Privacy policy

This page describes what each app actually does with your data. Where an app sends something off your device, it is named below.

Wy5

Your rankings are sent to a Wyome server so they can be counted into the community totals. You are identified by Apple’s anonymous identifier or by a device identifier — no name and no email address is stored, and there are no display names anywhere. Signing in uses Sign in with Apple, and it asks Apple for no name and no email address, so Apple passes on nothing but that anonymous identifier. Published standings are anonymous aggregates. Looking up a film, album or book queries Wikipedia and Wikidata.

Links to Amazon carry a Wyome affiliate tag, so Amazon can attribute a resulting purchase to Wyome and we may earn a commission. They are search links rather than product links, and nothing about you is sent to Amazon beyond the search itself and that tag. This is the only commercial tracking in any of the five.

Wy5 Premium is an auto-renewable subscription handled entirely by Apple. Wyome never sees your payment details, and whether you subscribe is not sent to the Wyome server.

WyHome

Everything you record stays on your device. There is one exception: finding a contractor. Searching sends the search text to Apple Maps, along with your location if you allow it, so results can be local. If you search near your home address, that address is sent to Apple to turn it into a map location. Reminders and calendar entries are written into your own Apple apps.

WyAuto

Everything stays on your iPhone. There is no account, no analytics, and no network requests of any kind.

WyHealth

This is the only one of the five that handles health data, and it is the only one where what you store leaves your device by design rather than as an aggregate. The iPhone app reads the Apple Health categories you approve and uploads them; the website reads them back. You choose the categories when the app first asks and can change or withdraw them at any time in iOS Settings under Privacy & Security → Health. Signing in uses your Apple account and no password is ever stored. Unlike Wy5, WyHealth does ask Apple for your email address, so your account can be found again and so you can be written to about it; if Apple gives a relay address in its place, that is what is kept.

What the app uploads is the readings themselves, not a summary of them: each figure with its unit, when it was recorded, and the name of the app or device that recorded it. Steps, distance, energy, exercise and stand minutes and flights climbed are added up into one figure per day on the phone before they leave it; heart rate, blood oxygen and respiratory rate go up as a day’s low, average and high; weight and other body measurements, blood pressure, blood glucose, resting and walking heart rate, heart-rate variability, cardio fitness and recovery go up reading by reading. Workouts are sent as the activity, its start and end, duration, energy and distance — never the route, and never your location. Sleep goes up as its stages, and the heart notices Apple Watch raises — high, low and irregular rhythm — as the time each was raised. The app also sends an identifier for your phone, so a later sync can pick up where the last one stopped. On the website you can fill in a profile — a display name, date of birth, sex, a goal and your preferred units — and that is held with the rest.

All of it is held by Supabase, a database service Wyome rents, on Amazon’s servers in Oregon, in the United States. Both the app and the website talk to it directly. The website’s own server, the one that draws your dashboard, reads your data from there each time you open a page and keeps no copy; it is the same DreamHost server as the other four sites, and what it logs is what every web server logs — the page requested, the time, your IP address and browser — never a reading. Every row is scoped to your account in the database itself rather than by the code that queries it, so one account cannot read another’s data even if a query is wrong. Readings and values are never written to server logs — the logs record how many samples arrived and of what type, never what they said. wyhealth.app loads nothing from anyone else: no analytics, no third-party script, and its fonts are served from the site rather than from a font network.

Your health data is not sold, not shared with advertisers, not used to train anything, and not shown to anyone else. There is no public element to WyHealth as there is to Athenana: nothing you store appears on a public page, and there is no community aggregate.

Lab results and a paid subscription are planned and not yet built, and nothing is sent to anyone for either today. When they arrive, the text of an uploaded lab PDF would be sent to Anthropic’s Claude API to read the marker names and values off it, and payment would be handled by Stripe so that Wyome never sees your card details. This page will be updated before either is switched on.

Athenana

Items you save are stored on a server operated by Wyome. When you save a link, the server fetches that page and, once, the pictures inside its article; it keeps a copy of the page, the pictures and a screenshot, and uses them for tagging and search. Reading the item afterwards shows those pictures from the copy stored on Athenana’s own server and never from the site, so the site is not told when you come back to it; a picture the server could not fetch is simply not shown. Signing in uses your Apple account and no password is ever stored. Pages and images you save are sent to Anthropic’s Claude API so they can be tagged automatically, so text in images can be read, and so a saved page can be summarised; that content is not used to train models. The same API ranks the morning reading list described below.

