Binding document · Privacy
What we hold, and what we do not.
This policy describes the data SalesWolf holds, who else it reaches, and how long it lasts. It is written against what the software actually does; where a claim would have run ahead of the code, the gap is on the page instead of the claim.
- Last updated
- 2026-09-15
- Issued by
- SalesWolf DOO
Who this is between
SalesWolf DOO, registered at Uroša Martinovića 9/44, 11070 Belgrade, Serbia (Reg. No. 21579874, Tax ID (PIB) 111949567), decides how your ACCOUNT data is handled — your email address, your sign-in, the workspace you belong to. For that data we are the controller.
The DEAL material you put into SalesWolf is different. Notes about a prospect, the text of a call, the name of a person on the buying side: you or your employer decide what goes in and what it is used for, and we process it on your instruction. For that data you are the controller and we are the processor. The DPA is the agreement that governs it.
What we hold
- Your account — email address, name if you gave one, and the sessions you are signed in with. There is no password, and none is stored: you sign in with a one-time code sent to your email address.
- What you enter about a deal — everything you type, paste or dictate: call notes, email text, the facts you confirm, the messages you write to the assistant.
- What we derive from it — the qualification facts extracted from your material, the drafts written from those facts, and numeric representations of short passages used to find related material later.
- Operational records — logs from running the product. Nothing about your visit to this website beyond the short-lived counter that sending the contact form leaves; see below.
- Billing records, once a workspace pays — set out under paying for seats, below.
Deal material routinely contains other people's names, job titles and words. That is personal data about them, and the section below on your obligations as controller is where it is dealt with.
A file you drop never reaches us
When you add a PDF, a Word document or a transcript, it is read on your own machine and only the text inside it is sent. The file itself is never uploaded, so there is no copy of it to keep, lose or hand over — and nothing about that depends on us remembering to delete it.
You can verify this without taking our word for it: open your browser's network tools while you add a document and watch what the request contains.
What a language model sees
SalesWolf reads your material with a language model. What we send is the material a task needs: the text you provided, the facts already on the deal, the people recorded on its account, your company's knowledge base, and the instruction we wrote for that task. We do not send your billing details or the text and facts of any other deal.
Every model request leaves through one gateway, which routes it to the company that serves the model. Those companies are named individually on the subprocessorspage, along with what reaches each one.
Where it goes
The gateway is based in the United States, and the model providers behind it operate outside the EU. Your material is therefore processed outside the EU. This page will not tell you otherwise, and no page of ours will, unless and until that changes.
The safeguard we rely on for that transfer:
Standard contractual clauses: those adopted by the Serbian Commissioner for Information of Public Importance and Personal Data Protection under the Law on Personal Data Protection, and the EU standard contractual clauses each subprocessor uses.
As for our own servers: this page makes no claim about where they are. That answer is going to change, and a claim about it is worth nothing until it is one we can hold to. When it is, it will be stated here.
Paying for seats
Paid seats are sold by Paddle, the Merchant of Record named in the terms. What you enter at checkout — your name, email address, billing address and payment details — goes to Paddle, which holds it as a controller in its own right, under its own privacy notice.
When a workspace buys seats, we keep what we need to know it has paid: Paddle's customer and subscription references, the plan, the seat count, the currency, the subscription's status, when the current period ends and any change Paddle has scheduled. A purchase is matched to your workspace by the workspace's own identifier, which the app hands to Paddle's checkout — not by the email address you pay with.
We also keep each event Paddle sends us about a purchase, as Paddle sent it. An event can carry the billing name, email address and address, the country, the amounts and the tax — never a full card number. Each one is deleted by the database 183 days after it arrives. That clock runs on its own: deleting a workspace or closing your account does not remove these events any sooner, because they are the record of what was charged.
When the workspace owner opens the Billing page in the app to subscribe, it loads Paddle's script from Paddle's servers, to show the price in your currency and to open checkout. Paddle's servers may set a bot-protection cookie on paddle.com while it runs. Paddle's script also tries to add Paddle's own analytics snippet; the app's security policy blocks it, so it never runs. No other page of the app loads it, and neither does the Billing page once a subscription is running.
What this website records
Nothing of ours. This website has no analytics of any kind — not a third-party tag, and not a self-hosted one either. Every page here is static HTML that asks your browser for its own fonts and stylesheets from this domain, and every page but two asks no other host for anything. Reading this page leaves no record with us that you were here.
