said network requests from the ZCode client pointed to an entity in Singapore, while the contracting party in the service agreement was Beijing Zhipu Huazhang. It asked Zhipu to clarify which entity was responsible for the uploads and whether any cross-border data transfer or overseas storage took place.
Written response requested by Oct. 10
Chengming asked Zhipu to provide a written reply by Oct. 10 and complete the following actions:
- immediately stop processing and fully delete all uploaded data, along with related derived data, caches, and backups;
- provide a complete list describing how the data was handled;
- explain where the data went, whether it was shared with third parties, whether it was used for model training, and whether any cross-border transfer occurred;
- explain how encryption private keys were stored and provide complete operation logs covering data access, downloads, and exports;
- clarify the exact scope of the previously used term 「destroyed」 in its public response;
- issue proof that deletion has been completed;
- provide a written commitment not to upload data without authorization again;
- lawfully provide access, copies, and explanations related to personal information;
- designate a formal communication channel;
- clarify the responsible entity and the status of any cross-border data transfer;
- provide the original text of the remediation statement that has already been published.
As of now, Zhipu has not issued a public response to the letter, according to the report.

