Privacy policy

This page describes what each app actually does with your data. Where an app sends something off your device, it is named below.

Wy5

Your rankings are sent to a Wyome server so they can be counted into the community totals. You are identified by Apple’s anonymous identifier or by a device identifier — no name and no email address is stored, and there are no display names anywhere. Signing in uses Sign in with Apple, and it asks Apple for no name and no email address, so Apple passes on nothing but that anonymous identifier. Published standings are anonymous aggregates. Looking up a film, album or book queries Wikipedia and Wikidata.

Links to Amazon carry a Wyome affiliate tag, so Amazon can attribute a resulting purchase to Wyome and we may earn a commission. They are search links rather than product links, and nothing about you is sent to Amazon beyond the search itself and that tag. This is the only commercial tracking in any of the five.

Wy5 Premium is an auto-renewable subscription handled entirely by Apple. Wyome never sees your payment details, and whether you subscribe is not sent to the Wyome server.

WyHome

Everything you record stays on your device. There is one exception: finding a contractor. Searching sends the search text to Apple Maps, along with your location if you allow it, so results can be local. If you search near your home address, that address is sent to Apple to turn it into a map location. Reminders and calendar entries are written into your own Apple apps.

WyAuto

Everything stays on your iPhone. There is no account, no analytics, and no network requests of any kind.

WyHealth

This is the only one of the five that handles health data, and it is the only one where what you store is sent to a Wyome server by design rather than as an aggregate. The iPhone app reads the Apple Health categories you approve and uploads them; the website reads them back. You choose the categories when the app first asks and can change or withdraw them at any time in iOS Settings under Privacy & Security → Health. Signing in uses your Apple account and no password is ever stored.

Lab results are yours to enter, by typing them or uploading a PDF. An uploaded PDF is stored, and its text is sent to Anthropic’s Claude API to pull out the marker names and values; that content is not used to train models. Whatever comes back is shown to you to confirm or correct before it is saved. If you subscribe, the written commentary on your dashboard is also produced by that API from your figures.

Every row is scoped to your account in the database itself rather than by the code that queries it, so one account cannot read another’s data even if a query is wrong. Readings and values are never written to server logs — the logs record how many samples arrived and of what type, never what they said.

Your health data is not sold, not shared with advertisers, not used to train anything, and not shown to anyone else. There is no public element to WyHealth as there is to Athenana: nothing you store appears on a public page, and there is no community aggregate.

Payment, if you subscribe, is handled by Stripe on the website. Wyome never sees your card details.

Athenana

Items you save are stored on a server operated by Wyome. When you save a link, the server fetches that page, keeps a copy of it and a screenshot, and uses them for tagging and search. Signing in uses your Apple account and no password is ever stored. Pages and images you save are sent to Anthropic’s Claude API so they can be tagged automatically, so text in images can be read, and so a saved page can be summarised; that content is not used to train models. The same API ranks the morning reading list described below.

You can also save into Athenana from a browser extension for Safari and Chrome, and from a Shortcut on iPhone and iPad. The extension sends the page’s address and title, its description and preview image where the page publishes them, and a screenshot of the visible tab — plus the text you had selected, if you saved a highlight. It sends these only when you click its button or use its right-click item: it does not read the pages you visit otherwise, and it does not run in the background. Because that screenshot is taken by your own browser rather than by the server, it shows the page as you were seeing it, including anything you were signed in to. The Shortcut saves a link or a photo you share to it, using a token that can do nothing but add items.

Nothing you save is published unless you turn publishing on for your account, which is off until you do. Each item then sits at one of three levels. Private is yours alone. Blog gives it an address of its own and puts it on your blog. Public is all of that and adds it to Athenana’s shared front page. A single account setting still hides everything whatever the individual items say, and it is deliberately a separate switch from the one that turns publishing on — an emergency stop and an opt-in are different things.

