Privacy policy
Effective 3 October 2026. This policy covers the Mework desktop app in every edition: on Windows the installer, the portable archive and the MSIX package distributed through the Microsoft Store; on macOS the app distributed as a disk image.
In short
Mework collects nothing. There is no Mework account, no telemetry, no analytics and no crash reporting, and the only server of the developer's that the app talks to is the download mirror for updates, described below. What you do in Mework stays on your computer, except the requests you direct it to make to services you choose.
What stays on your computer
Settings, projects, conversations, attachments and usage statistics are stored in %APPDATA%\com.mework.app and %LOCALAPPDATA%\com.mework.app on Windows, and in ~/Library/Application Support/com.mework.app on macOS, with caches in ~/Library/Caches/com.mework.app and ~/Library/WebKit/com.mework.app. Global memory and the configuration files you write are kept in ~/.mework (%USERPROFILE%\.mework on Windows), and project memory in each workspace's own .mework folder.
API keys and sign-in tokens never go into your settings or conversations. On Windows, API keys are kept in the Windows Credential Manager; on macOS they are sealed in ~/.mework/credential-vault with a key held by the Mework Safe Storage item in your login keychain. An OpenAI Codex sign-in is kept as an encrypted file in ~/.mework/codex-oauth, whose key is held in that same credential store. Mework stores no credential for Claude Agent; it uses the login that Claude Code keeps on your computer.
Uninstalling the app does not delete this data, except that the Windows installer's uninstaller removes the two folders under AppData when you tick Delete the application data. To delete everything, remove the folders above and ~/.mework, and the Mework entries in Windows Credential Manager or, on macOS, the Mework Safe Storage keychain item.
What leaves your computer, and to whom
Only to the services below, and only when you use them:
- Model providers you add (for example OpenAI, Anthropic, Google, Azure OpenAI, AWS Bedrock, Google Vertex AI, xAI, DeepSeek or any OpenAI-compatible endpoint) receive each request's conversation content, the files and tool results it includes, and your API key or sign-in. Their own privacy policies govern that data.
- OpenAI Codex signs in with your ChatGPT account at OpenAI, and its requests go to OpenAI. The Claude Agent provider runs the Claude Code executable that ships with Mework, which uses the Claude Code login already on your computer and sends its requests to Anthropic. Mework does not read, copy or forward that login, and it turns Claude Code's telemetry and error reporting off.
- Web search and fetch: the search service you configure receives your queries; the sites the agent fetches, and the pages you open in the built-in browser, receive ordinary web requests. To show a site's icon next to a search result, Mework requests that icon from the site itself.
- MCP servers, hooks and SSH machines you add receive what you configure them to receive. On each SSH machine you use, Mework also installs a small helper program in
~/.mework/remote. - Update check: the Windows installer and portable editions and the macOS edition ask GitHub (
api.github.com) for the latest release when you open Settings → System → Updates; GitHub sees your IP address and the app version. When GitHub cannot answer, they read the same information fromdl.mework.dev, Mework's download mirror on Cloudflare. A download started from that page comes fromdl.mework.dev, or from GitHub if the mirror fails, and that host sees your IP address and the app version too. The MSIX edition never checks. - Local model: when you choose to install it, its files are downloaded from Hugging Face, or from its mirror hf-mirror.com if you pick that source. On Windows, the llama.cpp runtime it runs on is downloaded from GitHub, and its Vulkan loader from LunarG (
sdk.lunarg.com).
Children
Mework is a tool for developers and is not directed at children under 13.
Changes
Changes to this policy are published on this page with a new effective date.
Contact
Questions about this policy: open an issue at https://github.com/catblob-hash/Mework/issues.