WerkLog

Privacy Policy

Version 1.0.11. Last updated August 11, 2026.

Public v1 summary: WerkLog is local-first and offline-first. Core capture works without an account. Optional backups can use your private iCloud/CloudKit database or, after you connect Google Drive, encrypted packages in its private application-data area. Diagnostic packages are never sent automatically and require your review and approval for each transmission. WerkLog does not use advertising or tracking; the optional Google integration includes SDK privacy declarations for limited analytics-related identifier, usage, and diagnostic data described below.

1. Controller and contact

For personal data that is actually received by the developer, the controller is:

Abas Hedayati Shirsavar
Hädrichweg 5, 88171 Weiler-Simmerberg
Email: shirsavar@outlook.de
Phone: +49 177 8708396

Most project data in WerkLog public v1 stays only on your device. The developer cannot access that local data unless you choose to send, share, export, or otherwise provide it outside the app.

2. Data stored inside WerkLog

WerkLog may store the following data inside the app environment to provide its core features:

3. Local-first storage and no default collection

WerkLog public v1 stores project data by default on your device inside the app-controlled environment. Core capture does not require an account, cloud backup, analytics, advertising, tracking, remote configuration, or an external artificial intelligence service.

WerkLog does not automatically send project content, analytics, diagnostics, or identifiers to the developer. If you enable iCloud Backup, WerkLog may store Timeline or Full System backup parts in your private CloudKit database. If you explicitly connect a Google Account and enable Google Drive Backup, WerkLog may upload encrypted Timeline or Full System backup packages to that account manually or according to the schedule you select. A sanitized diagnostic package is sent to WerkLog's private EU service only after you review and approve that specific transmission.

Developer Tools, Screen Feedback, and external diagnostics upload are not part of the public Release experience. Local AI voice features are available only in Advanced Mode after you enable Local AI and explicitly download or install a local voice model. The model download retrieves model files from the approved source you choose; WerkLog does not upload your voice notes or transcripts for Local AI processing. Scanner document capture is available in Advanced Mode and stores scanned pages, OCR text, and scan metadata locally on your device by default.

4. Legal basis and purposes where GDPR applies

Where the General Data Protection Regulation applies, WerkLog processes data for these purposes and legal bases:

WerkLog public v1 does not use app data for advertising, third-party tracking, profiling, automated decisions with legal or similarly significant effects, or sale to data brokers.

5. Device storage and access under German TDDDG

WerkLog stores and reads information on your device only as needed to provide the app functionality you request. This includes the local database, app files, media files, audio files, thumbnails, settings, permission-related state, and other technical app data needed for local operation.

WerkLog public v1 does not use cookies, tracking pixels, advertising identifiers, device fingerprinting, or hidden marketing identifiers.

Because this storage and access is necessary for the local app functionality requested by you, WerkLog treats it as strictly necessary device storage/access for public v1. Any later non-essential storage, tracking, analytics, or automatic diagnostics behavior would require a separate review and, where legally required, consent.

6. Hosting of this public website

This public privacy/support website may be hosted on Cloudflare Pages. Cloudflare may process technical website access data, such as IP address, request metadata, browser/device metadata, timestamps, and security/performance logs, as needed to deliver and protect these static web pages.

This website hosting is separate from the WerkLog iOS app. Visiting this public website does not give the developer access to your local WerkLog project data stored inside the app.

The public site should remain static and should not include analytics scripts, advertising tags, tracking pixels, contact forms, embedded third-party media, or non-essential cookies unless this policy and the App Store privacy answers are reviewed again.

7. Data not sent by default

By default, and while optional Google Drive Backup remains disconnected or disabled, WerkLog public v1 does not send the following data outside the app:

8. When data leaves the app

You may choose to move data out of WerkLog by sharing, exporting, copying, opening, sending content to another app, service, file destination, person, or support channel, downloading optional Local AI model files from the approved model source, or using a future separately explained integration.

If you enable Google Drive Backup, WerkLog requests only the Google Drive appDataFolder permission. Timeline Backup and Full System Backup are separate encrypted packages. They can include Project and Timeline metadata, posts, text, photos, videos, voice recordings and transcripts, scans and OCR text, properties, relations, checklists, reminder evidence, portable settings, and managed recovery files. Backup contents are encrypted on the device before upload. The recovery password stays in the device Keychain and is not uploaded; WerkLog cannot recover it.

If you enable iCloud Backup, WerkLog uses the private CloudKit database of the Apple Account already signed in on your device. Timeline and Full System backups can contain the same categories of project and recovery data needed to reconstruct the selected backup. WerkLog does not receive or store your Apple ID, iCloud password, or a separate iCloud recovery password.