The shared front page carries saved links and nothing else. A note, a highlight and an image can reach the blog level but never that page, because it is an anonymous stream and those are your own words, your own choice of passage and your own picture. Screenshots are never published anywhere, because a screenshot photographs the tab as it was and can catch a page you were signed in to. The pictures on the front page come from the publisher of the page being linked to, and a private comment you attach to a link is not published with it.

That front page is also a feed, at feed.xml and feed.json, and a blog carries its own. Worth knowing before you publish something: a page can be edited or taken down, but a feed entry has already been fetched and stored by whatever was subscribed to it.

A blog exists only if you choose a handle for it on your account page, and it lives at athenana.com/blog/ plus that handle. No handle means no blog and no address; the handle is the whole opt-in. It is independent of the shared front page, so you can have either without the other.

When a link is on the front page, the site it points to is told so, using the web’s standard Webmention notification; it carries the front page’s address and the link itself and nothing else, and sites that accept these often display them publicly. When a link leaves the front page, a follow-up notice is sent so the site can drop the mention.

Athenana counts how often each link on that front page is followed. A link there that points to another site goes through Athenana’s server before it takes you on, so that the following can be counted; what is stored is which link, and when. Not who: no address, no cookie and no identifier of any kind is kept beside it, so nothing there can tell one reader from another, or the same reader twice. Requests that say they are robots, and the invisible fetches a browser makes to speed up pages you have not clicked, are not counted — a robot that does not say so is. The counts are deleted after ninety days, and nothing on a blog, on a link’s own page, in a feed, or behind a sign-in is counted at all.

Those counts choose the five links in a weekly email you can ask for. If you ask, your address is stored so the email can be sent to you, and you are sent a link to confirm you meant it: nothing goes to an address that has not followed that link. It is used for nothing else and given to nobody, every issue carries a link that removes you, and the email itself carries no tracking — its links go straight where they point, and there is no image in it that reports whether you opened it.

Some sites refuse to serve a page to a server while serving it normally to a browser. When that happens Athenana asks the Internet Archive for an older copy, which means that page’s address is sent to archive.org. Only the address, and only for a page that could not be fetched directly.

Athenana also builds a reading list for you each morning, and building it means searching outside your own collection. It takes fifteen topics — the ten tags you use most, plus five drawn at random from the rest of the tags you use — and searches three places for each: Google News, Hacker News (through Algolia, which runs its search) and Flipboard. Only the topic word is sent, by the server rather than by your browser, with no identifier, no cookie and nothing about what you have saved; what comes back is a list of links to follow if you want them, and nothing on that page loads from any of the three. What those three do see, over time, is what this account reads about — the topics come from your own tags rather than from a generic list. A topic you drop on the Discover screen is never searched for again.

A saved song gets a play button, and so does a saved YouTube link. Along with a saved podcast episode, described next, it is one of the few things here that can reach somebody reading a page rather than the person whose account it is. When you save an Apple Music link, Athenana recognises it as a song from the address itself — it makes no extra request to Apple to do that — and asks YouTube whether it has the same recording, sending the artist and title and nothing about you. When you save a YouTube link there is nothing to ask: the address already names the video, so the server only fetches its cover picture. Either way, that cover is copied onto Athenana’s own server. That copy is the point: a page with a video on it loads nothing from Google and tells Google nothing, not even that the page was opened. Pressing play is the moment that changes. The player then loads from youtube-nocookie.com, and Google sees your IP address and which video you played. Play buttons can appear on the shared front page and on blogs, not only on your own pages, so this is worth knowing whether or not you have an account.

A saved podcast episode gets a play button too. Athenana reads the episode’s details — the show, the title, how long it runs — from the page it saved, and copies the artwork onto its own server, so a page carrying an episode loads nothing from anyone until you press play. What plays is not stored here: the audio comes from wherever the show is hosted, which differs from show to show and is often a redirect that exists to count downloads. That host sees your IP address and that the episode was played. Like the video player, the button carries no address for the audio until you press it, and like the video player it can appear on public pages as well as your own.

