Who is responsible
PLIXO LABS LTD is the controller for personal data processed through this website, account service, support channel, and optional website telemetry.
PLIXO LABS LTD, trading as Wrengle, company number 16883172, registered in England and Wales.
Registered office: 31 Spenser Road, Bedford, England, MK40 2AZ
Contact: support@wrengle.com
What this notice covers
It covers visits to wrengle.com, optional Clerk-backed accounts, the account dashboard, support correspondence, release downloads, and website analytics or diagnostics you explicitly accept. It does not turn your local desktop vault into a hosted workspace.
Your notes, transcripts, chart files, search index, and local vault contents are not uploaded to the account service. If you deliberately select a cloud AI, transcription, sync, agent, or integration provider in the desktop app, that provider processes the material needed for that request under the boundary shown in the app and its own terms. See Privacy and AI for those product-specific flows.
Data we process
- Account identity: Clerk user identifier, email address, first and last name, profile image URL, sign-in methods, and session information. Wrengle mirrors the identity fields needed for its account dashboard and deletion handling.
- Account profile: optional display name and workspace-role preference, plus timestamps and technical event identifiers needed to keep account changes ordered.
- Deletion safety records: a keyed HMAC digest of the former Clerk subject and deletion-event metadata. This is pseudonymous data: it contains no email, name, or raw Clerk identifier, but remains linkable by Wrengle when the same subject is presented. It prevents an erased identity from being silently recreated by a delayed event.
- Support: your email address and the information you choose to include in correspondence with support@wrengle.com.
- Service and security metadata: network and request metadata reasonably needed to deliver the site, prevent abuse, rate-limit account endpoints, and investigate incidents.
- Optional analytics: allowlisted, content-free product event fields such as a platform download click or portal open. The browser keeps PostHog identifiers only in memory, then sends those random pseudonymous identifiers with accepted events. PostHog also receives the request metadata needed to deliver an event; the production EU project must be configured to discard IP data; there is no autocapture, pageview capture, session replay, profile building, survey, advertising tracking, or remote feature flagging.
- Optional diagnostics: minimized Sentry error events. User, request, context, message, local-variable, stack-path, and frame-context details are removed or redacted before an event can be sent.
Why we use data
| Purpose | Lawful basis |
|---|---|
| Create and operate an optional account and dashboard | Contract, or steps you ask us to take before contract |
| Secure the service, prevent abuse, and preserve deletion fences | Legitimate interests in a secure and reliable service |
| Answer support requests | Contract and legitimate interests in customer support |
| Send optional analytics and diagnostics | Consent, which you can withdraw at any time |
| Meet legal, regulatory, and accounting obligations | Legal obligation |
Who receives data
- Clerk provides account identity, authentication, sessions, and account deletion.
- Railway and managed PostgreSQL infrastructure host the website and account data.
- PostHog EU receives allowlisted analytics and necessary request metadata only after opt-in; public deployment is blocked until its production project is configured to discard IP data.
- Sentry EU receives minimized diagnostics only after opt-in.
- GitHub and its delivery infrastructure host release pages and installer files. Following a release or download link sends request and network metadata to GitHub, which applies its own privacy terms.
- Support and email providers process messages you send to support.
We do not sell personal data. We do not share it for behavioural advertising. We may disclose information where law requires it, to protect rights or safety, or as part of a corporate transaction with appropriate safeguards.
International transfers
Production configuration restricts PostHog and Sentry to their EU regions, and we prefer UK or European hosting where the service offers it. Some suppliers or their support operations may nevertheless process data outside the UK. Where required, we rely on an adequacy regulation, the UK International Data Transfer Agreement or UK Addendum to approved standard contractual clauses, and supplier security measures.
How long we keep data
- Active account and profile data is kept while the account exists.
- Account deletion removes the live Wrengle identity/profile rows through the Clerk deletion flow. The keyed, pseudonymous deletion tombstone is retained as a safety fence.
- Public deployment is blocked until the production PostHog project limits optional analytics retention to no more than 12 months.
- Public deployment is blocked until the production Sentry project limits optional diagnostic-event retention to no more than 90 days.
- Support correspondence and security records are kept only as long as needed for the request, dispute, security purpose, or applicable legal requirement.
Your choices and rights
Optional telemetry is off until you accept. Use “Privacy choices” in the footer to accept, reject, or withdraw. Withdrawal takes effect for future collection immediately: PostHog is opted out and cleared, and the Sentry client is closed. On first load, before applying the current choice, Wrengle also removes PostHog browser identifiers left by older website builds. The retired app.wrengle.com origin serves a one-time local cleanup page before redirecting, so its origin-scoped cookies and Web Storage can be removed too. HTTP bookmarks first upgrade to HTTPS on that retired host because browser storage is separated by scheme.
Depending on the circumstances, UK data-protection law gives you rights to access, correct, erase, restrict, or object to processing; receive portable data; and withdraw consent. You may also complain to the UK Information Commissioner’s Office at ico.org.uk. Contact support@wrengle.com first if you would like us to help.
Age and changes
Wrengle accounts are for people aged 18 or over. We do not knowingly offer accounts to children. We may update this notice as the beta changes; the effective date above identifies the current version, and material changes will be presented through the website or account service.