Last updated September 2026.
WoodWright is owned and operated by Marcus Fall, a cabinetmaker, as an individual rather than a company. He is the person who sees anything you send, and the name the Windows installer is signed under. The terms say the same.
WoodWright is desktop software. Rooms, cabinets, cut lists, quotes and client details are files on your own disk, and no account is needed to draw, nest, print, or export. We have no copy of your work and no way to get one.
The app does reach our servers for two things, both plain requests for a public file: checking whether a newer version exists, and fetching the catalog of CNC and finish packs. Neither carries anything about your jobs.
If the app itself breaks and you are online, it sends us a crash report: the app version, your operating system, and the error's technical trace — with user folder names scrubbed before it leaves your machine. Never your jobs, your files, or your numbers. It is on by default so we can fix what broke, and Settings ▸ Privacy turns it off with one switch.
Once a day when it starts, and only if you are online, the app also tells us which version is running: the version number, your operating system, and a random install id it made up on first run. That id is not your account, your shop, or your machine, and it carries nothing about your jobs. When the app updates itself it says so the same way, so an update never counts as a new download. The same switch turns this off.
That same once-a-day message now carries three more things, so we can tell whether anyone is getting any use out of WoodWright at all: the largest number of cabinets you have ever had in one job, the largest number of rooms, and which pages you have opened by their names, such as work, cutlist or draftsman. That is the whole of it. Not a dimension, not a cabinet, not a file name, not a client, not a price — nothing about what you drew, only how far into the program you have been. We added it because fifty people had installed WoodWright and we had no honest way to know whether a single one of them had drawn a wall. The same switch turns this off with everything else.
The app also counts a few kinds of work, as bare numbers: whether you edited a job that day, and how many times you printed or saved a cut list, nested sheets, saved G-code or a DXF, or printed a drawing set, part labels or a shop-floor pack. For G-code it names the machine card you posted for and roughly how many programs, such as one, or two to five; for a drawing set, which preset. A day's counts go up in one small message the next time the app starts. Still not a dimension, a part, a file name, a client or a price.
After you save G-code, the next time you start the app it may ask you once whether that program cut right. Your answer goes to us with the machine card and the app version. Your email, your note and your machine's make, model, year and control software go only if you choose to type them. If you tell us your machine isn't listed, what you type there goes to us the same way. Nothing about the job goes. The same switch turns the counts and the question off.
When you ask for help from inside the app, it opens the support form on this site with a few facts already on it: the app version, your operating system, the page you were on and, while crash reports are on, the last error the app hit, with every file path taken out. The form shows you that line before you send, one click leaves it off, and nothing is filed until you press Send.
Shop Window is a second switch, off unless you turn it on. If you do, once a day for each job you changed it sends the shape of that job — cabinet types and sizes, door and drawer layouts, how each room is laid out, and what any assembly you built is made of — tied only to this install's random number. Never names, customers, addresses, prices, notes or files. It is kept apart from everything else we hold, for thirteen months, and Settings ▸ Privacy turns it off.
The AI render and the Draftsman are optional and off until you sign in and spend a credit. When you use them, one turn goes up: the text of that turn — what you typed, the job context the assistant needs (room notes, the parts it is working on), and the results of the steps it takes.
Before any of it is sent, the app's PII guard runs on your machine and replaces client names, email addresses, phone numbers and street addresses with stable placeholders — [CLIENT_1], [PHONE_1]. The table mapping a placeholder back to the real value stays in the job file on your disk and never crosses the wire; the app puts the real names back on screen for you to read. What the server holds is a transcript with no names in it.
A turn may also carry a picture the app itself drew of your design, so the assistant can look at what it just placed — there is nothing in those pixels that wasn't already going up as text. Photographs and PDFs you attach are off by default, because a photo carries faces, mail on a counter, a name and address in a title block, and no text redactor can reach a pixel.
An account exists only to hold your credit balance. Card details are entered on Stripe's own hosted pages — your card number never passes through WoodWright and we never store it.
There are no ad networks on this site and no tracking cookies. Two things record what happens here, and both are named below: our own event log, and Kicklace, which is our customer-records system. Kicklace loads a script on these pages; nothing else third-party does. Neither keeps a bare tally — each is one record per event.
Each record holds the page you were on, the site you came from, and which family of operating system you are running — Windows, Mac, or Linux. If you arrived through a link we published somewhere — a software directory, say — the tag on that link is kept with the visit, which is how we tell which of those listings actually sent anyone. Those records are strung together by a visitor id your browser generates at random and then keeps, so a visit reads as a visit rather than as scattered hits — and a second visit reads as the same browser coming back rather than as a stranger. It is a random string, it is not a cookie, and clearing your browser storage ends it. Both records use the sameid, deliberately: two ids would mean two half-people, and the point of keeping one at all is to be able to tell a returning reader from a new one.
If you click Download, that id is kept in your browser and stamped on the installer link, which ties the install back to the visit. Both records get the download, with no email address attached, because at that moment we do not have one — which is what lets the release-notes form under the download recognise you as the person who just downloaded rather than as a stranger who typed an address. If you later open a cloud account, we connect the id to that account's internal number. So browsing we first saw as anonymous can end up joined to an account — to an internal number, never to your name or your email.
The support form goes to that same log. Your message travels with it, along with the name and the email or phone you choose to leave — the fields are optional, but nothing you put in them is anonymous. A person reads it and a person answers it.
The wish list goes to that same log as a note: the things you tapped, what you typed, what you use now, your shop's size if you picked one, and an email only if you left one, used to answer you or to tell you something you asked for is in. Like a support note, it is also passed to Kicklace. A person reads it, and nothing in it is published.
The feedback form goes to that same log too, and it is the one place on this site that asks whether we may publish what you wrote. That box is unticked when the page loads. The record holds your note, the name and shop you typed, the email or phone you chose to leave, and the app version if the link you arrived on carried one. If you ticked the box, it also holds the exact sentence you were shown, whether you asked to be named or to stay anonymous, and the moment you ticked it. If you left it unticked, it holds that too — that you were asked, and said no. A person reads it. We publish nothing from this form unless that box was ticked, and if you change your mind afterwards, say so through the support form and we will stop using it.
We do not sell, rent, or trade your data, your job files, or your customers' details to anyone, and we never will. These are every company that touches any part of it, and what each one gets:
How long things are kept. A Draftsman run's working context expires seven days after the run settles, and the gate records behind it after thirty. A finished AI render is stored on our server for ninety days, then deleted automatically. Website analytics events expire after about thirteen months. That figure covers our own log; what Kicklace holds is kept under Kicklace's retention rather than this one, and we would rather say so than let one number stand for two systems. Shop Window snapshots expire after thirteen months. The map that ties a browser's visitor id to an account is kept while that account exists, because it is what keeps your own history yours instead of restarting you as a stranger. Billing records — the credit ledger and the per-turn usage that produced your bill — are kept while the account exists, because they are the record of what you were charged.
Getting your data deleted. Ask through the support form and we will delete the account, its sign-in, and the transcripts held against it.
This sits alongside the terms of use. Both are here to be read before you download anything, not after.