Legal
Privacy Policy
Last updated August 14, 2026
The short version
Your relationship graph is a file on your Mac. Wend for Mac keeps it in an encrypted database that the app unlocks with a key held in your macOS Keychain. Wend Labs does not hold that database and cannot read it.
What reaches us is your account and billing record, one row that tells us where to route an agent's request, and usage counters you can turn off. If you turn on the optional cloud, that copy of your graph facts lives in a Cloudflare account you create and own, and we route queries to it when your Mac is off. We never sell your data and we never train models on it.
Who we are
Wend (the “Service”) is operated by Wend Labs Inc., a Delaware corporation (“Wend,” “we,” “us”). You can reach us at [email protected].
Where your data lives
On your Mac
The people you save, the organizations, the links between them, every detail, every note, every promise, the source recorded on each fact and the audit entry recorded on each AI inference all live in one database on your own machine. It sits inside an encrypted container that the app unlocks at launch with a key stored in your Keychain. The key travels between your own devices through iCloud Keychain and is never sent to us.
You choose where your brain lives when you install the app, and you can change it later in one click.
Option one: cloud, with local sync
Your Mac stays the source of truth and answers instantly. A copy of your confirmed facts is kept in a Cloudflare account that you create and own, in a database (D1) and a small open-source proxy that the app deploys there for you. The scoped Cloudflare API token used to deploy it is held in your Keychain and is never transmitted to Wend Labs. When your Mac is off, an agent asking a question is routed by us to that copy so your brain still answers.
Three things about that arrangement, because they decide what it actually protects:
- The copy is not encrypted in a way that puts it beyond reach. Cloudflare, as the company running the database, can technically read it. We do not offer end-to-end encryption on this path and this page will never say otherwise.
- We are in the query path. When your Mac is off, the question an agent asks and the answer it gets pass through our router in memory so it can reach your deployment. We do not store them.
- What ownership means here is concrete: the account is yours, the database is yours, the bill is yours, and you can revoke our token, switch the cloud off, export the copy, or delete it, unilaterally, with the product still working on your Mac.
Option two: this Mac only
No copy is created anywhere. Only agents running on that Mac can reach your brain, and web agents get a single status response explaining that. You handle your own backups, which is why the app writes an encrypted backup file during setup and keeps it current.
What never reaches us
Wend for Mac reads your sources on your machine and stores only the facts it extracts. Two things are outside that: mail and events from a connected Google account, which we read on our servers, and a conversation you choose to send for a deep read.
Apart from those two, the following stay on your machine:
- Message text from WhatsApp, Messages, or any chat you import.
- The contents of the local databases the app reads, and the contents of any file, archive, PDF, image, audio, or video you drop into it.
- Your contacts and calendar as they exist on your machine.
- The encrypted graph database itself.
The list of hosts the app is allowed to contact is published, and the app contacts nothing else, so this is a claim you can check rather than one you have to accept.
What we do hold
Account information
You sign in with Google, so we hold your email address and the federated identity Google returns. If you turn on two-factor authentication we hold a time-based secret that lets us verify your codes. If you subscribe, our payment processor records your billing details on their side; we never see or store full card numbers.
One directory row per install
So that one unchanging link works from any agent, we keep a small routing record: which install belongs to which account, where to send a request right now, when we last heard from it, and when access tokens were issued or revoked. It carries no graph content.
Usage counters
The app reports a short list of counters: whether a step of setup completed, whether an agent connected, which deployment option is in use, and how large a graph is as a bucket rather than a number. No names, no facts, no free text. You can switch this off in the app, and when you do we record nothing rather than recording a zero.
Pages your agent publishes
When you or your agent create a booking link, a shared meeting brief, an intro page, or a profile card, the app sends us the small payload needed to render that page, and we serve it so the link works while your Mac is shut. Those payloads carry only content written for the person receiving the link. They never carry source text, provenance chains, or facts about anyone else.
Website and support
We log basic operational information for trywend.io: IP address, browser user agent, route accessed, response code, request duration. We use a product analytics tool on the website; the only personal identifier shared with it is your account UUID. We do not record session replays and we do not use advertising trackers. Mail you send us is kept with the thread it belongs to.
