Privacy

The Works is operated by Sebastian De Deyne. Contact: sebastiandedeyne@gmail.com.

Google supplies your identity, name and verified email for login. We do not retain Google access or refresh tokens.

When you enable Cloud, personal tasks, projects and notes are stored on our European MySQL backend to synchronize your devices. There is no sharing, billing, appearance sync or advertising.

MCP apps you authorize can read and edit your personal cloud content. Revoke their access in MCP settings. Content sent to those apps is subject to their own privacy practices.

Text-history entries expire after 90 days. The technical synchronization log retains prior non-purged snapshots for offline devices. Permanent purge removes content and history from the live database; minimal identifiers and operation receipts remain to prevent resurrection. Existing database backups expire after one day. No account-delete MCP tool is offered; contact the operator for access, correction or account removal requests.

Essential encrypted session cookies support Google login and OAuth consent. Cloudflare may also set essential security cookies to protect the website.

Redacted application logs do not include content, credentials or email addresses. Hosting-provider access logs retain request URLs and query strings, which can include short-lived OAuth authorization codes and state values during login and authorization. Application-log redaction does not remove those values from provider access logs.