Privacy
What we actually do with your data,explained to your grandmother
A plain-language account of what Waldo may access, what stays private, and what you control.

Listen
Loading audio · System voice
In this article
Almost nobody reads a privacy policy. They are written by lawyers, for other lawyers, in a font size chosen to end the conversation.
So here it is another way: the version you might explain to your grandmother. She is sharp, suspicious of anything free, and very likely to ask the one question you were hoping to skip.
Start with the permission#
Waldo does not arrive with permission to everything. You choose the tools it can use. Each connection has a specific job, and the autonomy setting decides whether Waldo explains an action, asks before taking it, or carries it out on its own.
No connection means no access. Removing a connection means Waldo stops using it. That is the first privacy rule because it is the one you can inspect without trusting a slogan.
Your private messages stay private#
Waldo needs to understand the shape of your day. That does not mean it needs to read every sentence you send.
For communication tools, the useful signals are metadata: volume, timing, and urgency. A crowded morning looks different from a quiet one. A burst of late activity looks different from a normal close to the day. Waldo can use that shape without reading the contents of your private messages.
This boundary matters. "Connect your inbox" should not quietly become "hand a machine every conversation you have ever had."
Your body is context, not content#
Your watch or ring records heart rate, sleep, movement, and other signals. Waldo uses those signals to understand what your day can reasonably ask of you.
The product is designed so biometric data stays on-device and inside your private Waldo instance. It is encrypted at rest and in transit. Waldo does not sell it, share it with third parties, or use it to train models.
That is not a medical claim. Waldo does not diagnose, treat, or prevent anything. It uses the signals your wearable already provides as context for ordinary decisions about time, load, and attention.
What an action should show you#
When Waldo moves something, the action should never appear out of nowhere. You see the reason, the tool it touched, and the change it made. You also keep the undo.
If the reason is wrong, the correction matters. The goal is not a mysterious system that becomes more confident while you become less certain. The goal is an agent you can inspect and correct.
This is also why autonomy is a setting rather than a personality test. You may want Waldo to suggest calendar changes and automatically handle a smaller class of routine actions. Someone else may want approval for everything. Both are legitimate.
What we will not decorate with a badge#
Security certifications mean something when an independent process has earned them. They mean nothing when a marketing page prints the logo early.
We will not claim certifications Waldo has not earned. We will not imply that encryption makes a product invulnerable. We will publish the concrete controls and legal terms that apply before asking you to trust sensitive data to the product.
European data law gives people qualified rights to access, correct, erase, and move personal data. Those rights are a baseline, not a personality trait a company gets to award itself.
The short version for the fridge#
You choose the connections. Private message content stays private. Biometric data stays on-device and inside your private Waldo instance. It is encrypted, never sold, never shared with third parties, and never used to train models.
Waldo should be able to explain what it touched and let you undo it. If that standard is not met, it is not ready for your data.