Draft for legal review. Nothing here is final until this notice is gone; items in [brackets] are still to be decided.
Privacy policy.
Wonder is a journal for your working life. Your journal is end-to-end encrypted: it is encrypted on your devices before it reaches us, and we cannot read it. This policy says what we do hold, why, for how long, and who helps us hold it. What we can read puts the technical side in plain English.
Who we are
Wonder is run by [legal entity name], [registered address], [company number]. We are the controller of the personal data described here. Write to us at [privacy contact email] about anything in this policy.
What we hold, and why
Your account
Your name, email address and a hash of your password (we never keep the password itself), or the account you signed in with (Google, Apple or GitHub). If you turn on two-step sign-in, we keep your authenticator secret encrypted, and hashes of your recovery codes. We need these to give you an account: the lawful basis is our contract with you.
Your journal
Entries, intentions, goals and Wonder’s reflections sync between your devices as ciphertext, encrypted with a key made on your device. We store that ciphertext, and a copy of your key that is itself encrypted with your password or journal passphrase (and, if you made one, with your recovery key). We cannot decrypt either. To keep your devices in step we also see, for each record, an id, its kind (entry, intention or reflection), when it last changed, whether it was deleted, and its size.
Wonder’s notes, reflections, annotations and doodles
If you use them (they need a subscription or a trial), your device decrypts the material for that day or week — or, for a doodle you ask for, the words you selected and the entry they’re in — your recent writing, goals and intentions, and the calendar events and meeting notes you choose to share — and sends it to our server, which passes it to Anthropic’s Claude to write the notes, and returns them. Nothing sent is stored or logged by us, and Anthropic processes it under [zero data retention terms]. Email addresses and phone numbers in it are removed first unless you say otherwise. You can turn notes off in Settings at any time. The lawful basis is our contract with you: it is the feature you asked for.
AI apps you connect
If you connect an app such as Claude or ChatGPT (over MCP), it reaches your journal through Wonder open in your browser, with the permissions you chose. Its requests pass through our server sealed so only Wonder can open them, and nothing is kept once answered. What that app then does with what it reads is between you and it: its own privacy policy applies. We keep a record of which apps you have connected, and Wonder keeps a log in your browser of what each one did, so you can see and remove them.
Payments
Stripe takes your card and billing details; we never see your card number. We keep your Stripe customer id and the state of your subscription, to know what you have paid for.
Running the service
Which devices are signed in (a name such as “Safari on macOS”, and when each was last seen); request logs with no content (the route, the result, how long it took, and a one-way hash of your account id); counters that slow down repeated sign-in attempts, keyed by hashes; and, unless you turn them off in Settings, error reports with no journal text in them and no name or email. We need these to keep Wonder working and secure: our legitimate interest.
Usage counts
Only if you turn on “Share usage counts” in Settings (it’s off unless you do): which things happen, such as writing an entry, setting an intention, connecting a calendar or an agent, or acting on a note, at most once a day each. Never what you wrote, and nothing typed. We also count that an account was made, that a subscription started, and that the Mac app was downloaded from our website (with no one attached). Each account appears only as a pseudonym, a keyed hash we can’t turn back into your account, so we can see how many people get from signing up to writing, and who comes back a week later, without seeing who. We keep these for [retention period]. The lawful basis is our legitimate interest in knowing what helps, and your consent for what the apps send.
Updates to the Mac app
When the Mac app checks for an update, it sends its version and a random id made when it was installed, so an update can reach a share of Macs at a time. The id says nothing about you and is not linked to your account.
Cookies and storage
One cookie, to keep you signed in on the website and web app. No advertising, no analytics and no tracking cookies. The web app keeps your journal and settings in your browser. The website’s fonts come from Google Fonts, so Google sees your IP address when a page loads. Cookies and storage has the detail.
Who helps us
These companies process personal data for us, under data processing agreements. The full list, with what each gets, where, and a record of changes, is on Subprocessors.
| Company | What for | What they get | Where | Agreement |
|---|---|---|---|---|
| Supabase | Database and sign-in | Your account (name, email, password hash), the encrypted journal and its wrapped keys, session hashes, subscription state | [region] | [DPA link] |
| Vercel | Hosting the server, website and web app | Everything our server handles, in memory only; request logs without content | [region] | [DPA link] |
| Anthropic | Wonder’s notes and reflections | The day’s or week’s material you share, for the length of each request, under zero data retention | [region] | [DPA link] |
| Stripe | Subscriptions and payments | Your name, email and payment details | [region] | [DPA link] |
| [Email provider] | Account emails (password resets, sign-in links) | Your email address and the message | [region] | [DPA link] |
| Sentry | Error reports, unless you turn them off | Error type, a scrubbed message and where in the code it happened; never journal text, your name or your email | [region] | [DPA link] |
Granola, your calendar and any agent you connect are not on this list: you connect them, and what they hold is under your own agreement with them. We will tell you by email at least [30] days before adding anyone new.
How long we keep it
Your account and journal, until you delete them. Deleting your account (on your account page) removes your account, journal, keys and sessions from our database at once; they leave our backups within [backup retention period]. Signed-in sessions last 30 days after last use. Request logs are kept for [log retention period]. Stripe keeps billing records as the law requires. The journal on your own devices stays there until you remove it.
Your rights
You can see and correct your details on your account page, export your whole journal from the app or web app (in Markdown and JSON), and delete your account. You can also ask us for a copy of what we hold about you, to restrict or object to how we use it, or to move it elsewhere: write to [privacy contact email]. If you think we have got something wrong, you can complain to [supervisory authority, e.g. the Information Commissioner’s Office].
Transfers
Some of the companies above process data outside [the UK / the EEA]. Where they do, we rely on [adequacy decisions / standard contractual clauses and the UK addendum].
Children
Wonder is not for anyone under [16].
Changes
If we change this policy in a way that matters, we will tell you by email before it takes effect.
Last updated [date of publication].