You ask from your own record.
The question starts where the relevant notes, calls, and decisions already live, encrypted in your browser before they reached our servers.
The Wheel is built to explain what happens to sensitive information in plain language. What enters, what stays encrypted, what leaves, and who can revoke access. This level of protection should not require a corporate contract or a personal server you run yourself.
The question starts where the relevant notes, calls, and decisions already live, encrypted in your browser before they reached our servers.
Search locates the right documents without unlocking your whole library. Only the matches you select get opened, and only while you’re working with them.
You get answers built from your own material, with the sources shown rather than summarized away.
In the product a permission is a grant: one provider, one purpose, one hour or thirty days, revocable. Every request checks the grant before anything leaves. No valid grant, no movement.
Your receipts page shows every permission you have given: what entered, what stayed private, what left and with which permission, and what came back.
Your notes and uploads are encrypted in your browser before they reach our servers. Keys are unlocked, never held: no raw key is stored anywhere, on any side. When you search, the key exists only in server memory while you work and is wiped when the session closes. That boundary is physical, not a policy.
You give permission once, as a grant. Every request checks it before anything leaves. You can revoke it at any time. Once something reaches an external provider, their logging is governed by their policies. That is why every external call is explicit and on the record here.
Your receipts page shows every permission: what entered, what stayed private, what left, and what came back. You can inspect each one and take it back.
Your data belongs to you. You can export it, and you can delete content on demand, including before any hypothetical change of control.
Your PIN opens a key for one task. The key exists only for that task, is never written down on any side, and seals again when the task ends.
Wondering what the original jointhewheel.com website collects? A beta-access email if you give us one, and anonymous page counts. That’s the list. Details in the privacy policy.
Sources and notes.
Your encrypted library
Receipts for user-granted external use
A record of your complete data
By default, your notes and uploads sit as ciphertext, with the keys in your hands. You grant AI-processing consent once; every request checks that grant before anything leaves. Granting access so the AI can help is privacy working, not privacy failing.
The alternative isn’t perfect secrecy. It’s no control: most AI products read your data by default, keys held by the vendor. We built the opposite: dark until you say otherwise.