Draft for legal review. Nothing here is final until this notice is gone; items in [brackets] are still to be decided.
What we can read.
In short: your journal is encrypted on your devices with a key only they hold, so the copy on our server is unreadable to us. The exceptions are the moments you ask Wonder to do something with your words, and they pass through without being kept.
What we can’t read
- Your journal. Entries, intentions, goals and reflections are encrypted on your Mac or in your browser before they sync. We store the scrambled result.
- Your key. The key that unscrambles it is made on your device. We keep a copy only after your device has locked it with your password (or journal passphrase), which we never store. If you make a recovery key, we keep a copy locked with that too.
- Your card. Stripe takes it; we never see the number.
What we can see
- Your name and email, whether you subscribe, and which devices are signed in.
- For each piece of the journal: an id, whether it’s an entry, intention or reflection, when it changed, and how big it is. Enough to sync, nothing about what it says.
When your words pass through
- Wonder’s notes, reflections, annotations and doodles. When you use them, your device decrypts that day’s or week’s material (for a doodle, just the words you selected and their entry) and sends it to our server, which hands it to Anthropic’s Claude and passes the answer back. It is in memory for the few seconds that takes, and never written down or logged. Email addresses and phone numbers are taken out first unless you say otherwise, and you choose which calendars and meeting notes are included. Turn notes off and nothing is sent.
- AI apps you connect (Claude, ChatGPT and others, over MCP). Their questions reach Wonder, open in your browser, sealed so only it can open them. It answers only what you allowed, and asks you before writing anything. The answer goes back through our server to the app you connected. Nothing is kept.
- Google Calendar on the web. Google won’t let a browser finish its own sign-in, so our server swaps the one-time code for your calendar tokens and hands them straight to your browser, keeping nothing. Your calendar is then read by your browser, never by us. On the Mac, the app does all of it itself.
- Exports. An export is decrypted on your device, for you. We never see it.
Last updated [date of publication].