Privacy Policy

Effective date: July 12, 2026 · Last updated: July 12, 2026

1. Who we are

Wendell is a product of Open Knowledge of New York, LLC (“we,” “us,” “our”). For privacy questions or to exercise any of the rights described below, contact support@okny.io.

2. What this policy covers

This policy describes how we handle information across two distinct product surfaces:

Different tiers receive different data. We describe each separately below. Our Chrome extension has its own Extension Privacy Policy, which applies together with this one.

3. Information we collect

Account information (both tiers, if you create an account): Email address, account display name, billing information (handled by our payment processor; we do not store full card numbers).

Waitlist information: Email address and, optionally, a free-text response describing what you’re working on. Used solely to notify you of pilot availability and send occasional product updates if you opted in.

Local tier — what stays on your machine: Your manuscripts, corpus, plot graph, ledger, provenance chains, and rubric scores. These never leave your machine through Wendell. If you use a bring-your-own LLM key, your prompts and completions go directly between your machine and the LLM provider you chose — Wendell does not proxy or log them.

Local tier — minimal telemetry (opt-in, off by default): If you opt in, we collect anonymized usage events (e.g., “build_kb_bundle ran successfully,” “rubric scored N scenes”). No content of your manuscripts, no file names, no LLM prompts.

Hosted tier — what we receive: Because we run the infrastructure, we necessarily receive your assembly artifacts, corpus files, and ledger events; LLM prompts and completions; graph database queries; and standard server logs. We treat this content as yours. We do not sell it. We do not share it.

Hosted tier — product-usage analytics (on by default, opt-out): To learn which of Wendell’s suggestions and questions are actually helpful, we record anonymized interaction events — which suggestion was shown, and whether you accepted, edited, or dismissed it — keyed to a one-way hashed account identifier. From these events we may derive a coarse working “persona” (e.g., which work domains you tend to use) to tailor which suggestions we surface. These events never include the content of your documents, your file names, or your LLM prompts. This is on by default for hosted accounts; you can turn it off at any time in Settings → Privacy, and turning it off stops new events for you immediately.

4. How we use information

We use the information described above to provide and operate the product, authenticate you, send transactional emails, send product updates if you opted in, debug errors, and comply with legal obligations. We also use the anonymized product-usage analytics described in Section 3 to measure which suggestions are helpful and improve which ones we surface — unless you have opted out.

We do not:

5. AI providers and the hosted tier

The hosted tier includes LLM API access. Under the hood, we route requests to one or more upstream AI providers. When you use AI features, your prompt and the relevant context are sent to the chosen provider for processing. We contractually require providers not to use your content to train their models, where their terms allow. We do not retain prompts and completions beyond what is needed to display them in your review rail and ledger.

The current list of providers is available on request from support@okny.io. If we change providers materially, we will notify hosted-tier users by email.

6. Cookies and analytics

The marketing site uses minimal analytics to understand which pages are visited. We do not use advertising cookies or cross-site trackers. You can decline non-essential cookies without losing site functionality. The product itself uses only the cookies needed to keep you signed in.

7. Data sharing

We share data only: with infrastructure providers that operate parts of the hosted tier on our behalf (each bound by a data processing agreement); when required by law (we will notify you unless legally prohibited); or in connection with a merger or asset sale, with prior notice and equivalent privacy commitments.

We do not sell personal information.

8. Data retention

9. Your rights

Depending on where you live, you may have the right to access, correct, delete, export, or object to certain processing of the personal information we hold about you, and to withdraw consent for optional processing (e.g., marketing emails). Email support@okny.io to exercise any right not available in self-serve account settings.

Product-usage analytics: you can opt out at any time in Settings → Privacy — no email required. Opting out stops new interaction events immediately.

EU/EEA and UK users: We process personal data under the lawful bases of contract, legitimate interest, and consent. You have the right to lodge a complaint with your local data protection authority.

California users: You have rights under the CCPA/CPRA including the right to know, delete, correct, and opt out of sale (we do not sell).

10. Security

We use industry-standard practices: encryption in transit (TLS), encryption at rest for hosted-tier content, scoped access controls, and audit logging. No system is perfectly secure; if a breach affects you, we will notify you and the relevant authorities as required by law.

11. Children

Wendell is not directed at children under 16 and we do not knowingly collect information from them.

12. International transfers

If you are outside the country where our infrastructure is located, your information will be transferred there. We rely on standard contractual clauses or equivalent safeguards for international transfers where required.

13. Changes to this policy

We will post material changes here and, for the hosted tier, notify you by email. Continued use after changes constitutes acceptance.

14. Contact

Open Knowledge of New York, LLC
support@okny.io