HOW IT WORKS · SECURITY
Where the work runs.
A Wend note does the work on your own Mac, not on our servers. Here is the path it travels and the model that keeps it in bounds.
How dispatch works.
- 01
You write on your phone.
The note is a plain document. Tap send and it heads for your paired Mac.
- 02
It reaches your Mac.
The Wend daemon on your Mac receives the note over an encrypted tunnel, auto-detects the right local repo, and stages the run.
- 03
Claude Code runs in your repo.
The daemon runs Claude Code against your actual repo, env, and CLIs, under the permissions you've already given Claude Code on your Mac.
- 04
The result streams back.
Output returns inside the same note, as a foldable block, streamed at reading speed.
Where your data lives.
Your prompts, code, and results run on your own Mac. They are not stored on Wend's servers.
In Mac mode, traffic travels directly between your phone and your Mac over an encrypted Cloudflare tunnel. It transits Cloudflare's edge in transit under TLS, but Wend never persists it. Cloud dispatch is disabled during alpha; Mac is the only path.
The safety model.
It uses your own Claude Code permissions.
A note can only do what you've already allowed Claude Code to do on your Mac — same config, same rules. Wend grants it no powers of its own.
No second key to your machine.
Wend runs Claude Code under your existing setup. If an action needs a permission you haven't granted Claude, it doesn't happen — exactly as at your desk.
Every run stays in the note.
The full run — what Claude did and which files it touched — streams back into the same note as a foldable block you can review.
What the backend stores.
- Your account, handled by Clerk (email and sign-in).
- A per-device pairing token, stored hashed — never in the clear.
- A push-notification token, so your phone can be pinged when a run finishes.
- Anonymous run stats — count, duration, cost — with no note, prompt, or code content, used to keep dispatch reliable.
What it never stores: No note text, no prompt text, no code, no results. Those stay on your Mac.
About the unsigned app.
The Mac app is currently unsigned — Apple notarization is pending. macOS Gatekeeper will warn you on first launch.
To open it the first time: right-click (or Control-click) the Wend icon in Applications, choose Open, then Open again in the dialog. One-time step, per machine.
Full install steps live on the download page.