Privacy Policy
WHO WE ARE
Ipek ("Ipek", the "App", the "Software") is a local-first desktop application for designing, running, and inspecting automation workflows on your own computer. Ipek is operated and published by LimanDoc ZZP, a sole proprietorship ("eenmanszaak") established in the Netherlands ("LimanDoc", "we", "us", "our").
LimanDoc ZZPBox A9239, Keurenplein 41
1069 CD Amsterdam, The Netherlands
Chamber of Commerce (KVK): 96410191
Contact: [email protected]
This Privacy Policy explains what information we do and do not process when you use Ipek, our website, and related services, and what your rights are. It is written to be read alongside our Terms of Use.
We are a small team, and especially in these early days we take your privacy seriously and personally. If anything in this Policy concerns you, or you would prefer that we handle your data differently, please contact us at [email protected]. We read and consider every request individually and will work with you - this matters to us.
THE SHORT VERSION
We built Ipek to keep your data on your machine.
- •Your projects, the files you process, your workflow outputs, your recordings, and your API keys stay on your device. We run no server that receives or stores them, and we cannot see, recover, or delete them for you.
- •Ipek has no AI of its own. You can connect your own AI client (for example Claude Code, Codex, or Cursor) to Ipek through a connection that stays on your computer. What your AI client reads from your project goes to its provider under your agreement with them, not to us.
- •When a workflow connects to a third-party service with your own key or credentials (for example an AI model provider, or a service such as Linear or Zendesk), your data travels directly from your device to that provider. We do not sit in the middle of that exchange.
- •During this early-release period, the App sends us, by default, limited diagnostic and usage information so we can fix bugs and improve the product. It never includes the contents of your files, your recordings, or your credentials, and you can ask us to stop at any time.
- •If you publish a dashboard to our hosting (an optional feature, currently by invitation only), its pages and the data shown on them are stored with our hosting provider so that the people you choose can view them.
The sections below give the detail.
1. SCOPE OF THIS POLICY
This Policy applies to:
- (a)the Ipek desktop application;
- (b)our marketing and documentation website;
- (c)the optional hosting for dashboards you publish from Ipek; and
- (d)communications you have with us (for example, support email).
It does not apply to third-party services you choose to connect to or use through Ipek, including the AI client you connect. Those services are operated by other companies under their own terms and privacy policies (see Sections 3 and 4).
2. DATA THAT STAYS ON YOUR DEVICE (WE HAVE NO ACCESS)
Ipek is local-first by design. The following are created and stored only on your own computer, and are never transmitted to us:
- •your projects, workflows, canvas layouts, schedules, and automation history;
- •the input files and folders you process;
- •the contents of those files (including any document text, images, extracted data, tickets, feedback, or message bodies inside them);
- •the outputs and run artifacts your workflows produce;
- •run history, logs, and manifests;
- •your Project document and your project database;
- •your recordings, including their screenshots, audio, and transcripts (see Section 5);
- •worker/plugin packages and any worker source code, including code written for you by the AI client you connect;
- •the API keys, tokens, and credentials you enter; and
- •your application settings.
This information is stored in your user profile and project folders on your device (for example, under an Ipek application-data directory and the project locations you choose). Because we operate no backend server that receives this information, we cannot access, retrieve, restore, or erase it on your behalf. You are responsible for backing it up and for the security of your device. Deleting it is done locally by you (see Section 15).
The only exceptions are information you choose to send elsewhere: to your AI client or to services your workflows call (Sections 3 and 4), to our hosting when you publish a dashboard (Section 7), and the limited diagnostic and usage information described in Section 6.
3. YOUR AI CLIENT AND THE LOCAL MCP CONNECTION
Ipek has no AI model of its own and makes no AI calls itself. To have an AI plan, build, and run workflows for you, you connect an AI client that you choose and pay for (for example Claude Code, Codex, Cursor, or another client that supports the Model Context Protocol, "MCP") to Ipek's local MCP server.
The MCP server is turned off until you turn it on in Settings. It runs on your own computer, accepts connections only from that computer (its loopback address), and requires a secret token that Ipek generates for you. While it is on, the AI client you connect can, within the permissions you set in Settings:
- •read your projects, workflows, worker source code, run outputs, the files in your project folders, your Project document, your project database, and your recordings, including their screenshots and transcripts;
- •write worker code, build and install workers, and change, run, and schedule workflows; and
- •publish dashboards, if you have signed in to dashboard hosting (Section 7).
