What does it read?
Only what an agent or a human explicitly hands to a Zephr tool call, the file paths, line ranges, and content digests for the anchors a claim cites, and the Git metadata (commit SHAs, branch, worktree identity) for the admitted worktree. The project boundary is approved once, and nothing outside it is read.
Zephr does not silently read arbitrary files, your terminal history, clipboard contents, or secret values. There is no background indexer in local mode — if no tool call was made, nothing was read. Fleet holds references to secrets, never the values themselves.