What we can see, and what we cannot
| Thing | Cloud, with local sync | This Mac only |
|---|---|---|
| Raw messages, mail, contacts, calendar bodies | Read on your Mac. We never receive them. | Read on your Mac. We never receive them. |
| Confirmed facts and provenance | Copied to your own Cloudflare database. | Held only on your Mac. |
| Cloudflare, the company | Can technically read that database. | No relationship. |
| Wend: usage counters | Yes, and you can switch them off. | Yes, and you can switch them off. |
| Wend: questions a web agent asks and the answers | Pass through our router in memory. Not stored. | Never. No route exists. |
| Anyone you send a link to | Sees the page you published. | Sees the page you published. |
When AI is involved
Reading a transcript and deciding who is in it happens on your Mac. The heavier reasoning happens in the AI agent you already use, under your own account with that provider and their terms, which is why the price of Wend does not change with how much you ask it.
Where Wend needs a model of its own, it is for turning a short piece of text, such as a name, a role, or a company, into the numeric vector that makes search work. Only that short text is sent, to a US-hosted provider contractually barred from training on it. Raw message text, mail bodies, and file contents are never sent. We do not use vendors who train on customer data.
Every fact an agent proposes about you or someone in your graph records where it came from, and any write that would rewrite who someone is waits for you to confirm it. Conflicting facts are shown to you, never resolved silently.
Connected accounts (Google, etc.)
When you connect Gmail, Google Calendar, or Google Contacts, the app on your Mac holds the tokens you authorize and calls Google directly. The mail and calendar content that comes back is read there, and the facts extracted from it are written to your local graph. That content does not pass through Wend Labs.
Specifically for Google APIs:
- We use Google data only to provide the Wend features you opted into: pre-meeting briefs from your calendar, event creation that you initiate, and identifying who you already meet with so the graph stays current.
- We do not transfer your Google data to third parties, do not use it for advertising including retargeting or personalized advertising, and do not let anyone on our side read it except where you explicitly grant permission to debug an issue you reported, where we are legally required to, or where it is necessary for a security investigation.
- Wend's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- You can revoke access at any time from inside the app or directly at myaccount.google.com/permissions. When you do, the app deletes the stored tokens and stops syncing.
Calendar event creation uses the calendar.app.created scope, which only allows Wend to modify events that Wend itself created. We never read, modify, or delete events created by you or by another app.
For Gmail specifically, Wend reads your mail to identify the people you correspond with and the commitments you make, and it drafts and sends individual messages that you write or approve. Every message goes to one named recipient from your own address and appears in your own Sent folder.
Wend does not provide email warming, deliverability warm-up, or inbox reputation services, for Google accounts or any other provider. Wend has no mailing lists, no sequences, and no bulk sending, and is not used to distribute unsolicited commercial email. Wend also does not provide a leads database and does not source contacts for you: every person in your graph comes from your own mail, calendar, and contacts, from files you give it, from pages you capture yourself, or from manual entry. Wend never adds a person you did not bring.
AI assistants you connect
You can point AI assistants you already use (Claude, ChatGPT, Cursor, and any other MCP client) at your brain. An assistant running on the same Mac reaches the app over a local socket, and no network is involved at all. An assistant running on the web is routed by us to your Mac while it is awake, or to your own cloud deployment when it is not, and the answer says which one served it.
Connecting an assistant means that assistant's operator processes whatever your conversations with it touch, under that operator's own privacy terms. Wend sends a connected assistant only what it asks for, scoped to your account. Every connected assistant is listed in the app with what it has done, and you can revoke any one of them on its own.
The browser extension
Wend for Chrome captures people and profiles from pages you open, in your own browser and your own session. It talks to the app on your Mac over Chrome's native messaging channel and to nothing else. It holds no Wend credential, declares no permission that reaches a Wend server, and posts nothing to us. Captures land in your local graph as proposals with the page URL and timestamp recorded as the source.
Research on your own provider account
Wend can fill in public background about people already in your graph (current role, past roles, location, education, each with a source). This runs on a research provider account that you create and hold yourself (Bright Data today), which keeps the data relationship between you and them. The app holds the key you provide on your Mac and uses it only when a lookup you asked for runs. When a lookup runs, the profile being looked up is sent to your provider under your account and their privacy terms.
Facts that come back arrive as proposals with their source attached. Disconnecting the provider deletes the key outright; facts you already approved stay, because they are yours.
Sharing
We share data only in three narrow situations:
- With the vendors that run our own infrastructure (accounts, payments, transactional email, hosting, analytics, and the embedding model described above). Each is bound by a data processing agreement, processes data only on our instructions, and is listed on our subprocessors page.
