xpsflow

Privacy

This site is a static website and a browser application. It is built to keep your data on your machine.

The browser workbench

The workbench at /app/ runs the complete xpsflow pipeline inside your browser using WebAssembly. Files you drop onto it are read into the page's memory and processed there. They are never uploaded: the page makes no network request that carries your data, and the site's Content Security Policy only allows the page to connect to its own origin for the application files it needs. Closing the tab discards everything. Reports you open are generated in the browser and shown from a temporary in-memory address.

What the site records

The site collects no personal information, sets no cookies, and runs no analytics or advertising scripts. It is hosted on Cloudflare Pages, which, like any web host, keeps standard server logs (such as the requesting IP address, the requested path and the time) for operating and securing the service under Cloudflare's privacy policy. The site's own code has no access to those logs beyond aggregate traffic counts.

The local install

When you install xpsflow on your own computer, everything runs locally. The optional assistant sends your typed requests and compact tool results (never raw spectra) to whichever model endpoint you configure; a local model keeps that on your machine, and a hosted one is governed by that provider's terms. The Model Context Protocol server runs on your machine and only reads the directory you point it at. The security documentation describes exactly what leaves the machine and when.

Changes

This page changes only when the site's behavior changes, and the change is recorded in the repository's history on GitHub.