Legal
Last updated: 12 July 2026
This Privacy Policy explains what personal data Woolfe (the “Service”), operated by Individual Entrepreneur Andrey Kokin (“we”, “us”, “our”), collects, why we collect it, and the choices you have. We act as the data controller for the personal data described here.
Contents
The data controller is Individual Entrepreneur Andrey Kokin, registered in the Republic of Armenia, at Manushyan Street 81/1, Arabkir, Yerevan 0012, Republic of Armenia. For any privacy question, contact [email protected].
We collect only what we need to run the Service:
| Category | Examples | Why |
|---|---|---|
| Account | Email address | To create your account and sign you in with a one-time code |
| Model API key | The AI model key you add | To generate content on your behalf; stored encrypted |
| Your content | Topics, keywords, settings, generated articles, projects | To provide the core Service and show your work back to you |
| Connections | CMS site URL and credentials you connect | To publish content to the CMS you choose |
| Subscription | Plan, status, billing identifiers | To manage your plan; payments are handled by our payment provider |
| Technical | IP address, request logs, timestamps | Security, rate-limiting, abuse prevention, and debugging |
We do not sell your personal data, and we do not use Your Content to train our own models.
If you are in the European Economic Area or the UK, we process your personal data under these legal bases:
We share personal data only with the service providers we need to operate the Service. We do not sell your personal data. Our current subprocessors are:
| Provider | Purpose | Data shared |
|---|---|---|
| Aeza | Server hosting and infrastructure. Servers are currently located in Europe. | All data stored by the Service (account data, your content, logs) |
| Cloudflare | DNS, CDN, network security and DDoS protection | IP address, request metadata, traffic passing through the network |
| Paddle | Payments, acting as merchant of record; handles billing and taxes | Billing details, transaction and subscription data (collected directly by Paddle) |
| Resend | Transactional email (sign-in codes, account emails) | Email address, message content |
| AI model provider you select (BYOK) | Content generation, using the API key you connect. You choose the provider. | The inputs you submit for generation (topics, keywords, settings) and the resulting output |
Bring your own key. Because you connect your own AI model API key, generation requests are sent directly to the AI provider you selected, and that provider processes them under its own terms and privacy policy — including whatever it says about using data for model training. We do not control those policies, and the choice of provider is yours. Review your provider's terms before submitting sensitive material through the Service.
Database. Your account data and content are stored in a database on our own hosted infrastructure (Aeza). They are not held by a third-party database service.
We may also disclose data if required by law, or to protect our rights, our users, or the Service. If we change our subprocessors, we will update this page.
We do not use advertising cookies, and we do not track you across other websites.
Our marketing pages set no cookies of our own. Once you sign in to the application, we store an authentication token in your browser's local storage so that you stay signed in, and our infrastructure provider may set strictly necessary cookies for security and network protection. These are essential for the Service to work and are not used for tracking or advertising. You can clear browser storage at any time from your browser settings, which signs you out.
We currently do not use advertising or analytics cookies that require consent, so we do not display a cookie consent banner. If we introduce analytics or any technology that requires consent, we will update this policy and, where required, ask for your consent first.
Your model API key is stored encrypted and used only to operate the Service for you; we never show your full key back to you after saving. When you generate content, the inputs you provide are sent to the AI model provider tied to your key in order to produce the output. Content you publish to a connected CMS is transmitted to that CMS at your instruction.
Training. We do not use your prompts, inputs, or generated content to train our own models, and we do not sell or license them to anyone for that purpose.
AI providers. Because you connect your own model API key, your inputs are sent directly to the AI provider you selected, and that provider processes them under its own terms and privacy policy — including whatever it says about using data for model training. We do not control those policies. Review your provider's terms before submitting sensitive material through the Service.
We keep personal data only as long as we need it to provide the Service, and delete it when it is no longer needed, subject to any legal retention requirements (for example tax and accounting rules).
| Data | Retention |
|---|---|
| Account data (email, settings) | While your account exists; deleted on request |
| Your content (projects, articles) | While your account exists; deleted on request or when you delete it |
| Model API key | Until you remove it, or until your account is deleted |
| One-time sign-in codes | Expire after 10 minutes; deleted within 24 hours |
| Server and security logs | Rotated in the ordinary course by our hosting infrastructure |
| Billing records | Held by our payment provider as required by applicable tax law |
Deleting your account. You can ask us to delete your account and its data at any time by emailing [email protected] from the address on your account. We will delete it without undue delay. Residual copies may persist in backups or logs for a limited period before being overwritten in the ordinary course.
We are established in the Republic of Armenia, which is outside the European Economic Area, and our subprocessors operate in various countries. This means your personal data may be transferred to and processed in countries other than the one you live in, including outside the EEA.
Where we transfer personal data of individuals in the EEA or the UK, we rely on appropriate safeguards required by applicable law, such as the European Commission's standard contractual clauses. You can request more information about the safeguards we use by emailing [email protected].
Depending on where you live, you may have the right to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, email [email protected]. You may also have the right to complain to your local data protection authority.
If you are a California resident, the California Consumer Privacy Act gives you the right to know what categories of personal information we collect and how we use them, to request deletion of your personal information, to opt out of the sale or sharing of personal information, and to receive equal service and pricing even if you exercise these rights.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. To exercise any CCPA right, email [email protected].
We use technical and organisational measures appropriate to the risk, including:
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a personal data breach affecting your rights, we will notify you and the relevant supervisory authority as required by applicable law, without undue delay.
The Service is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
We may update this Policy from time to time. If we make material changes, we will provide notice, for example by email or through the Service. The “last updated” date above shows the current version.
Questions about privacy? Email [email protected] or see our contact page.