You can also save into Athenana from a browser extension for Safari and Chrome, and from a Shortcut on iPhone and iPad. The extension sends the page’s address and title, its description and preview image where the page publishes them, and a screenshot of the visible tab — plus the text you had selected, if you saved a highlight. It sends these only when you click its button or use its right-click item: it does not read the pages you visit otherwise, and it does not run in the background. Because that screenshot is taken by your own browser rather than by the server, it shows the page as you were seeing it, including anything you were signed in to. The Shortcut saves a link or a photo you share to it, using a token that can do nothing but add items.

Nothing you save is published unless you turn publishing on for your account, which is off until you do. Each item then sits at one of three levels. Private is yours alone. Blog gives it an address of its own and puts it on your blog. Public is all of that and adds it to Athenana’s shared front page. A single account setting still hides everything whatever the individual items say, and it is deliberately a separate switch from the one that turns publishing on — an emergency stop and an opt-in are different things.

The shared front page carries saved links and nothing else. A note, a highlight and an image can reach the blog level but never that page, because it is an anonymous stream and those are your own words, your own choice of passage and your own picture. Screenshots are never published anywhere, because a screenshot photographs the tab as it was and can catch a page you were signed in to. The pictures on the front page come from the publisher of the page being linked to, and a private comment you attach to a link is not published with it.

That front page is also a feed, at feed.xml and feed.json, and a blog carries its own. Worth knowing before you publish something: a page can be edited or taken down, but a feed entry has already been fetched and stored by whatever was subscribed to it.

A blog exists only if you choose a handle for it on your account page, and it lives at athenana.com/blog/ plus that handle. No handle means no blog and no address; the handle is the whole opt-in. It is independent of the shared front page, so you can have either without the other.

A blog is also an account on the fediverse, which anyone on Mastodon can follow; a follow is accepted on its own, since everything on a blog is already public. When a note, a photo or a highlight is set to Blog or Public it is delivered, signed, to every follower’s server, which keeps its own copy and shows it there — a link you kept is never delivered, only what you wrote, and a delivered post cannot be taken back from servers that already hold it. Athenana stores each follower’s account and inbox address, their name, their server and whether it still answers; the follower count is public and the list is not. Replies, likes and boosts sent back are discarded, not stored. Clearing the handle takes the blog and the account down.

When a link is on the front page, the site it points to is told so, using the web’s standard Webmention notification; it carries the front page’s address and the link itself and nothing else, and sites that accept these often display them publicly. When a link leaves the front page, a follow-up notice is sent so the site can drop the mention.

An article can also be narrated and delivered to you as a podcast. When you ask for that, the article’s text is sent to Google’s speech service and comes back as audio, which is kept on Wyome’s server and played from there — your podcast app never contacts Google. It happens only for articles you flag. The feed has no password, because podcast apps cannot sign in: it is protected by a long unguessable address you can replace at any time, so treat it as a key rather than a link. Narrated audio is deleted after 90 days; the article itself stays.

An article can also be sent to your Kindle. When you ask for that, the article’s text, its picture, its address and any passages you kept from it are emailed to the Kindle address you saved, and Amazon converts the file and keeps it as a personal document in your Amazon account. Nothing else about the item goes with it — not its tags, and your note only if you tick the box for it — and nothing is sent unless you press the button, one article at a time. The address is accepted only if it is at kindle.com, so it cannot be used to mail your reading anywhere else. Wyome’s server sends it; your browser never contacts Amazon.

A saved link can also be shared to eleven services: Bluesky, Mastodon, RecLeague and Hacker News, which your browser goes to, and micro.blog, Are.na, Pinboard, Raindrop, Readwise Reader, Karakeep and MyMind, which Athenana’s server posts to with a token you gave it. What leaves is the same for all eleven — the original address you saved and the item’s title, and for two of them the item’s picture, never the archived copy, the screenshot, the summary, the tags, your note or the passages you kept — and nothing is shared unless you press the button, one item at a time. The four your browser goes to open that service’s own composer with the address and title filled in, so the service sees your IP address and those two things whether or not you then post; Mastodon’s is the server you named, and RecLeague is one of two places a picture goes with the link, only for an item you have published. The seven the server posts to receive the title and the address as a post on your micro.blog; the address and the item’s picture — the one you chose or the page’s own, never a screenshot — as a block in the Are.na channel you chose, served from Athenana at an address that stops working after a day, whether or not the item is published; or the address and title as a bookmark in your own Pinboard, Raindrop, Readwise Reader, Karakeep or MyMind account, MyMind through the same key you gave for importing from it. No button exists until its token does.

