Privacy at Wolfey.
Wolfey is a JBI product. This notice explains the information used by our website, account flow and early beta workspace at wolfey.xyz.
Information you share
We process your name, email address, account identifiers and verification status to create and secure your account. If you verify a phone number, our authentication provider processes that number and the verification attempt. Passwords are handled by the authentication provider; the Wolfey application does not store a readable copy.
Your workspace stores the business information you enter, including your company, website, offer, ideal customer, goals and sales preferences, along with saved versions and account activity. Support requests include the information you send us.
You can add clients manually, paste spreadsheet rows or import a CSV, including names, email addresses, companies, websites, phone numbers and notes. Client records can also contain relationship status and user-reported spending with its currency, period and date; these amounts are not verified payment records. The file is processed to preview and validate the rows; confirmed records and import details, such as the filename, column mapping, row numbers and file fingerprint, are stored in your workspace. Client records are available to authorized members of that workspace. Only import information you are permitted to use.
Google and GitHub sign-in
When you choose a social sign-in provider, it shares the account identifier, email and basic profile information available under the permissions you approve, such as your name and profile photo. We use this information to identify you, manage your account and provide your workspace.
Google sign-in requests only basic identity permissions: openid, email and profile. Signing in does not connect Gmail or a calendar. The optional connections below require a separate permission request.
Optional email and calendar connections
Where a connection is available, you can separately approve access to Gmail, Outlook, Google Calendar or Outlook Calendar. We receive the connected account identifier and email address. Mail permissions let Wolfey read selected messages; sending requires an additional provider permission and your explicit confirmation in Wolfey. Existing read-only grants do not gain sending permission automatically. Calendar access remains read-only: Wolfey does not create, change or delete provider calendar events.
A mail sync reads up to 25 recent Inbox messages and 25 recent Sent messages per connection. The stored snapshot includes senders, recipients, subjects, timestamps, read status and limited plain-text message content. Attachments are not downloaded. A calendar sync reads up to 100 events from your primary or default calendar, covering the previous seven days and next thirty days. Event information can include titles, descriptions, times, locations, attendee email addresses and meeting links. These are limited snapshots, not a complete backup or a continuously updated view.
Syncs are requested through the application. A successful sync replaces the current snapshot; failed syncs may leave the previous snapshot visible with its last-update time. Changed provider observations are also retained while the connection remains active. Email and calendar data is private to the Wolfey account that connected it, subject to continued workspace access; ordinary workspace membership does not grant other members access to your connected messages or events. Mailbox allowances are checked at workspace level, including accounts connected by other members, without sharing those members’ mailbox contents.
To describe your writing style, Wolfey can calculate simple observations from recent sent messages, such as typical length, greetings, thank-you phrases and questions. These calculations run in your browser and do not train a model or send your mailbox to an AI service. They describe the available sample, rather than your personality or the accuracy of an email. Drafts are never sent automatically.
Email you choose to send
When sending is available for your connected inbox, you review the sender, one recipient, subject and plain-text body before confirming. Wolfey passes that confirmed message to the selected email provider. This version does not send attachments, CC or BCC recipients, scheduled sequences or automatic follow-ups. Connecting an account, syncing, creating a draft or asking the assistant does not send an email.
Compose drafts stay in account- and workspace-scoped memory in the current browser tab and are cleared by a full reload. To prevent duplicate dispatch and show the result after a reload, Wolfey stores a protected send receipt containing the recipient, subject, a fingerprint of the reviewed content, status, timestamps and any provider message identifier. The receipt does not contain the message body. A later Sent-mail sync may import limited message content under the snapshot rules above. Provider acceptance does not prove delivery, reading or a reply. If the result is uncertain, Wolfey records that uncertainty and does not automatically retry the send.
Google data and Limited Use
Wolfey’s use and transfer of information received from Google APIs follow the Google API Services User Data Policy, including its Limited Use requirements. We use connected Google data to provide the features you choose, such as reading your conversations, preparing for meetings and drafting responses. Optional sharing with OpenAI is described below and requires your source selection.
