Skip to content
WerkLog
HomePrivacySupport
EN
EnglishDeutschفارسی
Menu
HomePrivacySupport
ENDEفا

WerkLog public information

WerkLog

Privacy Policy

Privacy Notice Version 1.0.11. Applies to WerkLog 1.0 (299). Last updated August 12, 2026.

Privacy at a glance: WerkLog is local-first and offline-first. Core capture works without an account. Project content stays on your device unless you choose an optional service such as iCloud Backup, Google Drive Backup, Apple Weather, export, sharing, or manual diagnostic delivery. WerkLog does not use advertising, sell personal data, or track you across apps and websites.

1. Controller and contact

The controller for personal data received directly by WerkLog is Abas Hedayati Shirsavar.

Privacy requests: privacy@werklogs.de. General support: contact@werklogs.de. The complete publisher address and legal contact information are available in the Legal Notice.

Most project data remains only on your device. The developer cannot access local project data unless you choose to send, share, export, back up, or otherwise provide it outside the app.

2. Data stored locally

WerkLog may store the following information in its app-controlled storage to provide the features you use:

  • Work profile information, profile photo, and optional local Apple profile connection
  • Project names, descriptions, addresses, coordinates, and Timeline records
  • Text notes, Quick Notes, statuses, Focus assignments, report settings, relations, and checklists
  • Photos, videos, document scans, scanned pages, OCR text, and related metadata
  • Voice notes, audio files, waveform samples, transcripts, and transcript metadata
  • Plans, reports, exported files, reminders evidence, and recovery metadata where a feature creates them
  • Local settings, consent records, thumbnails, caches, logs, and technical data required for app functionality

3. Local-first operation

Core project capture does not require an account, cloud backup, advertising, tracking, remote configuration, or an external artificial intelligence service. WerkLog does not automatically send project content to the developer.

Scanner capture, OCR, voice recording, installed Local AI processing, and ordinary Timeline work run on the device. A suitable Local AI model is optional. If no suitable model is installed, the related Local AI operation is unavailable or the app continues with its ordinary non-AI path.

4. Optional Apple services

Sign in with Apple for the local work profile

You may optionally connect Sign in with Apple from your WerkLog profile. WerkLog requests your full name, not your email address. Apple provides an app-specific user identifier and may provide your name on the first authorization. WerkLog stores the identifier and available name in this device's Keychain. Disconnecting the Apple profile connection deletes that local Keychain record.

Apple Maps and location

When you use address search, Nearby Places, map search, reverse address lookup, or an online map preview, the search text, map region, coordinate, or selected location may be sent to Apple's MapKit services to return the requested result. WerkLog does not perform background location tracking. You can enter an address manually if you do not grant location permission.

Apple Weather

Apple Weather is off until you review its separate disclosure and give consent in Location and Weather settings. When enabled, WerkLog sends the selected project coordinate, or a device coordinate obtained after your request, to Apple Weather to retrieve current conditions and a compact forecast. Project names, notes, photos, videos, voice recordings, and transcripts are not included in the weather request.

Weather cache entries are retained locally for up to seven days. A weather snapshot saved with a Timeline remains with that Timeline until you delete the relevant Timeline data. WerkLog does not use Apple Weather to track movement or refresh location in the background. Apple states that Weather location requests are not associated with your identity. See Apple Weather and Privacy.

iCloud and CloudKit backup

If you enable iCloud Backup, WerkLog stores Timeline or Full System backup parts in the private CloudKit database of the Apple Account already signed in on the device. WerkLog does not receive your Apple ID, password, or iCloud credentials.

Backups may run manually or according to the schedule you select. Restore is always explicit and verifies the backup before changing local data. Closed Timeline backups have no automatic retention limit. Only the two newest verified Full System backups are retained. Older verified Full System backups are deleted automatically from the selected private backup destination.

Apple Reminders, notifications, and sharing

When you explicitly create an Apple Reminder from a Timeline post, the selected reminder content is provided to Apple Reminders. Local notifications are scheduled through iOS when you enable them. Content you export or share is provided to the destination you select and is then controlled by that destination.

