Wolfix
Private beta · Summer 2026
Privacy policy · effective July 21, 2026

Privacy Policy

This Privacy Policy describes how Wolfix LLC ('Wolfix', 'we', 'us') collects, uses, and shares personal data when you use wolfix.io, the Wolfix application, and related services. Wolfix LLC is the controller of the personal data described in this policy, except where this policy states that we process data on a customer's behalf. You can reach us at support@wolfix.io.

1. Information we collect

Account data. When you create an account you provide an email address and a password; the password is handled by our authentication provider (Supabase) and is never stored in readable form. Where we offer sign-in through a third-party identity provider (such as Google or GitHub), we receive your email address and basic profile information (name and avatar) from that provider instead of a password. Your profile may additionally hold a display name, an avatar image, a timezone, a two-letter country code (derived once from your network location or set by you — we do not store your IP address in your profile), an interface-theme preference, and a record of how you found us.

Waitlist data. Joining the waitlist stores your email address, the referral code that brought you (if any), your own referral code, double-opt-in confirmation timestamps, and — once you confirm — your waitlist position (your position in the confirmation order). We do not ask for your name. If you unsubscribe, your address is added to a suppression list so we do not email you again.

Project and scan data. To analyse your project you give us a live URL and, where applicable, a repository reference or a provider connection (for example a Supabase project). Scanning reads your public pages and repository files and stores derived findings only: the frameworks, providers, and integrations we detected, the gaps we identified, and the generated report. We do not store your repository source code.

Payment data. Payments are processed by Stripe. We store Stripe identifiers (customer, subscription, price, and refund IDs), your plan and subscription status, and amounts in cents. Card numbers and card security codes never reach our systems. We also keep a payment-event log recording, per Stripe webhook event, the event identifiers, event type, and processing outcome — never the raw event payload and never card data.

Support data. If you contact support (including through a support form on a page we host for one of our customers), we store the name, email address, subject, and message you submit, together with a one-way hash of your IP address and your browser user-agent string, and we forward the message by email to its recipient.

Usage data. With your consent we collect product-analytics events (see "Cookies and analytics" below). We also keep security and operational logs; our logging pipeline deliberately redacts email addresses, IP addresses, credentials, and scan payloads before anything is written.

2. How we use your data

We use your data to provide the service: to operate your account, run scans you request, generate reports and documents, host pages you publish, process payments and program benefits (see the Program Terms), respond to support requests, and send the transactional email the service requires (waitlist confirmation and welcome messages, and spending-limit notifications you have enabled or that fire when a limit is reached).

We use pseudonymous operational records — cost and usage events keyed to account identifiers, funnel events, and error reports with personal identifiers removed — to keep the service reliable, detect abuse, and understand aggregate usage.

We do not sell personal data, and we do not use your data for third-party advertising.

3. AI processing

Report generation uses Anthropic's Claude API. During a scan we send Anthropic the derived detection signals from your project (detected frameworks, dependency names, service names, SEO metadata, DNS classification) and the rendered HTML of the public pages we scanned (for example your homepage and sign-up page). This content is processed to generate your report and is not stored by us beyond the report itself; under our commercial API terms Anthropic does not use it to train models.

Our team may also use internal, access-controlled AI-assisted administrative tools that process account records through the same Anthropic API under the same terms.

We never send your repository source code wholesale to any AI provider; only the derived signals and rendered public pages described above are transmitted.

4. Subprocessors and service providers

Supabase (hosting of our database, authentication, file storage, and email-sending functions) — receives all application data described in this policy. Vercel (application hosting and cookieless, aggregate web analytics on our marketing pages) — receives request data as our host. Stripe (payment processing) — receives your payment details directly; we receive only the identifiers described above. Anthropic (AI report generation) — receives the scan-derived content described in "AI processing".

GitHub (repository reads during code scans) — we read your repository through GitHub's API; GitHub receives the API requests involved. Browserless (remote page rendering, used in production scanning and PDF export) — receives the URL of the site being scanned so it can render the page. Resend (transactional email) — receives recipient email addresses and message content for the emails we send, including support messages we forward.

PostHog, hosted in the EU (product analytics) — receives anonymous, cookieless page-view events on hosted pages and, with your consent, limited interaction events in the application tied to a random account identifier (session recording is disabled). Google Analytics (marketing-site analytics) — loads only after you consent, with IP anonymisation enabled. Sentry (error monitoring) — receives error reports from which we strip email addresses, IP addresses, usernames, and credentials before sending; only an opaque account identifier is retained.

