The whole posture, including what we do not claim.
Where is it stored, what covers moving it, who can read it, how do you get it back, how do you make it go away. And what can an AI assistant change without a human agreeing.
The job to be done
A page for the pressure behind the query.
This is a posture page: concrete commitments and honest limits for readers accountable to a data policy.
Wend, measured
92
people from one WhatsApp read, before you grant a single permission.
0.63s
to read 69,000 messages and find the people in them. No model call.
2.4s
for one extraction on the Mac itself, at no cost.
Measured on a real Mac running macOS 26.4.1. On-device extraction needs Apple silicon with Apple Intelligence turned on.
How Wend helps people in the EU and UK
One transfer basis, stated plainly
The raw content Wend reads, message text, imported archives, screen captures, stays on your Mac, in whatever country you are in. What we run for you, the cloud copy of your graph and the account behind it, is covered by the European Commission's Standard Contractual Clauses, Commission Implementing Decision (EU) 2021/914, with supplementary technical measures, and the account layer sits in one US region. Ask for a copy of the clauses at [email protected] and you get one.
Accuracy becomes a link instead of a promise
Article 5(1)(d) asks for personal data to be accurate and current. In Wend every fact links to the email, page, note or recording it came from, nothing is stored until a person confirms it, and two sources that disagree are shown side by side rather than one silently overwriting the other. Every AI inference is recorded, and the log is part of your export.
An AI assistant cannot write to it on its own
Connected agents propose. A proposal is inert until a human approves it, and the agent that proposed it is recorded on the fact. The credential that can propose is never the credential that can confirm, which is the part worth checking in any tool where an assistant touches personal data.
Research runs on your own provider account
If you want public-web background on the people in your graph, you connect your own account with a data provider. The data relationship is between you and them, under their terms, which you can read and leave. We are a tool pointed at your account rather than a reseller of somebody else's data.
The exits work, and they are not a paid feature
Export is self-serve and never charged for: JSON for the graph plus your original files. Deletion hard-purges from the database and object storage inside 7 days. Appear in someone else's graph? The erasure form at /privacy/rtbf is open to you, answered within 30 days.
With Wend, you can
Open the exact email a fact came from when someone asks how you know it
Take everything with you as JSON plus your original files, whenever you want
Delete the account yourself and have it purged inside 7 days
Ask to be removed if you appear in a user's graph and are not a user yourself
The posture, item by item
- Storage
- Raw content, message text and screen captures, stays on your Mac. The graph syncs to a cloud copy Wend manages, and the account layer runs in one US region.
- Transfer basis
- Standard Contractual Clauses, Commission Implementing Decision (EU) 2021/914, plus supplementary technical measures. A copy of the clauses we use is available on request.
- Encryption in transit
- TLS on every hop, from your browser to the database to every provider we call.
- Encryption at rest
- Database and file storage are encrypted at the disk layer. Our infrastructure providers hold SOC 2 Type 2 and ISO 27001 for the layers they run; those are their certifications, and we attribute them rather than borrowing them.
- OAuth tokens
- The Google tokens that let Wend read your mail and calendar get a second layer: AES-256-GCM applied in the application before the token reaches the database, with the key held outside the database entirely.
- Isolation
- Row-level security filters every read and write against the signed-in account, and no AI output for one user can draw on another user's graph.
- Screen reading
- Ambient Mode is off by default and reads the screen, never the microphone. Password managers, secure fields and private windows are skipped, raw captures stay on the Mac, and everything it notices arrives as a proposal.
- On-device AI
- On Apple silicon with Apple Intelligence turned on, extraction and card reading run on the Mac itself. Screen captures are never sent to a cloud model.
- Connected agents
- Each assistant you connect is an OAuth client with its own grant. Agent writes are proposals, never direct commits, and the proposing agent is recorded on every one.
- Training
- No model provider in our stack is permitted to train on your content, and we do not work with vendors who train on customer data. The commitment is published in our privacy policy.
- Selling
- Never. No advertisers, no data brokers, no licensed insights.
- Provenance
- Every stored fact links to its source, and you can open that source from the fact.
