Skip to content

Local control

Wenlan Local Data and Privacy

Where Wenlan stores local AI work memory, what stays on your machine, and when connected model providers may see prompts.

Qi-Xuan LuUpdated 7 min read

At a glance

01

Quick answer: Wenlan's daemon, database, pages, sessions, and readable artifacts live locally by default.

02

Connected AI clients may still send prompts to their model providers; Wenlan keeps its own memory store local, inspectable, and removable.

03

The public wenlan.app website uses separate privacy-limited analytics; installed Wenlan still has no cloud sync or product telemetry by default.

01

Quick answer: what stays local

Wenlan's durable memory store, daemon database, Markdown pages, session handoffs, and project status files live on your machine by default.

There is no Wenlan cloud sync or telemetry path by default. Connected AI clients may still send prompts to their own providers, so treat memory content as sensitive project data.

02

Public website analytics

The public wenlan.app website is separate from the installed Wenlan runtime. It uses Vercel Web Analytics for aggregate website visits. Optional Umami and first-party collection can record bounded website actions such as downloads, GitHub links, setup links, release subscriptions, video-play clicks, example choices, source expansion, comparisons, and product-image views. These operation counts are not unique visitors, completed downloads, installations, or proof that a channel caused an action.

The Umami tracker is restricted to wenlan.app, excludes URL search parameters, and respects the browser's Do Not Track setting. Events carry placement, locale, content context, and a fixed destination category. Known launch links may also carry a predefined campaign, source, and medium; direct release-asset clicks include the public asset ID and release tag. Arbitrary query strings, memory content, code, commands, user file paths, names, email addresses, and stable account identifiers are not sent as event properties. A video-play click records intent to play, not viewing duration or completion.

The website stores a sanitized first landing path, referrer host, and UTM source, medium, and campaign in per-tab sessionStorage. It reuses that context for 30 minutes, then replaces it on the next capture; this is not a persistent visitor ID. Optional capture is skipped for Do Not Track. The form sends the submitted email to Resend. When acquisition properties are enabled, those fields and the signup locale are stored with the contact. Only predefined launch campaign labels, not the contact or arbitrary attribution fields, can be included in Umami events. GitHub's cumulative release download counters remain separate from individual contacts.

This website measurement does not add cloud sync or telemetry to installed Wenlan.

When enabled, the first-party endpoint stores daily aggregate operation counts in a dedicated Postgres database without automatic expiration. It accepts only known public page paths, finite event and source labels, language, placement, predefined interaction choices, and current release-asset identifiers. It does not store raw event timelines, submitted email, arbitrary referrer URLs, URL query strings, IP addresses, user-agent strings, cookies, or persistent visitor IDs in its analytics records. Infrastructure providers still process network requests under their own policies. The client respects Do Not Track and Global Privacy Control. Collection can be blocked, unavailable or rate-limited; reports disclose missing coverage and limits instead of treating missing data as zero. Source labels are client-reported context, not verified attribution.

03

Where data lives

Wenlan exposes human-facing artifacts under ~/.wenlan. The daemon database lives under the operating system's application data directory and is linked from ~/.wenlan/db for convenience.

The important files are readable without a special app: pages are Markdown, session logs are Markdown, and project status is stored beside the session records.

  • ~/.wenlan/pages/: distilled wiki pages.
  • ~/.wenlan/sessions/: session handoff logs.
  • ~/.wenlan/sessions/_status/: current project status records.
  • ~/.wenlan/bin/: installed Wenlan CLI, daemon, and MCP connector binaries.
  • ~/.wenlan/db/: link to the daemon's local database store.
  • macOS: ~/Library/Application Support/wenlan/.
  • Linux: ~/.local/share/wenlan/ or $XDG_DATA_HOME/wenlan/.
  • Windows: %LOCALAPPDATA%\origin\ (current runtime legacy directory).

04

Readable artifacts and retrieval

Raw captures and recall live in the daemon-owned store. Pages, session logs, and project status are readable Markdown projections under ~/.wenlan.

This keeps search fast and structured while giving people inspectable artifacts for pages, handoffs, and status without pretending every memory is a Markdown file.

05

Local memory setup

Wenlan stores, embeds, deduplicates, and serves hybrid search without requiring a local model download or Anthropic API key.

ANTHROPIC_API_KEY is only used when you explicitly opt into daemon-side Anthropic work with the key setup path. Optional model and API paths can add heavier language features, but they are not required for the basic memory loop.

06

Correction and deletion

If a memory is wrong, capture the correction with why it supersedes the old fact. If a memory should be removed entirely, use /forget with the memory ID.

Delete and forget operations are separate from service uninstall. For distilled pages, inspect the Markdown directly. User-edited pages are treated carefully so automated distillation does not overwrite human work casually.

07

Optional wenlan-relay connector (pre-release)

The standalone relay connector is pre-release and is not part of the installed public release defaults. It is not yet a publicly approved marketplace listing. You authorize a connected AI client through OAuth and approve its request in Wenlan on your device. Access is limited to one selected existing Space; changing that Space needs fresh explicit consent, and newly created Spaces are not automatically included.

Your knowledge library stays on your device; the relay keeps control-plane records so it can authenticate, route, and limit sessions. The public MCP endpoint is https://relay.wenlan.app/mcp. It exposes only three query tools — brief, recall, and get_page_sources — and recall still records the query and accessed memory identifiers in local activity history. The connected device must stay online so the relay can route each request to it and return the result.

Requests and results pass through Cloudflare's relay infrastructure to the connected AI client and, where applicable, its provider. Cloudflare and Wenlan's relay administrator can read requests and results while processing them. HTTPS protects traffic in transit; it is not end-to-end encryption that excludes these operators. Do not connect a Space containing credentials or other restricted text: the connector does not classify or redact sensitive content embedded in knowledge.

Technical expiry only denies further access and is not a physical-deletion time. Cleanup runs in bounded batches on a recurring schedule, so an outage or backlog can delay physical deletion beyond expiry, and infrastructure providers may retain their own diagnostics. There is no automatic migration of legacy relay records into this connector.

To stop access, disable Remote Access or revoke the relevant client grant, and retry if the app reports a pending disconnect. A confirmed disconnect removes the old device-management credential from the local profile and replaces the local connector credential; settings, knowledge, and activity records remain until separately deleted. Revoking access does not delete a query or result the connected client or its provider already received.

  • Categories: device and route identifiers, management-credential hashes plus the backend connector credential needed for routing, pairing and authorization identifiers with OAuth request fields and PKCE challenge, client registration metadata, token and grant receipts with device/route/Space bindings, session mappings, and IP-hash rate counters.
  • Purposes: pairing and consent checks, request routing to the online device, session binding, and abuse control.
  • Recipients: Cloudflare as the storage and network infrastructure provider, Wenlan's relay administrator for service operation, and the connected AI client and its provider for each query and returned result.
  • Retention: pairing and authorization requests and pending enrollments expire after 5 minutes; route and session mappings after 24 hours; access tokens after 15 minutes; refresh tokens, management credentials, and consent/grant records after 30 days; client registrations after 90 days. Aggregate abuse-control counters expire at the end of the current minute, hour, or UTC day depending on the endpoint.

Next

Backup and Migration

Back up Wenlan's readable artifacts and daemon data together, then verify the restored runtime before trusting recall.

Read next