THE WHEEL

Memory is not enough. Private work requires agency.

A crowd with one person highlighted inside The Wheel’s cog

The Wheel is built to explain what happens to sensitive information in plain language. What enters, what stays encrypted, what leaves, and who can revoke access. This level of protection should not require a corporate contract or a personal server you run yourself.

AI that puts you in control.

You ask from your own record.

The question starts where the relevant notes, calls, and decisions already live, encrypted in your browser before they reached our servers.

The Wheel finds what the work needs.

Search locates the right documents without unlocking your whole library. Only the matches you select get opened, and only while you’re working with them.

Answers are grounded in your sources.

You get answers built from your own material, with the sources shown rather than summarized away.

Nothing leaves without your permission.

In the product a permission is a grant: one provider, one purpose, one hour or thirty days, revocable. Every request checks the grant before anything leaves. No valid grant, no movement.

The record shows what moved.

Your receipts page shows every permission you have given: what entered, what stayed private, what left and with which permission, and what came back.

Mechanics you can point to, not just promises.

Encryption in your browser

Your notes and uploads are encrypted in your browser before they reach our servers. Keys are unlocked, never held: no raw key is stored anywhere, on any side. When you search, the key exists only in server memory while you work and is wiped when the session closes. That boundary is physical, not a policy.

Access by permission

You give permission once, as a grant. Every request checks it before anything leaves. You can revoke it at any time. Once something reaches an external provider, their logging is governed by their policies. That is why every external call is explicit and on the record here.

Receipts

Your receipts page shows every permission: what entered, what stayed private, what left, and what came back. You can inspect each one and take it back.

Deletion and export

Your data belongs to you. You can export it, and you can delete content on demand, including before any hypothetical change of control.

How the keys work

Your PIN opens a key for one task. The key exists only for that task, is never written down on any side, and seals again when the task ends.

Wondering what the original jointhewheel.com website collects? A beta-access email if you give us one, and anonymous page counts. That’s the list. Details in the privacy policy.

Four questions The Wheel always answers

What entered

Sources and notes.

What's private

Your encrypted library

What left and where

Receipts for user-granted external use

What came back

A record of your complete data

The Wheel only see what you ask us to.

By default, your notes and uploads sit as ciphertext, with the keys in your hands. You grant AI-processing consent once; every request checks that grant before anything leaves. Granting access so the AI can help is privacy working, not privacy failing.

The alternative isn’t perfect secrecy. It’s no control: most AI products read your data by default, keys held by the vendor. We built the opposite: dark until you say otherwise.

Read the FAQ →

A no-training promise can be true and still incomplete. Before sharing sensitive work, consider how a provider can use your data under its own terms.

What is collected, specifically.

Can the company train, improve, develop, or evaluate with your content? The verb changes the answer.

What happens to de-identified or aggregated versions of your data?

Who owns what the system learned about you: inferences, memory, writing-style profiles?

What leaves the platform when AI processes a request, and did you know before it left?

Do the terms grant rights beyond training, such as “improve,” “develop,” “create derivative works”, and do those rights survive account closure?

What survives deletion? Safety logs, compliance holds, and memory features can outlive a delete.

Can your conversations inform advertising, even with training off?

Does the promise change by tier, or does everyone get the same protections?

Check the receipts of this site right in your browser