Summary
This policy covers the RunWield coding harness, the wld CLI, and runwield.dev. RunWield runs on your machine. Your Plans, sessions, and credentials are stored locally. RunWield collects no telemetry and operates no cloud service that receives this data.
When you use an AI provider, RunWield sends the working context directly to that provider. The sections below explain those connections and the optional ways you can share data.
What RunWield stores on your machine
~/.wld/stores settings insettings.json, credentials inauth.json, model configuration inmodels.json, the update cache inupdate-check.json, and sharing secrets incollaboration-secrets.json.~/.wld/sessions/stores session transcripts as append-only JSONL files. These files are plaintext and include prompts, tool results, and file content shown to the model.- Your project's
.wld/directory stores runtime state, Plan locks, and staging data.docs/plans/stores Plans as plain Markdown.docs/work-records/stores Work Records. - Memories are stored through the locally installed
mnemotecatool.
Delete the files to delete the local data. RunWield does not keep a cloud copy.
API keys and sign-in credentials
RunWield stores API keys and OAuth tokens from wld login on your machine in~/.wld/auth.json. You can also configure API keys in ~/.wld/models.json. These are plaintext files, not encrypted credential stores.
RunWield creates auth.json with 0600 file permissions and its directory with 0700 permissions. These restrict access to your account where the operating system supports these permissions.
Your credentials are never sent to RunWield. They are used only to authenticate requests to the provider they belong to.
What is sent to AI providers
On each model turn, the working context goes directly from your machine to the AI provider you configured. This context can include prompts, file contents read by tools, edits and diffs, command output, tool results, and images. Custom providers use the baseUrl you set.
RunWield never receives this content. The provider processes it under its own privacy terms. Review those terms before you send sensitive data.
No telemetry
RunWield collects no telemetry: no analytics, crash reports, usage pings, or tracking identifiers. No RunWield-operated endpoint receives your user data.
Network requests
The CLI automatically checks GitHub Releases for a newer version. This is an unauthenticated request to GitHub's Releases API, with a local 6-hour cache in ~/.wld/update-check.json. It retrieves release version information and sends no user content or tracking identifier. GitHub processes the request under its own privacy statement.
The following connections occur when you request these operations or use the agent tools:
wld updatedownloads installers from GitHub Releases with SHA-256 verification. RunWield does not automatically download or install updates.wld shareuploads a session as a secret GitHub Gist through your ownghCLI. A secret Gist is accessible to anyone with its link.wld remotecopies~/.wldto the SSH host you choose over SSH/SFTP.wld installfetches packages from npm or git sources.- Web search and fetch tools use the locally installed
ketchtool. Queries and URLs are sent to the search backends that ketch is configured to use. - The
bashtool can run any command your account can run, including network commands. It is not a sandbox.
Optional collaboration
Plan sharing uses a Plan Server that you host yourself, such as with Podman or an OCI container. There is no default server, and RunWield does not host it.
Plan content is encrypted on your machine with AES-256-GCM before upload. The server stores ciphertext and minimal routing metadata, not plaintext Plan content.
This website
runwield.dev is a static site hosted on GitHub Pages. It uses no cookies, analytics, or trackers. GitHub logs standard request data, such as IP addresses and user agents, underGitHub's privacy statement.
By default, the “Try It With Me” form opens your own email client with a message addressed tobeta@runwield.dev. We use that email only to reply about the beta.
Changes and contact
Last updated: .
When this policy changes, we update the date on this page. For privacy questions, emailbeta@runwield.dev.