nintek
AppsiOSAbout
← Workshop

Workshop Privacy Policy

Effective August 23, 2026 · Last reviewed August 23, 2026

Workshop is a private, account-backed woodworking project companion. The current web workspace remains active; native build 2.2.1 (13) is attached and in internal TestFlight, not public. Apple and Microsoft sign-in create separate Workshop accounts.

PrivacySupportTerms
On this pageScope and identityData processedStorage and device dataOptional URL analysisExport, deletion, and retentionProviders and sharingContact

Scope and account identity

This policy explains how Nintek (“we”, “us”) handles information inWorkshop on the web and in its private native builds. Workshop is a single-user project companion for planning and documenting woodworking and Shaper projects.

Sign in with Apple and Microsoft are independent identity paths. Even when both providers use the same email address, they create separate Workshop accounts, databases, uploads, exports, and deletion scopes. There is no automatic cross-provider account linking.

Workshop does not use third-party advertising, advertising identifiers, or cross-app tracking. It processes account, project, file, optional analysis, and operational data needed to provide and secure the service.

Information Workshop processes

  • Account information. A stable provider identifier and the basic profile fields Apple or Microsoft makes available, such as name and email. Apple may provide a private relay address. Apple authorization data needed for account revocation is stored encrypted.
  • Project information. Projects, Shaper projects, templates, parts, dimensions, cut plans, stock, materials, shopping lists, instructions, costs, progress, build logs, finish records, notes, and related settings.
  • Files. Project photos, drawings, selected images, Journaling Suggestions you choose to attach, and other account uploads.
  • Imported source material. A URL and the page content fetched for analysis when you ask Workshop to turn a project page into an editable draft.
  • Operations. Request timing, errors, account-lifecycle checkpoints, backup manifests, and security records needed to run, restore, troubleshoot, and protect the service.

Server storage and device data

Each Workshop account has a private per-user SQLite database. Photos and other uploads are kept in account-scoped upload storage. The service runs on Microsoft Azure and uses HTTPS in transit. Access is limited to service and support operations that require it.

On iPhone and iPad, authentication credentials use protected platform storage. App preferences and compact widget or Live Activity snapshots can use local app and App Group storage. Camera, photo-picker, Live Text, Pencil, notification, and Journaling Suggestions data is accessed only when you choose the related feature.

Workshop is online-only for account data on both web and native. The native app is a REST client with no local database mirror. Unit-conversion tables work without a server, and native widgets can show a stale last-synced snapshot, but projects, edits, uploads, shopping, logs, analysis, and deletion require a live connection. Device snapshots are not an independent backup.

Optional project URL analysis

Workshop contacts a project URL only when you ask it to analyze that page. The server rejects private and loopback network destinations, retrieves the public page, removes page markup, and sends the relevant source text to Anthropic to produce a structured draft. If the analysis provider is not configured or available, the feature returns an error rather than inventing a successful result.

Review dimensions, materials, safety instructions, and generated details against the source before using them in a physical build. Automated project extraction is not engineering or safety advice.

Export, deletion, backups, and retention

Workshop’s downloadable JSON is a project-list summary, not a complete account archive: it omits detail tables, authentication state, and uploads and cannot be imported as a restore. Operator recovery bundles are separate and exist to recover the service, not to provide a user export.

In the native app, account deletion revokes stored Apple credentials before local Workshop data is removed. If Apple revocation fails, deletion stops and leaves the account data intact for a safe retry. Microsoft-backed deletion removes Workshop data without deleting the Microsoft account. Each action is scoped to the current provider-backed Workshop workspace; Apple and Microsoft workspaces are not automatically linked or merged, and deleting one does not delete the other.

The service retains seven local daily recovery bundles. Protected off-host daily copies use a 30-day lifecycle and monthly copies a 366-day lifecycle, with 14-day soft delete. Restoring a point from before an account deletion can resurrect files, so the recovery runbook requires a human operator to reconcile later deletions before reopening. That reconciliation is not an automated restore feature.

Workshop data lifecycle and account-control boundaries
Data or controlWhere it livesExport or backupDeletion and retention
Workshop account identityAn isolated Workshop identity derived from either Microsoft or Apple sign-in. The providers create separate Workshop accounts unless a future linking feature explicitly joins them.The project-summary export includes no provider credential or complete account profile. Apple and Microsoft provide controls for their own accounts.In-app account deletion removes the selected Workshop identity and data. It does not delete the Apple or Microsoft account or a Workshop account created with the other provider.
Projects, parts, lists, logs, and other structured contentA private per-user SQLite database hosted on Microsoft Azure.Settings can download a JSON project-list summary. It omits project detail tables, account state, and uploads and has no import path, so it is not a complete backup.Deleting content removes it from the active account according to the feature. Deleting the account purges the selected per-user database after required provider revocation succeeds.
Photos and uploaded filesAccount-scoped upload storage on the Azure-hosted service, separate from the per-user SQLite database.The JSON project summary does not include uploads. Keep original files separately if you need an independent copy.Account deletion removes the selected account’s uploads. Historical recovery bundles can retain copies until their scheduled retention expires.
Recovery bundlesChecksummed bundles contain database and upload state. The service keeps seven local daily bundles and publishes protected off-host daily and monthly recovery copies.These are operator disaster-recovery artifacts, not user-downloadable account backups.Local copies retain seven bundles. Off-host daily copies use a 30-day window, monthly copies a 366-day window, plus 14-day soft delete. A restore requires manual deletion reconciliation before reopening.
Optional URL-analysis input and outputThe requested URL and extracted project material are sent to Anthropic only when you ask Workshop to analyze a project page; the editable result is stored in the selected account if you save it.Saved result data follows the project-summary limits above; the source website remains independent.Delete the saved Workshop content or selected account. Anthropic and the source site may retain provider-side records under their own terms.
Device snapshots, credentials, and support mailProtected app, Keychain, App Group, widget or Live Activity storage on the device, plus Nintek’s mailbox if you contact support.Device snapshots are not a complete project backup. You control any support message you send.Account deletion clears Workshop credentials and native account state after server confirmation. Support mail may be retained for response, security, or legal needs.

Scroll horizontally to read all four columns →

Providers, sharing, and account boundaries

We do not sell personal information. Microsoft provides Azure hosting and Microsoft identity. Apple provides Apple sign-in and its revocation service. Anthropic processes selected URL-analysis inputs. A source website receives an ordinary server request when you ask Workshop to analyze it. Each provider handles its part under its own terms and legal obligations.

Deleting Workshop cannot delete the underlying Apple or Microsoft account, provider security records, or source-site logs. Information may also be disclosed where required by law or reasonably needed to protect the service.

Children, changes, and contact

Workshop is intended for a general adult audience and is not directed to children. We do not knowingly create Workshop accounts for children.

We may update this policy when the product, providers, release state, or data practices change. The dates at the top identify this version.

Privacy and data questions can be sent toprivacy@nintek.com. Product help is available on Workshop Support. Use of Workshop is subject to theNintek Terms of Use.

Evidence note. Reviewed against the current Workshop web service and immutable Workshop-for-iOS build 13 authority 32248fc on August 23, 2026.

© 2026 Nintek
TermsSupportPrivacy questions