Data Policy
Effective May 21, 2026
What you put into Wanderwhim is yours. Your topics, sources, notes, and writings belong to you. We store them so the app can do its job, and we hand them to AI subprocessors only when you take an AI action. We do not sell your data, we do not use it for advertising, and we do not train any model on it.
This page is the long-form, plain-English version of how your content moves through the system. For the legal framing, see the Privacy Policy.
Where your content lives
Your content is stored in a managed database hosted in the United States. Embeddings (the numeric vectors that power the hex map and similarity search) live in the same database via a vector index. Application servers are also hosted in the US.
Encryption
- In transit. All traffic between your browser, our servers, and our subprocessors is encrypted with TLS.
- At rest. Our database provider encrypts data at rest by default. Backups inherit the same encryption.
What gets sent to AI providers, and when
Nothing leaves our database for an AI provider until you press a button that calls one — explore a topic, deepen a source, generate a writing prompt, ask a question of a region, and so on.
When you do trigger an AI action, the request typically includes:
- The titles and content of the sources relevant to that action.
- The topic name and short context (description, region names).
- The prompt template for the action you chose.
Embeddings are generated whenever you add or edit a source. The source text is sent to our embeddings provider, which returns a numeric vector. The vector is stored in our database. The original text is not retained by the embeddings provider under the API terms we use.
Subprocessors
Our current AI subprocessors are listed below. This list is a snapshot — we will update it when we add or change a provider.
- OpenRouter — routes AI requests to the right model provider. Does not retain prompts or train on them.
- Anthropic — large language models. Does not train on API inputs by default.
- OpenAI — large language models. Does not train on API data by default.
- VoyageAI — embeddings. Does not train on customer data.
What we will never do
- We do not sell your data.
- We do not use your content for advertising.
- We do not train any model on your content.
- We do not share your content with third parties outside the subprocessors listed here.
Deletion cascades
- Deleting a source removes its embedding, its notes, and any region linkages.
- Deleting a topic removes its sources, regions, explorations, and suggested sources.
- Deleting your account removes everything above plus your profile and usage history. The purge completes within 30 days across our active database and backups.
Stripe retains a record of past transactions for tax and audit compliance, even after the rest of your account is gone.
Data export
Self-serve export is available from Settings → Export your data. You get a .zip of Markdown files containing your topics, sources, notes, saved explorations, regions, and writings — structured to open directly as an Obsidian vault. Embeddings are derivable from the source text and are not included.
If anything looks off in your export, email [email protected] and we’ll sort it out.
v1 — last updated May 21, 2026. We’re a solo team. If something here is unclear or you have a privacy concern, email [email protected] and we’ll respond personally.