We do not sell Google user data or use it for advertising or credit decisions. Human access to Google message or event content requires your documented agreement to specific data, except when necessary for security purposes (including investigating a security bug or abuse) or legal compliance. Access to aggregated, anonymized information for internal operations remains subject to applicable privacy requirements.
Disconnecting a provider
Disconnecting in Connections removes the affected stored access credentials, synced mail or calendar content and retained provider observations from Wolfey. A connection record, including its account email and disconnected status, may remain. Send receipts and their abuse-prevention metadata are retained separately so disconnecting does not erase an uncertain result or allow a repeated dispatch. Original messages and events stay with the provider.
For Google, disconnecting one service also disconnects the other Google service for the same connected account because Google can revoke the combined grant. Wolfey requests Google revocation, but local removal does not guarantee that the provider completed it. For Microsoft, disconnect removes Wolfey’s stored credentials; it does not automatically revoke the provider’s consent grant. You can review or remove remaining access in your Google account connections or Microsoft app permissions. An organization-managed Microsoft account may also require your administrator’s assistance.
Ask Wolfey
When enabled and you ask a question, Wolfey sends your question, relevant conversation context and the sources you select to OpenAI to generate a response. Saved business context is selected initially. CRM, activity, mail and calendar context are off initially and require your selection. Selected CRM context includes up to eight recent records with user-reported spending; selected activity includes up to twelve of your event names and dates, without event payloads. Selected mail context includes up to five saved subjects and excerpts from your own connections; selected calendar context includes up to eight saved event summaries from your own connections. Snapshot dates are included because these records may be out of date. Context can also include a client or public website you select. Changing source selections starts a new chat; existing saved chats keep their original source choices. Information you paste into your question becomes part of that request, so avoid including anything you do not want processed this way.
Wolfey requests that OpenAI not store the generated response through the API’s response-storage feature. This setting is not a promise of zero provider retention; OpenAI may process and retain information under its applicable service and abuse-monitoring policies. Wolfey saves completed chat exchanges, titles, selected source settings and displayed source references in your account so you can resume a conversation. Saved chats are private to your account within the workspace; other workspace members cannot read them. Draft questions remain in browser-tab memory. You can delete an individual saved chat from Wolfey. Saved answers or text you paste into chats remain until you delete that chat, including after disconnecting an email or calendar provider. A separate usage record stores request counts and token or cost metadata without prompt text. AI output can be inaccurate; review any draft or recommendation before using it. Asking Wolfey does not send an email or make changes with a provider.
Business research and billing
You can ask Wolfey to read a public business website and save a research brief. Each user-started run reads a limited number of permitted pages; it does not schedule ongoing research or send email. Briefs retain the source URLs, check time, extracted business claims, missing information and template drafts. Saved research runs are private to the account that requested them, while the business profile you choose to save is shared with authorized workspace members.
Where paid plans are available, a workspace owner or admin can open Stripe Checkout. Stripe collects and processes payment and billing details; Wolfey does not store card numbers. We retain the workspace’s Stripe customer, checkout and subscription identifiers, plan, subscription state, paid-period end and event verification records to provide access, reconcile payments and prevent duplicate subscriptions. Stripe may also process Tentey subscriptions under the same Wolfey business account; each application keeps its own customer and workspace binding.
Prices shown in Plan are USD per workspace per month. Paid subscriptions renew automatically until canceled. Manage billing opens Stripe’s portal to update payment methods, view invoices and cancel renewal at the end of the paid period. A payment confirmation from Stripe is required before paid access begins or renews. Account sign-out or deletion does not automatically cancel a Stripe subscription. Historical plan-access requests only recorded interest and did not charge a payment method. Email usage records enforce the workspace allowance separately from billing.
Refund requests are reviewed case by case. Contact roccotvon@gmail.com with your account email and invoice number for billing support.
Meeting assistance
Meeting assistance starts only when you choose Start and approve the audio source. It can capture shared tab or system audio and an optional microphone. In the Windows companion, system audio can include all sound playing on your device. Any screen video required by the browser capture API stays on your device and is not uploaded or analyzed. Use capture only with the permissions needed for your meeting.
