Wordless
Documentation中文
WORDLESS / TRUSTPUBLIC POLICY
Back to Wordless

Trust center / Google API disclosure

Privacy Policy

How Wordless handles local workspace data, Google account information, optional Google Drive app-data sync, and third-party services.

EffectiveAugust 8, 2026Last updatedAugust 8, 2026Public policy

On this page

01Overview02Google account data03Google Drive cloud sync04Use and disclosure05Local data and third parties06Storage and security07Retention and your controls08Children09Changes and contact

1. Overview

Wordless is a local-first desktop agent workspace maintained by Austin Patrician and Wordless contributors (collectively, “Wordless,” “we,” or “us”). This policy explains the information processed when you use the Wordless desktop application and this website.

Most Wordless data remains on your device. Google sign-in is optional. Google Cloud Sync is separately opt-in and is not enabled merely because you sign in.

2. Google account data

When you choose Sign in with Google, Wordless requests the minimum identity scopes needed to identify your account: openid, email, and profile.

Google dataPurposeWhere it is handled
Google account identifierAssociate the local Wordless account state with the Google account you selected.On your device.
Name, email address, and profile imageDisplay your signed-in identity in Wordless and show which account is used for optional sync.On your device.
OAuth access and refresh tokensMaintain the authorization you granted and call Google APIs on your behalf.Access tokens are short-lived; refresh credentials are stored using the operating system’s secure credential storage.

Wordless does not use your Google profile information for advertising, model training, or personalization outside the signed-in account experience.

3. Optional Google Drive cloud sync

Cloud Sync is off by default. If you explicitly enable it under Settings → Data & Privacy, Wordless requests https://www.googleapis.com/auth/drive.appdata. This scope permits Wordless to read and write only its own hidden application-data folder in your Google Drive. It does not permit Wordless to browse, read, or modify your ordinary Drive files.

Data that may be synchronized

  • Language, theme, font scale, reduced-motion, notification, and appearance preferences.
  • Default model and per-workbench model selections.
  • Enabled model identifiers and sanitized Provider configuration metadata, such as display name, Base URL, API type, compatibility settings, and model capability definitions.
  • Sync metadata such as update time, device identifier, conflict baseline, and Wordless app-data file identifiers.

Data excluded from cloud sync

  • API keys, passwords, OAuth credentials, authorization headers, and secrets.
  • Conversation history and prompts.
  • Workspace files and folders.
  • Generated presentations, spreadsheets, documents, browser artifacts, and other project outputs.

Wordless communicates directly from the desktop application to Google APIs. Wordless does not operate an intermediary server that stores a copy of your synchronized configuration.

4. How Google data is used and disclosed

Google user data is used only to provide the user-facing sign-in and optional synchronization features you choose. Wordless does not sell Google user data, use it for advertising, or share it with data brokers.

Information is disclosed to Google only as necessary to authenticate your account and store or retrieve Wordless files in your own Drive app-data folder. We may disclose information when required by law, to protect users and the service from fraud or abuse, or with your explicit direction.

Google API Limited Use disclosure

Wordless’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Local workspace data and third-party services

Sessions, workspace references, tool activity, generated artifacts, and application settings are primarily stored on your device. Wordless sends prompts and selected context to the model Provider you configure only when you initiate a model request. Google account profile data and Drive app-data are not intentionally included in model prompts.

Third-party services have their own policies:

  • Model Providers and MCP connectors: receive the requests or data you direct Wordless to send to them.
  • Google: provides sign-in and optional Drive app-data storage.
  • GitHub: provides repository, release, and update information.
  • Website hosting: may process standard server logs such as IP address, user agent, requested URL, response status, and access time for delivery and security.

You should review the privacy terms of every model Provider, connector, and external service you enable.

6. Storage and security

Wordless uses operating-system credential storage for Google refresh credentials and Provider secrets. Network requests use HTTPS. Cloud-sync payloads are filtered to remove fields whose names indicate keys, tokens, secrets, passwords, authorization data, credentials, or sensitive headers.

No system is completely secure. Keep your operating system updated, protect your device account, review tool approvals, and revoke credentials if you believe your device or account has been compromised.

7. Retention and your controls

  • Pause sync: disable Google Cloud Sync without disabling local Wordless features.
  • Delete cloud data: use Delete cloud data in Data & Privacy to remove Wordless configuration files from Drive appDataFolder without deleting local settings.
  • Sign out: disconnect the Google account and remove the locally stored Wordless authorization credential.
  • Revoke access: remove Wordless from Google Account third-party access. Revocation stops future access but may not itself delete existing app-data files, so delete cloud data first when possible.
  • Local deletion: delete sessions, workspaces, artifacts, settings, or the application’s local data using Wordless and operating-system controls.

Local data remains until you delete it or remove the relevant application data. Google Drive app-data remains until you delete it, remove it through Google controls where available, or Google deletes it under its own policies.

8. Children

Wordless is a general-purpose productivity tool and is not directed to children under the age required to independently consent to data processing in their jurisdiction. If you believe a child has provided personal information through Wordless, contact us so the issue can be reviewed.

9. Changes and contact

We may update this policy as Wordless features or legal obligations change. The “Last updated” date identifies the latest revision. Material changes will be published on this page before or when they take effect.

Privacy questions and deletion requests can be sent to 15014915381z@gmail.com or raised through the official Wordless repository.

Wordless

A local-first desktop agent workspace.

PrivacyTermsContactGitHub