Deleting or overwriting work is off by default. The other permissions are on by default, and you can turn each of them off.
Everything your AI client reads through this connection is processed by that client and its provider (for example Anthropic or OpenAI) under your own agreement with them, and may be sent to their servers. It does not pass through us, and we do not receive a copy. Choose your AI client, its settings, and the permissions you grant accordingly. Ipek removes common secrets, such as API keys, from the text it gives your AI client, but it does not remove other information.
4. DATA YOU SEND TO THIRD PARTIES USING YOUR OWN KEYS ("BRING YOUR OWN KEY")
Workflows and dashboards in Ipek can connect to third-party services using your own accounts, API keys, or credentials. These may include, depending on what you build:
- •AI / model providers, such as Anthropic (Claude) and Google (Gemini), used by AI-powered workers you configure;
- •services such as Linear, Zendesk, PostHog, or your broker; and
- •any other service you choose to call from a worker, or from a dashboard action that you approve.
When a workflow or dashboard does this, the data it is configured to send travels directly from your device to the third-party provider, authenticated with your own key. We do not proxy, intermediate, inspect, store, or retain that data, and we do not receive a copy of it.
Your use of each third-party provider is governed solely by your own agreement with, and the privacy policy of, that provider. You are responsible for reviewing those terms, for any charges on your provider accounts, and for deciding what data you send to them. Whether a provider uses your inputs or outputs to train its models is determined by your relationship with that provider, not by us. We do not host AI models, and we do not use any content you process to train models.
5. RECORDINGS
Ipek can record your screen and voice, or only your voice, so that your AI client can learn how you do a task. A recording starts only when you press Record, and pressing Record is your choice to capture everything shown on the recorded screen.
- •What is captured: screenshots before and after each click, typing, shortcut, app switch, and scroll; the names of the apps and windows you use; the text you type (Ipek tries to leave out password fields, but cannot guarantee it); and your microphone audio.
- •Where it is stored: in the recording's folder inside your project. If your project folder syncs to a cloud service, your recordings sync with it.
- •Transcription happens on your computer. Your audio is never sent to us or to anyone else to be transcribed. The first time, Ipek downloads a speech-recognition model (see Section 8).
- •The AI client you connect can read every recording in the project, including its screenshots and transcript (see Section 3), and what it reads goes to its provider. Screenshots are not redacted.
- •Deleting a recording in Ipek removes its folder from your device.
Only record what you have the right to record. If other people, their personal data, or confidential material can be seen or heard in a recording, make sure you are allowed to capture it and to share it with your AI provider.
6. DIAGNOSTIC AND USAGE INFORMATION WE RECEIVE
To operate, secure, debug, and improve Ipek, the App sends limited diagnostic and product-usage information to PostHog, our third-party product-analytics and error-reporting provider, which processes and stores it on servers located in the European Union (PostHog's EU Cloud). This information may include:
- •basic technical details about your installation and device, such as the application version, operating-system family and version, processor architecture, and language setting;
- •a randomly generated installation identifier that is not derived from your name, account, or device hardware;
- •events that describe how the application's features are used, for example which screens you open, when workflows and workers run and whether they succeed, which kind of AI client is connected and which Ipek tools it uses (the tool names and the size of each request, not the content sent through them), and how long recordings and transcriptions take (rounded, never their content);
- •the names you or your AI client give to projects, workflows, and workers, and short worker descriptions;
- •the README documentation of workers your AI client writes, with file paths, web addresses, and keys removed, so that we can improve how workers are built;
- •sanitized error and crash reports;
- •short, structured reports that an AI agent may submit when an Ipek feature blocks a task, behaves unexpectedly, is difficult to discover, or requires a substantial workaround. Ipek removes file paths, web addresses, keys, email addresses, and other common identifiers, limits the report length, and sends an anonymous report identifier, the agent surface, category, severity, blocked state, related feature names, workaround and suggestion presence flags, and a bounded sanitized summary. Ipek does not automatically attach project, conversation, client, prompt, file, workflow output, or customer data to these reports; and
- •the text you type into the App's feedback form, and any contact details you choose to include there.
We do not require an account or your name, and we identify your installation only by the random identifier above; we do not sell this information. Because names, worker documentation, and feedback can contain whatever was typed into them, they may themselves contain personal data, so please avoid putting sensitive personal information into them.
