Use cases Privacy FAQ Blog About Request beta access
Privacy by architecture

Protection asks who should be kept out. Ownership asks who has the right to decide.

Useful AI needs context. Private work needs custody. The Wheel is built so you can explain what happens to sensitive information in plain language: what enters, what stays encrypted, what leaves, and who can revoke access. It should not require an enterprise contract or a server you run yourself.

The decision point

The privacy question is really a custody question.

The frame we inherited · policy

“Will this vendor promise not to misuse the data?”

Policy matters, but it acts after the architecture has already decided where the data went and who could read it.

The frame we built for · custody

“Who decides what leaves, and can they take it back?”

Keys are unlocked for a task and never held, and the architecture enforces what you decide. Access that is limited, recorded, and reversible is not a privacy compromise; it’s privacy with a working control surface.

Privacy is not the absence of sharing. It is the ability to decide what is shared, why, who receives it, and when that access ends.

How context moves

What flows in, what stays private, what comes back.

You ask from your own record.

The question starts where the relevant notes, calls, and decisions already live, encrypted in your browser before they reached our servers.

The Wheel finds what the work needs.

Search locates the right documents without unlocking your whole library. Only the matches you select get opened, and only while you’re working with them.

Answers are grounded in your sources.

You get answers built from your own material, with the sources shown rather than summarized away.

Nothing leaves without your permission.

In the product a permission is a grant: one provider, one purpose, one hour or thirty days, revocable. Every request checks the grant before anything leaves. No valid grant, no movement.

The record shows what moved.

Your receipts page shows every permission you have given: what entered, what stayed private, what left and with which permission, and what came back.

The mechanisms

Four things you can point at, not promises.

Encryption in your browser

Your notes and uploads are encrypted in your browser before they reach our servers. Keys are unlocked, never held: no raw key is stored anywhere, on any side. When you search, the key exists only in server memory while you work and is wiped when the session closes. That boundary is physical, not a policy.

Access by permission

You give permission once, as a grant. Every request checks it before anything leaves. You can revoke it at any time. Once something reaches an external provider, their logging is governed by their policies. That is why every external call is explicit and on the record here.

Receipts

Your receipts page shows every permission: what entered, what stayed private, what left, and what came back. You can inspect each one and take it back.

Deletion and export

Your data belongs to you. You can export it, and you can delete content on demand, including before any hypothetical change of control.

How the keys work. Your PIN opens a key for one task. The key exists only for that task, is never written down on any side, and seals again when the task ends.

Wondering what this website itself collects? A beta-access email if you give us one, and anonymous page counts. That’s the list. Details in the privacy policy.

The handoff

An outside model gets enough context to help you reason, and no more.

Before anything reaches an outside model, three things happen. Your permission is checked. The receipt line is written before the request leaves, not after. And identifying details are swapped for neutral placeholders.

Your context, in your record

“We passed on the Acme Corp enterprise deal in Q3. Darryl from sales flagged integration concerns based on the technical review from August 12th. The $240K ARR wasn’t worth the custom work given our roadmap priorities.”

What actually goes out

“We passed on the [company] enterprise deal in [quarter]. [A colleague] from sales flagged integration concerns based on the technical review from [date]. The [amount] ARR wasn’t worth the custom work given our roadmap priorities.”

Detection is automatic, but no detector is perfect. That is why the receipt exists: what left, which provider, which permission, all on the record. The beta runs a fixed set of frontier and open-source models; over time, routing matches each question to the model that fits best. The most sensitive work never leaves at all: document-focused and privacy-sensitive questions run on a small model inside The Wheel’s private cloud.

The receipt contract

Four questions, always answerable.

Your receipts page shows every grant, and you can inspect or take back each one. Every run carries a full four-layer trace: result, trace, custody, what’s next.

An empty record is never presented as proof that nothing left.

The receipt: four questions, always answerable

What enteredthe sources and notes you brought into the work.
What stayed privateeverything that never left your encrypted library.
What left, and wherewhat reached an external model, under which grant.
What came backthe answers and summaries that returned to your record.
Access by your authority

We see your work when you ask us to.

By default, your notes and uploads sit as ciphertext, with the keys in your hands. You grant AI-processing consent once; every request checks that grant before anything leaves. Granting access so the AI can help is privacy working, not privacy failing.

The alternative isn’t perfect secrecy. It’s no control: most AI products read your data by default, keys held by the vendor. We built the opposite: dark until you say otherwise.

Read the FAQ →
Nine mechanisms to check

A no-training promise can be true, and still incomplete. The full picture takes nine questions.

Before you share sensitive work with any AI product, check these nine mechanisms. They shape how a provider can use your data under its own terms, and no-training language alone does not cover them.

What is collected, specifically.

Can the company train, improve, develop, or evaluate with your content? The verb changes the answer.

What happens to de-identified or aggregated versions of your data?

Who owns what the system learned about you: inferences, memory, writing-style profiles?

What leaves the platform when AI processes a request, and did you know before it left?

Do the terms grant rights beyond training, such as “improve,” “develop,” “create derivative works”, and do those rights survive account closure?

What survives deletion? Safety logs, compliance holds, and memory features can outlive a delete.

Can your conversations inform advertising, even with training off?

Does the promise change by tier, or does everyone get the same protections?

From the blog

I’m the Person Who Reads the Terms

What happens when you actually read the privacy policies of the tools you use every day, and what the answers tell you about who controls your work.

Read the post →

Privacy in practice

What custody looks like in the product.

A 45–60 second demonstration of the full custody loop, from question to receipt.

You ask a question from your record.

The question starts inside your encrypted library.

The relevant sources are selected.

Search surfaces matches without opening your whole library.

Your processing consent is checked.

You grant AI-processing consent once. Every request checks that grant before anything leaves. You can revoke it at any time, and no content moves until a valid grant exists.

The receipt line is written before the request leaves.

What is being sent, to which provider, under which permission. The receipt exists before the external call, not after.

The answer returns, grounded in your sources.

Citations point back to your original material, not to a summary.

The receipt shows what moved.

What entered, what stayed private, what left, what came back. Inspectable and revocable.

45–60 second product demonstration · in production

This page will embed the recording when it is ready.

The receipt

Check what this site does, right here in your browser.