Privacy
wordspace runs on your own machine. Documents, workspaces and browsing stay local; nothing is uploaded and no account is needed. This page covers the one thing that does leave your machine: anonymous usage statistics.
Why we collect it
We need to know how many people use wordspace, for how long, and what happened before a crash. Nothing beyond that is collected.
Every field in a report
A report contains exactly these fields and nothing else. Adding a field requires changing the plan document in the repository first.
| id | A random id generated on first launch. It carries no machine information. |
|---|---|
| v | App version. |
| os | Operating system (darwin / win32). |
| arch | CPU architecture (arm64 / x64). |
| osv | Major OS version only (26, not 26.5.2). |
| lang | Interface language (zh / en). |
| kind | Whether this report is a start, a heartbeat, or a crash. |
| mins | Minutes elapsed in the current session; heartbeats only. |
Three extra fields on a crash
A crash report is sent on the next launch, merged into the same request as the start report.
| reason | Crash reason, from a fixed set of values. |
|---|---|
| exitCode | Exit code. |
| trail | The last 50 lines of the action trail: window numbers, exit codes, sleep and wake markers. |
Never collected
These three categories are never included, even though the process has direct access to them. Reports contain no free-text fields.
- File names and paths
- Web addresses visited in the built-in browser
- Worktable items, calendar event titles, document content, clipboard
When it is sent
Once 30 seconds after launch, then every 5 minutes. Failures are dropped silently: no retries, no queue, nothing written to disk. Development builds send nothing.
How long it is kept
One row per machine per day, kept for 24 months. Crash records are kept for 90 days. The server does not record your IP address.
How to turn it off
Open settings and switch off "Anonymous usage statistics". Sending stops immediately and the random id stored on this machine is deleted. Turning it back on generates a new id that cannot be linked to earlier records.
