Summary
W1 sends your request and the bounded project context needed for the current model call to the hosted W1 service. Full local run traces stay on your computer by default. Remote product analytics are structural: counts, timing, cost, tool categories, outcomes, versions, and pseudonymous identifiers - not raw prompts, file contents, paths, shell commands, or model responses.
With the W1 mobile app, the work runs on a cloud machine that belongs to your account, in Johannesburg, South Africa. Your projects and threads are stored on that machine’s disk, and the context for each model request is sent from there, through the W1 service, to model providers outside South Africa.
What this policy covers
W1 is operated by SYNARA AI (Pty) Ltd (registration number 2025/921363/07), a company registered in South Africa with its registered address at 133 Derby Road, Kensington, Johannesburg, 2094. SYNARA AI (Pty) Ltd is the responsible party for your personal information under the Protection of Personal Information Act (POPIA), and “W1”, “we” and “us” in this policy mean that company.
This policy covers the w1lab.com website, the W1 desktop app for Windows, macOS and Linux, the VS Code extension, the W1 CLI, the W1 app for iPhone and Android, and the hosted W1 service behind them, including the cloud machines W1 runs for signed-in accounts.
What W1 processes
- Account information: your WorkOS account identifier, email address, and authentication session.
- Billing information if you subscribe: your plan, the Payfast subscription token and payment references, amounts and dates, and the receipts we sent you. Never your card number.
- Inference context: your message and the portions of project files, documents, prior conversation, tool results, and task state selected for a model request.
- Usage records: provider, model, input/output/cached token counts, latency, reasoning tier, exact provider cost when available, and the W1 thread/run/attempt identifiers needed for idempotent accounting.
- Structural product analytics: app version, platform, run status, tool names and counts, file extensions, command categories, cache facts, checkpoints, errors represented by safe codes, and pseudonymous installation, session, user, thread, turn, run, and attempt identifiers.
- Support information: messages and files you deliberately send to support.
- Your cloud machine, if you have one: the projects, files, threads and command output the W1 agent works with, stored on that machine’s disk, plus the machine’s region, state, start and stop times, and how much machine time it used this week.
- From the mobile app: images you choose to attach to a request, and the text of voice input. Both are sent with the request they belong to.
- Website visits: see The website below.
What stays local by default
This section is about W1 on your own computer: the desktop app, the VS Code extension and the CLI. With the mobile app, the same files live on your cloud machine instead (see Your cloud machine).
Your full run transcript and detailed trace stay on your own machine, in W1’s state folder under your home directory - not in the project folder. Run traces are written to ~/.w1/userdata/workspaces/<project>-<id>/runs/, where <project> is your project folder’s name and <id> is a short hash of its full path. Your conversation history itself is kept separately again, under ~/.w1/engine/. Versions of W1 before local state was isolated wrote traces into a .w1/ folder inside the project itself; if you have used W1 for a while, that folder may still exist and is now only ever read, never added to.
W1 does not send raw prompts, model output, file contents, full file paths, shell command strings, tool observations, bearer tokens, provider keys, or user documents to PostHog.
W1 does not scan your whole computer. Project tools operate against the folder you open and the access mode you select. Some commands chosen for your task may invoke software already installed on your machine; their effects are visible in the run.
The W1 mobile app
The W1 app for iPhone and Android is the control surface for your cloud machine. It sends your instructions and shows the results. The code W1 writes and runs lives on the cloud machine, not on your phone.
On the phone, the app keeps your sign-in in the phone’s secure storage and keeps copies of your threads so they open quickly. Uninstalling the app removes them. The app contains no advertising SDK.
The app asks for these permissions, each only when the feature needs it, and you can turn any of them off in your phone’s settings:
- Camera (iPhone and Android): to scan a pairing QR code.
- Microphone (iPhone only): for voice input. Your speech is turned into text on the phone by Apple’s on-device transcription, and only the text is sent. On Android, W1 does not ask for the microphone.
