Local-first vault and file ownership
Wrengle is organized around a vault: a local folder for notes and app-managed metadata. Back up the full vault folder, not only exported notes.
Features
Wrengle is built around private working memory. Every feature below is labeled with its current product status.
Detailed feature map
Wrengle avoids hiding beta edges. Use these labels to decide which workflows are ready for your work.
Wrengle is organized around a vault: a local folder for notes and app-managed metadata. Back up the full vault folder, not only exported notes.
Startup requests macOS microphone and screen/system-audio access before the workspace opens. Recording rechecks status without prompting and depends on the selected source, vault readiness, strict .app/live recovery storage, and local model availability. Mic + System remains the default where supported; Mic only and System only remain available. A denied macOS grant produces granular Limited mode instead of a feature-time system dialog, and Wrengle never silently downgrades that selected source. The current unpackaged Windows build cannot reliably request or report per-app microphone or system-audio permission, so startup reports native capture access as Not required without probing a device or the global desktop-app microphone switch. It does not enter Limited mode merely because that switch is off. If Windows or the selected device prevents capture, Record fails prompt-free with a capability-specific device-open error; Privacy always links to Windows microphone Settings for recovery. Eligible local transcription prepares bounded final-quality chunks during capture by default, independently of report mode, so Stop usually processes only the tail. A process-memory-only, read-only Live draft appears immediately from committed captions, and refinement corrects it. It remains visible through Stop and a UI reload while the active desktop process retains the session, but is never written to recovery, another disk file, logs, or telemetry. Temporary completed transcript records live inside the vault, so configured filesystem sync or backup can copy them while they exist; they are cleaned after save/report, recovery, discard, or no-speech cleanup. Wrengle does not retain a raw recording archive. Final-pass cloud transcription is opt-in where configured.
After finalization, the bounded canonical transcript display state can remain in process memory for up to 30 seconds so a UI reload crossing immediate recovery cleanup still converges on the final text. It is scoped to the exact open-vault epoch and clears on vault switch, expiry, or desktop restart.
The workspace uses an IDE-shaped file tree, editor, tabs, split panes, and keyboard command surface for fast note movement.
Search, focused-note find and replace, recent notes, starred notes, and command-palette entry points help recover context across local work.
Wrengle supports local chart files for desktop diagrams on a theme-aware surface, with shape and connector editing, canvas quick-add, inline object actions, undo/redo and arrange controls, zoom and fit controls, page tabs, context menus, and keyboard shortcuts. Chart files are local vault documents; chart projection files live in the vault, with local CRDT recovery state under vault app data. Split panes attached to the same local chart mirror edits live, including in-progress object moves. Hosted collaboration, remote presence, grouping, layers, comments, and templates are not included in this release. Browser editing and analytical spreadsheet charts are not part of this release.
Connect notes with wiki-style links and inline autocomplete. A backlinks panel shows where each note is referenced with surrounding context, flags broken or ambiguous links, surfaces unlinked mentions, keeps links intact when notes are renamed or moved, and maps how notes connect — both as rings around a single note and as an interactive graph of the whole vault you can pan, zoom, and explore.
The built-in assistant defaults to Auto. A connected AI key that Wrengle can read from the operating-system keychain selects the most recently connected or successfully verified provider, then OpenAI or Anthropic; without one, Auto falls back to Wrengle Local. This availability check does not validate the key with the provider. Explicit Local and provider selections remain sticky. A cloud assistant can receive prompt and approved workspace context, so hosted behavior should not be described as local-only.
