Connectors
Connectors let the model look things up in apps you already use: your Linear issues, your Notion pages, files you pick from Google Drive, and the notes and documents in a folder on your computer. They run from your browser, and they only read. A connector can't create, edit, or delete anything.
Connectors are in Beta. Connect them in Settings → Connectors, then switch one on for a chat from the composer's + menu. Settings lists your connectors first, then Where connector content goes: who can see what the model reads, and the switch that keeps it on attested nodes. Approvals follow once something is connected.
What connectors do
| Connector | What the model can look up |
|---|---|
| Linear | Search and list your issues, read one issue in full, and list projects. |
| Notion | Search your pages and databases, and read a page in full. |
| Google Drive | List the files you picked, and read one. It can't see or search the rest of your Drive. |
| Local folder | Get an overview of one folder on this computer, search its notes and documents by keyword, and read a file. |
The model decides when to look something up while it answers, as it does with built-in tools. Each lookup appears in the reply as a line such as Searched your Linear issues, with the items it found as chips beneath it. A chip links to the item in Linear, Notion, or Google Drive. Once nothing is waiting for you, lookups in a row fold into one line, such as "3 lookups · Linear, Notion", that expands to the full list. Denied lookups, and results you didn't send, get their own lines.
Lookup results aren't saved in your chat history; the model's answer is. If a later message needs the details again, the model looks them up again.
Connections are stored on this device, encrypted under your passkey. They aren't synced, so connect again on each device you use.
Use a connector in a chat
Switch it on
Open the + menu next to the message box. Under Use in this chat, switch on each connector this chat may use. Every connected app is listed in every chat's + menu, and none is on until you switch it on for that chat.
What you switched on shows as chips above the message box. Press × on a chip to stop using that connector in this chat.
Ask
Ask as you normally would: "what's still open on the launch project?" or "summarize the meeting notes in my folder from last week".
Approve each lookup
With approvals on, which is the default, each lookup waits for you first. Lookups the model asks for together arrive as one card, with a line for each. See Approving lookups.
The + menu's footer says Web search is off in chats that use connectors. That's one of the guardrails.
Connect Linear or Notion
Press Connect
In Settings → Connectors, find Linear or Notion under Your connectors and press Connect.
Sign in with the vendor
A popup opens on Linear's or Notion's own sign-in page. Sign in and approve access for ZeroSignal. Your password goes to the vendor, never to us, and the access the vendor grants is stored only in this browser.
If the popup is blocked, the row says Allow popups for this site, then try again. Cancel stops waiting, and after two minutes without an answer the row offers Try again.
Check the row
The row shows Connected.
Whichever vendor you connect, the app offers the model only a few lookup tools it chose itself, and refuses any call outside them. For Linear, the sign-in also asks for read access only, so the access itself can't change anything. Notion's sign-in grants wider access, so for Notion, read-only is the app's rule rather than a limit on the access.
Connect Google Drive
Connect in Settings
In Settings → Connectors, press Connect on the Google Drive row.
Sign in with Google
A Google popup asks which account to use and for permission to the Drive files
you use with ZeroSignal. That's Google's drive.file permission: access only to
the files you pick, never the rest of your Drive. Google's consent screen
describes what the permission allows in general, which includes editing those
files. ZeroSignal only reads them.
Pick files
Google's file picker opens next. You can open folders to find files, and select several at once, but you pick files rather than whole folders. The picker shows only the kinds of file the connector can read:
- Google Docs, Google Sheets (the first sheet only), and Google Slides
- PDF, Word (
.docx), Excel (.xlsx), HTML, CSV, Markdown, and plain text
A stored file over 20 MB can't be read. Google exports Docs, Sheets, and Slides as text, and limits an export to 10 MB.
If the picker asks you to sign in again or never loads, your browser is blocking Google's cookies on this site. Close closes the picker.
- Brave: close the picker, open Shields for this site (the lion icon in the address bar), then Advanced options, and set cookies to Allow all cookies. Brave reloads the page; then pick files again. This loosens Shields for this site only, and the app loads Google's code only while you connect Google Drive or pick files.
- Firefox: when Google asks to allow access to its cookies, choose Allow, and the picker loads.
Chrome and Safari need no change.
The row then shows how many files you picked. Open it to see the list, remove a file with ×, or press Pick files to add more. In a chat, Pick files from Google Drive… in the + menu does the same. As the row says, The model can read only the files you pick. You can pick up to 50; past that, the extra files aren't added and the app tells you.
Google's access lasts about an hour, and Google renews it only through its own sign-in window. So when you send a message in a chat with Google Drive on and less than ten minutes of access is left, the Google window opens again. If you're still signed in to Google, it may only flash open, or ask you to choose your account. Your message doesn't wait for it.
Connect a local folder
This needs a desktop Chromium browser, such as Chrome or Edge. On Safari,
Firefox, and every phone and tablet, the row reads Needs desktop Chrome or
Edge. Brave turns off the browser feature this uses, the File System Access
API, by default. On Brave the row shows how to turn it on at brave://flags.
