WrengleWrengle
Start

Security

Your workspace is a folder on your machine.

Your notes are files in a folder you chose, and they are never uploaded on their own. Everything that can leave your machine is listed below, with where it goes and whether it is on by default.

// local-first files · explicit boundaries · consented web telemetry
Data ownership

You hold the files.

Ownership here is literal, not a policy promise: the notes are files on your disk, and you can open them without Wrengle.

A vault is just a folder

Available

Your notes are ordinary files in a folder you picked. You can open them without an account, including when separately enabled document sync is unavailable.

Local indexes and history

Available

Search indexes, version history, and recovery data all sit on your device — either in the vault or in Wrengle's own folder on your machine. The recovery database itself is not uploaded; optional sync sends validated note and chart state separately.

Your backup is the folder

Beta

Because the vault is a folder, backing up your work means copying or syncing it like any other directory you care about. No export step, no proprietary format.

Version history is not a backup

Beta

Wrengle tracks changes to your notes and charts so you can roll one back. It does not cover attached files or app data, so keep backing up the whole folder.

What leaves your device18 surfaces

Every single thing that can leave, and where it goes.

Most of this list says it stays on your machine. The rest only moves because you turned a feature on, and the app names the destination before it sends anything.

Your notes and files
Stays on your machine

A vault is a folder on your computer. Signing in alone does not upload it. Optional sync and cloud requests have the separate boundaries below; the search index stays on your machine.

Optional sync and shared vaults
Wrengle’s sync service

Off by default. Turn sync on for a vault from Settings → Account and that vault’s notes, charts, whiteboards, whiteboard images, note frontmatter, and folder structure are kept the same on your own computers, including documents you do not have open. Server copies are encrypted in transit and at rest, but Wrengle can technically read them to operate the service. Attachments outside whiteboards do not sync. Turning sync off keeps your local files and does not delete existing server copies; Remove from server deletes the server copy after 30 days. Where sharing is enabled, one owner can invite up to 20 editors through verified-email invitations delivered by Resend. Editors may change or delete all synced content; only the owner manages sharing. Access removal stops future sync within five seconds, and downloaded local copies remain. The owner funds storage and deleting their account removes owned remote shared vaults.

Capture permissions
Your operating system

Wrengle asks macOS for microphone access when it launches. System audio is separate: on macOS 14.2 or later, you explicitly run a short audible test for the narrower audio-only permission before recording it; older macOS versions use the screen-capture permission. Say no and your notes and vault work as before while only the affected listening features stay unavailable. Review or test access later in Settings → Privacy & Data → Desktop access.

Generative AI using your own provider key
The provider you connected

Your prompt and the bounded note context you selected go directly to the OpenAI or Anthropic provider shown in the app. Wrengle is not in the path.

Generative AI using Wrengle AI credits
Wrengle, then the model provider

When a text-only Wrengle AI tier is selected — including the clean-install Fast assistant default — prompts and replies transit Wrengle and OpenAI for generation. That content is not retained in the account ledger or app logs, while OpenAI's service handling still applies. Fast maps to GPT-5.6 Luna, Balanced to GPT-5.6 Terra, and Deep to GPT-5.6 Sol. Upgrades retain saved explicit or Auto routes; Auto itself never selects managed AI, and managed requests do not fall back.

Meeting report drafted while recording
Memory, then your configured provider

Drafts build up in memory as the meeting runs, and are never written to disk or logs. If reports are enabled, bounded transcript and note text goes to the direct OpenAI or Anthropic provider shown in the app, or through Wrengle to OpenAI when the text-only Wrengle AI route is selected; meeting audio does not.

Transcript kept briefly after a meeting ends
Memory only, then cleared

The finished transcript normally stays in memory for up to 30 seconds. A reload already paging its bounded copy renews a 30-second idle lease, but never beyond ten minutes from attachment. It is never logged, and it clears when you switch vaults or quit.

Provider keys and connection tokens
Your operating system keychain

Keys live in the macOS keychain, never in your notes, settings, or logs. macOS may ask you to allow access the first time; deny it and only the feature that needed it stops working.

Gmail draft from a workflow
Gmail, only after you approve

Wrengle shows you the exact recipient, subject, and body, and nothing reaches Google until you approve it. It only ever creates drafts — it never sends mail, and it cannot run on a schedule.

