Guide · Native app

The Zimac desktop app

Zimac is a local-first AI workspace for Mac and Windows. Conversations, working memory, documents, profiles, and most app state live on your device; the model route you choose receives the prompt and selected context needed for each answer.

Use this guide for the shell around the work. It covers installation, model access, navigation, storage, and platform boundaries. The individual specialist, Studio, and panel guides cover what each workspace can do.

Native desktop

A bundled Mac or Windows app, not a hosted browser workspace.

Durable memory

Chats and working context persist locally between sessions.

Focused workspaces

Specialists, Studios, panels, and slash commands share one shell.

Visible gates

Consequential external actions are staged for approval where supported.

Current desktop requirements: macOS 13 or newer on Intel or Apple silicon, or 64-bit Windows 10/11. Use the official downloads page for signed release metadata and SHA-256 checksums.

What the app is#

The desktop app brings together a roster of specialists, a shared local memory layer, and dedicated workspaces for planning, review, data, design, operations, people, and connected services. You can stay in a conversation and ask for work in plain language, or open a Studio when the work benefits from a persistent visual surface.

It is a native window backed by the operating system’s WebView: WKWebView on macOS and WebView2 on Windows. The interface ships inside the application. The app does not require you to maintain a localhost web server or keep a browser tab open.

Install & start#

  1. Download the installer for your platform. On Mac, open the DMG and move Zimac to Applications. On Windows, run the per-user installer; it does not require an administrator account.
  2. Choose model access during setup. You can use Zimac’s hosted gateway, connect a supported provider directly, or point the app at a compatible local endpoint.
  3. Ask a real question. The initial conversation is enough to create your first chat. Add files, integrations, or durable memory only when you want them.
  4. Open Settings when you need to change the route. Setup can be rerun without deleting your notes or memory.
iPhone is a companion, not the desktop build. The current iOS beta is distributed through TestFlight and can pair with a desktop device. Some desktop-only surfaces are absent; see Platform differences.

Choose a model route#

The app separates its local working state from model inference. Your route determines where a prompt is processed:

Zimac hosted gatewayUses a Zimac token and metered hosted inference. The gateway processes and forwards the prompt, selected context, and model response.
Direct providerUses your provider credential from the operating system credential store and sends requests directly to that configured provider.
Compatible endpointPoints at an OpenAI-compatible service such as a local server. Whether data leaves the device depends on where that endpoint runs.
Local-first does not mean every model call is local. A cloud model must receive the prompt and selected context to answer it. Zimac shows and limits the context it assembles, but the privacy policy of the chosen route still applies.

For step-by-step provider setup, use Getting started.

The main conversation belongs to the selected specialist. Switching specialists changes the expertise and available tools, while chat history stays organized by teammate. Three other surfaces handle different kinds of work:

Useful starting points
open the Studio picker/projects/reviewopen settings

Context & actions#

Zimac can answer from local memory, documents, mounted folders, calendar and mail sources, connected services, or context you attach for one turn. Availability depends on what you have configured. A source being connected does not mean every item from it is copied into memory.

Read operations and external changes are different. Connections and Workflows classify operations by risk; exact writes can pause for a one-time approval. Other first-party cards similarly show the payload before a consequential action. Always read the card: an assistant draft, suggestion, or preview is not proof that the external action already happened.

Source boundaries stay feature-specific. Import creates durable memory from selected files. Files mounts keep a searchable view of a folder. Clipboard history stays transient unless you explicitly choose Remember. Consult each guide before assuming a source is copied, synchronized, or editable.

How replies show their work#

While a response forms, Context Bloom can show host-observed recall, tool activity, and specialist consultations. It compacts when prose begins and disappears when the turn settles. The host does not derive it from confident assistant prose, and it is not hidden chain-of-thought.

