What it installs, what it connects to, where it keeps things
The facts a firm's IT or security reviewer asks for before a lawyer may try Continuation Drafter, on one page that prints cleanly. Each is stated for the current release and linked to where it is shown in more detail.
What is installed
- One program. A macOS app, or a single command-line binary for macOS, Windows or Linux. No installer runs, no administrator rights are needed, and nothing is added to startup.
- No service and no background process. While it is open it serves its own interface to your browser on 127.0.0.1, this computer only, and it stops when you quit it.
- Signed. The macOS app and binaries carry an Apple Developer ID signature and are notarized by Apple; the Windows binary is Authenticode-signed with Geeks in the Woods as the verified publisher. For the first days of a new release Windows may still say the file isn't commonly downloaded and preselect Delete, because Windows scores reputation per release, separately from the signature; the publisher line is the check. The download page shows how to check both.
Every network connection it makes
This is the complete list for the current release. It is checked against the program's source on every change, so a connection added later cannot ship without this list growing first.
| Connection | When | Goes to |
|---|---|---|
| Drafting and scoring, through the model server you run | Every run | Ollama on this computer by default, or an OpenAI-compatible server you started. Local traffic only, unless you point it at another machine. |
| Asking that server to download a model | Only when you press Pull | Your model server, which fetches the model from its own registry |
| Drafting and scoring through the provider you chose | Only if you set up a remote provider with your own key | OpenRouter, OpenAI, Anthropic. The provider also answers two small requests: a model's context window, and its list of models for the picker. |
| A check for updates, and the download of the new release | Only when you press Check for updates, or run update |
GitHub's public releases page for this program. The request carries nothing about you. A release is installed only after its signature, its checksum and, on a Mac, Apple's signature all verify. |
| Licence renewal | Only with a paid licence, near its expiry. No licence is on sale at present, so today this call is never made | The licence server, sending the key's ID, its token and the program's version, and nothing else |
| A check whether it is already running | On launch | 127.0.0.1, this computer only |
Nothing else. The tool sends no telemetry, no analytics and no crash reports. The offline mode in Settings refuses the update check and the licence renewal. It does not block a remote provider you have chosen yourself: to keep a specification on the computer, use a model on the computer. Using your own provider key covers that choice.
Where it keeps things
- One folder in your home directory,
.continuation-drafter. Nothing is written anywhere else, except files you export yourself. - Settings, and any provider key you save, in
config.jsonthere, readable only by your user account on macOS and Linux (mode 0600). A key can instead come from the environment and never be written at all. - Matters, each a file in the
mattersfolder there, readable only by your account (files 0600 in a 0700 folder on macOS and Linux). - The trash is deleted after a number of days you set, 30 unless you change it.
Providers, and what they keep
Only relevant if you choose a remote provider. Whether one is acceptable for a particular matter is the practitioner's judgment and depends on facts we do not have, such as the engagement terms and the provider's own contract.
| How it runs | What is kept |
|---|---|
| A model on your own computer | Nothing leaves the computer, as long as the model server runs on it too. The specification goes only to that server. |
| Claude through OpenRouter | Anthropic keeps no prompts or answers by default, except on its Fable and Mythos models, which it keeps for 30 days for safety monitoring. The tool also asks for a prompt cache, which holds the start of each prompt, mostly the specification, in memory for up to an hour after its last use. |
| Claude with your own Anthropic key | No prompt cache: the Anthropic endpoint this tool uses does not support one. Otherwise as above: nothing kept by default, except on Fable and Mythos models, kept for 30 days. |
| OpenAI, with your own OpenAI key | The tool asks for the shortest prompt cache OpenAI offers, which depends on the model: minutes on older models, up to 24 hours on gpt-5.5, and 30 minutes after last use on gpt-5.6 and later. OpenAI says cached data may be kept encrypted in GPU-local storage. |
| OpenAI models through OpenRouter | OpenRouter does not pass the cache setting on, so OpenAI's own default for the model applies. |
| Other models through OpenRouter | The model runs on whichever host OpenRouter chooses, and that host's policy decides what it keeps. One question can reach more than one host: in a test, four calls about one specification went to four different companies. |
How a download can be checked
- Apple Developer ID signature and notarization on the macOS app and binaries.
- Authenticode on the Windows binary, publisher Geeks in the Woods.
- A
checksums.txtcovering every file in a release, itself signed, which is what the update check verifies before installing anything. - A software bill of materials for every binary, published beside it.
This website
This site uses Cloudflare's web analytics: page views, page timings, and coarse data such as country and browser. It is cookieless, it does not fingerprint your device, and it builds no profile across visits or across sites. The website and the program are separate: no specification and no draft ever reaches this site, and the binary you download makes no analytics call of any kind.
Questions from a review that this page does not answer: [email protected]. More on confidentiality in the FAQ.