Choose the folder
In Settings → Connectors, press Choose folder on the Local folder row and pick a folder of notes and documents, such as an Obsidian vault or a project's docs.
Allow access
Your browser asks to let the app view the folder. The app only ever asks to read, and the row says so: Read-only. ZeroSignal never changes your files.
Let it index
The app indexes the folder on this device and shows its progress. Nothing leaves the device while it does. When it's done, the row shows the folder's name and how many files it holds. Press the chevron beside them for a line saying what it left out and why. The index is stored on this device, encrypted.
What gets indexed:
| File type | Size limit per file |
|---|---|
Markdown (.md, .markdown) and text (.txt) | 1 MB |
PDF and Word (.docx) | 20 MB |
HTML (.html, .htm) | 5 MB |
The index holds up to 10,000 files, and the scan stops after 50,000 files and folders. For a folder that big, the row's stats line says Stopped after scanning … items. Choose a smaller folder.
The first time a chat uses the folder in a browser tab, the app checks for changed files in the background. Re-index in the row's ⋯ menu does the same on demand.
Chrome can drop folder access when it restarts, and the row then asks you to Allow access again. When Chrome asks, choose Allow on every visit so access lasts after a restart.
Approving lookups
Two switches under Settings → Connectors → Approvals decide when the app stops to ask you. Approvals appears once something is connected.
| Setting | Default | What it does |
|---|---|---|
| Ask before each lookup | On | Before lookups run, a card shows what the model wants to do, such as Search your Linear issues?, and with what. Details shows every argument in full, exactly as the vendor will receive it. |
| Review results before sending | Off | After lookups run, and before their results reach the model, a card asks Send these to the model? and lists what was found. Full result shows exactly what will be sent. |
The model often asks for several lookups at once. Those arrive as one card, titled with what they are, such as Read 6 files? or Allow 3 Linear lookups?, with a line per lookup. Open a line for its arguments and Details. Uncheck a line and that lookup won't run; the model is told you declined it. A long list shows its first few lines and Show N more, and the lines you haven't shown stay unchecked until you show them.
On a request card:
-
Allow N runs the checked lookups. A card for a single lookup has Allow once instead.
-
Always allow runs the checked lookups, then lets the same connectors look things up without asking:
- for this reply, such as Linear, for this reply: until the model's answer is done. If a lookup by another connector comes up, the app asks again.
- in this chat: until the chat ends.
- in every chat: to take this back, press Remove next to the connector under Always allowed in every chat in Settings.
On a phone, Always allow… opens a sheet with all three.
-
Deny all skips every lookup on the card, and the model is told you declined them. A card for a single lookup has Deny.
A card waits up to 10 minutes, or less if your session would lock sooner, and expires as a whole. Its line then reads Not answered in time, with Ask again, which writes the reply again.
On a review card, there's a line per result, with its size. Uncheck a line and that result isn't sent. Send N passes the checked results to the model and Don't send holds them all back. A card for a single result asks Send this to the model?, with Send and Don't send. The card also says where the results go: The operator you route to will see this., or on an attested node that forwards to a provider, which provider. "Always allow", even for this reply, skips only the request card; with both switches on, you still review each round of results.
What each party can see
Settings → Connectors → Where connector content goes sums it up, with a link to the Privacy Policy:
Your connectors run from your browser. ZeroSignal never sees your tokens or your data. The vendor sees the API access it would see anyway. Connector content is visible to the operator you route to. On attested nodes the operator can't read it: it stays on the node, or goes to one named provider that confirms zero data retention.
In more detail:
| Party | What it sees |
|---|---|
| ZeroSignal | Nothing. Your browser talks to Linear, Notion, and Google directly, and the access tokens are stored only on your device, encrypted. |
| The vendor (Linear, Notion, Google) | The API access it would see anyway: your account, and the lookups the model runs in it. |
| The operator you route to | What the model reads, because connector content joins your prompt like text you paste. If the operator relays a frontier model to the lab that publishes it, that lab sees it too. |
| The operator of an attested node | Nothing it can read. The content stays on the node, or goes to one named provider that confirms zero data retention. See Attested nodes. |
The model's answer can quote what it read. Like any message, it's saved in the chat and sent with every later message there, so the operators who answer those messages see it too.
Local folder has no vendor. The index is built and searched on this device, and what leaves it is only what the model reads: matching snippets, file paths, and the files it opens. Before anything leaves, the app replaces these with [redacted secret]:
- private keys
- AWS, GitHub, GitLab, Slack, Stripe, Google, and npm keys and tokens
- OpenAI- and Anthropic-style API keys
- JSON web tokens
- wallet recovery phrases of 12 or more words
Key and credential files, such as .pem files and SSH keys, are never opened
at all. The row's stats line, under its chevron, counts what it redacted. This
redaction applies to the local folder only. Content from Linear, Notion, and
Google Drive is sent as it is.
For how each kind of node handles your prompt, see What the operator can see. For what an attested node's hardware check proves, see Verifying an attestation.
Attested nodes
Under the summary in Settings → Connectors → Where connector content goes is one switch, Only use attested nodes for connectors, off by default:
Connector content goes only to hardware this browser has verified, where the operator can't read it.
