This policy explains what happens to data when you use the werk desktop application and, where enabled, the optional account features operated by the werk project. Summary up front:
-
werk is local-first. Your SAP metadata, indexes, digital
twins, generated documentation, chats, and settings are stored on your
machine, in your workspace, by default in a gitignored
.local/directory. - The default build has no telemetry. Nothing is sent anywhere unless you configure it or explicitly use a feature that does.
- You choose every network flow. AI providers, web search, accounts, and update checks are each described below — most are optional, and a fully offline setup (local models, no account) is supported.
1. Data that stays on your machine
Connection profiles (system host, user, credential references), indexed SAP content (customizing, custom code, authorizations), the digital twin, generated docs and reports, chat history, ad-hoc skill scripts, and app settings are written only to your local workspace. Deleting the workspace deletes this data. Note that indexed authorization data may include SAP user names and role assignments — treat your workspace as containing personal data and protect it accordingly.
SAP passwords and session cookies are stored in your local configuration/credential files (on Windows, werk additionally uses the OS credential manager). The werk authors never receive them.
2. Data that can leave your machine — only when you use the feature
- AI providers you configure (bring your own key). When you chat or run agents, prompts — which may include SAP source code, configuration, dumps, and other content from your landscape — are sent directly from your machine to the provider and model you configured (for example OpenAI, Anthropic, Azure OpenAI, Mistral, or a local Ollama instance). These transfers are governed by that provider’s terms and privacy policy under your account. If you configure a fully local model, prompts never leave your machine.
- Web search (optional). If you enable web search, your search queries go to the provider you configured (Tavily, Brave, or a self-hosted SearXNG).
- Software updates. The app checks GitHub (our releases) for update manifests, sending your current version and platform. The Windows installer may download the Microsoft WebView2 runtime from Microsoft.
- Optional account features (where enabled). If you create an account: your email address and display name (via Firebase Authentication); anonymized usage counters for plan limits; billing status (payments are processed by Stripe — we never see full card details); and, if you enable profile sync, an end-to-end encrypted copy of your profile — our servers store only ciphertext and cannot read it.
- Voluntary feedback and bug reports. Only what the dialog shows you before sending, after redaction, and only when you choose to send it.
3. Legal bases (GDPR)
For account features, we process account data to perform our contract with you (Art. 6(1)(b)), usage counters for our legitimate interest in operating the service fairly (Art. 6(1)(f)), and any consent-based flows (e.g. feedback) only with your consent (Art. 6(1)(a)), which you may withdraw at any time.
4. Retention
Workspace data: kept locally until you delete it. Account data: kept until you delete your account or request deletion. Billing records: kept as long as tax law requires. Voluntary feedback: kept until the issue is resolved and then deleted.
5. Your rights
Where GDPR, UK GDPR, CCPA, or similar laws apply, you have rights to access, correct, export, and delete your personal data, and to object to or restrict processing. For account data, contact [email protected] and we will respond within the statutory period. For workspace data, you hold the only copy — delete it locally.
6. Security reporting
If you believe you found a security vulnerability, please follow the responsible-disclosure instructions in the repository’s SECURITY.md. Please do not report vulnerabilities through public issues.
7. Children
werk is an enterprise development tool and is not directed at anyone under 16.
8. Changes
This policy may be updated; the effective date above will change and the update will be surfaced in the app. Continued use after a change constitutes acceptance.
9. Contact
[email protected] — or the postal address published at getwerk.dev.