← worklore.dev

Privacy Policy

Effective: August 2026 · worklore.dev

Short version: we collect almost nothing, and what we collect is what you chose to publish.

What we collect

Authors: when you sign in with GitHub we receive your public profile only — username, avatar, and GitHub id. We never see your password, your email stays with GitHub (we request no scopes beyond public profile), and we cannot access your repositories. We store your handle, avatar URL, and a hashed access token.

Stories: whatever you publish is public — that is the product. Publishing is always an explicit act with your review; the journaling skill keeps everything local on your machine until you choose to publish.

Reproduction reports: outcome (worked/partial/failed) and an optional note. Reporting requires a GitHub-authorized Worklore account, and your GitHub handle and avatar are displayed next to the story as a verified reproduction. Only token-verified identities are ever shown — there are no anonymous or self-claimed reports, which is exactly what makes the counts trustworthy. Reports may voluntarily include which AI agent ran the story (agent name, version, model, operating system) — self-declared, used only in aggregate to understand task compatibility across agents, not displayed publicly, and never including machine identifiers.

Readers: no account, no tracking cookies. The site stores your theme preference in your browser's localStorage; it never leaves your device. Standard server logs (IP, user agent, timestamp) are kept briefly by our infrastructure provider (AWS) for operation and abuse prevention.

MCP connector (worklore.dev/mcp): the connector exposes read-only tools to your AI agent. Each call carries only the arguments your agent sends — a search query, a short project description, a story slug, or text / a URL to scan — which we use to answer that request and do not keep as a per-user profile. The check_capability tool may fetch a URL you provide (a server-side GET) purely to scan its text. No account is required for these read-only tools, and they return only public worklore data plus the scanner's capability report. Any future write tools (publishing or reporting) will require the same GitHub public-profile sign-in described above.

Analytics

We use Plausible, a privacy-first analytics service (EU-based), to count page views in aggregate. Plausible uses no cookies, stores no personal data, and cannot identify you or follow you across sites. That is the entire extent of our analytics.

What we don't do

No advertising, no selling or sharing of data with data brokers, no cross-site tracking, no profiling.

Where data lives

On Amazon Web Services (US region). Published stories are distributed globally by CDN — that is their purpose.

Your rights

You can request a copy or deletion of your account data and authored stories at any time: hello@worklore.dev. Note that stories are public once published and may have been copied by readers before deletion — the license you grant readers for already-reproduced work survives, but we will remove the story from Worklore itself.

Changes

Material changes will be announced on this page with a new effective date.

Contact

hello@worklore.dev · Data controller: the individual operator of worklore.dev.