Athenana counts how often each link on that front page is followed. A link there that points to another site goes through Athenana’s server before it takes you on, so that the following can be counted; what is stored is which link, and when. Not who: no address, no cookie and no identifier of any kind is kept beside it, so nothing there can tell one reader from another, or the same reader twice. Requests that say they are robots, and the invisible fetches a browser makes to speed up pages you have not clicked, are not counted — a robot that does not say so is. The counts are deleted after ninety days, and nothing on a blog, on a link’s own page, in a feed, or behind a sign-in is counted at all.

Those counts choose the five links in a weekly email you can ask for. If you ask, your address is stored so the email can be sent to you, and you are sent a link to confirm you meant it: nothing goes to an address that has not followed that link. It is used for nothing else and given to nobody, every issue carries a link that removes you, and the email carries no tracking — its links go straight where they point, and there is no hidden image that reports whether you opened it. The pictures and typeface in it come from Athenana’s own server and are the same for every reader, so nothing in the message can tell anyone that you opened it.

Some sites refuse to serve a page to a server while serving it normally to a browser. When that happens Athenana asks the Internet Archive for an older copy, which means that page’s address is sent to archive.org. Only the address, and only for a page that could not be fetched directly.

Athenana also builds a reading list for you each morning, and building it means searching outside your own collection. It takes fifteen topics — the ten tags you use most, plus five drawn at random from the rest of the tags you use — and searches three places for each: Google News, Hacker News (through Algolia, which runs its search) and Flipboard. Only the topic word is sent, by the server rather than by your browser, with no identifier, no cookie and nothing about what you have saved; what comes back is a list of links to follow if you want them, and nothing on that page loads from any of the three. What those three do see, over time, is what this account reads about — the topics come from your own tags rather than from a generic list. A topic you drop on the Discover screen is never searched for again. The same morning, Athenana writes a short briefing of what your feeds carried, from their headlines and one-line summaries, and — for feeds you tick for it — five short facts per story, fetching the article itself when the feed’s summary is only a line. Both are written by Anthropic’s Claude API from text the server sends; your browser contacts nobody, and nothing from your own library goes with it.

A saved song gets a play button, and so does a saved YouTube link. Along with a saved podcast episode, described next, it is one of the few things here that can reach somebody reading a page rather than the person whose account it is. When you save an Apple Music link, Athenana recognises it as a song from the address itself — it makes no extra request to Apple to do that — and asks YouTube whether it has the same recording, sending the artist and title and nothing about you. When you save a YouTube link there is nothing to ask: the address already names the video, so the server only fetches its cover picture. Either way, that cover is copied onto Athenana’s own server. That copy is the point: a page with a video on it loads nothing from Google and tells Google nothing, not even that the page was opened. Pressing play is the moment that changes. The player then loads from youtube-nocookie.com, and Google sees your IP address and which video you played. Play buttons can appear on the shared front page and on blogs, not only on your own pages, so this is worth knowing whether or not you have an account.

A saved podcast episode gets a play button too. Athenana reads the episode’s details — the show, the title, how long it runs — from the page it saved, and copies the artwork onto its own server, so a page carrying an episode loads nothing from anyone until you press play. What plays is not stored here: the audio comes from wherever the show is hosted, which differs from show to show and is often a redirect that exists to count downloads. That host sees your IP address and that the episode was played. Like the video player, the button carries no address for the audio until you press it, and like the video player it can appear on public pages as well as your own.

You can also bring a library in as a file — the bookmarks file any browser exports, or a Pinboard, Reeder, Instapaper or Pocket export. It is read on Athenana’s server and nothing in it is sent anywhere: no page in it is fetched during the import, and the file itself is deleted as soon as its rows are in. A bookmark marked private there is saved as private. Reading the pages afterwards, a few hundred a day, is the same process described above for anything you save.

You can also forward an email into Athenana, to an address of your own that only you know. The message is saved as a page: its text, and the pictures it carries. A PDF attached to it is saved as a document of its own, private like the message; nothing else attached is kept. A picture the sender attached inside the message needs no request — it arrived with it. A picture the message merely links to somewhere else is fetched once, by the server, when the message is saved, and a copy is stored. Newsletters carry invisible images whose only purpose is to tell the sender that a message was opened, and by whom, so anything declaring itself 1×1 or 0×0 — the shape of a tracking pixel — is never requested. A tracker that declares an ordinary size is requested like any other picture, so this reduces that tracking rather than preventing it. Reading a saved message shows you its words and its pictures, each one from the copy the server stored and never from the sender — a picture it could not fetch is simply not shown. The stored pictures also become the item’s thumbnail and the photograph Athenana takes of the message itself, which is where you see how it arrived. Every one of them is served from Athenana’s own server, so reading a saved message contacts nobody.

