# Privacy Policy

_Last updated: 2026-08-25._

wander is two things, and only one of them involves us at all.

- The app. A program on your Mac or iPhone that edits files in your own folders.
  No account, no telemetry, nothing uploaded. Nothing you write reaches us, ever.
  If this is all you use, the rest of this page does not apply to you.
- wander.md and wander cloud. The hosted half: you sign in and turn the cloud on
  for a vault, and that vault's contents travel to our servers. It is off until
  you switch it on, per vault.

The same split runs through the [terms](/terms). What follows is exactly what
stays, what leaves, and what we can read.

## The short version

- A folder you open is a folder on your disk. The app edits the files and uploads
  nothing.
- Nothing leaves your device until you sign in and turn wander cloud on, and then
  only for the vaults you turn it on for.
- There is no end-to-end encryption. What you sync is stored so that our servers
  can read it, because the web editor, published pages, search and the history
  views are built on that.
- You can turn it off, and you can delete everything.

## What stays on your device

Plain folders and single files, always. A vault with wander cloud off, always. That
covers your notes, the version history in the hidden `.wander` folder, your
comments, your tags and your local search index. The app has no telemetry and
phones nothing home.

## What leaves your device when the cloud is on

You sign in with Apple, once, for the app. Then you choose wander cloud per vault.
For a vault you turned it on for, these travel to our servers:

- the files in it: notes, images, PDFs, attachments, everything in the folder
- its history: every version, the change that made it, and which device wrote it
- comments and ink
- the small state files in `.wander` that make a vault a vault: block ids, tags,
  favorites, folder styles
- a name for the device, so history reads "Anton's MacBook Pro" and not a random
  id. You choose it, and it starts as the computer's name
- your email address and the handle you claim
- a record of each sync: how long it took, how many objects moved, whether it
  worked. Counts and durations only, never a file name, never a path, never a line
  of your text

A vault with the cloud off sends none of it.

## What we can read

Everything in that list. There is no end-to-end encryption today and we will not
imply otherwise: the server reads your notes so it can render them, search them,
show a diff, serve a page you published and answer an agent you authorized. If
that is not the trade you want, leave the cloud off for that vault or for all of
them. The app is complete without it.

We do not read your notes for anything else. No advertising, no model training, no
selling, nobody here browsing your vault. Access is limited to what keeping the
service running needs, and to support, and support means you asked us.

Modes where the server holds only ciphertext are designed and not built. This page
changes when they ship.

## What other people can read

A vault is private. Private means a request for it answers "not found" to everyone
but you, and search engines are told to stay out.

Making a file, a folder or a vault public is publishing: anyone with the address
can read those bytes and search engines can index them. It takes your click, per
vault or per path, and you can take it back.

## Where it is stored

Cloudflare, in Europe: files and history in R2, the index and your account in a
Postgres database in Ireland. Email to you goes through tinysend, which we also
build.

## How long we keep it

- While the cloud is on for a vault we keep its full history. That is the point of
  it: the device folds and prunes old fine-grained edits after a month, the cloud
  is the long memory.
- Turn the cloud off for a vault and the server copy is scheduled for deletion. It
  goes about 30 days later. Turn it back on inside that window and it comes
  straight back.
- Sync records are kept 30 days, then deleted.
- Delete your account and all of it goes: tokens, devices, vaults, history, and the
  handle. Your vaults are turned off the moment you ask, so anything you published
  stops resolving right then, and your email, name and picture are erased in the
  same act. The rest is held for 30 days so a mistake is recoverable, then it is
  gone for good, and the username is held with it so nobody can take it in the
  meantime. Delete from your account page on wander.md, or in the app under
  Settings, Cloud. Recovering it inside those 30 days means asking us at
  wander@tinysend.com.

## The website

wander.md serves the marketing pages, the manual, your account, and any pages you
publish. There is no analytics script on it, no tracker, no cross-site cookie.
Cloudflare records requests the way any web host does, ip address, browser, page,
and we use that to keep the site up. Signing in sets a session cookie, and that is
the only cookie we set. If you email us we use your message and address to answer
it.

## Other companies

- Apple: the App Store, purchases, and Sign in with Apple, under Apple's own
  privacy policy. We receive a name and an email address, which may be Apple's
  relay address.
- Cloudflare: hosting and storage, as above.
- tinysend: the email we send you.

No advertising networks. We do not sell or share your data.

## Agents

An agent you authorize gets a token under your account and reads and writes through
the same doors your own devices use. It sees what your account sees, so give one a
token only when you mean it.

## Children

wander is not directed at children under 13 and we do not knowingly collect their
data.

## Your rights

Export every vault as a zip from your account page, or one vault from its own
settings page, any time and without asking. Ask us for a correction, or for
anything the export does not cover, and we do it.

## Changes

We date this page when it changes. A change that widens what leaves your device is
said in the changelog too, not only here.

## Contact

wander@tinysend.com
