Privacy
Wandlet rewrites text you select. This page says what leaves your device, what we keep, and what we never do.
Last updated 26 August 2026 · Applies to the Wandlet app and to wandlet.app.
This is the whole policy, not a summary of a longer document — written plainly so it can actually be read. Questions go to the address in the legal notice.
The short version
- Only the text you selected is sent. Not your keystrokes, not your files, not the rest of your clipboard.
- It travels over TLS, is passed to the AI provider, and streams straight back. It is not stored and not used for training.
- No advertising, no ad networks, no profiles, nothing sold.
- Analytics only if you say yes. Decline and nothing is loaded — not a script, not a request.
- Signing in is optional. If you never sign in, there is no account and nothing personal to hold.
Who we are
Wandlet is provided by ModelStat, a sole proprietorship registered in the Netherlands, trading as Wandlet. ModelStat is the data controller. The legal notice carries the registered address and contact details for everything on this page.
What we collect
If you sign in with Google or GitHub: your email address and name, so we know which account is yours. A session token that keeps you signed in. And a usage record — which action you ran and when — so your limit can be counted and shown back to you.
That usage record does not include the text you transformed. It does include what the action cost in credits, and which account paid — because for a team action, that is not always you.
If you buy credits
Payments are handled by Stripe, which acts as its own controller for the payment itself. When you buy credits you give Stripe your card details and billing information directly — we never see or store them. Stripe tells us that a payment succeeded, for which account and how much, and gives us a customer reference so your receipts stay together. That is all we keep.
We hold a record of each purchase and each credit movement on your account, because it is your balance and an accounting record we are required to keep. Stripe's own handling of your data is covered by its privacy policy.
Teams
If you invite someone to a team, we process the email address you give us in order to send them one invitation. If they never accept, the invitation expires and is deleted.
If you join a team, the team's owner can see how many credits you have spent running the team's actions, and can set a limit on it. They cannot see the text you transformed — nobody can. This is the direct consequence of the owner paying for your usage, and accepting the invitation is where you agree to it.
Files you publish
If you use an action that publishes a file — an artifact — we store that file so the share link works, and it is served to anyone who has the link until it expires. What you put in it is up to you; this is the one part of Wandlet that stores your content rather than passing it through. You can delete an artifact from your account page at any time, and they expire on their own.
The text you transform
When you run an action, the text you selected — and nothing else — is sent over an encrypted (TLS) connection, passed to the AI provider that generates the rewrite, and streamed straight back to you. It is not stored, and it is not used to train any model.
The provider may process it on servers outside the European Economic Area, so please don't transform passwords, full payment card numbers or health details.
What the app can see on your device
The desktop app watches for one thing: the double-tap of ⇧ Shift. It reads and writes the clipboard only at the moment you run an action, and puts back what was there before. It checks whether the field you are in can be edited, so it knows whether to replace or fall back to the clipboard.
It does not log your keystrokes and does not watch what you type.
One thing the app reports on its own: if its hotkey listener stops receiving keystrokes — which the app notices itself, and which is usually the operating system withdrawing a permission — it tells our server that this version, on this operating system, lost its shortcut. That message contains nothing about you and nothing you typed. It exists because a broken shortcut is invisible from our side: you would simply find that Wandlet stopped working, and we would never know.
Cookies and local storage
This is the whole list. Everything above the last two rows is strictly necessary to run a service you asked for; those two are yours to allow or refuse.
| What | Purpose | Consent |
|---|---|---|
| wandlet_session | Keeps you signed in after you use Google or GitHub. | Essential |
| wandlet_oauth_state | Ties a sign-in attempt to your browser so it can't be hijacked. | Essential |
| wandlet-consent | Remembers the cookie choice you made, so we don't ask again. | Essential |
| wandlet-theme | Remembers whether you picked the light or dark theme. | Optional — off unless you allow it |
| ph_… | A random id that lets PostHog count your visits as one person rather than several. Stored in your browser, not a cookie. Deleted the moment you decline. | Optional — off unless you allow it |
Analytics
If — and only if — you allow it in the cookie banner, this website loads PostHog, hosted in the European Union, to count pageviews and clicks. It tells us which pages get read and where people give up. It does not record your screen, and it does not capture what you type into a form.
Decline and nothing is loaded at all — not the script, not a request, not an identifier. Change your mind either way from ; withdrawing takes effect immediately and deletes the identifier.
Separately, and regardless of that choice, we count things on our own servers that never involve your browser: how many actions were run, and on which plan. Those are tied to your account, not to a tracking id, and they are the same numbers your usage page shows you.
Who else sees it
The AI provider, which receives the selected text. Google or GitHub, only if you choose to sign in with them. Stripe, if you buy credits. Resend, which delivers the few emails we send — a waitlist confirmation, a team invitation — and therefore receives the address it is sent to. Our hosting provider, which runs the servers. PostHog, if you allowed analytics. Slack, which receives an operational alert when someone creates an account, buys credits or sends feedback — that message contains the email address you signed up with, so that a small team can answer you. Nobody else — we don't sell data and we don't use it for advertising.
How long we keep it
A session lasts until it expires or you sign out. Your account details and usage records exist while your account does — delete the account and they go with it. You can export or delete everything from your account page.
Your rights
In the EU and EEA you can ask for access to your data, correction, deletion, a copy to take elsewhere, and you can object to processing (GDPR Articles 15–21). Write to the address in the Legal notice. You can also complain to your local data protection authority.
Changes
If this policy changes we update the date at the top, and for anything significant we say so in the app.