Privacy
Wandlet rewrites text you select. This page says what leaves your device, what we keep, and what we never do.
Last updated 13 August 2026 · Applies to the Wandlet app and to wandlet.app.
This is the short form, written to be read. The full text is available on request — ask at the address in the Impressum.
The short version
- Only the text you selected is sent. Not your keystrokes, not your files, not the rest of your clipboard.
- It travels over TLS, is passed to the AI provider, and streams straight back. It is not stored and not used for training.
- No advertising, no analytics, no third-party trackers, no profiles.
- Signing in is optional. If you never sign in, there is no account and nothing personal to hold.
Who we are
Wandlet is provided by the company named in the Impressum, which is also the data controller. That page carries the postal and email address for everything on this one.
What we collect
If you sign in with Google or GitHub: your email address and name, so we know which account is yours. A session token that keeps you signed in. And a usage record — which action you ran and when — so your limit can be counted and shown back to you.
That usage record does not include the text you transformed.
The text you transform
When you run an action, the text you selected — and nothing else — is sent over an encrypted (TLS) connection, passed to the AI provider that generates the rewrite, and streamed straight back to you. It is not stored, and it is not used to train any model.
The provider may process it on servers outside the European Economic Area, so please don't transform passwords, full payment card numbers or health details.
What the app can see on your device
The desktop app watches for one thing: the double-tap of ⇧ Shift. It reads and writes the clipboard only at the moment you run an action, and puts back what was there before. It checks whether the field you are in can be edited, so it knows whether to replace or fall back to the clipboard.
It does not log your keystrokes and does not watch what you type.
Cookies and local storage
This is the whole list. Everything but the last row is strictly necessary to run a service you asked for.
| What | Purpose | Consent |
|---|---|---|
| wandlet_session | Keeps you signed in after you use Google or GitHub. | Essential |
| wandlet_oauth_state | Ties a sign-in attempt to your browser so it can't be hijacked. | Essential |
| wandlet-consent | Remembers the cookie choice you made, so we don't ask again. | Essential |
| wandlet-theme | Remembers whether you picked the light or dark theme. | Optional — off unless you allow it |
Who else sees it
The AI provider, which receives the selected text. Google or GitHub, only if you choose to sign in with them. Our hosting provider, which runs the servers. Nobody else — we don't sell data and we don't use it for advertising.
How long we keep it
A session lasts until it expires or you sign out. Your account details and usage records exist while your account does — delete the account and they go with it. You can export or delete everything from your account page.
Your rights
In the EU and EEA you can ask for access to your data, correction, deletion, a copy to take elsewhere, and you can object to processing (GDPR Articles 15–21). Write to the address in the Impressum. You can also complain to your local data protection authority.
Changes
If this policy changes we update the date at the top, and for anything significant we say so in the app.