Build node-based workflows with Goal, Fetch, AI step, Write note, and Final review steps, dry-run the current draft step by step, run it immediately, or activate one daily or specific-days trigger with a pinned live version. Action steps use one searchable picker for enabled custom actions, trusted local plugins, and supported Apps instead of raw IDs; a removed target stays visibly unavailable. Gmail → Create draft configures recipient and subject, takes its exact body from upstream output, and shows the complete draft before a 24-hour manual approval. It currently uses Dry run, where upstream AI or Fetch output is simulated but approval creates a real Gmail draft. Its encrypted intent and complete recovery snapshot are durable before Google is contacted, and the same-vault approval can be reopened after restart. The upstream body is limited to 100,000 characters and oversized full recovery snapshots are refused safely. That full snapshot and exact request can remain encrypted for seven days; only the new bridge's content-safe plaintext metadata, opaque keyed bindings, and receipts can remain for 90 days. Recipient and subject remain in normal local workflow settings until edited or deleted; legacy preview-authored plaintext configuration can remain until app-data cleanup or uninstall. It creates drafts only, never sends them, and cannot run unattended or on a schedule. Trigger edits preserve the pinned snapshot; draft edits require an explicit validated live-version update. A manual Run stays bound to the vault open when it starts, so switching vaults cannot redirect its note write. Within one app process, only one user-started foreground workflow execution per current vault is admitted across manual Run and automation Run now; reopening Workflows reconnects to either kind and continues compact status checks. An interrupted acknowledgement reuses its exact start request for one hour; after that bounded window Wrengle discovers any active run but requires a fresh user action instead of silently redispatching it. Run now immediately shows in-progress and retains terminal detail; scheduled launches move from queued to running to terminal. Before persisting a Run now claim, the backend revalidates the live automation; a version changed after the dry run is rejected without a queued result or a consumed occurrence. New, resumed, or edited schedules wait for the next occurrence; an already-active schedule can catch up once after app or vault downtime. A finite automation queue feeds bounded heavy-work capacity: excess due triggers wait for a later scan and admitted work can stay queued for up to 10 minutes. Manual Run, automation Run now, and scheduled executions each have a fixed 30-minute limit. Stop requests cancellation at safe boundaries; already-started provider, fetch, or note work may finish. Hide only closes the detail view. For unattended executions, edit/overlap locks remain held until cleanup drains; compact status releases them when cleanup completes, and best-effort full terminal detail loading does not extend them. Within one running app process, the same automation cannot overlap; there is no cross-process guarantee. The scheduler scans about once a minute, so start can be nearly 60 seconds late plus queue delay. Pause or deletion does not cancel claimed queued or running work. Wrengle and the matching vault must be open; general durable execution history, general automatic retry, and unattended Action, Terminal, or Coding agent steps are not included. Persisted timeout and interruption outcomes are sanitized and content-free.
A saved meeting moves directly from its transcript to one editable report: summary, decisions, action items, follow-up, discussion, and open questions. Automatic generation starts after transcript save, Manual waits for Generate report, and an idle saved report keeps Generate report available in either mode as an explicit recovery path. An admitted automatic-report request survives an initial save failure and resumes only after a successful user retry or recovery plus current-policy revalidation. During automatic report generation, a bounded in-memory preview can fill those fields before the saved report replaces it; preview shortening never truncates the finished report, and partial content is never persisted, logged, or included in telemetry. Provider preparation is cancellation-aware and bounded to 8.5 seconds for explicit Ollama or 20 seconds for other routes; Ollama discovery uses one direct, no-proxy request capped at three seconds and 1 MiB.
Hold the shortcut for Quick Dictation into the focused note or assistant draft, or switch to Voice Control for exact editor, workspace, configured-agent, and terminal triggers. On macOS, microphone access is resolved at startup; the picker, local level test, and shortcuts only recheck status and never trigger a later operating-system permission prompt. The current unpackaged Windows build reports native permission as Not required without probing the device or the global desktop-app microphone switch. A blocked Windows device-open attempt fails prompt-free, and Privacy always links to Windows microphone Settings for recovery. Speech and analysis default to Auto. Connected keys that Wrengle can read from the operating-system keychain choose cloud routes without another setup toggle: speech prefers the most recently connected or successfully verified provider, then OpenAI, Deepgram, or ElevenLabs; analysis prefers the most recently connected or successfully verified AI provider, then OpenAI or Anthropic. This availability check does not validate a key with its provider. Without an eligible key, Auto falls back to local models. Explicit Local choices and turning Cloud voice features off remain sticky. Cloud speech sends microphone audio and supported hints to its provider; cloud analysis sends bounded transcript text context, not microphone audio or note bodies, to its provider. Meeting transcription remains local-first and separate. Deletes are confirmation-gated; terminal commands and agent requests can have effects outside Wrengle’s voice Undo.
Trusted local WASM actions and plugin views can be loaded from developer folders. Declarations are not grants; local app-install grants gate host APIs and write capabilities create app-mediated proposals. Marketplace, remote install, and compatibility promises are not in v1.
Product surface
This visual introduces the desktop workspace concepts. It is illustrative rather than a pixel-accurate screenshot of the current app.