When transcription is enabled, short audio segments pass through the authenticated Wolfey server to OpenAI. Live guidance can send recent transcript text and selected saved business context to the assistant. Wolfey does not save meeting audio, transcript or notes in its database, browser storage or desktop files. They remain in the current view's memory; usage records retain request identifiers, duration, model, reservation and status without the recording. OpenAI's applicable service and abuse-monitoring policies still apply.
When transcription is unavailable, the local audio check meters your selected audio without uploading it. A labeled rule-based conversation guide can use a typed note without an AI call. Pause stops processing; Stop, sign-out or page exit releases the capture. The Windows companion uses a separate sign-in session. Optional capture protection depends on the recording software and does not guarantee that an overlay is invisible in a screen share.
Verification and abuse prevention
We use account and verification information to manage sessions, recover access and prevent repeated free-account claims. For this purpose, the application database stores a protected, keyed fingerprint of a verified phone number rather than the raw number. This fingerprint is still associated with your account; it is not anonymous.
The phone fingerprint and free-access record are retained after a number change or account deactivation to prevent the same number from repeatedly claiming free access. A verified phone does not establish someone’s legal identity.
Phone-call assistance
Calls can help you prepare a script and follow a normal phone call played on speakerphone near your computer. A calendar connection is optional. Wolfey saves the call title, optional client and scheduled time, goal, script and the business context used for that script. These call sessions are private to your account within the workspace. The script and context are fixed when live assistance starts so another open view cannot silently change them during the call.
Only choosing Start live help enables microphone processing. A local sound check does not upload audio. During assistance, short microphone segments and recent transcript text pass through Wolfey to OpenAI for transcription and suggestions. This mode does not capture screen or system audio, dial your phone, detect cellular call state, or reliably distinguish speakers. Use it with the permissions needed for your conversation. Wolfey does not retain raw audio or full transcripts; they remain temporarily in the current view. OpenAI's applicable service and abuse-monitoring policies still apply.
You choose which summary, outcome and next step to save after the call. A saved outcome is your report, not independently verified agreement evidence. Saved scripts and reviewed outcomes can be reopened in the web or desktop app; temporary transcripts do not move between devices. You can delete a saved call from Calls. Usage records retain request and cost metadata without audio or transcript text. Starting assistance, saving a script or reviewing an outcome does not send a follow-up or contact anyone.
Services that help operate Wolfey
- Clerk handles the new account flow, social sign-in, sessions and email/phone verification. Delivery services used by Clerk process verification messages.
- Supabase stores workspace and account-access records, imported clients, connected-provider snapshots and encrypted connection credentials. It also provides authentication for existing accounts during our transition.
- Vercel hosts the website and server functions.
- Stripe handles subscription payments, invoices and the billing portal when you choose a paid plan.
- Resend delivers account emails for the existing Supabase authentication flow.
- OpenAI processes optional assistant, call-script, live guidance and enabled meeting or phone-call transcription requests, as described above.
These services process the information needed for their role. Hosting and authentication services also process request and security details, such as IP addresses, browser information, session identifiers and errors. Authorized operators may access account and operational information needed to support the service or investigate an issue. Connected Google content is subject to the specific human-access limits above; a general support request does not by itself authorize reading your messages or events.
Cookies and browser storage
Authentication cookies and related browser storage keep you signed in and support verification and recovery. Short-lived, account-scoped view caches make navigation faster. Onboarding drafts may be saved temporarily in account-scoped browser session storage. Compose drafts and research draft edits stay in the current tab, as described above. Clearing site data removes local drafts and may sign you out. It does not delete records already saved to your real workspace.
Retention and your choices
Account and workspace records are retained while providing the service. Security records, saved history and the phone fingerprint described above may remain after account deactivation. This early beta does not yet provide a self-service export or deletion tool.
For access, correction, deletion or a question about retention, contact family@wolfey.xyz. We may need to verify your control of the account before handling a request. Deactivating a sign-in account or removing Wolfey from your Google or GitHub connected apps does not by itself delete workspace records or retained abuse-prevention records.
Changes to this notice
We will update this page as Wolfey’s data use changes. The date above identifies the current notice. Questions about this notice can be sent to family@wolfey.xyz.