Privacy Policy

WaxFrame is local-first and designed to minimize the data it handles. This page explains exactly where your data lives, the disclosed Claude relay exception, and what the third-party services you connect can see.

Effective May 25, 2026.

The short version

Local-first, no account database, no tracking

WaxFrame has no account system, document database, analytics, telemetry, advertising, or tracking cookies. The application UI and project state run in your browser. The disclosed Claude relay forwards requests in transit without application-level persistence; third-party AI providers receive the requests you direct to them.

The one piece of data that ever leaves your browser to a service operated by WaxFrame's developer is Claude traffic, which passes through a relay that does not log or store it. That single exception is detailed below.

Frequently Asked

Is WaxFrame self-hosted or air-gap safe?

Yes. WaxFrame is vanilla HTML/CSS/JS with no build step, no application server, and no database — it runs entirely as static files, either from GitHub Pages or from a downloaded ZIP opened directly in your browser (file://). On an air-gapped machine with no internet access at all, the app itself loads and runs fine; you'd only lose the ability to call AI providers, since those requests need a live connection to each provider's API.

Do I need to create an account?

No. There is no WaxFrame account, login, or signup at any point. You bring your own API keys for the AI providers you want to use, and everything else — your projects, documents, and settings — is stored locally in your browser.

Is there a subscription?

No. WaxFrame Pro is a one-time $19 lifetime license, not a subscription — sold once through Gumroad with no recurring charge. The only ongoing cost is pay-as-you-go usage billed directly by whichever AI providers you connect, typically around $0.30 per full hive review.

Do I need my own AI provider API keys?

Yes, for the paid Pro edition — WaxFrame uses API keys you obtain and control yourself. Requests go directly to each provider except Claude, whose requests pass through the disclosed WaxFrame-operated Cloudflare relay without being logged or persisted. The free WaxFrame edition works without API keys using a manual copy-paste workflow.

What WaxFrame stores, and where

Everything stays in your browser

Your API keys, your projects, your documents, your session history, and your preferences (theme, mute, hive setup) are stored locally in your browser using localStorage and IndexedDB. This data is per-browser-profile and per-machine: what you save on your work laptop does not appear on your phone, and clearing this site's browser data removes it.

This local data is not encrypted at rest. Any code or browser extension running in the same browser profile that can read your storage can read it — the same threat model as any site-scoped browser storage. On shared or untrusted devices, use a separate browser profile or clear site data when you finish.

Where your data goes when you run the hive

To the AI providers you choose

When you run a round, WaxFrame sends your prompt and document text from your browser straight to the AI providers you have configured — OpenAI, Google, xAI, Mistral, Perplexity, Cohere, Together AI, DeepSeek, and any custom or server-based endpoints you add. Your API keys are sent only with those requests, only to those providers.

Each provider receives, processes, and handles that data under its own privacy policy and terms — not WaxFrame's. What a provider does with your prompts and documents (including whether it retains them or uses them for training) is governed by your agreement with that provider. Review each provider's policy before sending sensitive content.

The one exception — Claude

Anthropic's API does not currently allow direct browser requests (no CORS), so Claude traffic routes through a small Cloudflare Worker operated by WaxFrame's developer at waxframe-claude-proxy.weirdave.workers.dev(opens in a new tab). The Worker forwards your request straight to Anthropic and does not log or persist your API key or prompt content — but it necessarily sees them in transit while forwarding. This relay exists only to satisfy the browser's CORS requirement; it adds no storage and no analytics.

Every other provider connects directly browser-to-provider with no WaxFrame intermediary.

The AI API Pricing page fetches a small data blob

When you visit the AI API Pricing page on waxframe.com, your browser fetches the latest pricing data from a small Cloudflare Worker at waxframe-pricing.weirdave.workers.dev(opens in a new tab). The Worker returns a JSON blob of provider/model pricing and logs nothing — its source is in the WaxFrame repo at tools/pricing-worker/ if you want to verify. If the Worker is unreachable (you're offline, on an air-gapped network, or visiting from a portable ZIP build) the page falls back to the embedded snapshot that ships with the page and surfaces a banner letting you know.

This is the only page that makes any automatic outbound request on load. Every other helper page is fully static.

Buying WaxFrame Pro

Payments are handled by Gumroad

WaxFrame Pro licenses are sold through Gumroad. Your payment details and purchase information are collected and processed by Gumroad under its own privacy policy — WaxFrame never sees or stores your payment information. After purchase, your license key is stored locally in your browser and verified against Gumroad's license API when you activate Pro. WaxFrame keeps no record of who owns a license.

Hosting

Static hosting on GitHub Pages

The WaxFrame site is served as static files via GitHub Pages at waxframe.com. As with any web host, GitHub may record standard technical request data (such as IP address and user agent) in its own server logs under GitHub's privacy practices. WaxFrame adds no tracking on top of this and receives none of that log data.

Your control

You hold all of it

Because your data lives only in your browser, you control it completely. Clear this site's browser data to erase everything WaxFrame has stored locally, including your saved API keys. Revoke an API key at the provider's console at any time to cut off access. WaxFrame is fully open source under AGPL-3.0, so every claim on this page is independently auditable in the source.

Children

WaxFrame is a developer/productivity tool and is not directed at children under 13. WaxFrame has no account, document database, analytics, or telemetry; data sent to configured providers and the Claude relay is described above.

Changes & contact

If this policy changes, the effective date above will be updated and the change will appear in the public repository history. Questions or concerns? Open an issue on GitHub(opens in a new tab) — that is the contact channel for WaxFrame.

See also the Terms of Use and the full API Key Guide for the technical disclosure on key storage.
↑ Back to top

Open Source & Privacy

WaxFrame is fully open source under the AGPL-3.0 license. Every line of code is public and auditable.

Local-first WaxFrame has no database or app server. Everything runs in your browser. Your documents and session data live in your browser only — they never sit on a WaxFrame server because there isn't one.
No Tracking No analytics, no telemetry, no cookies, no accounts. Nothing is tracked.

Read the full Privacy Policy and Terms of Use, or read the source on GitHub(opens in a new tab)

WaxFrame

About

Version
LicenseAGPL-3.0 — open source, free to use and modify with attribution. Read license(opens in a new tab)
AuthorR David Paine III — weirdave.com(opens in a new tab)
TestingCandy
StackVanilla HTML, CSS, JavaScript — no framework or install required; no account or document database.

Built with ❤️ by WeirDave and Claude.

WaxFrame Pro

Enter your license key to continue.

Don't have a key? Buy WaxFrame Pro(opens in a new tab)

Manage License

Your WaxFrame Pro license is active.

••••••••-••••••••-••••••••-••••••••