Security & privacy
Your memory stays yours.
Wend holds the people in your life and what they told you, and Wendy can act on it. So this page is the exhaustive answer to two questions: who can reach it, and who can send anything.
Three commitments
We never train on your data. Not our models, not anyone’s. Our model providers are contractually barred from training on your content, and the commitment is a term of our Terms of Service.
Your graph is one person’s memory. Never pooled with anybody else’s. No AI output for one user can draw on another user’s graph.
We never sell your data. No advertisers, no data brokers, no licensed ‘insights’.
The write path is the security model
You do not control which model runs this month, or what a web page said to it mid-task. So the guarantee is structural: there is no code path from an agent call to a committed fact.
Every fact has a source, and you approved it.
How agent writes are governed
You approve every agent write
Any agent you connect can only propose. Nothing it writes is saved until you confirm it, on any surface. Sources you pick yourself on your Mac are the other case: you choose the source, you see its count, it lands, and one click takes the whole import back out.
Prompt injection can only make a proposal
Instructions hidden in a page or a document arrive as a line on your review page, with the agent that made it named and the source it claims attached. Untick it and it is gone.
Every write arrives attributed
Which assistant proposed it, in which session, and the email, page, note or transcript it came from. Click any claim in your graph and see where it came from. When several agents share one memory, knowing who asserted what is the difference between a record and a rumor.
Conflicts are surfaced, never auto-resolved
When two sources disagree about a fact, Wend shows you both and you decide. It never silently overwrites what you approved, and every AI inference that touches your data is logged in a trail you can browse.
Agents are revoked one at a time
Account → Agents lists every assistant, Mac, browser and key holding a credential. Revoke one and it stops on its next request, while the rest keep working.
Four permissions, granted one at a time
Read asks about your network and changes nothing. Propose files a proposal you confirm. Draft writes words that do not leave. Send asks for a send and confirms one. They are separate grants, so an assistant you want reading and never sending gets exactly that: it does not see the send tools in its own list, and asking anyway is refused by the server with the permission it would have needed. The check is on the credential, never on a hint in a tool description.
Deletion is never delegated
No agent can delete anything. Removing people, facts or your whole account is yours alone.
What Wendy may do, and what she may not
She acts as Wendy, on your behalf, and never as you
She signs her own name on every surface, says so if somebody asks whether they are talking to you, and never writes under your name. This is checked on what the model actually produced, not only requested in its instructions: a line claiming to be you is refused before it is sent. There is no mode that sends under your identity and none is planned.
You read the words before they go
Anything leaving for another person is shown to you exactly as it will arrive, and it goes only after you say so. Editing a draft produces a new preview, because an approval has to be of the words that actually go out rather than of an earlier version of them.
A text is a draft you send yourself
For iMessage, Wendy writes the words and sends you a link. You open it, read them, edit them if you want, and one tap hands the message to your own Messages, on your own thread and your own number. Wend never sends an iMessage for you. The link is single-use, short-lived and bound to that one message, so a forwarded link sends nothing.
Where she reaches you
Telegram and email, and neither needs an install. There is no voice, phone or SMS surface, and WhatsApp is not a channel she uses. She connects to Telegram from a one-time link in your account, so a stranger’s chat cannot reach your graph.
Instructions inside content are never authority
Wendy reads mail, messages and pages that other people wrote. Nothing in that content can authorise a send. A request to act has to come from you, on a surface you connected, and the send still waits for your confirmation.
Every act is on the record
What she did, where it went, what came back and whether you approved it are kept against the relationship, in the same ledger you can read in the app.
What reading looks like on your Mac
Extraction runs on the machine
Wend reads WhatsApp, Contacts, Calendar, iMessage, Apple Mail and Granola notes where macOS already keeps them, and works out the people and facts there. The bulk import sends none of your messages to a model. The one exception is a conversation you choose to have read in depth, which is priced before it runs.
Your Mac’s own record of who you talk to
Behind the permissions your Mac already has sit stores almost nothing reads: call history, the message and call donations macOS keeps for Siri and Spotlight, notification history, and the related names in your Contacts. Wend reads them in place, on macOS 13 through 26, working out the shape of each store when it opens it rather than assuming one version. What it keeps from them is who, when and how often.
Reading the words is tiered, and it runs here
A cheap pass runs on every item on this machine. A model on the chip runs on the slice that deserves one, when Apple Intelligence is available and the Mac is not hot, on battery or out of its daily budget. Anything skipped is queued with the reason rather than dropped. That pipeline has no cloud lane: message and mail bodies are not sent to a cloud model by it.
Each source is a switch
Nothing is read until you turn it on. WhatsApp needs no permission from macOS, Contacts and Calendar ask once, and iMessage needs Full Disk Access, which macOS will not offer to grant on its own and which never blocks setup.
Your calendar is read here, and never written
Connect a Google calendar in the Mac app and this machine reads it directly, on a read-only connection: Wend cannot create, move or cancel an event. The entries it caches stay here the way message bodies do, so a description and a location never leave the Mac. What reaches your graph is the meeting, its time and the people who were in it.
Ambient Mode reads the screen, never the microphone
Turned on, Wend reads the window you are working in through macOS accessibility and remembers the people in it, with the app, window and page URL as the source on every capture. It never listens and never records. Password managers are never walked, secure fields and private windows are skipped, the raw text stays on your Mac, and everything it notices arrives as a proposal you confirm. Off by default, one click to pause.
