Wend.
ProductPricing
Sign inGet access

Security & privacy

Your memory stays yours.

Wend holds the people in your life and what they told you, and Wendy can act on it. So this page is the exhaustive answer to two questions: who can reach it, and who can send anything.

Three commitments

  • 01

    We never train on your data. Not our models, not anyone’s. Our model providers are contractually barred from training on your content, and the commitment is a term of our Terms of Service.

  • 02

    Your graph is one person’s memory. Never pooled with anybody else’s. No AI output for one user can draw on another user’s graph.

  • 03

    We never sell your data. No advertisers, no data brokers, no licensed ‘insights’.

The write path is the security model

You do not control which model runs this month, or what a web page said to it mid-task. So the guarantee is structural: there is no code path from an agent call to a committed fact.

Every fact has a source, and you approved it.

How data moves through Wend, from the sources on your Mac to the agents that ask about them.
1731READ ON THIS MACCONNECTED IN THE CLOUDGOOGLE WILL NOT HAND DATATO A LAPTOP, SO WE READ THESEYour MacBookWEND.DB · THE ONLY COPYWend serversREAD YOUR MAIL · CAN ONLY PROPOSEYour cloud copyA CLOUDFLARE MIRROR RUN BY WEND · YOUR MAC KEEPS THE ORIGINALThe Wend routerONE LINK, WHEREVER YOU AREYOUR AGENTSOR ANYTHING ELSE THAT SPEAKS MCPWHERE A MODEL READS YOUR CONTENTOur model, automatically: mail and calendar from a connected Google account areread on our servers and turned into proposals.Our model, when you ask: one conversation you pick, priced before it runs. Thebulk import sends nothing, ever.Your model, through the Mac app: its message tools hand raw lines to the agentyou run there, so that content goes to your agent's provider, not to us.The model on the Mac itself: with Apple Intelligence, Ambient Mode and cardscans extract on-device, and that raw text never leaves the machine.names, dates and the wordsincluding mail bodiespush · the only write keypropose onlyquery · read only keyMCP · reads, never writes

How agent writes are governed

  • You approve every agent write

    Any agent you connect can only propose. Nothing it writes is saved until you confirm it, on any surface. Sources you pick yourself on your Mac are the other case: you choose the source, you see its count, it lands, and one click takes the whole import back out.

  • Prompt injection can only make a proposal

    Instructions hidden in a page or a document arrive as a line on your review page, with the agent that made it named and the source it claims attached. Untick it and it is gone.

  • Every write arrives attributed

    Which assistant proposed it, in which session, and the email, page, note or transcript it came from. Click any claim in your graph and see where it came from. When several agents share one memory, knowing who asserted what is the difference between a record and a rumor.

  • Conflicts are surfaced, never auto-resolved

    When two sources disagree about a fact, Wend shows you both and you decide. It never silently overwrites what you approved, and every AI inference that touches your data is logged in a trail you can browse.

  • Agents are revoked one at a time

    Account → Agents lists every assistant, Mac, browser and key holding a credential. Revoke one and it stops on its next request, while the rest keep working.

  • Four permissions, granted one at a time

    Read asks about your network and changes nothing. Propose files a proposal you confirm. Draft writes words that do not leave. Send asks for a send and confirms one. They are separate grants, so an assistant you want reading and never sending gets exactly that: it does not see the send tools in its own list, and asking anyway is refused by the server with the permission it would have needed. The check is on the credential, never on a hint in a tool description.

  • Deletion is never delegated

    No agent can delete anything. Removing people, facts or your whole account is yours alone.

What Wendy may do, and what she may not

  • She acts as Wendy, on your behalf, and never as you

    She signs her own name on every surface, says so if somebody asks whether they are talking to you, and never writes under your name. This is checked on what the model actually produced, not only requested in its instructions: a line claiming to be you is refused before it is sent. There is no mode that sends under your identity and none is planned.

  • You read the words before they go

    Anything leaving for another person is shown to you exactly as it will arrive, and it goes only after you say so. Editing a draft produces a new preview, because an approval has to be of the words that actually go out rather than of an earlier version of them.

  • A text is a draft you send yourself

    For iMessage, Wendy writes the words and sends you a link. You open it, read them, edit them if you want, and one tap hands the message to your own Messages, on your own thread and your own number. Wend never sends an iMessage for you. The link is single-use, short-lived and bound to that one message, so a forwarded link sends nothing.

  • Where she reaches you

    Telegram and email, and neither needs an install. There is no voice, phone or SMS surface, and WhatsApp is not a channel she uses. She connects to Telegram from a one-time link in your account, so a stranger’s chat cannot reach your graph.