Jira issue from the editor
Atlassian, after you review the ticket

A Wrengle account starts the Atlassian OAuth handoff; long-lived tokens stay in the OS keychain and the broker keeps only encrypted, short-lived exchange records. For each ticket, Wrengle sends the selected site, project, and issue type plus the summary and description you reviewed. It is editor-only in v1. An unknown outcome is never retried automatically — check Jira before clearing the action lock.

Cloud meeting transcription
The provider you selected

Off unless you turn it on. If you do, bounded chunks for the final pass go to the fixed OpenAI or Deepgram model you selected. Live captions stay local. Wrengle does not silently switch providers, resend an ambiguous request, or substitute a local final pass.

Dictation and voice commands
Your machine and any provider you enabled

Local Whisper keeps speech recognition on-device. Cloud dictation sends audio to OpenAI, Deepgram, or ElevenLabs. Light edit and Voice Control analysis use the OpenAI or Anthropic route Automatic resolved, or the model you selected explicitly. Light edit sends the current transcribed utterance and up to four recent dictated sentences from the same voice session, all captured within one exact target: the note, assistant draft, Plugin Builder prompt, or chart text field. While one in-progress phrase and its exact target remain active, Light edit may analyze provisional transcript snapshots that can later be superseded or cancelled, but no more often than once every 1.5 seconds; each request can use provider quota or billing, or Wrengle AI credits. Turning live preview off suppresses those during-speech calls; final cleanup still runs. Accepted corrections to earlier dictated sentences apply as one undoable atomic change, while the current unfinalized phrase remains grey ghost text until finalization. It does not send that target's identity, microphone audio, or separately read or attach arbitrary typed text, the note body, or surrounding chart content; the payload is bounded to those dictated slots. Quick Dictation with Verbatim skips analysis.

In-progress meeting recovery files
Your vault, so a folder sync may copy it

Paged transcript records, long-report evidence checkpoints, and content-free ownership state live temporarily under .app/live/. Evidence can include derived summaries, decisions, actions, follow-up, discussion, and open questions. An external folder-sync service can copy them; Wrengle document sync does not. They never hold raw audio and are removed after the session safely settles.

Encrypted meeting audio while finalizing
Private app data on your machine

Authenticated encrypted audio blocks live outside the vault and its Git/sync boundary. They are bound to the exact vault and recovery-directory identity that created them. Wrengle decrypts only bounded ranges, removes them after canonical finalization succeeds, and can retain them locally when finalization needs attention.

Local editor recovery database
Stays on your machine

Wrengle keeps enough on disk to restore what you were typing after a reload or crash. The recovery database stays local; optional live document sync sends validated note and chart edits separately.

External AI agents you configure
That agent, and whatever it talks to

An agent you configure runs as a normal program on your machine with your permissions. Wrengle limits its own file tools to your vault, but it cannot restrict what the agent itself does.

App diagnostics
Content-free diagnostics endpoint

On by default and switchable off in Settings. It reports which features were used and what errors occurred — never your note contents — under an identifier that resets when you quit.

This website
Restricted cookieless or consented enhanced analytics through PostHog EU

Basic cookieless analytics counts page views and leaves on successfully rendered, reviewed public routes unless you object. It sends canonical paths without query strings or fragments, referring origin, and coarse browser, OS, and device details through t.wrengle.com to PostHog EU; it sends no page content or interactions and leaves no PostHog identity in browser storage. PostHog assigns cookieless sessions during ingestion when the required server-hash mode is enabled. Enhanced analytics can add Web Vitals and strictly allowlisted structural interactions only on those same routes after opt-in: metric name/value/delta/rating and interaction event type/tag/bounded sibling positions. Text, attributes, classes, IDs, selectors, link destinations, and custom augmentation are removed. Auth, account, callback, admin, API, error, and unknown routes remain excluded, and session replay stays disabled. Both lanes disable Beacon and use credentialless fetch. The project must enable Cookieless server hash mode, discard IP data, and retain analytics for no more than 12 months. Diagnostics is a separate Sentry choice. Global Privacy Control, Do Not Track, a basic objection, or Decline all stops every website telemetry lane.

This describes the current beta. If you handle genuinely sensitive material, read the AI and privacy guide and the known limitations first — they carry the exact caps, retention windows, and failure modes behind every row above.

If a recorded meeting is the specific thing you cannot risk uploading, read how Wrengle keeps meeting audio off a cloud notetaker.

Download

Try it on your next call.

Free while in beta, and nothing to sign up for. Download it, point it at a folder, and record a meeting — you will know within one call whether it is for you.