Extraction can run on the chip itself
On Apple silicon with Apple Intelligence, Wend extracts facts, reads business cards and builds briefings on the Mac itself. Bigger jobs route to the cloud; the sensitive raw never does.
The extension reads the page you are on
It works inside your own logged-in session and captures only the page you asked it to capture. It never sees a password, and it does not watch your browsing.
What we can see
Your account and your billing
Your email, your subscription state, and the invoices Stripe holds for it. Those records sit on our own infrastructure, in a single US region (Northern Virginia).
One directory row per install
So that one unchanging link can find your graph, whichever way you deployed it. It says where to route, not what is in there.
A heartbeat, unless you turn it off
On first launch, when setup finishes, and once a day on open, Wend reports its version, your Mac’s architecture and OS version, how far through setup you are, and which SIZE BAND your graph falls into. Never a count, never a name. There is a switch that stops it.
Google mail and events, and any deep read you ask for
Your chat databases and archive contents stay on your Mac. Mail and events from a connected Google account are read on our servers, and so is one conversation you pick to have read in depth, priced before it runs. A calendar connected in the Mac app is read there, not here.
A day too big to plan here
Planning runs on your Mac whenever the day fits the model on the chip. A bigger day is solved on our servers, and what travels is the shape of it: free windows as clock times, your task summaries and your own preference sentences. Never a meeting title, never an attendee, never anything else a calendar entry holds.
Your cloud copy
Setup provisions a managed Cloudflare mirror that Wend runs, and Wend is in the query path: it is how your agents read your graph when the Mac is closed. It is not zero-knowledge, so Wend and Cloudflare can technically read a mirror we host. Message bodies, screen captures, cached calendar entries and other raw content are never copied to it. Some earlier installs keep their mirror in their own Cloudflare account instead, where only Cloudflare could.
The encrypted vault, and its index
Raw content you back up sits in our object storage as ciphertext we hold the wrapped key for, not as text we read. We also hold its index: which source a blob came from, which month it covers, how big it is and how many items it holds. That index is how a second Mac finds your archive without listing the whole store, and it is metadata about your data rather than the data.
Questions your agents ask the web
Public-web research is routed through us to the provider on your key. The provider sees the name or profile URL being looked up, never your graph and never the other people in it.
GDPR-aligned via SCCs
For users in the EU, EEA, or UK, transfers of that account data to the US are covered by the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914) plus supplementary technical measures. Access, correction, deletion and portability apply in full.
Encryption, and the key you bring
Your graph is a file only you can open
It lives in Wend’s own folder on your Mac, which macOS keeps readable only by your user account. With FileVault on, the disk under it is encrypted too.
Your raw archive is encrypted before it leaves
Message and mail content backed up to Wend’s cloud vault is encrypted on your Mac first, with a key wrapped for your account rather than held in the open. The honest sentence, and the one we hold ourselves to: encrypted at rest and unlocked by your login, readable only by you and the agents you authorize. Not ‘we can never read it’, which would be a claim about our own architecture that you have no way to check.
Encrypted in transit
TLS on every hop: your Mac to us, us to your cloud copy, and us to every provider we call.
AES-256-GCM on tokens and provider keys
The Google tokens that let Wend read your mail and calendar, and any research-provider key you connect, are encrypted at the application layer, with the key held outside the store entirely.
Encrypted at rest, not end to end
Content Wend reads is encrypted at rest. It is not end to end encrypted, because an agent has to be able to read it. Our account, billing and directory records sit on managed infrastructure with disk-level encryption, and row-level policies filter every read against the signed-in account.
Research runs on your account, not ours
Filling in what someone does now, where they are, and where they worked before runs on a data-provider account you create and hold, such as Bright Data. You paste the key once. You agree to the provider’s terms directly, you see what they charge, and you can revoke the key or leave with the account.
Account controls
Full export, always
The app writes your whole graph to a JSON file on demand, read from the database on your Mac. It works offline and it keeps working if you stop paying.
Two-factor on deletion
Account deletion asks for your second factor whenever you have 2FA enrolled, because the operation that destroys your graph deserves the strongest gate you have set up. Export requires your signed-in session.
Self-serve deletion
Delete your graph in the app and it is gone from your Mac and from your cloud copy. Delete your Wend Labs account and we hard-purge the records we hold within 7 days.
Right to be forgotten, including for non-users
If you appear in a Wend user’s graph and want out, submit a request at /privacy/rtbf. We remove what we hold, notify the customer, who has one-click tools to remove you, and write back within 30 days. We cannot search or delete a graph on someone else’s machine.
Check it yourself
The engine that stores and governs your graph, the schema, the propose-and-confirm write path, provenance and recall, is open source under AGPLv3 as wend-core. Read the code that governs the writes, run it yourself, and hold us to it.
Found something? Email [email protected] or use private vulnerability reporting on that repository. Disclosure details are published at /.well-known/security.txt, dependency scanning runs on the open-source core, and security patches come before feature work.
Wend’s Google integration is going through Google’s production verification, which includes an independent security assessment (CASA Tier 2) for the restricted Gmail scope. While that runs, connecting Gmail shows Google’s unverified-app screen and is open to a limited number of accounts. Calendar and Contacts are not restricted scopes and are unaffected. Wend itself holds no certification. Our infrastructure providers hold SOC 2 Type 2 and ISO 27001 for the layers they run, and those are theirs, not ours.
Questions about a specific case?
Email [email protected] for security reports, or [email protected] for everything else.