During a scan we may also query public registries and lookup services (trademark, copyright, and business registries, and domain and search-visibility checks) using your project or app name and deployed URL. These queries do not include your account details.

5. Cookies and analytics

We use first-party cookies that are necessary for the service: authentication session cookies, an anonymous session identifier, a referral-attribution cookie recording which partner link brought you to us, and a short-lived cookie used when we ask you to re-confirm your password for sensitive actions.

Analytics on the marketing site and in the application load only after you accept them in the consent banner; your choice is stored in your browser and you can decline without losing any functionality. Our marketing pages additionally use a cookieless, aggregate traffic counter that stores nothing on your device. Pages we host for customers record page views without cookies and without a persistent identifier.

Your theme preference on the marketing site is stored in your browser. We do not use third-party advertising cookies.

6. Data we process on behalf of our customers

Wolfix hosts pages (for example privacy, terms, and support pages) for our customers' products. If you submit a support request on one of those pages, we collect and forward your name, email address, and message on that customer's behalf; the customer is the controller of that data and Wolfix processes it to route the request. Feedback widgets on our help pages record only the article and an anonymous session identifier — no name or email.

7. Data retention

Account data, projects, scan findings, and reports are retained for as long as your account exists. When you close your account, access is disabled immediately and your display name and avatar are removed; the remaining records are retained in a closed state until they are permanently erased in response to an erasure request (see "Your rights"). Waitlist entries are retained while the waitlist program runs; unsubscribed and suppressed addresses are kept on the suppression list so that we honour your opt-out.

Pseudonymous operational records — cost and usage events, funnel events, and the payment-event log, none of which contain your email address or name — may be retained after account deletion for accounting, security, and audit purposes.

Support messages are retained so that the recipient can act on them. Encrypted provider tokens (for example a connected Supabase project) are retained until you disconnect the provider or delete your account.

8. Your rights

You can access and correct your profile data in your account settings, and you can delete your account directly from the privacy section of your settings. Account deletion is a closure: it takes effect immediately — your sign-in is disabled, your display name and avatar are removed, and your projects, scans, and reports stop being accessible. The underlying records are retained in a closed state until they are permanently erased in response to an erasure request.

You may also ask us to access, correct, delete, or export the personal data we hold about you, or object to or restrict our processing of it, by emailing support@wolfix.io. This includes requesting the permanent erasure of a closed account's records. We respond to verified requests within 30 days.

If you are in the EU, UK, or another jurisdiction with a supervisory authority, you have the right to lodge a complaint with that authority. We would appreciate the chance to address your concern first.

9. Legal bases and statutory rights

Where the GDPR or UK GDPR applies, we process your data on the following legal bases: performance of a contract (providing the service you signed up for), legitimate interests (service security, abuse prevention, and operational records), consent (analytics and optional notifications, which you can withdraw at any time), and legal obligation (accounting and tax records).

Where the CCPA/CPRA applies: we do not sell or share personal information as those terms are defined there, and we do not use sensitive personal information beyond providing the service. You will not be discriminated against for exercising your rights.

Consistent with our Program Terms, nothing in this policy limits or excludes rights that cannot be waived under applicable law.

10. Security

All traffic is encrypted in transit. Provider tokens and stored credentials are encrypted at rest with AES-256-GCM; API tokens we issue are stored only as keyed one-way hashes and can never be read back from our database. Access to production data is restricted, and our logging pipeline redacts credentials, email addresses, and IP addresses before log entries are written.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as required by applicable law.

11. International transfers

Wolfix LLC is a United States company, and the service providers listed above process data in the United States and the European Union (our product-analytics provider is EU-hosted). Where personal data of EU or UK residents is transferred outside those jurisdictions, we rely on our providers' standard contractual clauses or equivalent safeguards.

12. Children

Wolfix is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact support@wolfix.io and we will delete it.

13. Changes to this policy

We will update this policy when our data practices change, and will update the effective date above when we do. For material changes affecting registered users, we will give notice in the application or by email before the change takes effect.

14. Contact

Wolfix LLC — support@wolfix.io. Please include enough detail for us to identify your account or request.