witness

Privacy policy

Effective 2026-10-02 · Jobbin AB, org. no. 556893-2452

This policy says what personal data witness processes, why, for how long, and where — in the terms the GDPR uses, because that is the law that applies. Jobbin AB, org. no. 556893-2452, Stockholmsvägen 60a, 181 42 Lidingö, Sweden, is the company behind witness. Questions and requests go to support@witness.nu.

Two roles, and which one applies to you

For the console, billing, this website and support, we decide what is processed and why: we are the controller, and this policy is the whole story.

For what is inside a project — the findings, the comments, the images, and the names of the people who wrote them — the customer who created the project decides. They are the controller and we are their processor, under the data processing agreement. If you write in a project or read one, the organisation that gave you the link is who to ask about your data; we act on their instructions.

What we process as controller

Data Where it comes from Why Legal basis
Name, email address, organisation name Signing in to the console or the app (through Clerk) To know who manages an organisation and to reach them Performance of the contract
Billing address, VAT number, the last digits and expiry of a card Checkout (through Stripe); we never see the full card number To charge for the Team plan and to invoice correctly Performance of the contract; legal obligation (VAT, bookkeeping)
Invoices and payment history Stripe Bookkeeping Legal obligation — the Swedish Bookkeeping Act requires seven years
Emails you send us You Support, privacy requests, security reports Legitimate interest in answering you
Request logs: IP address, URL, time, response code Cloudflare, when a request reaches the service Operating and debugging the service, investigating abuse Legitimate interest in running a reliable, safe service
IP address, transiently The rate limiter To keep one address from flooding the service Legitimate interest; not stored by us, only counted for a minute

We do not profile anyone, do not run analytics on this site or in the product, and do not sell or share data for advertising.

What we process as processor

A project holds what the people using it put there: cards, comments, prose about the project itself, and images. Every write records who made it — a name that a person types once and the browser remembers, or the name an agent gives — because a finding without an author is half a finding. Those names are personal data, and they belong to the customer's project.

Project data is stored in the European Union. Every project's compute and storage is pinned to the EU in configuration, and so are the images. This was decided before the first project existed and cannot be changed per project.

How long

Data Kept
A project and its images Until the customer deletes it, or thirty days after the agreement ends. Deletion is immediate: the project, its links and its images are gone at once.
Nightly backups of projects Thirty days, then removed automatically. A deleted project therefore disappears from backups within thirty days. An archived project keeps one backup copy for as long as it stays archived, so that copy can be older than thirty days; taking it out of the archive or deleting it removes it at once.
Console account Until the organisation is deleted, plus thirty days.
Invoices and payment records Seven years, as Swedish bookkeeping law requires.
Support email As long as the matter is open, and up to two years after, so we can follow up.
Request logs Up to seven days, held by Cloudflare.

Where, and who else is involved

We use three companies to run witness. Each is listed with what it does and where at /legal/subprocessors, and we announce additions there and by email to account holders thirty days ahead.

Cookies, and why there is no banner

There is no consent banner on this site or in the product, because nothing here needs consent.

No advertising, analytics or tracking cookies are set anywhere on witness.nu.

Your rights

You may ask us to access, correct, delete or export the personal data we hold about you as controller, to restrict or object to our processing of it, and to withdraw consent where consent was the basis. Write to support@witness.nu; we answer within a month. If we hold your data as a processor — because it is inside someone's project — we will pass your request to the customer, who is the one that can act on it.

What your own device keeps, you can remove yourself without asking us.

In a browser, that is the name you write under, how the console shows your projects, and the project links in the app. Clear this site's data in that browser and they are gone from the device.

The Mac app has no site data to clear. It keeps what a browser keeps, the values listed above for the Mac app, and, for its sessions: each transcript, which agents you work with and your defaults for them, where each project's working folder and repositories are on that Mac, which GitHub repository each one came from and the branch its last session started from, and the last project page you had open. All of it is in three folders named nu.witness.desktop, in Application Support, Caches and WebKit inside the Library folder of your home folder. Quit the app and delete those three folders, and it is gone from that Mac.

Two things are not ours to remove. The folders a session worked in hold your own code; keep or delete them as you like. And your agents keep their own records, as they always do: Claude Code under .claude/projects in your home folder, Codex under .codex. Deleting the three nu.witness.desktop folders does not touch those records. Each agent says how to remove what it keeps.

You may complain to a supervisory authority. Ours is the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten, Box 8114, 104 20 Stockholm.

Changes

We will change this policy when what we do changes. The effective date at the top moves, the previous version stays in our public source history, and account holders are told by email about changes that matter.