5. Optional Google Drive Backup

Google Drive Backup is optional. When you connect it, WerkLog uses Google Sign-In and requests only the non-sensitive Google Drive appDataFolder scope. WerkLog may receive your Google user identifier, email address, display name, authorization state, and access tokens needed to operate the connection. Tokens are managed by the Google Sign-In SDK. WerkLog does not receive your Google password.

WerkLog stores only a one-way account fingerprint in its rebuildable local backup catalog. Backup files are placed in your Google Drive private application-data area, which is hidden from the normal Drive file list and is accessible to WerkLog only while you authorize the connection.

Timeline Backup and Full System Backup are separate encrypted packages. Depending on the backup type, they may contain project and Timeline metadata, posts, text, photos, videos, voice recordings, transcripts, scans, OCR text, properties, relations, checklists, reminder evidence, portable settings, and managed recovery files. Encryption happens on the device before upload. The recovery password remains in this device's Keychain and is not uploaded. WerkLog cannot recover a lost recovery password.

Backups may run manually or according to the schedule you select. Closed Timeline backups have no automatic retention limit. Only the two newest verified Full System backups are retained. Older verified Full System backups are permanently deleted from the private application-data area.

Disconnecting Google revokes WerkLog's authorization but does not delete existing backups. To delete all hidden WerkLog backup data from Google Drive, open Google Drive settings, choose Manage apps, find WerkLog, and choose the option to delete hidden app data. You can also revoke WerkLog access from your Google Account's third-party connections page.

WerkLog uses Google user data only to provide the visible Google Drive Backup and Restore features. It does not transfer Google user data for advertising, data brokerage, profiling, surveillance, cloud AI, or unrelated analytics. This use is subject to the Google API Services User Data Policy, including its Limited Use requirements.

The embedded Google SDK privacy declarations include Name, Email Address, Phone Number, Coarse Location, User ID, Device ID, Other Usage Data, Other Diagnostic Data, and Other Data Types for App Functionality and/or Analytics. Other Diagnostic Data is declared as not linked to you. The remaining Google Sign-In declarations are linked to the Google user. None is declared as tracking. These declarations are reflected in WerkLog's App Store privacy answers.

6. Local AI and model downloads

Voice notes remain usable without AI. Apple's on-device speech transcription may be unavailable for some languages or devices, including Persian on unsupported configurations. If you explicitly enable Local AI and install a compatible local voice model, WerkLog can process supported voice review and transcription work on the device, including Persian. Results remain suggestions or local artifacts until you review, apply, detach, or delete them.

Approved optional voice models are downloaded from Hugging Face only after your action. Hugging Face may receive network information such as your IP address and request metadata while delivering the model file. WerkLog does not send voice notes, transcripts, project content, scans, or OCR text to Hugging Face. See the Hugging Face Privacy Policy.

WerkLog does not use cloud transcription, cloud OCR, external AI processing, voice translation, or speaker recognition in this release. Document OCR and Persian-script detection or normalization run locally.

7. Manual diagnostic delivery

WerkLog keeps a bounded, sanitized set of technical diagnostic events locally for up to seven days. These events are not advertising analytics and are never sent automatically.

You may manually prepare a diagnostic package, review its summary, and approve its delivery. Approval authorizes only that package and its bounded retry window of up to seven days. Cancelling before approval sends nothing. A failed or cancelled transmission leaves the local package available for your review or deletion.

A diagnostic package may include event times, app module and event codes, operation results, occurrence counts, app version and build, a package-specific pseudonymous correlation value, checksum, byte count, sanitization statistics, and limited allowlisted technical metadata. It must not include project names, project addresses, note text, photos, videos, voice recordings, transcripts, account credentials, or access tokens.

Approved packages are sent over HTTPS to WerkLog's private Cloudflare service. Apple App Attest and a pseudonymous installation hash protect the submission endpoint. The package is stored in a private EU-jurisdiction Cloudflare R2 bucket for no more than 30 days. The local package is deleted automatically only after a verified delivery receipt is returned. Screen Feedback remains limited to Debug and Beta builds and is not available in the public Release build.

8. Public website hosting

The WerkLog public website at www.werklogs.de is hosted through Cloudflare. Cloudflare may process IP addresses, request and routing metadata, browser or device information, timestamps, and security or performance logs to deliver and protect the website.

The website is separate from the iOS app and cannot access local WerkLog project data. The current website does not use advertising, analytics scripts, tracking pixels, embedded third-party media, contact forms, or non-essential cookies. See the Cloudflare Privacy Policy.

