INkSTAGE Privacy Policy
INkSTAGE ("the App") is a local-first desktop writing tool for
authors. Projects are stored in
.inwx files at locations chosen by the user and are not
automatically uploaded to a developer server. When a user runs an AI
feature, however, the context described below may be transmitted
through the selected connection. This policy explains local storage,
AI data transfer, credentials, and deletion controls.
1. Information Stored on the Device
-
Project data — Manuscripts, titles and document
tree data, synopses, notes, tags, snapshots, media, and AI sessions
are stored in the project's
.inwxfile. - App settings — Theme, layout, recent project and external-document paths, editor modes, and selected AI connection and model may be stored in the user's app-data directory or webview storage. These global preferences are outside the encrypted project.
- AI credentials — OpenAI, Anthropic, and Google API keys; Codex sign-in tokens; and custom AI server details may be stored depending on the connection selected (see §2).
The App contains no developer-operated advertising account, behavior-profiling system, or manuscript analytics collector.
2. AI Credential Storage
- Provider API keys — OpenAI, Anthropic, and Google API keys are stored in the operating system's credential store (Windows Credential Manager or macOS Keychain).
- Codex sign-in — OpenAI access and refresh tokens plus the ChatGPT account identifier are stored in a local file encrypted with XChaCha20-Poly1305 by a key kept in the operating system's credential store. Tokens are not exposed to the UI.
- Claude Code — When the local Claude Code CLI is selected, the App uses the authentication managed by that CLI and does not directly read or store Claude account credentials.
- Custom servers — The OpenAI-compatible server URL and optional app token are stored in local app settings. Do not store a sensitive token on a public or shared operating-system account.
3. Information AI Features May Transmit
AI features create a network request only when the user actively sends a message, requests an edit, or starts image generation. Depending on the feature, a request may include:
- The user's prompt, selected text, and conversation history from that AI session
- Project name, description, document count and word count, plus the current document's title and body context
- Documents, search results, snapshot information, and tool results read by the AI agent while carrying out the user's request
- A GPT Image 2 prompt, image size, and quality setting
- The ChatGPT/Codex account identifier and authentication token used to display Codex usage limits
4. AI Connection Paths
- Direct APIs — Requests are sent from the device to OpenAI, Anthropic, or Google Gemini using the API key saved by the user.
- Codex sign-in — ChatGPT/Codex sign-in uses OpenAI authentication and ChatGPT Codex response, image-generation, and usage endpoints. This path follows a sign-in flow compatible with the Codex CLI and may change if OpenAI changes its service.
- Claude Code — Requests run through the installed local Claude Code CLI and are processed under the connected Claude account and Anthropic policies.
- Local or custom servers — Requests are sent to the OpenAI-compatible endpoint entered by the user, such as LM Studio. Whether the server is actually local and how it retains data depend on its operator.
5. Third-Party Processing and Model Training
The App does not sell user data. Retention, human review, and use of AI input or output for model improvement may differ by API versus consumer account, free versus paid tier, and the settings of the selected provider. Review the latest policy for the selected route before sending sensitive or unpublished work.
- OpenAI — Privacy Policy · How data is used
- Google Gemini — Gemini API Additional Terms · Google Privacy Policy
- Anthropic — Anthropic Privacy Center
6. Storage Security and Limits
-
Every data value in an
.inwxproject is encrypted with XChaCha20-Poly1305 and bound to its row identifier. - The project content key is protected by an Argon2id-derived password or recovery-code key, or by a device key stored in the operating system's credential store.
- Cloud AI connections use HTTPS. Transport security for a local or custom server depends on the URL and server configured by the user.
- Encryption at rest cannot prevent every access while a project is unlocked in the App or if the operating-system user account is compromised.
7. Retention, Deletion, and User Control
-
Projects — Delete documents in the App or delete
the
.inwxfile at its saved location. Uninstalling the App does not necessarily delete project files stored elsewhere by the user. - AI sessions and media — These are deleted within the relevant project and remain inside its encrypted storage boundary.
- API keys — Removing a provider key in Settings deletes that credential from the operating system's credential store.
- Codex sign-in — Signing out deletes the locally sealed Codex token file. OpenAI-side sessions and data controls remain governed by OpenAI settings and policy.
- App settings and recent paths — App configuration and webview storage may need to be removed separately from the operating system's app-data area.
- Provider-side data — Retention, access, and deletion of data already sent to an external service follow that provider's or server operator's policies and account tools.
8. Age Requirements
The App is not designed to knowingly collect children's personal information. Users of AI features must meet the age and regional requirements of the selected provider. For example, the current Gemini API Additional Terms require API users to be at least 18 years old.
9. Changes to This Policy
When features or external service paths change, this page and its “Last updated” date will be revised.
10. Contact
Privacy and data-processing inquiries: [email protected]