Privacy
There is nothing to collect.
Weft has no server. No account, no sign-up, no backend of ours for your data to sit in. That is not a policy choice we could reverse quietly; it is how the product is built.
Last updated 14 August 2026
The app
Weft runs on your own computer. Your saved posts, the search index, the tags, the themes and the answers all live in a database on that machine. We cannot see any of it, because there is nowhere for it to go.
The browser extension
The extension reads the responses each platform has already loaded in your own
signed-in tab, and posts them to the Weft app on your machine at
localhost. Specifically:
- It never reads, stores or transmits your passwords or cookies. It relies on the browser session you are already in, which it has no access to.
- It sends nothing to us. The only destination it writes to is your own machine.
- It reads only your own saved surfaces: X bookmarks, Reddit saved, LinkedIn saved posts, Instagram Saved, YouTube Watch Later, Substack and Medium reading lists.
- If you enable the optional Instagram DM import, it reads posts that were shared with you in direct messages. That import is off unless you turn it on.
AI
By default every model runs locally: embeddings in the app process, and the language model in a container beside it. Nothing is sent anywhere.
If you choose to use a cloud model, you supply your own API key and your requests go directly from your machine to that provider under your own account and their terms. We are not in that path, and we never see the key: it is encrypted at rest on your machine with a secret that is not stored in the database.
This website
No analytics, no tracking pixels, no error reporting, no usage pings, no cookies. The fonts are served from this domain rather than a CDN, so loading this page tells nobody anything, including us. The interactive demo runs entirely in your browser and stores its sample data in your browser's own storage; clearing site data removes it.
The waitlist
The Mac app goes out by invite, and the form asking for your email is the one place on this site where you can hand us something. It is the only one. Filling it in is a deliberate act; reading these pages still tells us nothing.
What the row holds, in full:
- The email address you typed.
- The platforms you ticked, if you ticked any. The field is optional and the form submits without it.
- Which page the form was on, and the referring site if you arrived from somewhere other than this one.
- A two-letter country, which Cloudflare attaches to the request at the edge. We do not perform a lookup, and no IP address is stored.
- The date you joined, and later the dates your invite was issued and used.
It is used to send you an invite. Not a newsletter, not a launch sequence, not a reminder: one email, when there is a build for you. The list is not shared, sold, or loaded into any other tool, and it is stored on our own Cloudflare account rather than with a form or mailing service. Ask us to remove you and the row is deleted, which is a single instruction with nothing else to chase.
None of this touches the app. Weft still has no account and no server, and nothing on the waitlist is connected to anything in your library, because there is no path between them.
If you ask us something
If you email us, we have whatever you chose to send.
Changes
If this ever changes in a way that means data leaves your machine, it will be stated here and in the release notes, with the date. A product with no server cannot start collecting quietly, but it can be rewritten, so this is the commitment: it would be announced, not discovered.
Contact
Email [email protected].