- Audit log
- Every AI inference that touches your data is recorded, and the full log is included in your export.
- Your rights
- Access, rectification, erasure and portability apply in full. Hosting location does not reduce them, and your right to complain to your supervisory authority is unaffected.
- Export and deletion
- Export is self-serve and never charged for. Deletion asks for two-factor auth when you have it enrolled, and hard-purges inside 7 days.
- Non-users
- Erasure requests from people who appear in a user's graph go through /privacy/rtbf, and we confirm action within 30 days.
- Subprocessors
- Published at /legal/subprocessors, with what each one processes.
- Independent assessment
- An independent security assessment of our restricted Gmail scope, CASA Tier 2 as part of Google's production verification, is in progress. Not finished.
What we do not claim
- No EU-only hosting. The raw content stays on your Mac, but the cloud copy of your graph is infrastructure we run and the account layer is in one US region under Standard Contractual Clauses. If your review requires hosting that stays inside the EU, we are the wrong fit today.
- No SOC 2 and no ISO 27001 for Wend itself. Those belong to the infrastructure providers underneath us, for the layers they run.
- CASA Tier 2 and Google production verification are in progress, not complete.
- Only the engine is open source. wend-core is published under AGPLv3, so the schema, the write path, provenance and recall can be read and checked. The hosted service around it is not open, and there is no self-host build, so do not treat the AGPL repository as an audit of everything we run.
- Your content is encrypted at rest but not end to end. An assistant has to be able to read what you save in order to be useful, and our Terms say so instead of burying it.
- The assistant you connect is governed by your agreement with its vendor, not by ours. What Anthropic or OpenAI do with a conversation you have with them is between you and them. What we control is that they get only what you asked for and can write nothing without your approval.
- No binding corporate rules and no Article 42 certification. The Standard Contractual Clauses are the mechanism, and they are the only one we rely on.
- We will not guess what your procurement or data protection review needs. Email [email protected] and we will tell you plainly what we can and cannot sign today.
FAQ
Is Wend GDPR compliant?
Compliance depends partly on how you use a tool, so here is the checkable part on our side. We name a lawful transfer mechanism (Standard Contractual Clauses, Decision (EU) 2021/914) and will send you the clauses. We publish our subprocessors. Access, rectification, erasure and portability are supported and never charged for. Every AI inference is logged. Nobody in our stack trains on your content. What we do not do is claim a certification, because we do not hold one for Wend itself.
Do you store data in the EU?
The raw content Wend reads stays on your Mac, in whatever country you are in. The graph also lives in a cloud copy we manage, and the account layer runs in one US region under Standard Contractual Clauses. We do not offer EU-only hosting today.
What is the legal basis for sending my data to the US?
The European Commission's Standard Contractual Clauses, Commission Implementing Decision (EU) 2021/914, together with supplementary technical measures: encryption at rest, application-level encryption of stored OAuth tokens, strict access controls and an audit log. You can request a copy of the clauses we use at [email protected].
What can a connected AI assistant do with my data?
Read what you connected, and propose changes. It cannot commit anything: proposals wait for a human, and the proposing agent is recorded on each one. Tools that let an assistant write directly put an automated system in the position of asserting facts about identifiable people.
Can I use Wend from the UK?
Yes. Our privacy policy covers the EU, EEA, UK and Switzerland under the same Standard Contractual Clauses framework, and your UK GDPR rights are unaffected. If your review specifically needs the UK addendum or an international data transfer agreement on paper, ask before you sign up rather than after, and you will get a straight answer about what exists today.
Are you SOC 2 or ISO 27001 certified?
Not for Wend itself. Our infrastructure providers hold SOC 2 Type 2 and ISO 27001 for the layers they run, which is a real part of the posture but is their certification. The independent assessment we are going through, CASA Tier 2 for the restricted Gmail scope, is in progress and not complete.
Relationship memory built for people in the EU and UK.
It installs on your Mac, builds the graph out of what is already there, and answers from the AI you already use. Every fact keeps its source. $29 a month, flat at any network size.
Access is invite only right now.