PRIVACY
WorkPilot runs on your Mac.
There is nowhere for us to look.
Effective 2026-08-23 · Applies to the WorkPilot macOS app and this website
The short version
- No account. You never register with WorkPilot. There is no WorkPilot login, no WorkPilot server holding your work.
- Your work stays in a normal folder. Threads, knowledge, images and video are written to your Mac as ordinary files. Delete the app and they remain.
- No analytics, no ads, no telemetry. The app ships with no analytics, advertising or crash-reporting SDK. We do not count your clicks.
- What leaves your Mac, you chose. Your prompts go to the AI vendor you selected for that thread — not through us. Anything that publishes externally stops for your approval first.
01What is stored on your Mac
WorkPilot keeps your working data as plain files under your Documents folder, plus a small application-data area for app state.
- Threads, knowledge, skills, generated media — Markdown, images and video under
~/Documents/WorkPilot.
- App state — settings, thread index and usage counters, in the app's own data area.
- Credentials — API keys and tokens are encrypted with the operating system's secure storage (Keychain on macOS) and written to a permission-restricted file. They are never placed in browser storage inside the app.
Because these are ordinary files, your own backup tools (Time Machine, iCloud Drive, Dropbox, a NAS) may copy them. That is under your control, not ours.
02What leaves your Mac, and who receives it
WorkPilot connects directly to the services you enable. Your content is not proxied through a WorkPilot server, because there isn't one.
| Recipient |
What is sent |
When |
| Anthropic · OpenAI · Google · Moonshot |
Your prompts, and the files or images you attach to that thread. |
Only for the engine you selected, when you send a message. Each vendor's own privacy policy applies. |
| Media & voice providers |
The prompt and reference material needed to generate an image, video or voice. |
Only when you use a media or voice feature that you have connected. |
| GitHub |
A normal web request. GitHub sees your IP address, as with any download. |
When you download a release, or open the changelog. |
| boice Inc. update server |
An update check. The server sees your IP address and the version you are running. No content from your threads is sent. |
On startup and when you check for updates. |
We want to be exact here: the update server is operated by boice Inc., so update checks are the one place where we see anything at all — and what we see is an IP address and a version number. Nothing you write, generate or attach is included.
03What we do not do
- We do not embed analytics, advertising, attribution or crash-reporting SDKs in the app.
- We do not sell, rent or share your data. There is no data business behind the free price.
- We do not train models on your content.
- We do not require an account, an email address or a payment method to use WorkPilot.
04Team sharing
A Shared Space is a folder you already own — a NAS, Dropbox, Google Drive, anything. Members join with a code. Files are written to that folder and never pass through us. Each member signs in with their own AI subscription, so no credentials are shared.
Before files are shared, WorkPilot scans for things that should not leave — environment files, private keys, repository internals — and stops to ask.
05This website
- No analytics or advertising scripts run on these pages, and no cookies are set for tracking.
- Your language choice and the latest-version lookup are stored in your browser only, on your device.
- The download button asks GitHub which release is newest, so GitHub receives that request. Fonts are loaded from Google Fonts, which receives your IP address as a result.
- If you donate, the payment is handled entirely by that platform. We never see your card details.
06Your control
Because everything is a file on your own machine, you exercise your rights directly: open the folder to see your data, move it, back it up, or delete it. Deleting the folder deletes the data — we hold no copy to erase on your behalf. Disconnecting an engine stops any further transmission to that vendor.
Content you have already sent to an AI vendor is held under that vendor's policy. Requests to delete it must go to them.
07Changes and contact
If this policy changes in a way that affects what leaves your Mac, we will say so in the release notes rather than quietly editing this page.
Questions can be raised at GitHub Issues.
You can also write to .
← Back to WorkPilot