WrengleWrengle
Start

Privacy and AI

Every AI feature tells you where it is sending your work.

Wrengle keeps vault files, search, and default transcription local and names the exact route used for generative work, whether that is Wrengle AI or a provider key of your own. Each cloud feature discloses the bounded context it needs.

Modes8 modes

What leaves your machine.

Local data capabilities and cloud generative requests have separate, explicit boundaries.

What stays on your machine

Beta

Your vault, search and embeddings, recordings, and Local Whisper transcription stay local. Generative AI and optional sync have separate cloud boundaries. Interactive HTML previews can contact HTTPS services and send page data, but they cannot read sibling files or other vault content.

Automatic AI routes

Beta

Assistant and voice-analysis Auto use the most recently connected or verified eligible AI provider, then OpenAI, then Anthropic, with that provider's reviewed default model. Auto never picks Wrengle AI. The clean-install Wrengle AI Fast assistant route is a concrete saved default, not Auto, and upgrades preserve their existing route. With no usable Auto route, Wrengle asks for setup instead of sending anything.

Your own provider key

Beta

Keys are stored in the macOS keychain — never in your notes, settings, or logs. Wrengle only checks a key is there at startup; whether it actually works is not tested until you make a request.

Wrengle AI

Beta

The text-only prepaid alternative to holding a key yourself. Prompts and replies are uploaded through Wrengle to OpenAI for generation, then return through Wrengle; that content is not retained in the account ledger or application logs, while OpenAI's service handling still applies. Fast, Balanced, and Deep have published mappings, signing in includes no free credit, and the route never falls back.

Meeting reports

Beta

If reports are enabled, the complete transcript goes to the route shown in the app in bounded contiguous shards, along with bounded meeting-note and title context — text only, never meeting audio. Long reports can make multiple sequential provider calls; on Wrengle AI they are reserved together, so a report either runs or never starts.

What the assistant can see

Beta

The note you are in, the text you selected, wider workspace context, or supported images you attach — but only what the request you made actually needs.

External agents

Beta

In Assistant and Inline Assist, external agents run as normal programs with your permissions and talk to their own providers. Plugin Builder supports only its exact reviewed Claude Code 0.70.0 route: an existing Assistant account sign-in is reused through an app-scoped secure-store identity. The reviewed runtime preserves native HOME for macOS Keychain discovery while keeping configuration and workspace state in scratch. Builder excludes ambient API keys, ADC, and service-account credentials, exposes MCP-only tools, and requires its macOS sandbox. Gemini CLI and Codex fail closed as unsupported in Builder and remain Assistant-only.

Telemetry choices

Beta

App diagnostics are on by default and switchable off in Settings. Basic cookieless analytics counts page views and leaves on successfully rendered, reviewed public routes unless you object. It sends canonical paths without query strings or fragments, referring origin, and coarse browser, OS, and device details through t.wrengle.com to PostHog EU; it sends no page content or interactions and leaves no PostHog identity in browser storage. PostHog assigns cookieless sessions during ingestion when the required server-hash mode is enabled. Enhanced analytics can add Web Vitals and strictly allowlisted structural interactions only on those same routes after opt-in: metric name/value/delta/rating and interaction event type/tag/bounded sibling positions. Text, attributes, classes, IDs, selectors, link destinations, and custom augmentation are removed. Auth, account, callback, admin, API, error, and unknown routes remain excluded, and session replay stays disabled. Both lanes disable Beacon and use credentialless fetch. The project must enable Cookieless server hash mode, discard IP data, and retain analytics for no more than 12 months. Diagnostics is a separate Sentry choice. Global Privacy Control, Do Not Track, a basic objection, or Decline all stops every website telemetry lane.

Tradeoffs

When it happens, and what exactly gets sent.

Three places where a provider can be involved. Speech and meeting-transcription choices remain separate from generative AI routing.

When you ask the assistant something, it can include the text you selected, the note you are in, or wider workspace context — only what that request needs. Wrengle names the route before dispatch: the OpenAI or Anthropic provider you connected, or Wrengle AI and the tier it will spend credits on.

Meeting reports use the same cloud-only generative boundary and are configured separately. Wrengle names the exact provider and model before it sends the complete transcript in bounded contiguous shards with bounded meeting-note and title context — never meeting audio. A long report can make multiple sequential shard and hierarchical-reduction calls. Do not generate a report when that text must stay on your device.
FAQ

Privacy questions.

Generative AI is cloud-only. A clean install starts assistant chat on Wrengle AI Fast; upgrades retain their explicit or Auto choice, and you can switch to your own OpenAI or Anthropic key at any time. Wrengle remains local-first for the vault, files, search and embeddings, recordings, and Local Whisper transcription.

Yes. The built-in assistant and voice analysis left on Automatic can use a connected OpenAI or Anthropic key. Wrengle shows the resolved provider and reviewed default model, and requires setup when no usable key exists. Voice analysis never falls back to a local generative model. Speech and meeting transcription remain separately configured.

App diagnostics record which features ran and what errors happened — never your content — and you can switch them off in Settings. On this website, basic cookieless analytics counts views and leaves on reviewed public routes unless you object. It sends canonical paths without query strings or fragments, referring origin, and coarse device details through t.wrengle.com to PostHog EU; it sends no page content or interactions and stores no PostHog browser identity. Enhanced analytics can add Web Vitals and strictly allowlisted structural interactions on those same reviewed public routes after opt-in. They retain only metric name/value/delta/rating or interaction event type/tag/bounded sibling positions. Hard-navigation Web Vitals stay bound to the public route that loaded the document; SPA transitions cannot reattribute them, an excluded document stays ineligible, and back-forward-cache metrics are rejected. Authentication, account, callback, admin, API, error, and unknown routes stay excluded; URLs remain canonical and session replay stays disabled. Website diagnostics remains a separate choice, and sending work to an AI provider is a separate feature choice covered above. Global Privacy Control, Do Not Track, and Decline all stop every website telemetry lane.

Your provider keys are stored in the macOS keychain rather than in Wrengle’s own files, so the app has to ask the system to read them when it starts. Enter your Mac login password, not your provider key. “Always Allow” stops it asking again. Deny it and only the feature that needed that key stops working. After startup, using the app never triggers another prompt.

No. No account, no name, no email address, no payment. If you choose to create an optional account later, that does involve handing over identity details, and the Privacy Notice covers exactly what happens to them.