ZCode code-upload dispute escalates as company demands Zhipu erase all uploaded data

ZCode code-upload dispute escalates as company demands Zhipu erase all uploaded data

N
News Editor
2026-09-20 02:33:51
A dispute over Zhipu’s ZCode coding tool has moved into formal legal action after Taiyuan Chengming Technology sent the company a 12-page legal letter over what it described as unauthorized data uploads. According to the company, ZCode did not merely transmit small code snippets. It allegedly packaged and uploaded entire workspaces, including source code, system architecture, Git history, database passwords, API keys, cloud service credentials, and personal information tied to employees and end users. Chengming said one default workspace contained 32,932 files and about 411 million plaintext characters that were packaged for processing. A separate project contained 1,947 files and roughly 144 million characters, and only failed to reach Zhipu’s cloud because 32 consecutive upload attempts did not succeed. The company said the materials involved trade secrets, technical assets, and personal information. The letter also raises cross-border data questions. Chengming said ZCode’s Chinese privacy policy lists Beijing-based Zhipu as the service provider and data processor, while the English version names Zhipu’s wholly owned Singapore subsidiary and states that services are usually provided from Singapore and personal data is usually processed there. Chengming is asking where the data was stored, whether any overseas transfer occurred, whether it was shared with third parties, and whether it was used for model training. Zhipu had previously apologized, attributed the issue to the "codebase indexing" feature, said the problem had been fixed, and pledged to open-source ZCode and accept third-party review.

A dispute over Zhipu’s ZCode tool has moved beyond public criticism and into formal legal action.

Taiyuan Chengming Technology has sent Zhipu a 12-page legal letter, saying ZCode automatically packaged and uploaded far more than isolated code snippets. The company said the uploads involved entire workspaces, including source code, system architecture, Git history, database passwords, API keys, cloud service credentials, and personal information belonging to employees and end users.

Company says full workspaces were packaged for upload

According to Chengming, its default workspace contained 32,932 files and about 411 million plaintext characters that were packaged for processing. Another project contained 1,947 files and roughly 144 million characters. That project did not successfully reach Zhipu’s cloud only because 32 consecutive upload attempts failed.

The company said the data involved trade secrets, technical assets, and personal information.

Letter asks whether data was transferred overseas or used for training

The dispute has also raised questions about cross-border data handling. Chengming said ZCode’s Chinese privacy policy lists Beijing Zhipu as the service provider and data processor. The English version, however, names Zhipu’s wholly owned Singapore subsidiary and states that the service is usually provided from Singapore and that personal data is usually processed there.

On that basis, Chengming asked Zhipu to explain where the data was stored, whether any overseas transfer took place, whether the data was provided to third parties, and whether it was used for model training.

Zhipu had apologized and said the issue was fixed

Zhipu previously apologized and said the problem came from the "codebase indexing" feature. The feature was enabled by default in its early rollout, and repository data could be uploaded when generating Repo Wiki.

Zhipu said the relevant data would be destroyed after use, that the issue had been fixed, and that it would open-source ZCode and accept third-party review.

Chengming demands deletion and keeps legal options open

Chengming is not treating "fixed" as the end of the matter. In its letter, the company demanded that Zhipu completely delete all related data from servers, object storage, caches, backups, and disaster recovery systems. It also asked for complete access and export logs, along with proof of deletion.

The company said it also reserves the right to file complaints with regulators, bring civil litigation, and report suspected trade secret infringement to judicial authorities.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.