For a substantive settled answer, an expandable Decision trace can group the evidence available to that turn as Observed, Recalled, Inferred, and Unknown. It is a bounded, host-created availability ledger—not a sentence-by-sentence citation map, confidence score, or record of private model reasoning. The separate References view lists links named in the answer without claiming they were verified.

The reply toolbar also offers deterministic Copy as transforms for Slack mrkdwn, Jira wiki markup, an email draft, and plain text. The email option opens the default mail app and copies the full body to the clipboard because a long mailto: draft may be clipped.

Daily-flow assists#

Frame & Sight#

On macOS, Frame lets the main app recede to a thin, click-through border while an interactive edge tab follows across Spaces and displays. Its tray can surface bounded Volition, Night Shift, and Cadence cards; you can open the full text, return to Zimac, give feedback, snooze, or dismiss supported items. The neutral Frame does not itself observe the screen.

Sight is the optional observation leg. It is off by default, requires Screen Recording permission, and must be armed with an explicit Observe click for each session. The current build observes the primary display, excludes Zimac's windows and the cursor, samples changed frames at no more than one per second, and runs OCR on device. Raw pixels are never persisted or transmitted. Secret-redacted recognized text may use your configured model route for distillation, and accepted memories carry receipts and undo.

Current Sight limits: no Windows screen capture, window/app scope picker, or capture denylist. Pausing, unsticking Frame, quitting, or a capture failure ends the session.

Platform differences#

PlatformCurrent scopeImportant limits
macOS 13+Full desktop build, universal for Intel and Apple silicon.Native Apple Mail/Calendar access, Clipboard collection, Call Copilot capture, screen context, and the Bash Terminal rely on macOS permissions or services.
Windows 10/11 x64Core chat, memory, Studios, panels, connected services, and Windows credential storage.Some Mac-native integrations are unavailable. The current Terminal backend expects /bin/bash and is not a portable Windows shell.
iPhone betaCompanion shell over the shared core, distributed through TestFlight.Calendar, Mail, and Terminal are hidden; native desktop capture features are not present. Pairing can carry your setup and selected shared state.

Feature cards and connection status in the app are authoritative for the build and device you are using. A guide may describe a capability that only appears when its platform, permission, credential, or plugin is available.

What stays local#

Durable chats, working memory, notes, documents, profiles, plugins, playbooks, pairing state, and learned preferences are stored under Zimac’s local data locations. Sensitive app-private stores use opaque .zdata files and are encrypted when at-rest sealing is active; portable exports and plugin manifests keep their interoperable formats. Zimac normally stores the data key and provider credentials in macOS Keychain or Windows Credential Manager, with an owner-only, non-synced local fallback. If no key location is writable, sealing is unavailable. Legacy .json stores remain readable for migration and are removed after the next successful write.

Some features necessarily use services outside the device: the model route you choose, third-party integrations you connect, org-readable Sites, account and licensing services, and encrypted team relay. The exact disclosure contract differs by feature; “local-first” is a storage default, not a claim that networking never occurs.

Zimac cannot recover data for which it has no server-side copy. Keep your own device backups and understand the in-app backup boundary before deleting the app or using an erase command.

Backups & recovery#

Open Settings → Account & security → Data backups to inspect local snapshots or request a backup immediately. Backups are compressed and integrity-checked, and the app can recover a damaged memory log from a good local snapshot at launch.

The visible restore action restores the memory store from the newest backup; it does not promise to roll every other app store back to the same point. In-app backups remain on the same device, outside iCloud by default, so they are not a substitute for a separate machine backup.

Before moving encrypted data or retiring a computer, use Settings → Recovery key to export a passphrase-wrapped recovery code and keep the code and passphrase separately. Import it on the destination computer and relaunch Zimac before opening the moved data. Zimac receives neither value and cannot recreate either one.

Erase actions differ. Erasing personal memory deliberately keeps backups and connections. Erasing all local data removes backups, plugins, pairing, setup, activation, and stored Zimac credentials as well. Read the confirmation text before proceeding.