We do NOT collect, receive, or have access to: your projects or the files you process; the contents of those files; your folder paths or folder structure; your Project document; your recordings, including their screenshots, audio, and transcripts; your project database; your API keys, tokens, credentials, environment values, or other secrets; your worker source code; or your workflow outputs. Error and crash reports are scrubbed to remove file paths, secrets, and similar sensitive values before they are sent.
Default during early release, your legal basis, and your choice. During Ipek's current early-release period, this diagnostic and usage reporting is enabled by default and starts when the App first launches, because it is especially important for finding and fixing problems while the Software is young. We process this limited information on the basis of our legitimate interests (Article 6(1)(f) GDPR) in operating, securing, and improving the Software. When you first run the App, we show you a notice that links to this Policy and our Terms of Use, and you may object to and opt out of this processing at any time by contacting us at [email protected]. Events that cannot be sent right away are kept on your device and sent later.
7. HOSTED DASHBOARDS (OPTIONAL, BY INVITATION)
Ipek can publish a dashboard to hosting that we operate, so that the people you choose can view it in their browser. This feature is optional and currently offered by invitation only. Nothing is published unless you sign in and publish.
- •What is uploaded: the dashboard's pages, with the data from your project database that they show, taken from one snapshot; the styles and scripts the pages need; and a technical summary of the release, such as the dashboard identifier, file names, sizes and checksums, data timestamps, and the web addresses the pages link to. Run history and automation details are included only if the dashboard is set to include them.
- •Signing in: to publish, you approve each device once in your browser. We keep the account you sign in with, a device record named after your operating system, and a log of publishing actions. Ipek keeps the device credential in your operating system's keychain.
- •Who can view it: only people who sign in with an account we have agreed with you, for example the accounts of your organization's domain. Published dashboards are not public.
- •Where it is stored: with Cloudflare (its Workers, D1 database, and R2 storage services), with data located in Western Europe.
- •Unpublishing takes a dashboard offline straight away, but its earlier versions stay stored so that you can roll back. To have them deleted from our hosting, contact us at [email protected] and we will delete them.
We store and serve published dashboards only on your behalf, to show them to the people you have chosen, and for no other purpose. You are responsible for the data you choose to publish and for who may view it.
8. DOWNLOADS THE APP MAKES
The App downloads some files from the internet. Each host necessarily receives standard request information, such as your IP address, the file requested, and the application version and platform. This information is used only to deliver the file and is not used to identify you.
- •Updates: Ipek checks for a newer version and downloads installers from our update and distribution hosting (Cloudflare). You are not required to install updates.
- •Marketplace: the catalog of workers and workflows, and the packages you install, come from our hosting on Cloudflare.
- •Build tools: when you set up or build workers or dashboards, Ipek downloads the Gradle build tool (from gradle.org) and code libraries (from Maven Central, Google's Maven repository, and the Gradle Plugin Portal).
- •Speech model: when you set up recordings, Ipek downloads a speech-recognition model of about 150 MB from Hugging Face.
9. WEBSITE INFORMATION
If you visit our website, our hosting provider (Cloudflare) processes standard technical information such as your IP address, browser type, and the pages requested. We also count page views and a few actions on the website, such as clicks on the download button and waitlist sign-ups, using PostHog (EU Cloud). This website analytics does not use cookies and does not store anything in your browser. Where the law requires consent for non-essential cookies or analytics, we will ask for it.
If you join our waitlist or mailing list, we process the email address you provide, on the basis of your consent, to notify you about availability, launch, discounts, and related updates. The signup form is hosted on Cloudflare, and the email addresses are stored with our email provider, Resend (Resend, Inc.), which we also use to send these messages. You can withdraw your consent and unsubscribe at any time, after which we will remove your address from the list.
10. PURCHASE AND BILLING INFORMATION
Ipek is currently provided free of charge and does not require an account. If we introduce paid plans in the future, purchases will be handled by third-party payment processors. In that case, those processors will receive the information necessary to complete your transaction (such as your email address and payment details). We would receive transaction and billing records (for example, that a purchase occurred, the amount, and your email address) but not your full payment-card details. Any such email address would be used to process and support your purchase and to send service-related messages, and not for unrelated marketing without your consent.
11. SUPPORT COMMUNICATIONS
If you email us or otherwise contact us for support, we process the information you provide (such as your email address and the contents of your message) in order to respond and to keep records of support requests. Please do not send us sensitive files, secrets, or credentials in support messages.
