Privacy
A small, clear data boundary.
Wander keeps detailed exploration history on your Mac. The shared service stores the minimum identity, security, and usage records needed to run generation responsibly.
Stored on your Mac
- Starting points and fields shown
- Answers and rabbit-hole selections
- Visit duration and exit reason
- Generated or fallback source
- Recent topics used to prevent repeats
- A rotating Wander refresh token in macOS Keychain
Stored by the Wander service
- Your Google account identifier and email address
- Hashed session records, device identifier, expiry, and revocation time
- Generation workflow, timestamp, model, token counts, and result status
- A salted hash of the connecting IP address for abuse controls
The service does not store Wander prompts, generated responses, answers, branch choices, or local visit history in its database.
Generation requests
Wander sends the prompt needed for a reveal or rabbit hole to its model gateway. The signed-in Google email is included for service attribution. Request data may be retained according to the model gateway's service configuration.
Credentials
Model credentials, Google OAuth secrets, signing secrets, and database credentials stay on the Wander service. They are never included in the macOS app.
Updates
This notice will be updated when Wander's data handling changes. Last updated 24 August 2026.