  • Instructions inside content are never authority

    Wendy reads mail, messages and pages that other people wrote. Nothing in that content can authorise a send. A request to act has to come from you, on a surface you connected, and the send still waits for your confirmation.

  • Every act is on the record

    What she did, where it went, what came back and whether you approved it are kept against the relationship, in the same ledger you can read in the app.

What reading looks like on your Mac

  • Extraction runs on the machine

    Wend reads WhatsApp, Contacts, Calendar, iMessage, Apple Mail and Granola notes where macOS already keeps them, and works out the people and facts there. The bulk import sends none of your messages to a model. The one exception is a conversation you choose to have read in depth, which is priced before it runs.

  • Your Mac’s own record of who you talk to

    Behind the permissions your Mac already has sit stores almost nothing reads: call history, the message and call donations macOS keeps for Siri and Spotlight, notification history, and the related names in your Contacts. Wend reads them in place, on macOS 13 through 26, working out the shape of each store when it opens it rather than assuming one version. What it keeps from them is who, when and how often.

  • Reading the words is tiered, and it runs here

    A cheap pass runs on every item on this machine. A model on the chip runs on the slice that deserves one, when Apple Intelligence is available and the Mac is not hot, on battery or out of its daily budget. Anything skipped is queued with the reason rather than dropped. That pipeline has no cloud lane: message and mail bodies are not sent to a cloud model by it.

  • Each source is a switch

    Nothing is read until you turn it on. WhatsApp needs no permission from macOS, Contacts and Calendar ask once, and iMessage needs Full Disk Access, which macOS will not offer to grant on its own and which never blocks setup.

  • Your calendar is read here, and never written

    Connect a Google calendar in the Mac app and this machine reads it directly, on a read-only connection: Wend cannot create, move or cancel an event. The entries it caches stay here the way message bodies do, so a description and a location never leave the Mac. What reaches your graph is the meeting, its time and the people who were in it.

  • Ambient Mode reads the screen, never the microphone

    Turned on, Wend reads the window you are working in through macOS accessibility and remembers the people in it, with the app, window and page URL as the source on every capture. It never listens and never records. Password managers are never walked, secure fields and private windows are skipped, the raw text stays on your Mac, and everything it notices arrives as a proposal you confirm. Off by default, one click to pause.

  • Extraction can run on the chip itself

    On Apple silicon with Apple Intelligence, Wend extracts facts, reads business cards and builds briefings on the Mac itself. Bigger jobs route to the cloud; the sensitive raw never does.

  • The extension reads the page you are on

    It works inside your own logged-in session and captures only the page you asked it to capture. It never sees a password, and it does not watch your browsing.

What we can see

  • Your account and your billing

    Your email, your subscription state, and the invoices Stripe holds for it. Those records sit on our own infrastructure, in a single US region (Northern Virginia).

  • One directory row per install

    So that one unchanging link can find your graph, whichever way you deployed it. It says where to route, not what is in there.

  • A heartbeat, unless you turn it off

    On first launch, when setup finishes, and once a day on open, Wend reports its version, your Mac’s architecture and OS version, how far through setup you are, and which SIZE BAND your graph falls into. Never a count, never a name. There is a switch that stops it.

  • Google mail and events, and any deep read you ask for

    Your chat databases and archive contents stay on your Mac. Mail and events from a connected Google account are read on our servers, and so is one conversation you pick to have read in depth, priced before it runs. A calendar connected in the Mac app is read there, not here.

  • A day too big to plan here

    Planning runs on your Mac whenever the day fits the model on the chip. A bigger day is solved on our servers, and what travels is the shape of it: free windows as clock times, your task summaries and your own preference sentences. Never a meeting title, never an attendee, never anything else a calendar entry holds.

  • Your cloud copy

    Setup provisions a managed Cloudflare mirror that Wend runs, and Wend is in the query path: it is how your agents read your graph when the Mac is closed. It is not zero-knowledge, so Wend and Cloudflare can technically read a mirror we host. Message bodies, screen captures, cached calendar entries and other raw content are never copied to it. Some earlier installs keep their mirror in their own Cloudflare account instead, where only Cloudflare could.

  • The encrypted vault, and its index

    Raw content you back up sits in our object storage as ciphertext we hold the wrapped key for, not as text we read. We also hold its index: which source a blob came from, which month it covers, how big it is and how many items it holds. That index is how a second Mac finds your archive without listing the whole store, and it is metadata about your data rather than the data.

  • Questions your agents ask the web

    Public-web research is routed through us to the provider on your key. The provider sees the name or profile URL being looked up, never your graph and never the other people in it.

