Privacy & trust
Know what moves.
Know what stays.
Woodwide has three data boundaries: your machine, your configured extraction provider and the Woodwide server. Redaction and screening reduce disclosure risk. They are not guarantees.
Start local, choose whether to use cloud extraction, and review before sharing. Each choice has its own controls and limits.
01 / Your machine
Successful extraction writes a screened playbook as canonical JSON and readable Markdown under ~/.woodwide/playbooks/ or your WOODWIDE_HOME. The local copy is saved before an optional upload. Records also contain session identifiers and extraction metadata.
New or replaced playbook files use owner-only permissions and atomic replacement. Filesystem permissions are not encryption or protection from another process running as you. Exported copies are independent files.
Private local setup with init --local requires no Woodwide account or server and turns sharing and benchmark telemetry off. Reading, searching and exporting existing memory makes no model or network calls. Extraction is a separate choice.
02 / The extraction provider
When extraction is enabled, the configured provider receives a redacted digest derived from your transcript: prompts, tool descriptions, truncated outputs, error lines and detected corrections. Filters may miss source-related, identifying or confidential content.
Automatic Codex-session extraction uses your authenticated Codex CLI. Other sessions use Anthropic API access when configured, otherwise Claude CLI; automatic API failure can fall back to Claude CLI. Explicit provider settings can change this routing. OpenCode and Gemini backfill may use a different provider from the original session.
The Codex adapter runs in a temporary directory with repository context, optional tools and user-configured providers disabled. It supports the standard authenticated Codex provider; a Codex failure does not silently move the digest to Anthropic. These restrictions reduce risks but do not make model output trusted.
Provider storage rules, subscriptions, API charges and quotas still apply. Unlimited Woodwide corrections and checks do not make provider inference free. Turn extraction off in the setup controls to stop new model calls while retaining existing memory.
03 / The Woodwide server
Optional contributions contain a generalized playbook, lessons, metrics, a salted session hash, visibility and redaction/client-version metadata. The extraction pipeline does not send raw transcript files or its digest to the Woodwide server. Intended exclusions are not an absolute promise: inspect the proposed contribution before approving it.
Network recall sends a task/error query and stack context. The server can associate authenticated requests and contributions with an account. Omitted identity in a public result does not mean anonymity from the operator. Ordinary request metadata can include an IP address.
Sharing is optional and is not required for free-beta network checks. Sharing and benchmark telemetry are separate settings. With telemetry enabled and an account configured, extraction can send session-level harness/model, task class, reported outcome, cost/turn metrics, stack and a salted session hash. Aggregation thresholds are not a guarantee of anonymity.
When Google sign-up is available, it opens the Woodwide account service. This website does not collect your Google password or ask for an API key. Signing in alone does not enable sharing or telemetry.
Guidance is not permission
Supported hooks can block recognized credential-file reads and secret-dumping patterns. Hook coverage varies by harness and tool. Output scanning, redaction and safety screening cannot detect every secret or adversarial instruction. An MCP guard is advisory unless the host invokes and enforces it.
Local history and network playbooks are untrusted observations. Check the current request, conditions, exceptions and verification before acting. Reported outcomes and model confidence do not independently prove that a fix worked. Historical costs are not measured savings.
Auto-consume is optional and off by default. It accepts eligible, screened guidance for the current task without another Woodwide confirmation; it does not launch a headless agent or subagent or grant tool, destructive-action or upload authority. Offer expiry does not turn off secret protection or correction capture. It also cannot erase text already in your agent’s context.
Retention, removal and current limits
Removing hooks stops observation through those hooks; it does not stop manually invoked processing or delete retained data. Stop active workers before removing local data. Deleting the whole Woodwide data directory also removes its configuration. Remove independently exported files separately; harness transcripts are managed by the harness.
Memory commands re-screen older records with current rules. Existing exports do not update themselves when rules change. Retracting an owned network lesson removes it from future retrieval, not from already surfaced copies, exports, the parent playbook or the entire account.
A public deletion process and retention schedule have not been published. Uninstalling or retracting a lesson does not delete an account or erase existing uploads. Consider these limits before sharing.
This website
This website’s application code includes no analytics SDK, tracking pixels or browser credential storage. Copy buttons write the displayed command to your clipboard only when you click them.
For product or privacy questions, contact sanjaygbhat@gmail.com. Do not send API keys, credentials or raw transcripts. This contact is not a published deletion procedure or a retention guarantee.
These application controls do not describe how the hosting platform handles request logs. A preview label or robots directive does not make a page private.
Client and server licenses differ
Core, CLI and Claude Code plugin: Apache License 2.0, as specified by the repository’s client license. Server: source-available, proprietary, under its separate server license. Do not describe the complete service as Apache-2.0 or assume that permission to use the client covers the server.
Contribution-data terms are still drafts. The beta does not offer contributor payouts or independently verified savings.
Review the setup controls →