The Work is a self-inquiry app. By default, we collect no personal data. Everything you write stays in your browser, saved in localStorage, until you erase it or it expires after 14 days.
We use one strictly necessary cookie (PHPSESSID) to keep your session safe from cross-site request forgery (CSRF). The cookie is removed automatically when you close your browser.
When you use the AI coach or generate an AI reflection, your message is forwarded to x.ai (Grok) to get a reply. We do not store these messages on our server. x.ai processes the messages under their own privacy policy (x.ai privacy).
If you voluntarily click "Share with coach", your session is emailed to the coach (info@skep.co). This only happens after explicit consent via a checkbox. We do not request your email address; only your name (optional).
Because we do not persist anything on our servers, there is normally nothing to delete or access. For sessions shared by email, you can request deletion via info@skep.co.
All connections are encrypted (HTTPS). Session cookies use HttpOnly, Secure, and SameSite=Lax flags. CSRF tokens protect against request forgery.
Questions? info@skep.co