Privacy policy
This policy says what personal data witness processes, why, for how long, and where — in the terms the GDPR uses, because that is the law that applies. Jobbin AB, org. no. 556893-2452, Stockholmsvägen 60a, 181 42 Lidingö, Sweden, is the company behind witness. Questions and requests go to support@witness.nu.
Two roles, and which one applies to you
For the console, billing, this website and support, we decide what is processed and why: we are the controller, and this policy is the whole story.
For what is inside a project — the findings, the comments, the images, and the names of the people who wrote them — the customer who created the project decides. They are the controller and we are their processor, under the data processing agreement. If you write in a project or read one, the organisation that gave you the link is who to ask about your data; we act on their instructions.
What we process as controller
| Data | Where it comes from | Why | Legal basis |
|---|---|---|---|
| Name, email address, organisation name | Signing in to the console or the app (through Clerk) | To know who manages an organisation and to reach them | Performance of the contract |
| Billing address, VAT number, the last digits and expiry of a card | Checkout (through Stripe); we never see the full card number | To charge for the Team plan and to invoice correctly | Performance of the contract; legal obligation (VAT, bookkeeping) |
| Invoices and payment history | Stripe | Bookkeeping | Legal obligation — the Swedish Bookkeeping Act requires seven years |
| Emails you send us | You | Support, privacy requests, security reports | Legitimate interest in answering you |
| Request logs: IP address, URL, time, response code | Cloudflare, when a request reaches the service | Operating and debugging the service, investigating abuse | Legitimate interest in running a reliable, safe service |
| IP address, transiently | The rate limiter | To keep one address from flooding the service | Legitimate interest; not stored by us, only counted for a minute |
We do not profile anyone, do not run analytics on this site or in the product, and do not sell or share data for advertising.
What we process as processor
A project holds what the people using it put there: cards, comments, prose about the project itself, and images. Every write records who made it — a name that a person types once and the browser remembers, or the name an agent gives — because a finding without an author is half a finding. Those names are personal data, and they belong to the customer's project.
Project data is stored in the European Union. Every project's compute and storage is pinned to the EU in configuration, and so are the images. This was decided before the first project existed and cannot be changed per project.
How long
| Data | Kept |
|---|---|
| A project and its images | Until the customer deletes it, or thirty days after the agreement ends. Deletion is immediate: the project, its links and its images are gone at once. |
| Nightly backups of projects | Thirty days, then removed automatically. A deleted project therefore disappears from backups within thirty days. An archived project keeps one backup copy for as long as it stays archived, so that copy can be older than thirty days; taking it out of the archive or deleting it removes it at once. |
| Console account | Until the organisation is deleted, plus thirty days. |
| Invoices and payment records | Seven years, as Swedish bookkeeping law requires. |
| Support email | As long as the matter is open, and up to two years after, so we can follow up. |
| Request logs | Up to seven days, held by Cloudflare. |
Where, and who else is involved
We use three companies to run witness. Each is listed with what it does and where at /legal/subprocessors, and we announce additions there and by email to account holders thirty days ahead.
- Cloudflare hosts the service. Project data is pinned to Cloudflare's EU locations. Cloudflare, Inc. is a US company certified under the EU–US Data Privacy Framework, and our agreement with it includes the EU standard contractual clauses.
- Clerk provides sign-in for the console and for the app. This is the one place data about a person — the account holder — is processed in the United States. Clerk, Inc. is certified under the EU–US Data Privacy Framework and signs the standard contractual clauses. Nothing inside a project goes to Clerk.
- Stripe takes payment. For European customers the contracting entity is Stripe Payments Europe, Ltd. in Ireland; Stripe, Inc. in the US is certified under the Data Privacy Framework for the processing it does.
Cookies, and why there is no banner
There is no consent banner on this site or in the product, because nothing here needs consent.
- Opening a project link in a browser sets one cookie,
witness_token, which holds the link's credential so that it is not in the address bar on every later request. It isHttpOnly, scoped to that one project's path, and lasts a year. It is strictly necessary for the thing you just asked for — opening the project — so no consent is required, and there is nothing to opt out of short of not opening the link. - Signing in — at the console, or in the app at witness.nu/app — sets the session cookies Clerk needs to keep you signed in. They exist only for that purpose. If you are signed in and open a project of your organisation, one of them — Clerk's session cookie — is also read when your browser asks for an image attached to a card, because that is the one request a page cannot put a credential on any other way. It is checked to see that the image is yours to look at and used for nothing else; it is strictly necessary for showing you the card you opened, so no consent is required there either.
