Ipek

Privacy Policy

Last updated: 1 October 2026 · Version: 1.3

WHO WE ARE

Ipek ("Ipek", the "App", the "Software") is a local-first desktop application for designing, running, and inspecting automation workflows on your own computer. Ipek is operated and published by LimanDoc ZZP, a sole proprietorship ("eenmanszaak") established in the Netherlands ("LimanDoc", "we", "us", "our").

LimanDoc ZZP
Box A9239, Keurenplein 41
1069 CD Amsterdam, The Netherlands
Chamber of Commerce (KVK): 96410191
Contact: [email protected]

This Privacy Policy explains what information we do and do not process when you use Ipek, our website, and related services, and what your rights are. It is written to be read alongside our Terms of Use.

We are a small team, and especially in these early days we take your privacy seriously and personally. If anything in this Policy concerns you, or you would prefer that we handle your data differently, please contact us at [email protected]. We read and consider every request individually and will work with you - this matters to us.

THE SHORT VERSION

We built Ipek to keep your data on your machine.

The sections below give the detail.

1. SCOPE OF THIS POLICY

This Policy applies to:

It does not apply to third-party services you choose to connect to or use through Ipek, including the AI client you connect. Those services are operated by other companies under their own terms and privacy policies (see Sections 3 and 4).

2. DATA THAT STAYS ON YOUR DEVICE (WE HAVE NO ACCESS)

Ipek is local-first by design. The following are created and stored only on your own computer, and are never transmitted to us:

This information is stored in your user profile and project folders on your device (for example, under an Ipek application-data directory and the project locations you choose). Because we operate no backend server that receives this information, we cannot access, retrieve, restore, or erase it on your behalf. You are responsible for backing it up and for the security of your device. Deleting it is done locally by you (see Section 15).

The only exceptions are information you choose to send elsewhere: to your AI client or to services your workflows call (Sections 3 and 4), to our hosting when you publish a dashboard (Section 7), and the limited diagnostic and usage information described in Section 6.

3. YOUR AI CLIENT AND THE LOCAL MCP CONNECTION

Ipek has no AI model of its own and makes no AI calls itself. To have an AI plan, build, and run workflows for you, you connect an AI client that you choose and pay for (for example Claude Code, Codex, Cursor, or another client that supports the Model Context Protocol, "MCP") to Ipek's local MCP server.

The MCP server is turned off until you turn it on in Settings. It runs on your own computer, accepts connections only from that computer (its loopback address), and requires a secret token that Ipek generates for you. While it is on, the AI client you connect can, within the permissions you set in Settings:

Deleting or overwriting work is off by default. The other permissions are on by default, and you can turn each of them off.

Everything your AI client reads through this connection is processed by that client and its provider (for example Anthropic or OpenAI) under your own agreement with them, and may be sent to their servers. It does not pass through us, and we do not receive a copy. Choose your AI client, its settings, and the permissions you grant accordingly. Ipek removes common secrets, such as API keys, from the text it gives your AI client, but it does not remove other information.

4. DATA YOU SEND TO THIRD PARTIES USING YOUR OWN KEYS ("BRING YOUR OWN KEY")

Workflows and dashboards in Ipek can connect to third-party services using your own accounts, API keys, or credentials. These may include, depending on what you build:

When a workflow or dashboard does this, the data it is configured to send travels directly from your device to the third-party provider, authenticated with your own key. We do not proxy, intermediate, inspect, store, or retain that data, and we do not receive a copy of it.

Your use of each third-party provider is governed solely by your own agreement with, and the privacy policy of, that provider. You are responsible for reviewing those terms, for any charges on your provider accounts, and for deciding what data you send to them. Whether a provider uses your inputs or outputs to train its models is determined by your relationship with that provider, not by us. We do not host AI models, and we do not use any content you process to train models.

5. RECORDINGS

Ipek can record your screen and voice, or only your voice, so that your AI client can learn how you do a task. A recording starts only when you press Record, and pressing Record is your choice to capture everything shown on the recorded screen.

Only record what you have the right to record. If other people, their personal data, or confidential material can be seen or heard in a recording, make sure you are allowed to capture it and to share it with your AI provider.

6. DIAGNOSTIC AND USAGE INFORMATION WE RECEIVE

To operate, secure, debug, and improve Ipek, the App sends limited diagnostic and product-usage information to PostHog, our third-party product-analytics and error-reporting provider, which processes and stores it on servers located in the European Union (PostHog's EU Cloud). This information may include:

We do not require an account or your name, and we identify your installation only by the random identifier above; we do not sell this information. Because names, worker documentation, and feedback can contain whatever was typed into them, they may themselves contain personal data, so please avoid putting sensitive personal information into them.

We do NOT collect, receive, or have access to: your projects or the files you process; the contents of those files; your folder paths or folder structure; your Project document; your recordings, including their screenshots, audio, and transcripts; your project database; your API keys, tokens, credentials, environment values, or other secrets; your worker source code; or your workflow outputs. Error and crash reports are scrubbed to remove file paths, secrets, and similar sensitive values before they are sent.