12. HOW WE USE THE INFORMATION WE RECEIVE
We use the limited information described in Sections 6-11 to:
- •provide, maintain, secure, and improve Ipek and our website;
- •diagnose, reproduce, and fix bugs, crashes, and reliability problems;
- •understand which features are used so we can prioritize development;
- •deliver software updates and Marketplace downloads;
- •host the dashboards you publish;
- •process and support purchases (if and when paid plans exist); and
- •respond to your requests and comply with our legal obligations.
13. SHARING AND SUB-PROCESSORS
We do not sell your personal data. We share the limited information we receive only with service providers who process it on our behalf and under contract, namely:
- •PostHog, our product-analytics and error-reporting provider (EU servers);
- •Cloudflare, for website and waitlist hosting, for distributing the application's downloads, update files, and Marketplace packages, and for hosting published dashboards;
- •Resend (Resend, Inc.), which stores our waitlist/mailing-list email addresses and delivers our waitlist and product emails; and
- •if and when paid plans exist, our payment processor(s).
The hosts the App downloads build tools and the speech model from (Section 8) receive those requests directly from your device and are not our processors.
We may also disclose information where required by law, to enforce our terms, or to protect our rights, users, or the public. If we are involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to this Policy.
We do not act as a controller or processor of the content you keep on your device, or of what your AI client or your workflows send to third parties under your own agreements and keys (Sections 2-5); for that content, you and/or your chosen provider are responsible.
14. INTERNATIONAL TRANSFERS
We seek to keep the information we receive, and the dashboards you publish, within the European Union. Where any processing by a service provider involves a transfer of personal data outside the European Economic Area, we rely on appropriate safeguards recognized under the GDPR, such as European Commission adequacy decisions or Standard Contractual Clauses.
15. DATA RETENTION
- •Data on your device is retained until you delete it; we hold no copy of it.
- •Diagnostic and usage information (including any analytics queued locally on your device before it is sent) is retained only as long as needed for the purposes above - as a general rule, no longer than 24 months - and is then deleted or aggregated.
- •Published dashboards, including earlier versions, are kept until you ask us to delete them or we close the hosting. Unpublishing alone takes a dashboard offline but does not delete it. Sign-in records and the log of publishing actions are kept while you use dashboard hosting and for a reasonable period afterwards.
- •Support correspondence is kept for as long as needed to handle your request and for a reasonable period afterwards.
- •Waitlist and mailing-list details are kept until you unsubscribe or we close the list.
- •Billing records, if any, are kept for as long as required by applicable law (under Dutch law, business and tax records must generally be kept for seven years).
16. YOUR RIGHTS
Under the GDPR and applicable Dutch law, and in relation to the limited personal data we actually process, you have the right to: access your data; have it rectified; have it erased; restrict or object to its processing; data portability; and, where processing is based on consent, to withdraw that consent at any time. To exercise these rights, contact us at [email protected]. We may need to verify your request.
Please note that, because Ipek stores your projects, files, recordings, and outputs only on your own device and we hold no copy and no account identifying you, we are often unable to locate or act on that on-device content for you - you remain in direct control of it.
You also have the right to lodge a complaint with your local supervisory authority. In the Netherlands, this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
17. CHILDREN
Ipek is not directed to children. It is intended for users who are at least 16 years old, or older where required by local law. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can address it.
18. SECURITY
We take reasonable measures to protect the information we receive and the dashboards you publish. However, no method of transmission or storage is completely secure. Importantly, because Ipek is local-first, the security of your projects, recordings, outputs, and the API keys and credentials you enter depends primarily on the security of your own device and operating-system account. API keys and credentials you enter for workers are stored locally on your device, within the application's settings and project configuration (not in a dedicated operating-system keychain) and without additional encryption by Ipek; treat your device, your backups, and those credentials accordingly, and revoke any key you believe has been exposed. Recordings can contain anything that was on your screen or said aloud, and local run logs and outputs may contain data drawn from your inputs or from the services your workflows call, so review them before sharing them with us or with others. The Software is provided "as is" as described in the Terms of Use.
19. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. We will post the revised version with a new "Last updated" date and, where the changes are material, we will take reasonable steps to bring them to your attention. Your continued use of Ipek after the changes take effect constitutes acceptance of the updated Policy.
20. CONTACT
If you have any questions, requests, or complaints about this Privacy Policy or your data, contact us at:
LimanDoc ZZPBox A9239, Keurenplein 41
1069 CD Amsterdam, The Netherlands
Email: [email protected]