- The project page remembers one thing in your browser's local storage: the name you typed when you first wrote something (
project.actorName). The console remembers whether you last saw your projects as a list or on a layout (witness.console.view). None of them leaves your browser. - The app at witness.nu/app keeps, in the same local storage, the project links you have pasted into it (
app.projects) and which groups you have opened (app.openGroups). A link is the whole credential, so those links are keys: they are on that device because you put them there, they stay on it — there is no account they belong to and nothing syncs them anywhere — and clearing this site's data in your browser removes them. That is also how you take a project off a phone you are done with. Signing in to the app does not change that: an account lists the projects your organisation owns beside them, and the links you pasted stay where they are, on the device, yours to remove. - The app kept those same links under an older name (
app.registers) before the product's vocabulary changed. It moves them across the first time you open it, and drops the old key once it has read the new one back and seen that the move landed. Where that write cannot happen — a browser in private mode, or one that is out of room — the old key stays exactly where it is, so that a failed move loses nobody their links, and the app tries again next time you open it. Forgetting a project takes it out of both. Clearing this site's data removes both as well. - In the Mac app, pressing Sign in stores one value in local storage (
witness.desktop.signInState) so that the browser tab it opens can prove it is answering that same attempt when it hands the app window a session. It is a random value, not a credential — it identifies the attempt, not you — and it is removed once sign-in finishes; pressing Sign in again replaces it. - In the Mac app, the tray at the foot of the page tells you what happened to a session while you were elsewhere, and what it has not yet told you is remembered in local storage (
witness.sessions.notices) so that it survives a reload: the session's id, its project's id, whether it asked, finished or failed, and when, nothing else. It never leaves that device, and an entry is dropped once you dismiss it, see that session, or the session moves on. An older version kept the sessions you had dismissed underwitness.sessions.dismissed; the app removes that key the first time it reads the new one. - In the Mac app, the panel that shows a session's changed files remembers, for each session, in local storage (
witness.changes.sessions): the session's id, whether you last had the panel open, whether it took the whole width or stood beside the conversation, which of its two views you chose, and whether its list of files was shown — nothing about any file. It keeps the fifty sessions you changed it in most recently and drops older ones. It never leaves that device. An older version kept one set of these settings for every session underwitness.changes; the app removes that key when it opens. - In the Mac app, which sections beside an open session you closed or opened (Running, Pull requests, Cards, Artifacts, About) is remembered in local storage (
witness.sessions.rail), so the next session you open shows them the same way. That is one open-or-closed value per section and nothing else. It never leaves that device. - Whether you chose Light or Dark under Appearance, in the menu behind your name, is remembered in local storage (
witness.appearance). That is one word, and nothing at all while you leave it on System. It never leaves that device. - In the Mac app, whether you turned off the suggestions above a session's message box, in Settings › This Mac, is remembered in local storage (
witness.promptSuggestions). That is one value, on or off, and nothing else. It never leaves that device. - In the Mac app, which projects' teams you paused in Sessions, so the app starts none of their given cards there, is remembered in local storage (
witness.teamPaused). That is a list of project ids and nothing else. It never leaves that device.
No advertising, analytics or tracking cookies are set anywhere on witness.nu.
Your rights
You may ask us to access, correct, delete or export the personal data we hold about you as controller, to restrict or object to our processing of it, and to withdraw consent where consent was the basis. Write to support@witness.nu; we answer within a month. If we hold your data as a processor — because it is inside someone's project — we will pass your request to the customer, who is the one that can act on it.
What your own device keeps, you can remove yourself without asking us.
In a browser, that is the name you write under, how the console shows your projects, and the project links in the app. Clear this site's data in that browser and they are gone from the device.
The Mac app has no site data to clear. It keeps what a browser keeps, the values listed above for the Mac app, and, for its sessions: each transcript, which agents you work with and your defaults for them, where each project's working folder and repositories are on that Mac, which GitHub repository each one came from and the branch its last session started from, and the last project page you had open. All of it is in three folders named nu.witness.desktop, in Application Support, Caches and WebKit inside the Library folder of your home folder. Quit the app and delete those three folders, and it is gone from that Mac.
Two things are not ours to remove. The folders a session worked in hold your own code; keep or delete them as you like. And your agents keep their own records, as they always do: Claude Code under .claude/projects in your home folder, Codex under .codex. Deleting the three nu.witness.desktop folders does not touch those records. Each agent says how to remove what it keeps.
You may complain to a supervisory authority. Ours is the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten, Box 8114, 104 20 Stockholm.
Changes
We will change this policy when what we do changes. The effective date at the top moves, the previous version stays in our public source history, and account holders are told by email about changes that matter.