The first is /pricing. It loads Paddle's script from Paddle's servers and asks Paddle for the price in your currency. That request carries the address your browser connects from, which Paddle uses to work out your country, and the two plan prices — nothing about you beyond that. Paddle's servers may set a bot-protection cookie on paddle.com while it runs. Paddle's script also tries to add Paddle's own analytics snippet; the site's security policy blocks it, so it never runs.
The second is /contact. As soon as the page opens, it loads Cloudflare Turnstile from Cloudflare's servers to tell a person from a bot before the form is sent. Turnstile processes the address your browser connects from, a fingerprint of its secure connection, its User-Agent header, and our site key and the page it runs on. Cloudflare lists those signals, and says it uses them only to detect bots and to improve that detection, in its Turnstile Privacy Addendum. When you send the form, our server asks Cloudflare to confirm the check, and passes on the address your request came from.
That is a claim you can check rather than take on trust: view the source of any page on this site and search it for the word script. On most pages you will find exactly one tag: a block of JSON describing what that page is, for search engines and the assistants that read us. It carries no address to fetch and no code to run. Some pages carry none at all. /pricing and /contact each carry one more — our own script, served from this domain — and no page carries any other kind. It is also checked on our side every time the site is built, so it cannot quietly stop being true.
One honest qualification, because "no record anywhere" would be a different and false claim: the request reaches us through Cloudflare, which carries the traffic and keeps its own logs of doing so, as it does for the product. Cloudflare and Paddle are named on the subprocessorspage with what reaches each.
Writing to us through the form
The form on /contact asks for your name, your email address, what the message is about, and the message. When you send it, our server emails those four things to [email protected] or, for a request about personal data, to [email protected], with your address set as the one a reply goes to. Cloudflare delivers that email. The message is kept in that inbox. None of it is written to SalesWolf's database.
So that nobody can use the form to flood those inboxes, each send counts against the address your browser connects from. That count is a record in our database holding the address and a tally, and it expires at most twenty minutes after it is created, when the database deletes it automatically. Our server's log notes what kind of request arrived and whether it was sent, never your name, email address or message.
Operational logs
Running the PRODUCT — the signed-in application, not this website — produces logs: which request was served, which background job ran, what failed. They carry identifiers for the account and the deal involved and, when something breaks, the error's own text. They are kept for 30 days and then deleted automatically by the database, not by anyone remembering to.
These exist because a service nobody can see going wrong is a service nobody can fix. They are the one thing we do keep, and they are the reason the section above says this website records nothing rather than saying we record nothing.
How long your work lasts
Your material stays until you delete it. There is no automatic expiry on a deal you are working — a deal you have not touched in a year is still there.
When you delete a deal, it stops being visible immediately and becomes unrecoverable 90 days later, when the database removes it. That window exists so a deletion you regret on Monday is not final; it is also the window in which we can still recover it if you ask. Its dependents — the material you captured, the drafts, the chat sessions — follow the same clock. The numeric search vectors are the exception: those are removed outright at the moment of deletion, because they can be rebuilt from the material and there is no reason to hold them.
The history of changes on a deal expires on the age of each change rather than on deletion, and is a separate policy that happens to use the same number today.
Closing your account deletes the account and the deals you own on the same terms.
Cookies
Signing in sets a cookie that keeps you signed in. That is the only cookie the product uses. On /pricing, and on the app's Billing page while the owner subscribes, Paddle's servers may set a Cloudflare bot-protection cookie (__cf_bm) on paddle.com — their domain, not ours — that expires within half an hour. On /contact, Cloudflare Turnstile sets no cookie. Neither cookie is for advertising or tracking, which is why this site has no cookie banner to dismiss.
Your rights
If you are in the EU or the UK you have the right to ask for a copy of your personal data, to have it corrected, to have it deleted, to take it elsewhere, and to object to how it is handled. Most of these you can exercise directly in the product without asking anyone. For the rest, write to [email protected] and you will hear back from a person.
You can also complain to your national data protection authority. We would rather you told us first, but that right does not depend on it.
Changes to this policy
When this policy changes in a way that matters, the date at the top changes with it. That date moves on meaning, never on a typo, so a date you have already read is one you can skip. We will not quietly widen what we do with your material and leave you to notice.
Contact
[email protected] reaches a person about anything on this page.