9. Device permissions

WerkLog requests a protected iOS permission only when a feature needs it:

  • Camera: capture photos, videos, and document scans.
  • Microphone: record voice notes and video audio.
  • Photos: import photos and videos you select.
  • Speech Recognition: use Apple's supported local transcription path.
  • Location: select a work location and, with separate consent, request Apple Weather for that location.
  • Reminders: create an Apple Reminder after your explicit action.
  • Notifications: show local completion, reminder, or backup notifications you enable.

10. Retention, deletion, and control

  • Local project data remains until you edit or delete it, remove app data, or uninstall WerkLog, subject to iOS behavior and backups you control.
  • Weather cache entries remain for up to seven days. Timeline weather snapshots remain with the Timeline.
  • Local diagnostic events remain for up to seven days. Delivered diagnostic packages remain in the private EU R2 bucket for no more than 30 days.
  • Closed Timeline backups have no automatic retention limit. Only the two newest verified Full System backups are retained.
  • Support and privacy correspondence is kept only as long as reasonably required to answer the request, maintain security, resolve disputes, or meet legal obligations.
  • Cloudflare, Apple, Google, Hugging Face, and destinations you select apply their own retention rules to information they process.

After a verified Timeline backup and recovery check, you may explicitly remove only byte-identical local files to free device storage while preserving Timeline records. Files can be downloaded again from the selected backup destination. Forgetting a recovery password removes only the local Keychain item and does not delete backup files.

11. Purposes and legal bases

Where the GDPR applies, processing may rely on the following legal bases:

  • Requested app functionality: Article 6(1)(b), to provide features you choose, including capture, account connection, backup, restore, export, reminders, and support.
  • Consent: Article 6(1)(a), where WerkLog asks for separate consent, including Apple Weather and manual diagnostic delivery. You may withdraw consent for future processing without affecting processing that was lawful before withdrawal.
  • Legitimate interests: Article 6(1)(f), for proportionate security, reliability, abuse prevention, website delivery, and support, balanced against your rights.
  • Legal obligations: Article 6(1)(c), where information must be processed or retained to comply with applicable law.

WerkLog does not use personal data for advertising, cross-app tracking, data brokerage, profiling, or automated decisions with legal or similarly significant effects.

12. Device storage under German TDDDG

WerkLog stores and reads the local database, files, media, audio, thumbnails, settings, permission state, and other technical information needed to provide the app functionality you request. This storage and access is treated as strictly necessary under section 25(2) TDDDG. WerkLog does not use advertising identifiers, device fingerprinting, tracking pixels, or hidden marketing identifiers.

13. Service providers and international processing

Depending on the optional feature you use, Apple, Google, Cloudflare, or Hugging Face may process limited personal data or request metadata as described above. These providers may process information in the European Economic Area and in other countries, including the United States.

Where GDPR transfer rules apply, transfers must rely on an applicable safeguard, such as an adequacy decision, participation in a recognized data privacy framework, or approved contractual safeguards. The current details and applicable transfer mechanisms are described in each provider's privacy policy:

  • Apple Privacy Policy
  • Google Privacy Policy
  • Cloudflare Privacy Policy
  • Hugging Face Privacy Policy

14. Your privacy rights

You can usually access, correct, export, or delete local project data directly in WerkLog. You can revoke iOS permissions in device settings, withdraw Apple Weather consent in WerkLog settings, disconnect Apple or Google inside the app, delete Google hidden app data through Google Drive settings, and delete local diagnostic packages before delivery.

Where GDPR applies and the controller has received personal data from you, you may have rights to access, correction, deletion, restriction, portability, objection, and withdrawal of consent. You may also lodge a complaint with a competent data protection supervisory authority.

To exercise these rights, email privacy@werklogs.de.

15. Children

WerkLog is not directed to children and does not knowingly request children's personal data.

16. Policy updates

This policy may be updated when WerkLog's data practices, providers, or legal obligations change. If a change materially affects how data is stored, used, sent, or protected, WerkLog may show an updated notice in the app and request confirmation before the changed processing begins.

Contact and Support | Legal Notice | WerkLog Home

WerkLog
HomePrivacySupportLegal NoticeVersion History

© 2026 WerkLog