DeepWork
Privacy · effective 2026-09-11

Everything stays on your Mac. Check it yourself.

No account. No server. No sync. DeepWork never takes screenshots and never reads what you type. It has no network code at all.

A tracker that reads your window titles has to earn trust. This page says exactly what is kept, and gives you the commands to see for yourself.

What it records

Six things. Nothing else.

SignalWhat is keptWhy
App nameAlwaysWhich app you were in
Window titleOnly outside browsers, and never from private appsProject detection (a file name in your editor)
WebsiteThe domain only, like github.com. Never the full URL. Never the page title, unless you turn that on.Classify the site, show where time went
Repo folder nameThe folder name only. Never the file path.A project hint
Time and kindHow long, and whether it was deep, shallow or a distractionThe whole point of the app
Lock-in sessionsThe task name you typed and the apps you allowedSo your history makes sense
What it never records

The list people ask about.

  1. 01
    Full URLs. Only the domain.
  2. 02
    Page titles, unless you turn on "Store page titles from browsers". It is off by default.
  3. 03
    Keystrokes, or anything about what you type. The app never asks for Input Monitoring.
  4. 04
    Screenshots or screen recordings.
  5. 05
    File paths. Only a folder name, for git repos.
  6. 06
    Anything from private apps beyond the app name. Password managers, Messages, Mail, WhatsApp, Telegram, Signal, Discord, Slack, FaceTime, Photos and Contacts are on the list from the start. You can add any app.
  7. 07
    Anything while paused, or while your screen is locked.
  8. 08
    Incognito windows in Chrome, Brave, Edge and Vivaldi.
Where it lives

One file. Yours.

~/Library/Application Support/DeepWork/deepwork.db

A plain SQLite file. Its permissions are 0600, so only your macOS account can read it. Open it with any SQLite viewer. Nothing is hidden or encoded.

Your controls

In the app, not in a support ticket.

  1. 01
    Pause tracking. Menu bar, the "…" menu: 15 minutes, 1 hour, or until you resume. The menu bar reads "Paused".
  2. 02
    Private apps. Name and time only. Add your own, or restore the defaults.
  3. 03
    Private sites. Not even the domain is kept. The time still counts.
  4. 04
    Window titles expire. 7, 30, 90 days, or forever. Default 30. The hours behind them stay.
  5. 05
    Recording now. Settings shows the exact row being written, live.
  6. 06
    Reset today. Delete all history. Projects and settings stay.
Permissions

Three prompts from macOS, and why.

  1. 01
    Accessibility. Reads the window title and the document a window shows, so hours land on the right project. Without it, time still counts, it just lands in "Unassigned".
  2. 02
    Automation, per browser. Reads the current tab's URL, turns it into a domain, and drops the rest.
  3. 03
    Automation for System Events. Only if you start a lockdown. Hides apps that are not on your allowlist.

Notifications are optional, for the daily summary. Input Monitoring is never requested.

Sharing

The card carries numbers, not titles.

A share card has your totals, your project names, one insight line and the handle you typed. "Post on X" copies the image to your clipboard and opens x.com in your browser. The app uploads nothing.

Shortcuts and tools like Hammerspoon can read one word from DeepWork: your focus phase (idle, warming up, building, deep, peak). Never a title, never a site.

Check it yourself

Four commands. Terminal. Your Mac.

No network connections while the app runs:

lsof -i -a -p $(pgrep -x DeepWork)

prints nothing

The permissions the app is built with:

codesign -d --entitlements :- /Applications/DeepWork.app

one entitlement, for Apple Events. No network entitlement.

No full URL in your own database:

sqlite3 ~/Library/Application\ Support/DeepWork/deepwork.db "SELECT COUNT(*) FROM segments WHERE url != '';"

prints 0

And open the database in any SQLite viewer and look.

The app's build refuses to compile if networking or screen-capture code is ever added. If this policy changes, the date at the top of this page changes with it.