  • GDPR-aligned via SCCs

    For users in the EU, EEA, or UK, transfers of that account data to the US are covered by the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914) plus supplementary technical measures. Access, correction, deletion and portability apply in full.

Encryption, and the key you bring

  • Your graph is a file only you can open

    It lives in Wend’s own folder on your Mac, which macOS keeps readable only by your user account. With FileVault on, the disk under it is encrypted too.

  • Your raw archive is encrypted before it leaves

    Message and mail content backed up to Wend’s cloud vault is encrypted on your Mac first, with a key wrapped for your account rather than held in the open. The honest sentence, and the one we hold ourselves to: encrypted at rest and unlocked by your login, readable only by you and the agents you authorize. Not ‘we can never read it’, which would be a claim about our own architecture that you have no way to check.

  • Encrypted in transit

    TLS on every hop: your Mac to us, us to your cloud copy, and us to every provider we call.

  • AES-256-GCM on tokens and provider keys

    The Google tokens that let Wend read your mail and calendar, and any research-provider key you connect, are encrypted at the application layer, with the key held outside the store entirely.

  • Encrypted at rest, not end to end

    Content Wend reads is encrypted at rest. It is not end to end encrypted, because an agent has to be able to read it. Our account, billing and directory records sit on managed infrastructure with disk-level encryption, and row-level policies filter every read against the signed-in account.

  • Research runs on your account, not ours

    Filling in what someone does now, where they are, and where they worked before runs on a data-provider account you create and hold, such as Bright Data. You paste the key once. You agree to the provider’s terms directly, you see what they charge, and you can revoke the key or leave with the account.

Account controls

  • Full export, always

    The app writes your whole graph to a JSON file on demand, read from the database on your Mac. It works offline and it keeps working if you stop paying.

  • Two-factor on deletion

    Account deletion asks for your second factor whenever you have 2FA enrolled, because the operation that destroys your graph deserves the strongest gate you have set up. Export requires your signed-in session.

  • Self-serve deletion

    Delete your graph in the app and it is gone from your Mac and from your cloud copy. Delete your Wend Labs account and we hard-purge the records we hold within 7 days.

  • Right to be forgotten, including for non-users

    If you appear in a Wend user’s graph and want out, submit a request at /privacy/rtbf. We remove what we hold, notify the customer, who has one-click tools to remove you, and write back within 30 days. We cannot search or delete a graph on someone else’s machine.

Check it yourself

The engine that stores and governs your graph, the schema, the propose-and-confirm write path, provenance and recall, is open source under AGPLv3 as wend-core. Read the code that governs the writes, run it yourself, and hold us to it.

Found something? Email [email protected] or use private vulnerability reporting on that repository. Disclosure details are published at /.well-known/security.txt, dependency scanning runs on the open-source core, and security patches come before feature work.

Wend’s Google integration is going through Google’s production verification, which includes an independent security assessment (CASA Tier 2) for the restricted Gmail scope. While that runs, connecting Gmail shows Google’s unverified-app screen and is open to a limited number of accounts. Calendar and Contacts are not restricted scopes and are unaffected. Wend itself holds no certification. Our infrastructure providers hold SOC 2 Type 2 and ISO 27001 for the layers they run, and those are theirs, not ours.

Questions about a specific case?

Email [email protected] for security reports, or [email protected] for everything else.

Wend.

Wend.

Wend knows everyone you know, notices who you talk to, and plugs your whole network into the AI you already use. Every fact has a source, and you approved it.

Product

  • Get access
  • Wend for Mac
  • Planner
  • Manifesto
  • Pricing
  • Wend for Chrome
  • Open source (wend-core)
  • Sign in

Compare

  • Best personal CRMs 2026
  • Wend vs Dex
  • Wend vs Mesh (Clay)
  • Dex alternatives
  • Mesh (formerly Clay) alternatives
  • Monica HQ alternatives
  • Assistant memory alternatives
  • All alternatives
  • All head-to-heads

Use cases

  • For founders
  • For investors
  • For chiefs of staff
  • For job-seekers
  • All audiences

Free tools

  • Warm-intro response rate
  • Who do I know at…
  • Intro request template
  • Follow-up cadence
  • All free tools

Resources

  • Blog
  • Glossary
  • Security & privacy
  • About

Company

  • Your account
  • Contact
  • Privacy
  • Terms
  • Subprocessors
  • DPA
Encrypted at rest·Never sold·Never used to train AI·Open core (AGPLv3)·GDPR transfers via SCCs·Sitemap

© 2026 Wend Labs Inc. · trywend.io

Built by Ansh Vasani and Ava Yu.

Ask AI about Wend

PerplexityChatGPTGoogle