Default during early release, your legal basis, and your choice. During Ipek's current early-release period, this diagnostic and usage reporting is enabled by default and starts when the App first launches, because it is especially important for finding and fixing problems while the Software is young. We process this limited information on the basis of our legitimate interests (Article 6(1)(f) GDPR) in operating, securing, and improving the Software. When you first run the App, we show you a notice that links to this Policy and our Terms of Use, and you may object to and opt out of this processing at any time by contacting us at [email protected]. Events that cannot be sent right away are kept on your device and sent later.

7. HOSTED DASHBOARDS (OPTIONAL, BY INVITATION)

Ipek can publish a dashboard to hosting that we operate, so that the people you choose can view it in their browser. This feature is optional and currently offered by invitation only. Nothing is published unless you sign in and publish.

We store and serve published dashboards only on your behalf, to show them to the people you have chosen, and for no other purpose. You are responsible for the data you choose to publish and for who may view it.

8. DOWNLOADS THE APP MAKES

The App downloads some files from the internet. Each host necessarily receives standard request information, such as your IP address, the file requested, and the application version and platform. This information is used only to deliver the file and is not used to identify you.

9. WEBSITE INFORMATION

If you visit our website, our hosting provider (Cloudflare) processes standard technical information such as your IP address, browser type, and the pages requested. We also count page views and a few actions on the website, such as clicks on the download button and waitlist sign-ups, using PostHog (EU Cloud). This website analytics does not use cookies and does not store anything in your browser. Where the law requires consent for non-essential cookies or analytics, we will ask for it.

If you join our waitlist or mailing list, we process the email address you provide, on the basis of your consent, to notify you about availability, launch, discounts, and related updates. The signup form is hosted on Cloudflare, and the email addresses are stored with our email provider, Resend (Resend, Inc.), which we also use to send these messages. You can withdraw your consent and unsubscribe at any time, after which we will remove your address from the list.

10. PURCHASE AND BILLING INFORMATION

Ipek is currently provided free of charge and does not require an account. If we introduce paid plans in the future, purchases will be handled by third-party payment processors. In that case, those processors will receive the information necessary to complete your transaction (such as your email address and payment details). We would receive transaction and billing records (for example, that a purchase occurred, the amount, and your email address) but not your full payment-card details. Any such email address would be used to process and support your purchase and to send service-related messages, and not for unrelated marketing without your consent.

11. SUPPORT COMMUNICATIONS

If you email us or otherwise contact us for support, we process the information you provide (such as your email address and the contents of your message) in order to respond and to keep records of support requests. Please do not send us sensitive files, secrets, or credentials in support messages.

12. HOW WE USE THE INFORMATION WE RECEIVE

We use the limited information described in Sections 6-11 to:

13. SHARING AND SUB-PROCESSORS

We do not sell your personal data. We share the limited information we receive only with service providers who process it on our behalf and under contract, namely:

The hosts the App downloads build tools and the speech model from (Section 8) receive those requests directly from your device and are not our processors.

We may also disclose information where required by law, to enforce our terms, or to protect our rights, users, or the public. If we are involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to this Policy.

We do not act as a controller or processor of the content you keep on your device, or of what your AI client or your workflows send to third parties under your own agreements and keys (Sections 2-5); for that content, you and/or your chosen provider are responsible.

14. INTERNATIONAL TRANSFERS

We seek to keep the information we receive, and the dashboards you publish, within the European Union. Where any processing by a service provider involves a transfer of personal data outside the European Economic Area, we rely on appropriate safeguards recognized under the GDPR, such as European Commission adequacy decisions or Standard Contractual Clauses.

15. DATA RETENTION

16. YOUR RIGHTS

Under the GDPR and applicable Dutch law, and in relation to the limited personal data we actually process, you have the right to: access your data; have it rectified; have it erased; restrict or object to its processing; data portability; and, where processing is based on consent, to withdraw that consent at any time. To exercise these rights, contact us at [email protected]. We may need to verify your request.

Please note that, because Ipek stores your projects, files, recordings, and outputs only on your own device and we hold no copy and no account identifying you, we are often unable to locate or act on that on-device content for you - you remain in direct control of it.

You also have the right to lodge a complaint with your local supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

17. CHILDREN

Ipek is not directed to children. It is intended for users who are at least 16 years old, or older where required by local law. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can address it.

18. SECURITY

We take reasonable measures to protect the information we receive and the dashboards you publish. However, no method of transmission or storage is completely secure. Importantly, because Ipek is local-first, the security of your projects, recordings, outputs, and the API keys and credentials you enter depends primarily on the security of your own device and operating-system account. API keys and credentials you enter for workers are stored locally on your device, within the application's settings and project configuration (not in a dedicated operating-system keychain) and without additional encryption by Ipek; treat your device, your backups, and those credentials accordingly, and revoke any key you believe has been exposed. Recordings can contain anything that was on your screen or said aloud, and local run logs and outputs may contain data drawn from your inputs or from the services your workflows call, so review them before sharing them with us or with others. The Software is provided "as is" as described in the Terms of Use.

19. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. We will post the revised version with a new "Last updated" date and, where the changes are material, we will take reasonable steps to bring them to your attention. Your continued use of Ipek after the changes take effect constitutes acceptance of the updated Policy.

20. CONTACT

If you have any questions, requests, or complaints about this Privacy Policy or your data, contact us at:

LimanDoc ZZP
Box A9239, Keurenplein 41
1069 CD Amsterdam, The Netherlands
Email: [email protected]