- Notifications (optional): alerts that a run finished, needs you, or hit a problem. If you turn them on, the app registers a push token for your phone with the W1 service. The alert itself is a fixed line of text and the identifier of the thread: it never contains your prompt, your files, or anything W1 wrote. It is delivered through Expo’s push service and then Apple (iPhone) or Google (Android). You choose which alerts you get in the app’s settings, and W1 does not send the ones you turn off. Signing out or deleting your account removes the token.
- Photos: attaching an image uses the system photo picker, which shares only the image you choose. On iPhone, saving an image asks for permission to add to your photo library.
- Local network (iPhone): used only if you connect the app to a W1 machine on your own network.
On Android, W1 does not request access to your microphone or shared storage, or permission to draw over other apps.
Your cloud machine
When you sign in on the mobile app, W1 can create a cloud machine for your account: a small Linux computer (2 shared CPUs, 4 GB of memory and a 10 GB disk) hosted by Fly.io in Johannesburg, South Africa. Its region is fixed when it is created. The disk is encrypted at rest by the host.
- What runs on it: the W1 agent, and the W1 server the app connects to. Your projects, the files the agent creates or changes, your threads and command output are stored on its disk.
- Who can reach it: the machine belongs to your account alone and is never reassigned to another account. The app connects to it only after W1 checks that the machine is yours, and that connection is tied to a key held on your phone. The agent on the machine holds a token that can only make model requests for your account. W1 operates the hosting account, so W1 can stop, restart or remove machines to run the service, keep it secure, or stop abuse.
- What leaves it: the context for each model request (see Model providers), web searches the agent makes for your task, and structural analytics. Analytics about the machine carry its state, region and minutes of machine time, never what is on its disk.
- When it stops: on its own when nobody is connected and no run is going; after 12 hours of running with no model request; when it has used its machine time for the week, until the weekly reset on Friday at 17:00 South African time; and when you sign out of the app. A stopped machine keeps its disk, and your work is there when it starts again.
- When it is destroyed: when you delete your account, together with its disk. If a machine is replaced, the old one is stopped at once and destroyed with its disk 7 days later.
Model providers
To do the work, W1 sends your request and the context selected for it to a large language model. W1 does not host these models itself. Requests go from the W1 service to OpenRouter, which passes each one to a company that hosts the model.
- For the current W1 model, which the mobile app, your cloud machine and current desktop builds use, W1 sets which hosting providers a request may go to and a list it may never go to. That list excludes providers W1 classes as China-linked, including the model maker’s own endpoint, and OpenRouter enforces it on every request.
- Every model request W1 sends asks OpenRouter to use only providers that do not store prompts or train on them.
- Outdated desktop builds that still ask for an earlier model are routed under a different provider list. Keeping W1 updated keeps you on the list above.
When the agent searches the web or reads a web page for your task, the search terms or the page address go to Jina AI, which returns the results.
How we use data
- Provide authentication and the hosted inference service.
- Perform the project work you request and preserve thread continuity.
- Meter usage, enforce beta limits, detect duplicate billing attempts, and show your usage.
- Diagnose crashes, transport failures, cache regressions, and product reliability using structural events.
- Respond to support, security, deletion, and access requests.
- Prevent abuse and protect the service and other users.
W1 does not sell your project content or use it for targeted advertising.
Service providers
W1 uses specialized providers to operate the service:
- Cloudflare for the public website, API, storage, and edge infrastructure, and for Turnstile, which checks that a form was sent by a person.
- WorkOS for account authentication.
- Payfast to take card payments for paid plans. Your card number never reaches W1: Payfast holds it, and we receive a subscription token, the amount, and a payment reference.
- OpenRouter and the selected model provider to process model requests (see Model providers).
- Fly.io to host cloud machines and their disks, in Johannesburg.
- Jina AI for the web searches and page reads the agent makes for your task.
- PostHog for privacy-sanitized product analytics.
- Meta to measure W1’s advertising on Meta, from the website only (see The website).
- Resend for account, beta, support, and product email where applicable.
- Expo, with Apple and Google, to deliver the mobile app’s optional push notifications.
- GitHub to track the support requests you send us.
- Microsoft, Apple and Google for application distribution and updates on their platforms.
These providers process data under their own terms and privacy commitments. W1 sends each provider only the information needed for its role.
