Skip to main content

Local-first, privacy and security

Watcher is designed to run entirely on your own machine.

No telemetry​

Watcher has no telemetry, analytics, crash upload, update check, or Watcher-operated cloud service. Nothing about your project or runs is sent to Elixir Nexus. Your tests may still make their own network requests.

Local-only dashboard​

  • The server binds to the loopback interface (127.0.0.1) only. It is not reachable from other machines on your network.
  • Both http://127.0.0.1:<port> and http://localhost:<port> work.
  • Requests with a foreign Host header, or from a browser page on another origin or port, are rejected.

These checks protect against other websites in your browser. They are not authentication: other programs running on your own computer can still reach the local server.

Your project files​

Watcher does not modify your package.json, lockfile, Playwright configuration, tests or .gitignore. It does not write temporary configuration into your project.

Watcher writes only:

  • .watcher/watcher.db in your project root, for run history.
  • Temporary directories in your operating system's temp folder, for test collection and Playwright Tools sessions.

Playwright itself still writes its normal configured outputs.

What run history contains​

History stores run metadata, the run recipe, final per-test results, and references to reports and artifacts. It does not store console logs, raw error messages or stack traces, environment variables, report or artifact contents, or Codegen output.

Test names and titles are stored as written. Watcher does not detect secrets in titles, so avoid putting secrets in them.

Report and artifact contents​

Where content access is available (see Reports and artifacts), Watcher reads only files referenced by a recorded run, and only inside your project. It refuses links and unsafe paths, sends files as downloads, and never renders HTML. Content is not cached or uploaded.

Watcher is not a filesystem sandbox. A deliberate, concurrent change to files by another process running as your user may not be detected. Artifacts can contain credentials or personal data, and Watcher does not redact them.

Reporting a security issue​

Email security issues to support@elixirnexus.dev. Do not post vulnerability details, credentials or other sensitive technical information on Discord. See Support and feedback.