Illustrative desktop preview · Local vault / Meetings
Search · New tab · FocusTranscript, decisions, and action items stay connected to the note that carries the work forward.
Actions pulled forward
Highlights
The homepage highlights are reused here for scanning and comparison.
Notes live in local files with app-managed metadata beside the vault. Back up the folder, not a hosted workspace.
Record and transcribe into one saved note, then create one six-field final report automatically or on demand.
The built-in assistant defaults to Auto: a connected AI key that Wrengle can read from the operating-system keychain selects its cloud provider, otherwise Wrengle falls back to Local. This availability check does not validate the key with the provider. Explicit Local and provider choices remain sticky, and local only means local when the effective workflow actually runs locally.
Move through local notes with search, focused-note find and replace, recent notes, command-palette entry points, and wiki-style links with a backlinks panel that shows where each note is referenced, plus an interactive graph of how the whole vault connects.
Wrengle supports local chart files for desktop diagrams, with shape and connector editing, canvas quick-add, and inline object actions. Chart files are local vault documents; chart projection files live in the vault, with local CRDT recovery state under vault app data. Split panes attached to the same local chart mirror edits live, including in-progress object moves. Hosted collaboration, remote presence, grouping, layers, comments, and templates are not included in this release. Browser editing and analytical spreadsheet charts are not part of this release.
Open files, trigger actions, search the workspace, rebuild indexes, and move through the app without leaving the keyboard.
Build a node-based workflow, preview a manual Gmail draft with its exact recipient, subject, and upstream-produced body, run an autonomous-safe current draft, or activate one daily or specific-days trigger with a pinned live version. Gmail currently uses Dry run: upstream AI or Fetch output is simulated, while approval creates a real draft. Approval is durable for 24 hours and can reopen after restart with the same vault. The upstream body is limited to 100,000 characters and oversized full recovery snapshots are refused safely. Its full recovery snapshot and exact request can remain encrypted for seven days; only the new bridge’s content-safe plaintext metadata, opaque keyed bindings, and receipts can remain for 90 days. Recipient and subject remain in normal local workflow settings until edited or deleted; legacy preview-authored plaintext configuration can remain until app-data cleanup or uninstall. Gmail creates drafts only and never runs unattended or sends mail. Trigger edits preserve the pinned snapshot; draft changes require an explicit validated live-version update. Run now immediately shows in-progress and retains terminal detail; scheduled launches move from queued to running to terminal. New, resumed, or edited schedules wait for the next occurrence; an already-active schedule can catch up once after app or vault downtime. A finite automation queue feeds bounded heavy-work capacity: excess due triggers wait for a later scan, admitted work can stay queued for up to 10 minutes, and active runs time out after 30 minutes. Within one running app process, the same automation cannot overlap; there is no cross-process guarantee. The scheduler scans about once a minute, so start can be nearly 60 seconds late plus queue delay. Dismissal, pause, or deletion does not cancel claimed queued or running work. Wrengle and the matching vault must be open; there is no general durable execution history or general automatic retry.
Move directly from the saved transcript to one editable six-field report: summary, decisions, action items, follow-up, discussion, and open questions.
Hold the shortcut for Quick Dictation in the focused note or assistant draft, or use Voice Control for exact editor, workspace, configured-agent, and terminal triggers. Speech and analysis default to Auto: connected keys that Wrengle can read from the operating-system keychain select cloud providers, otherwise Wrengle falls back to local models. That availability check does not validate a key with its provider. Cloud dictation sends microphone audio and supported recognition hints to OpenAI, Deepgram, or ElevenLabs; cloud analysis sends bounded transcribed text context, not audio, to OpenAI or Anthropic. Explicit Local choices and turning Cloud voice features off remain sticky. Deletes are confirmation-gated, while terminal commands and agent requests are not covered by voice Undo.
Local WASM developer-preview runtime, plugin views, UI contributions, AI-built offline custom views and stateful offline feature apps with plugin-scoped JSON state, local grants, first-use consent, write proposal approvals for manual plugin actions, diagnostics, and current limits. Plugin Builder does not create bounded read/write host bridges in this release; workspace-aware generated plugins are future work. Marketplace distribution and remote install are not in v1.
Download
The download page checks the latest GitHub release and offers only expected exact-named assets that are uploaded there. Optional identity accounts are available in Beta and are not required for local use. Purchases, licenses, billing, and gated downloads remain future portal work.