You can also forward an email into Athenana, to an address of your own that only you know. The message is saved as a page: its text, and the pictures it carries. A picture the sender attached inside the message needs no request — it arrived with it. A picture the message merely links to somewhere else is fetched once, by the server, when the message is saved, and a copy is stored. Newsletters carry invisible images whose only purpose is to tell the sender that a message was opened, and by whom, so anything declaring itself 1×1 or 0×0 — the shape of a tracking pixel — is never requested. A tracker that declares an ordinary size is requested like any other picture, so this reduces that tracking rather than preventing it. Reading a saved message shows you its words and not its pictures: the reading view carries no image of any kind. The stored pictures become the item’s thumbnail and the photograph Athenana takes of the message itself, which is where you see how it arrived. Every one of them is served from Athenana’s own server, so reading a saved message contacts nobody.

You can also post into Athenana from any third-party app that speaks Micropub, the web’s standard for that. Such an app works only with a token you issue to it from your own account, and you can revoke it.

Common to all

None of the five carries advertising, and none carries a third-party tracker that runs on its own. The one thing counted anywhere is Athenana’s tally of how often each front-page link is followed, described above — a number against a link, kept on Wyome’s own server, with nothing beside it that identifies anyone. There are two third-party players anywhere — the YouTube player behind a saved song’s play button in Athenana, and the audio player behind a saved podcast episode’s — and each loads only when you press play, as described above. The one commercial identifier anywhere is Wy5’s Amazon affiliate tag, described above. No data from any of them is sold, and none is shared with anyone except where this page says otherwise — Apple Maps for WyHome’s contractor search, Wikipedia and Wikidata for Wy5’s look-ups, Amazon for Wy5’s shopping links, the Claude API for Athenana’s tagging, summaries and reading-list ranking and for reading WyHealth’s lab uploads, Stripe for WyHealth’s subscriptions, the Internet Archive when a site refuses to serve Athenana a page, Google when Athenana looks for a saved song’s video or you press play on one, a podcast’s own host when you press play on a saved episode, Google News, Hacker News and Flipboard when Athenana searches for your morning reading list, and the Webmention notices Athenana’s front page sends to the sites it links.

This website

wyome.com itself sets no cookies, runs no JavaScript and contains no analytics. Its fonts are served from this site rather than from a font network, so loading a page here contacts nobody but this server.

Like nearly every web server, this one records each request it serves in a log: the address of the page requested, the time, the requesting computer’s IP address, the browser it identified itself as, and — where the browser sends one — the address of the page you followed a link from. These logs are kept for about a week and then deleted automatically. They are not analytics: nothing is added to a page to produce them, no identifier is set, and no visitor is followed from one page to the next.

The site statistics page publishes two narrow slices of those logs. The first is referrals: the addresses of pages that linked here, how many times each was followed on a given day, and which page it led to. The second is counts — how many requests each site received per day, and how many came from each country.

The country map is worked out from IP addresses, and that deserves saying plainly. The address is compared against the public register of which blocks are allocated to which country, on this server, using a copy of that register held here; no address is sent anywhere to do it. Only the resulting per-country totals are kept. The addresses themselves are never stored beyond the ordinary log described above, never published, and cannot be recovered from the page: a country total is the only thing that survives. Nothing on the page carries an IP address, a browser identifier, a time of day, or anything else describing an individual visit, and there is no way to work back from it to a person.

Data retention & deletion

Wy5 keeps your rankings for as long as your account exists, so they stay counted in the community totals. You can delete your account from within the app, in Settings: it removes your account and your rankings, and the community totals are recomputed without them. If you would rather ask, support@wyome.com will do it.

WyHome and WyAuto store nothing off your device, so there is nothing on a Wyome server to delete: removing the app removes everything. WyAuto’s receipt photos are held on the device with the rest of its records.

Athenana keeps what you save until you remove it. You can delete your account from within it, under Settings: it removes the account and everything saved in it, including anything in the trash. If you would rather ask, support@wyome.com will do it.

Questions: support@wyome.com.

Last updated 7 September 2026.