Woolfe.

Legal

Privacy Policy

Last updated: 12 July 2026

This Privacy Policy explains what personal data Woolfe (the “Service”), operated by Individual Entrepreneur Andrey Kokin (“we”, “us”, “our”), collects, why we collect it, and the choices you have. We act as the data controller for the personal data described here.

Contents

  1. Who we are
  2. Data we collect
  3. How we use it
  4. Legal bases (GDPR)
  5. Sharing & subprocessors
  6. Cookies & similar technologies
  7. Your content & keys
  8. Retention
  9. International transfers
  10. Your rights
  11. California privacy rights (CCPA)
  12. Security
  13. Children
  14. Changes
  15. Contact

01Who we are

The data controller is Individual Entrepreneur Andrey Kokin, registered in the Republic of Armenia, at Manushyan Street 81/1, Arabkir, Yerevan 0012, Republic of Armenia. For any privacy question, contact [email protected].

02Data we collect

We collect only what we need to run the Service:

CategoryExamplesWhy
AccountEmail addressTo create your account and sign you in with a one-time code
Model API keyThe AI model key you addTo generate content on your behalf; stored encrypted
Your contentTopics, keywords, settings, generated articles, projectsTo provide the core Service and show your work back to you
ConnectionsCMS site URL and credentials you connectTo publish content to the CMS you choose
SubscriptionPlan, status, billing identifiersTo manage your plan; payments are handled by our payment provider
TechnicalIP address, request logs, timestampsSecurity, rate-limiting, abuse prevention, and debugging

We do not sell your personal data, and we do not use Your Content to train our own models.

03How we use it

04Legal bases (GDPR)

If you are in the European Economic Area or the UK, we process your personal data under these legal bases:

05Sharing & subprocessors

We share personal data only with the service providers we need to operate the Service. We do not sell your personal data. Our current subprocessors are:

ProviderPurposeData shared
Aeza Server hosting and infrastructure. Servers are currently located in Europe. All data stored by the Service (account data, your content, logs)
Cloudflare DNS, CDN, network security and DDoS protection IP address, request metadata, traffic passing through the network
Paddle Payments, acting as merchant of record; handles billing and taxes Billing details, transaction and subscription data (collected directly by Paddle)
Resend Transactional email (sign-in codes, account emails) Email address, message content
AI model provider you select (BYOK) Content generation, using the API key you connect. You choose the provider. The inputs you submit for generation (topics, keywords, settings) and the resulting output

Bring your own key. Because you connect your own AI model API key, generation requests are sent directly to the AI provider you selected, and that provider processes them under its own terms and privacy policy — including whatever it says about using data for model training. We do not control those policies, and the choice of provider is yours. Review your provider's terms before submitting sensitive material through the Service.

Database. Your account data and content are stored in a database on our own hosted infrastructure (Aeza). They are not held by a third-party database service.

We may also disclose data if required by law, or to protect our rights, our users, or the Service. If we change our subprocessors, we will update this page.

06Cookies & similar technologies

We do not use advertising cookies, and we do not track you across other websites.

Our marketing pages set no cookies of our own. Once you sign in to the application, we store an authentication token in your browser's local storage so that you stay signed in, and our infrastructure provider may set strictly necessary cookies for security and network protection. These are essential for the Service to work and are not used for tracking or advertising. You can clear browser storage at any time from your browser settings, which signs you out.

We currently do not use advertising or analytics cookies that require consent, so we do not display a cookie consent banner. If we introduce analytics or any technology that requires consent, we will update this policy and, where required, ask for your consent first.

07Your content & keys

Your model API key is stored encrypted and used only to operate the Service for you; we never show your full key back to you after saving. When you generate content, the inputs you provide are sent to the AI model provider tied to your key in order to produce the output. Content you publish to a connected CMS is transmitted to that CMS at your instruction.

Training. We do not use your prompts, inputs, or generated content to train our own models, and we do not sell or license them to anyone for that purpose.

AI providers. Because you connect your own model API key, your inputs are sent directly to the AI provider you selected, and that provider processes them under its own terms and privacy policy — including whatever it says about using data for model training. We do not control those policies. Review your provider's terms before submitting sensitive material through the Service.

08Retention

We keep personal data only as long as we need it to provide the Service, and delete it when it is no longer needed, subject to any legal retention requirements (for example tax and accounting rules).

DataRetention
Account data (email, settings)While your account exists; deleted on request
Your content (projects, articles)While your account exists; deleted on request or when you delete it
Model API keyUntil you remove it, or until your account is deleted
One-time sign-in codesExpire after 10 minutes; deleted within 24 hours
Server and security logsRotated in the ordinary course by our hosting infrastructure
Billing recordsHeld by our payment provider as required by applicable tax law

Deleting your account. You can ask us to delete your account and its data at any time by emailing [email protected] from the address on your account. We will delete it without undue delay. Residual copies may persist in backups or logs for a limited period before being overwritten in the ordinary course.

09International transfers

We are established in the Republic of Armenia, which is outside the European Economic Area, and our subprocessors operate in various countries. This means your personal data may be transferred to and processed in countries other than the one you live in, including outside the EEA.

Where we transfer personal data of individuals in the EEA or the UK, we rely on appropriate safeguards required by applicable law, such as the European Commission's standard contractual clauses. You can request more information about the safeguards we use by emailing [email protected].

10Your rights

Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, email [email protected]. You may also have the right to complain to your local data protection authority.

11California privacy rights (CCPA)

If you are a California resident, the California Consumer Privacy Act gives you the right to know what categories of personal information we collect and how we use them, to request deletion of your personal information, to opt out of the sale or sharing of personal information, and to receive equal service and pricing even if you exercise these rights.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. To exercise any CCPA right, email [email protected].

12Security

We use technical and organisational measures appropriate to the risk, including:

No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a personal data breach affecting your rights, we will notify you and the relevant supervisory authority as required by applicable law, without undue delay.

13Children

The Service is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

14Changes

We may update this Policy from time to time. If we make material changes, we will provide notice, for example by email or through the Service. The “last updated” date above shows the current version.

15Contact

Questions about privacy? Email [email protected] or see our contact page.