Skip to content
Stealward Download for Mac

About

Why I built Stealward.

Portrait of Hzao (Zac), the independent developer behind Stealward

I’m Hzao (Zac), the independent developer behind Stealward. I design and build the product, keep it running, and answer the messages that come in.

I began building Stealward in 2024, while I was still at university. It was first released in August 2026. This is where it came from, why I kept going, and the standards I have tried to hold it to.

Where it started

Stealward began as my university thesis.

The idea came from a problem I knew well. I often worked in public places, and every short trip away from the table presented the same choice: pack everything up, ask a stranger to watch it, or leave it and hope.

That question became my university thesis. I explored whether the devices we already carry could quietly watch over one another, then built the first version of Stealward to test the idea. By graduation, I had a working project, but not yet the product I believed the problem deserved.

After graduating, I kept building Stealward independently on weekends while working full-time as a software engineer at Google1. Two years after the work began, the thesis project became a released product. The reason I continued was the same reason I started: I still wanted a better answer to that moment when you have to step away.

Testing an early version of Stealward in my university library

1 Stealward is an independent project and is not affiliated with Google.

Why another one

I thought the category could do more.

When I began working on Stealward, most of the anti-theft apps I found were built around a single piece of local detection, such as movement or a disconnected power cable. They could sound an alarm, but their remote updates often felt delayed or incomplete. I could be told that something had happened without feeling that I truly understood what was happening.

I also could not find a product that brought the available signals together or used AI to help make sense of changes in the scene. A movement alert could tell me that something had moved, but I still could not reliably see an up-to-date view of what was happening. I was left wondering what had moved, what happened next, and whether my belongings were still where I had left them.

Many of these apps still cost $10 to $30 a year. I did not want to build another product within the same boundaries. If I was going to ask people to pay for Stealward, it should give them timely, dependable information and a much clearer sense of what was happening, wherever they were.

The standard

Awareness, not just an alarm.

I wanted Stealward to bring together every useful signal a device can offer. It should tell you what is happening while it is happening, let you look in live, and keep you in control from another device you have with you.

That breadth only matters if the product can be trusted. A security app should be responsive, resilient, private, and predictable. It should recover when connections change and behave carefully when the answer is uncertain. It should work on the day someone actually needs it.

That is the standard I believe this category deserves. Reaching it requires more than adding features. It requires a level of engineering care that people may never see, but should be able to feel every time they use the product.

Privacy

Privacy was a starting point.

I have been particular, perhaps even obsessive, about privacy for much longer than Stealward has existed. My first app was Numpkin, a bill-splitting app I made at university. It was not a security product, but I still built it with end-to-end encryption. I believed a service should not have the ability to read its users’ data unless that access was essential to making the service work.

That same conviction shaped Stealward from the beginning. Privacy was never something I planned to add after the product worked. Before asking what Stealward could do, I kept asking what it should never need to see.

Stealward does not sell your data or share it with third parties for their own use. Most of the personal content the service carries, even the names of your devices, is end-to-end encrypted and therefore unreadable to Stealward in the first place.

Your live video stream is end-to-end encrypted too. Stealward can carry it between your devices, but cannot view it.

Example: what I can see in Stealward’s Cloudflare D1 database (development environment) Almost all personal information Stealward stores is end-to-end encrypted. In the database, it appears only as ciphertext, and I do not hold the keys to decrypt it.

That question has often led me down the longer and more difficult engineering path. I believe that difficulty belongs with the developer, not the user. For a product that places a camera near your devices, your belongings, and the spaces around you, that is simply part of building it responsibly.

Stealward is available worldwide. Most of the service runs on Cloudflare, with each account assigned to Cloudflare’s infrastructure in the user’s region: Asia-Pacific, North America, Europe, or Oceania. Your data stays in that region unless you request an account transfer. The detailed answers live in the Privacy Policy and the Support Center.

The business

Stealward answers to the people who use it.

Stealward is supported by its paid plans. It has no advertising, and its business does not depend on selling personal data. The clearest way I know to keep the product aligned with its users is to build something genuinely worth paying for.

Questions are welcome.

If you have a question, a concern, or want to understand a decision I have made, send it over. I read every message that comes in.

Or email [Email Loading Failed] directly.