User guide

Your data

Where all of this lives, what leaves your machine, and what this build of XataWorks does not do at all.

Two questions, and the second is the one an IT department asks: where does all of this live, and what leaves the machine.

On your machine

XataWorks keeps its state in a directory of its own, named after the application:

PlatformLocation
macOS~/.xataworks/
Linux~/.xataworks/
Windows%USERPROFILE%\.xataworks\

What is in there:

  • Your chats — every conversation, in full.
  • Your agents — their instructions, tools, browser preferences and settings.
  • Your skills — as folders. See Skills.
  • Your connections — their settings, and their credentials.
  • Browser state — bookmarks, history, saved passwords if you opted in, remembered tabs, and the permissions you have granted.
  • The call log, if logging is on.

Deleting that directory resets XataWorks completely. Backing it up backs up everything above, credentials included — treat a copy of it with the care you would treat the credentials themselves.

What leaves your machine

Your conversations go to the model provider. What you type, what the agent reads, and what your tools return are sent to whichever provider you configured, to produce each reply. That is the service doing the thinking, and the arrangement is between you and them — see Getting started.

Page tools act on the sites you are on. When the agent uses one, the action happens on that website, in your session. Nothing about it passes through anybody else.

Connections talk to their own servers. A connection reaches whatever it was built to reach, with its own credentials.

And nothing else. XataWorks has no account system. It makes no requests to any account service, at launch or ever — there is no account to sign in to, no token to store and no subscription to check.

This is a property of how XataWorks was built rather than a setting somebody could switch, which means it is verifiable: an organisation watching this application’s network traffic will see it talk to the model provider, to the sites you visit, and to the connections you added — and to nothing else.

Things worth knowing

  • Skills are plain text on disk. Do not put secrets in one.
  • Saved passwords are opt-in. XataWorks stores a browser password only if you ask it to.
  • A stored credential cannot be read back out of the interface. A token shows as configured; there is no reveal.
  • The call log can be cleared per site or entirely, and logging can be switched off. See Approvals and permissions.

The shape of what is configurable

File ▸ Preferences… opens one window with everything in it, grouped into five headings. Worth scrolling through once, because several of the settings people go looking for are not where they expect.

The Preferences window. A sidebar lists sections under five headings: Account, with AI Providers; Agents & Skills, with Agents, Skills, Add-ons and Variables; Integrations, with Connections and External connections; Browsing, with Browser, Passwords and WebMCP Log; and Advanced, with Folder Watchers and Developer. The AI Providers panel is shown, headed Assistant (interactive): a Default provider selector reading OpenRouter, a Model selector, a note that a Claude command-line tool was detected on this machine, and a second section headed “API keys for automation (agents & scheduled runs)”.
Every section, in one sidebar. A heading is a label rather than a destination — clicking one takes you to the first section beneath it.
HeadingWhat is under it
AccountAI Providers — which provider and model this application runs on, and the stored key agents and scheduled runs use.
Agents & SkillsAgents, Skills, Add-ons, Variables.
IntegrationsConnections — servers you add; External connections — other programs reaching XataWorks.
BrowsingBrowser, Passwords, WebMCP Log.
AdvancedFolder Watchers, Developer.

Two habits the window has, both useful: there is a search box above the sidebar that narrows which sections are offered without changing the one on screen, and closing the window with unsaved edits asks rather than deciding for you.

If you are evaluating this for an organisation

The three claims above are the ones that matter, and all three are checkable rather than promised: the state is in one directory you can look in, the network traffic is to the provider you configured plus the sites you visit, and there is no account service in the picture at all.

What an agent may do on which site is decided per site and per agent, and the record of what it did is in the call log. Those are the two places to point an auditor at.

Back to all user-guide articles.