The website
- Analytics: PostHog records page views and clicks on w1lab.com. It is served through w1lab.com itself and sets a first-party cookie that app.w1lab.com shares, so a visit can be connected to the account you later sign in with.
- Advertising measurement: the Meta Pixel on the website records page views and when someone clicks a download or asks for a download link. For those two actions the site also sends the event to Meta from our server, with your IP address, browser user agent, Meta’s own cookies if present, and, for the email form, a one-way SHA-256 hash of your email address. Your email address itself is never sent to Meta.
- Download links: each download records the platform, the time, any referral code, and a one-way hash of your IP address, to count downloads. These records are deleted after 90 days.
- “Email me the link”: we send that one email with the download links and do not add you to a mailing list.
- Contact and support forms: your message goes to the W1 team and is tracked in GitHub so it gets an answer.
Where data is processed
W1 is operated by SYNARA AI (Pty) Ltd from South Africa. Your cloud machine and its disk are in Johannesburg. Most other processing happens outside South Africa: model requests go to model providers outside South Africa, PostHog stores analytics in the United States, and Cloudflare serves the website and stores account and usage records on its global network. Using W1 means your information is processed in those countries.
Retention
- Local traces remain until you delete them or remove the project.
- Authentication sessions expire and may be revoked when you sign out.
- Usage records are retained long enough to operate the beta, reconcile cost, prevent duplicate charging, and meet legal/accounting requirements.
- A detailed trace is uploaded only when you deliberately share it for support or enable an explicit internal diagnostic mode. Support traces are scheduled for deletion after 30 days unless a security or legal need requires longer retention.
- Account contact information remains until the account relationship ends or you request deletion, subject to legal requirements.
- A sign-in session lasts 30 days and is renewed while you keep using it.
- Your cloud machine and its disk are kept while your account exists, and destroyed when you delete it.
- When you delete your account, W1 keeps only what the account deletion page lists: if you paid, the minimum invoice record of each payment for 5 years as South African tax law requires, with no name or email attached; and an id-only marker for 400 days so the deleted account cannot be signed back into.
- Website download records are deleted after 90 days.
Your controls
- Choose which project folder W1 can access.
- Select the access mode and review important changes before shipping them.
- Turn off optional telemetry in the application settings where available.
- Delete local run traces in the desktop app: Settings → Privacy & data → Clear now, which removes stored run traces and per-thread logs immediately. Deleting the
runs/folder named above by hand does the same thing, but note that it does not remove your conversation history, which lives under~/.w1/engine/. - Delete everything W1 has stored locally, conversation history included, with Settings → Remove W1 data, or by removing the
~/.w1folder. If an older version of W1 left a.w1/folder inside a project, remove that too. - Sign out to revoke the local session. Signing out of the mobile app also stops your cloud machine.
- Allow or deny each mobile app permission in your phone’s settings.
- Request access, correction, export, or deletion by emailing support.
Some data is required to provide inference, authentication, security, and usage accounting. If you do not want that processing, do not submit the request or use the hosted service.
Your rights and deleting your account
You can ask us for a copy of the personal information W1 holds about you, ask us to correct it or delete it, and object to how it is processed. Email support@w1lab.com. If you are not satisfied with our answer, you can complain to the Information Regulator of South Africa or to the data protection authority where you live.
You can delete your account and the data tied to it in the app, on the web, or by email. The web and email routes do not need the app:
- In the mobile app: Settings → W1 Account → Delete account.
- On the web: app.w1lab.com/account/delete. Sign in and confirm.
- By email to support@w1lab.com from the address you sign in with. We complete email requests within 30 days.
The account deletion page lists exactly what is deleted, what is kept, and why.
Children
W1 is not made for children. If you are under the age at which you can agree to the Terms where you live, a parent or legal guardian must authorize your use. If you believe a child is using W1 without that, email support@w1lab.com and we will delete the account.
Contact and changes
Email support@w1lab.com for privacy questions or data requests. The responsible party is SYNARA AI (Pty) Ltd, Reg. 2025/921363/07, 133 Derby Road, Kensington, Johannesburg, 2094, South Africa. W1 serves beta users in multiple countries. We may update this policy as the beta changes; the effective date above will change when the policy does.