The Google application-data area is hidden from the normal Drive file list and is accessible only through WerkLog's authorized integration. WerkLog may show the connected Google Account email or name and stores only a one-way account fingerprint in its rebuildable local catalog cache. WerkLog does not receive or store your Google password.

Once data leaves WerkLog, the destination may process it under its own terms and privacy practices. Apple and iOS features such as device backup, iCloud backup, App Store services, system permissions, and system sharing are controlled by Apple and your device settings, not by WerkLog.

Google processes Google sign-in and Drive storage under Google's terms and privacy practices. WerkLog does not use Google Drive Backup for advertising, analytics, tracking, profiling, or cloud AI.

The final Xcode aggregate privacy report shows that the embedded Google Sign-In and GoogleDataTransport privacy manifests declare Name, Email Address, Phone Number, Coarse Location, User ID, Device ID, Other Usage Data, Other Diagnostic Data, and Other Data Types for App Functionality and/or Analytics. Other Diagnostic Data is declared as not linked to you; the remaining Google Sign-In entries are declared as linked to you. None is declared as tracking. These SDK declarations are included in WerkLog's App Store privacy disclosures.

9. Device permissions

WerkLog may request iOS permissions for Camera, Microphone, Speech Recognition, Photos and videos, Location, Notifications, Reminders, and internal device APIs used for local file storage, sharing, audio, media, settings, and required system features. You can manage or revoke permissions in device settings.

10. Retention, deletion, and local control

Local project data remains on your device until you edit it, delete it, remove app data, or uninstall the app, subject to iOS behavior and any backups you control through Apple services.

Timeline backups are created only after a Timeline becomes closed and have no automatic retention limit. Full System Backup retains only the two newest fully verified versions; older verified versions are permanently deleted from the selected private backup destination. Restore is always explicit and verifies integrity, storage, and identity safety before applying data; Google Drive restore also verifies the recovery password.

After a verified Timeline backup and recovery check, you may explicitly remove only byte-identical local files to free device space while keeping the Timeline records on the device. Those files can be downloaded again from the selected backup. Disconnecting Google revokes WerkLog's authorization but does not delete backups already stored in Google Drive. Forgetting the recovery password removes only the local Keychain item.

Data you manually export, share, copy, or send is controlled by the destination you choose. If you contact the developer or send support/privacy information, the developer should keep that information only as long as reasonably needed to respond, maintain security, resolve disputes, and comply with legal obligations.

11. Your privacy rights

Because public v1 keeps project data local by default, you can usually access, correct, export, or delete your project data directly inside the app or by managing app data on your device.

Where GDPR applies and the developer actually receives personal data from you, you may have the right to request access, correction, deletion, restriction, portability, objection, and consent withdrawal where applicable. You also have the right to lodge a complaint with a competent data protection supervisory authority.

Privacy requests can be sent to shirsavar@outlook.de.

12. Children

WerkLog is not directed to children and does not knowingly collect children's personal data in public v1.

13. External services, AI, Scanner, and future features

The public v1 app does not depend on cloud services, external AI services, online processing, or third-party analytics for core project capture. Google Drive Backup is a separate optional feature.

Voice notes remain usable without AI. Local transcription may be unavailable for unsupported languages or devices. Persian may show an unsupported-language warning in v1.

Scanner document capture and OCR are local-device features in public v1. OCR quality and language support may vary by device, document quality, and iOS support.

Local AI voice review is optional in Advanced Mode and runs on the device with an installed local model. It may help with local voice transcription, including Persian, but quality depends on the model, audio, device, and language. Local AI output is stored as a suggestion or artifact until you review, apply, detach, or delete it. Cloud transcription, voice translation, speaker recognition, cloud OCR, analytics, remote diagnostics, and external AI processing are not enabled for public v1.

14. Manual diagnostic delivery

WerkLog records a bounded, sanitized set of technical diagnostic events locally. It never sends them automatically. A package can be transmitted only after you select it, review its summary, and approve that specific send.

A diagnostic package may contain event times, app module and event codes, operation results, occurrence counts, app version and build, a package-specific pseudonymous correlation value, checksum, byte count, sanitization statistics, and limited allowlisted technical metadata. It must not contain project names, project addresses, note text, voice recordings, transcripts, account credentials, or access tokens.

Approved packages are sent over HTTPS to WerkLog's private Cloudflare service and stored in a private EU-jurisdiction R2 bucket for no more than 30 days. Apple App Attest and a pseudonymous installation hash protect the submission endpoint. Public Release does not expose Screen Feedback; that tool remains limited to Debug and Beta builds.

15. Updates

This policy may be updated in the future. If there is a significant change to how WerkLog stores, uses, sends, or protects data, WerkLog may show the updated notice in the app and ask for confirmation again.