You can also post into Athenana from any third-party app that speaks Micropub, the web’s standard for that. Such an app works only with a token: one you issue to it from your own account, or one it asks for over IndieAuth, where you are shown the app’s address and what it wants to do and, if you approve, it receives a token for that and your blog’s address as your identity. Either can be revoked from your account.

Common to all

None of the five carries advertising, and none carries a third-party tracker that runs on its own. The one thing counted anywhere is Athenana’s tally of how often each front-page link is followed, described above — a number against a link, kept on Wyome’s own server, with nothing beside it that identifies anyone. There are two third-party players anywhere — the YouTube player behind a saved song’s play button in Athenana, and the audio player behind a saved podcast episode’s — and each loads only when you press play, as described above. The one commercial identifier anywhere is Wy5’s Amazon affiliate tag, described above. No data from any of them is sold, and none is shared with anyone except where this page says otherwise — Apple Maps for WyHome’s contractor search, Wikipedia and Wikidata for Wy5’s look-ups, Amazon for Wy5’s shopping links, the Claude API for Athenana’s tagging, summaries and reading-list ranking, Amazon when you send a saved article to your Kindle, MyMind when you import your library from it with a key you gave, Bluesky, Mastodon, RecLeague, Hacker News, micro.blog, Are.na, Pinboard, Raindrop, Readwise Reader, Karakeep or MyMind when you share a saved link to one of them, the Internet Archive when a site refuses to serve Athenana a page, Google when Athenana looks for a saved song’s video or you press play on one, a podcast’s own host when you press play on a saved episode, Google News, Hacker News and Flipboard when Athenana searches for your morning reading list, and the Webmention notices Athenana’s front page sends to the sites it links. All five sites run on servers at DreamHost, which hosts them and can see whatever is on them; WyHealth’s health data is the exception: it is held by Supabase in the United States, and the DreamHost server only reads it to draw your page.

This website

wyome.com itself sets no cookies, runs no JavaScript and contains no analytics. Its fonts are served from this site rather than from a font network, so loading a page here contacts nobody but this server.

Like nearly every web server, this one records each request it serves in a log: the address of the page requested, the time, the requesting computer’s IP address, the browser it identified itself as, and — where the browser sends one — the address of the page you followed a link from. These logs are kept for about a week and then deleted automatically. They are not analytics: nothing is added to a page to produce them, no identifier is set, and no visitor is followed from one page to the next.

The site statistics page publishes two narrow slices of those logs. The first is referrals: the addresses of pages that linked here, how many times each was followed on a given day, and which page it led to. The second is counts — how many requests each site received per day, and how many came from each country.

The country map is worked out from IP addresses, and that deserves saying plainly. The address is compared against the public register of which blocks are allocated to which country, on this server, using a copy of that register held here; no address is sent anywhere to do it. Only the resulting per-country totals are kept. The addresses themselves are never stored beyond the ordinary log described above, never published, and cannot be recovered from the page: a country total is the only thing that survives. Nothing on the page carries an IP address, a browser identifier, a time of day, or anything else describing an individual visit, and there is no way to work back from it to a person.

Data retention & deletion

Wy5 keeps your rankings for as long as your account exists, so they stay counted in the community totals. You can delete your account from within the app, in Settings: it removes your account and your rankings, and the community totals are recomputed without them. If you would rather ask, support@wyome.com will do it.

WyHome and WyAuto store nothing off your device, so there is nothing on a Wyome server to delete: removing the app removes everything. WyAuto’s receipt photos are held on the device with the rest of its records.

Athenana keeps what you save until you remove it. You can delete your account from within it, under Settings: it removes the account and everything saved in it, including anything in the trash. If you would rather ask, support@wyome.com will do it.

WyHealth keeps your readings until you ask for them to be removed. There is not yet a delete button in the app or on the site; write to support@wyome.com and the account, its readings and its profile are deleted together. Withdrawing Health access in iOS Settings stops new readings leaving the phone but does not remove what was already uploaded.

Questions: support@wyome.com.

Last updated 20 September 2026.