- To respond to a valid legal demand from a competent authority, after reviewing it for scope and pushing back where appropriate. A demand for your graph is one we cannot satisfy, because we do not hold it.
- If we ever sell or transfer the company, your account moves with the Service under the same terms.
Your own Cloudflare deployment is not on that list, because it is not our infrastructure. You contract with Cloudflare directly, under their terms, in an account you control.
Your rights
Anywhere in the world, you can:
- Export everything, from inside the app, in JSON, CSV, and vCard. It reads a local file, so it works offline and it works after you stop paying.
- Edit or delete any individual record from inside the app.
- Delete your graph by deleting it in the app, which removes the local database and, if you turned the cloud on, the copy in your Cloudflare account.
- Delete your Wend Labs account, and with it the account, billing, directory, and counter records described above, from your account page or by writing to [email protected]. Once you confirm, we purge those records within seven days.
- Ask us anything, including who reads what and when, at [email protected].
If you live in the EU you have additional rights under GDPR, including the right to object, the right to portability, and the right to lodge a complaint with your local supervisory authority. If you live in California you have the rights described in the CCPA. We honor both, regardless of where you live.
Who decides what: roles
For your account, billing, the directory row, security logs, and the website analytics above, we decide the purposes, so we are the controller.
For the contents of your graph, you decide who goes in, what is recorded, and what gets researched, so you are the controller. Most of the time we are not a processor of it either, because it never reaches us. Where it does reach us, which is the routing path when your Mac is off and the payloads behind pages you publish, we act as your processor on the terms in our Data Processing Addendum.
The practical consequence: because you chose what to collect, the rights the people in your graph have run against you, and the app gives you search, correction, export, and permanent deletion at no charge so you can honour them without asking us. If one of them contacts us instead, we will pass the request along rather than reaching into your machine.
People in your graph
Wend lets you store information about other people. If someone you have saved asks us to remove their information, they can submit a form at trywend.io/privacy/rtbf. We will remove what we hold, and there is a real limit worth stating: graphs live on customers' own machines, so we cannot search them and cannot delete from them. What we do is notify the customer, who has the tools to act, and tell the requester what we did.
Retention
We keep your account for as long as you want it. There is no automatic purge schedule, because an automatic schedule means somebody loses a graph they thought was safe.
If a subscription lapses, the app enters Archive Mode: your graph remains where it is, readable, searchable, and exportable, and your cloud copy remains in your own Cloudflare account. Nothing is deleted for non-payment, and nothing is deleted for inactivity. Deletion happens on your explicit request only, in the app or by writing to [email protected], after which we purge what we hold within seven days, keeping only what the law requires, such as invoices. Operational logs are retained for at most ninety days.
Where our own records sit
The account, billing, directory, and counter records described above are stored in the United States, encrypted at rest and in transit. You choose the region of your own cloud database when the app deploys it, so if residency matters to you, it is your choice to make rather than ours.
If you are in the EU, EEA, UK, or Switzerland, our records about you are transferred to and stored in the United States. We rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), together with supplementary technical measures, as the legal transfer mechanism. You can request a copy of the clauses we use at [email protected]. This does not reduce the rights you have under EU law.
Cookies and your choice
On your first visit to trywend.io we ask before measuring anything. Nothing optional loads until you answer: no analytics script is added to the page, no analytics cookie is set, and no request leaves your browser for one.
Essential cookies keep you signed in, keep your session secure, and remember the consent choice itself. They cannot be turned off, because without them the website does not work.
Analytics cookies record which pages get visited and which buttons get clicked, against a random identifier. They never carry anything from your graph. We do not sell or share this data and we do not use it for cross-context behavioural advertising.
If you are in the EEA, the UK, or Switzerland, analytics stays off until you switch it on, and refusing takes one click on the first screen. Elsewhere analytics is on by default and you can turn it off on that same screen or at any time afterwards. Clearing your cookies resets the question.
Children
Wend is not intended for anyone under sixteen. We do not knowingly collect data from children. If you believe a minor has signed up, write to us and we will delete the account.
Changes
We may update this policy as the product evolves. When we do, we will post the new version here and update the “Last updated” date at the top. If a change is material, we will email you at least thirty days before it takes effect.
Contact
Questions, concerns, polite disagreements, all welcome at [email protected].