Local-first, privacy and security
Watcher is designed to run entirely on your own machine.
No telemetry
Watcher has no telemetry, analytics, crash upload, update check, or Watcher-operated cloud service. Nothing about your project or runs is sent to Elixir Nexus. Your tests may still make their own network requests.
Local-only dashboard
- The server binds to the loopback interface (
127.0.0.1) only. It is not reachable from other machines on your network. - Both
http://127.0.0.1:<port>andhttp://localhost:<port>work. - Requests with a foreign
Hostheader, or from a browser page on another origin or port, are rejected.
These checks protect against other websites in your browser. They are not authentication: other programs running on your own computer can still reach the local server.
Your project files
Watcher does not modify your package.json, lockfile, Playwright configuration, tests or .gitignore. It does not write temporary configuration into your project.
Watcher writes only:
.watcher/watcher.dbin your project root, for run history.- Temporary directories in your operating system's temp folder, for test collection and Playwright Tools sessions.
Playwright itself still writes its normal configured outputs.
What run history contains
History stores run metadata, the run recipe, final per-test results, and references to reports and artifacts. It does not store console logs, raw error messages or stack traces, environment variables, report or artifact contents, or Codegen output.
Test names and titles are stored as written. Watcher does not detect secrets in titles, so avoid putting secrets in them.
Report and artifact contents
Where content access is available (see Reports and artifacts), Watcher reads only files referenced by a recorded run, and only inside your project. It refuses links and unsafe paths, sends files as downloads, and never renders HTML. Content is not cached or uploaded.
Watcher is not a filesystem sandbox. A deliberate, concurrent change to files by another process running as your user may not be detected. Artifacts can contain credentials or personal data, and Watcher does not redact them.
Reporting a security issue
Email security issues to support@elixirnexus.dev. Do not post vulnerability details, credentials or other sensitive technical information on Discord. See Support and feedback.