What stays on your machine
BetaYour vault, search and embeddings, recordings, and Local Whisper transcription stay local. Generative AI and optional sync have separate cloud boundaries. Interactive HTML previews can contact HTTPS services and send page data, but they cannot read sibling files or other vault content.
Assistant and voice-analysis Auto use the most recently connected or verified eligible AI provider, then OpenAI, then Anthropic, with that provider's reviewed default model. Auto never picks Wrengle AI. The clean-install Wrengle AI Fast assistant route is a concrete saved default, not Auto, and upgrades preserve their existing route. With no usable Auto route, Wrengle asks for setup instead of sending anything.
Your own provider key
BetaKeys are stored in the macOS keychain — never in your notes, settings, or logs. Wrengle only checks a key is there at startup; whether it actually works is not tested until you make a request.
The text-only prepaid alternative to holding a key yourself. Prompts and replies are uploaded through Wrengle to OpenAI for generation, then return through Wrengle; that content is not retained in the account ledger or application logs, while OpenAI's service handling still applies. Fast, Balanced, and Deep have published mappings, signing in includes no free credit, and the route never falls back.
If reports are enabled, the complete transcript goes to the route shown in the app in bounded contiguous shards, along with bounded meeting-note and title context — text only, never meeting audio. Long reports can make multiple sequential provider calls; on Wrengle AI they are reserved together, so a report either runs or never starts.
What the assistant can see
BetaThe note you are in, the text you selected, wider workspace context, or supported images you attach — but only what the request you made actually needs.
In Assistant and Inline Assist, external agents run as normal programs with your permissions and talk to their own providers. Plugin Builder supports only its exact reviewed Claude Code 0.70.0 route: an existing Assistant account sign-in is reused through an app-scoped secure-store identity. The reviewed runtime preserves native HOME for macOS Keychain discovery while keeping configuration and workspace state in scratch. Builder excludes ambient API keys, ADC, and service-account credentials, exposes MCP-only tools, and requires its macOS sandbox. Gemini CLI and Codex fail closed as unsupported in Builder and remain Assistant-only.
App diagnostics are on by default and switchable off in Settings. Basic cookieless analytics counts page views and leaves on successfully rendered, reviewed public routes unless you object. It sends canonical paths without query strings or fragments, referring origin, and coarse browser, OS, and device details through t.wrengle.com to PostHog EU; it sends no page content or interactions and leaves no PostHog identity in browser storage. PostHog assigns cookieless sessions during ingestion when the required server-hash mode is enabled. Enhanced analytics can add Web Vitals and strictly allowlisted structural interactions only on those same routes after opt-in: metric name/value/delta/rating and interaction event type/tag/bounded sibling positions. Text, attributes, classes, IDs, selectors, link destinations, and custom augmentation are removed. Auth, account, callback, admin, API, error, and unknown routes remain excluded, and session replay stays disabled. Both lanes disable Beacon and use credentialless fetch. The project must enable Cookieless server hash mode, discard IP data, and retain analytics for no more than 12 months. Diagnostics is a separate Sentry choice. Global Privacy Control, Do Not Track, a basic objection, or Decline all stops every website telemetry lane.