With it on, connectors run only on a node whose attestation your browser has checked itself, and whose operator can't read the content because the node runs the model itself or forwards to one named provider that confirms zero data retention. It applies to connectors only. To send every request only to attested nodes, use Only use attested nodes in Settings → Model routing.
When the model you've chosen isn't on such a node, the + menu says Connectors are set to attested nodes only, and this model's node isn't attested., with Switch model.
When no attested node can run connectors at all, connectors pause:
- Your connectors in Settings shows Paused, and under the switch, No attested node can run connectors right now explains: Connectors are paused while this is on. They resume when an attested node is available.
- Connector chips read · paused.
- The + menu says Connectors are set to attested nodes only, and no attested node can run them right now., with Connector settings.
While the switch is on, a chat that has already used connectors continues only on an attested node. On any other node the app refuses the message before sending or paying anything, and shows This chat can only continue on an attested node. Continue in a new chat carries your unsent message to a fresh chat, without the connector history. If the node's key simply hasn't been checked yet, the card offers Try again; give it a moment.
Guardrails
These are fixed rules, not settings.
- Read-only. The model gets only lookup tools, with ZeroSignal's own descriptions, and is told the connectors are read-only.
- Web search goes off. While a connector is on in a chat, no web search tool is sent with your message. Once the model has called a connector in a chat, even for a lookup you denied, web search stays off in that chat for good, and a line under that reply says Web search is off in this chat because it used connectors. Text in a connected app may have been written by someone else, and could try to get the model to send your data to a web address. Press New chat on that line to search the web again.
- Some models can't use connectors. That covers models without tool support, and a few model families that fail at connector lookups. The + menu says Not available with and the model's name, with Switch model.
- Each reply has limits. A reply can make only so many lookups, in total and per connector, and read only so much. Past a limit, the line reads Not run: lookup limit reached or Not run: this turn's reading budget is used up, and the model answers from what it has. A long file or result is shown in part, and the model can ask for the rest in a later lookup.
Disconnecting and deleting
| Connector | How | What it removes |
|---|---|---|
| Linear, Notion | ⋯ → Disconnect, then confirm | The sign-in, from this device. The vendor keeps ZeroSignal's access until you remove it there, and the confirmation links to where you do that. |
| Google Drive | ⋯ → Disconnect, then confirm | The access token and your picked files, from this device. If Google's access hasn't expired, the app also asks Google to revoke it. Once it has expired, the confirmation links to your Google Account's connections page instead, where you remove ZeroSignal yourself. |
| Local folder | ⋯ → Disconnect, then confirm | The folder's index and the app's access to it, from this device. As the confirmation, Disconnect Local folder?, says, your files stay as they are. |
Answers based on a lookup stay in their chats, as the Linear, Notion, and Google Drive confirmations say: Chats keep what they already read. A disconnected connector's chip disappears from chats, and comes back in those chats if you connect it again.
To stop the model reading one Google Drive file, remove it from the list with ×. You can revoke ZeroSignal's Google access at any time at myaccount.google.com/connections. Change folder on the local folder's ⋯ menu swaps in another folder and indexes it from scratch.
Locking or signing out leaves your connections stored, encrypted, on this device. Sign in with your passkey and they're back. A lookup card that was waiting for you closes, and none of its lookups run.
Moving to a new account deletes the old account's connections, picked files, and folder index from this device. Your connector settings carry over, but the new account starts with nothing connected. The move doesn't revoke Google's access, so revoke it at the link above if you won't connect Google Drive again.
Google Drive and your data
Plainly, for anyone deciding whether to connect Google Drive:
- What's accessed. Only the files you pick in Google's file picker, through
Google's
drive.filepermission. For each file: its name, type, size, and last-modified time, and its contents when the model reads it. The app also receives a temporary Google access token and an opaque identifier for your Google account, which it uses to tell apart files picked under different accounts. It doesn't request your name, email address, or profile photo. - What it's used for. Only to show you the files you picked and, in a chat where Google Drive is on, to let the model list and read them to answer you. ZeroSignal doesn't use it for advertising, doesn't sell it, and doesn't use it to develop or train general-purpose AI models.
- Where it's stored. On your device. The access token and the list of picked files are encrypted under your passkey. File contents are fetched from Google when the model reads a file, and aren't saved in your chat history. The model's answer, which may quote or summarize a file, is saved like any other message, encrypted on your device.
- Who receives it. Google, which receives the app's requests for your files. The operator that answers your message, which receives what the model reads, and the lab behind a frontier model where the operator relays to it. ZeroSignal doesn't receive it: it's never sent to our servers. Google's sign-in and file-picker code is loaded from Google when you use them.
- Removing it. Remove a file in Settings, disconnect Google Drive, or revoke access at myaccount.google.com/connections.
ZeroSignal's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The Privacy Policy covers this in its "Google User Data" section.
What's next
- Privacy & security: what each party in the system can see.
- Built-in tools: web search and the other tools that run on the operator's node.
- Settings: every connector setting in one place.