Last updated: 2026-08-25.
wander is two things, and only one of them involves us at all.
- The app. A program on your Mac or iPhone that edits files in your own folders. No account, no telemetry, nothing uploaded. Nothing you write reaches us, ever. If this is all you use, the rest of this page does not apply to you.
- wander.md and wander cloud. The hosted half: you sign in and turn the cloud on for a vault, and that vault's contents travel to our servers. It is off until you switch it on, per vault.
The same split runs through the terms. What follows is exactly what stays, what leaves, and what we can read.
The short version
- A folder you open is a folder on your disk. The app edits the files and uploads nothing.
- Nothing leaves your device until you sign in and turn wander cloud on, and then only for the vaults you turn it on for.
- There is no end-to-end encryption. What you sync is stored so that our servers can read it, because the web editor, published pages, search and the history views are built on that.
- You can turn it off, and you can delete everything.
What stays on your device
Plain folders and single files, always. A vault with wander cloud off, always. That
covers your notes, the version history in the hidden .wander folder, your
comments, your tags and your local search index. The app has no telemetry and
phones nothing home.
What leaves your device when the cloud is on
You sign in with Apple, once, for the app. Then you choose wander cloud per vault. For a vault you turned it on for, these travel to our servers:
- the files in it: notes, images, PDFs, attachments, everything in the folder
- its history: every version, the change that made it, and which device wrote it
- comments and ink
- the small state files in
.wanderthat make a vault a vault: block ids, tags, favorites, folder styles - a name for the device, so history reads "Anton's MacBook Pro" and not a random id. You choose it, and it starts as the computer's name
- your email address and the handle you claim
- a record of each sync: how long it took, how many objects moved, whether it worked. Counts and durations only, never a file name, never a path, never a line of your text
A vault with the cloud off sends none of it.
What we can read
Everything in that list. There is no end-to-end encryption today and we will not imply otherwise: the server reads your notes so it can render them, search them, show a diff, serve a page you published and answer an agent you authorized. If that is not the trade you want, leave the cloud off for that vault or for all of them. The app is complete without it.
We do not read your notes for anything else. No advertising, no model training, no selling, nobody here browsing your vault. Access is limited to what keeping the service running needs, and to support, and support means you asked us.
Modes where the server holds only ciphertext are designed and not built. This page changes when they ship.
What other people can read
A vault is private. Private means a request for it answers "not found" to everyone but you, and search engines are told to stay out.
Making a file, a folder or a vault public is publishing: anyone with the address can read those bytes and search engines can index them. It takes your click, per vault or per path, and you can take it back.
Where it is stored
Cloudflare, in Europe: files and history in R2, the index and your account in a Postgres database in Ireland. Email to you goes through tinysend, which we also build.
How long we keep it
- While the cloud is on for a vault we keep its full history. That is the point of it: the device folds and prunes old fine-grained edits after a month, the cloud is the long memory.
- Turn the cloud off for a vault and the server copy is scheduled for deletion. It goes about 30 days later. Turn it back on inside that window and it comes straight back.
- Sync records are kept 30 days, then deleted.
- Delete your account and all of it goes: tokens, devices, vaults, history, and the handle. Your vaults are turned off the moment you ask, so anything you published stops resolving right then, and your email, name and picture are erased in the same act. The rest is held for 30 days so a mistake is recoverable, then it is gone for good, and the username is held with it so nobody can take it in the meantime. Delete from your account page on wander.md, or in the app under Settings, Cloud. Recovering it inside those 30 days means asking us at wander@tinysend.com.
The website
wander.md serves the marketing pages, the manual, your account, and any pages you publish. There is no analytics script on it, no tracker, no cross-site cookie. Cloudflare records requests the way any web host does, ip address, browser, page, and we use that to keep the site up. Signing in sets a session cookie, and that is the only cookie we set. If you email us we use your message and address to answer it.
Other companies
- Apple: the App Store, purchases, and Sign in with Apple, under Apple's own privacy policy. We receive a name and an email address, which may be Apple's relay address.
- Cloudflare: hosting and storage, as above.
- tinysend: the email we send you.
No advertising networks. We do not sell or share your data.
Agents
An agent you authorize gets a token under your account and reads and writes through the same doors your own devices use. It sees what your account sees, so give one a token only when you mean it.
Children
wander is not directed at children under 13 and we do not knowingly collect their data.
Your rights
Export every vault as a zip from your account page, or one vault from its own settings page, any time and without asking. Ask us for a correction, or for anything the export does not cover, and we do it.
Changes
We date this page when it changes. A change that widens what leaves your device is said in the changelog too, not only here.