Trust · what we don’t keep
Your file never reaches us.
A PDF, a Word document or a transcript you add is read on your own machine, and only the text inside it is sent. We can’t hand over a file we never had. We do keep that text, though — and this page is the list of everything we hold, everywhere it goes, and what we haven’t built yet.
Where the line is
Stays on your machine
The file
The PDF, the Word document, the transcript. It is opened by code running inside your browser, and there is no endpoint on our side for it to be sent to.
Its name
We never learn what you called it. Nothing in the request carries a filename.
Its size and its type
Neither reaches us. There is no record on our side that a file was involved at all, rather than a paste.
Anything we could not read
A format the parser does not handle is refused on your own machine, before anything is sent. It fails where the file already is.
Crosses to us
The text inside it
Verbatim, exactly as the parser read it — the same thing you would get by selecting all and copying. Everything else on this page is about what happens to that text.
None of that has to be taken on trust. Open your browser’s network tools, add a document, and read the request that leaves: its body has one field in it, and that field is text.
What we keep
The text stays. That is the honest half of this page.
The text you added, word for word
Until you delete the deal
The facts drawn out of it, and the drafts written from those facts
Until you delete the deal
Your account — your email address and the sessions you are signed in with. There is no password, and none is stored: you sign in with a one-time code sent to your email address
Until you close it
The numbers we search your material with
Deleted outright the moment you delete the deal — no window at all
The history of changes on a deal
90 days from each change, on its own clock, deleted or not
Server logs — which request was served, which job ran, what broke
30 days
The billing events Paddle sends us once a workspace pays — the billing name, email address and address, the amounts and the tax, never a full card number
183 days from arrival, deleted workspace or not
Delete a deal and it is gone from view at once, and gone for good 90 days later, when the database removes it on a schedule nobody has to remember. That window is not a grace period we grant ourselves — it is there so a deletion you regret on Monday is not final, and it is the only window in which we could still get it back for you.
Where your text goes to be read
SalesWolf reads your material with a language model, and a task is sent only what it needs: the text you provided, the facts already on that deal, the people recorded on its account, your company’s knowledge base, and the instruction we wrote for that task. Never the text or facts of another deal, yours or anyone else’s.
Every model request leaves through one gateway, and that gateway is a company based in the United States, which routes the request onward to whoever serves the model. Your material is therefore processed outside the EU. This page will not tell you otherwise, and no page of ours will unless that changes.
Each company that receives anything is named individually, with what reaches it, on the subprocessors page. There is no second list on this page: one of the two would eventually be wrong.
What this website records
Nothing.
On this page: no tracker, no cookie, no third-party script, no record that you were here. This page is a file. It was written when the site was built, and the server hands you the same bytes it hands everyone without learning anything on the way.
Checkable the same way the boundary above is, and worth thirty seconds: view the source of this page and search it for the word script. You will find exactly one tag, and it is a block of JSON describing what this page is, for search engines and the assistants that read us. It carries no address to fetch and no code to run. Two pages differ. /pricing runs a script of ours that loads Paddle's script from Paddle's servers to show the price in your currency, which may let Paddle set a bot-protection cookie on paddle.com — and our security policy blocks the analytics snippet Paddle's script tries to add. /contact runs a script of ours that loads Cloudflare Turnstile from Cloudflare's servers, which checks the form for spam by asking Cloudflare and sets no cookie. No other page carries any other kind.
What that word doesn’t cover
Your request still crosses Cloudflare
It terminates the connection and carries every request we serve, this page included. We did not build a way around that, and it is named — with exactly what it handles — on the subprocessors page.
This is about the website, not the product behind it
Sign in and our servers do start keeping operational records — which request was served, which job ran, what broke — on the short clock the table above gives them. That row is not an exception to this section. It is the other half of it.
What we do not have
No page here carries a badge, because there is nothing to put on one. What follows is the list we would rather you read from us than work out later.
A SOC 2 report, an ISO 27001 certificate, or an audit of any kind.
The claims on this page are properties of the code rather than of a policy. A file has no endpoint to arrive at. The retention windows are indexes the database enforces on its own. The number in the sentence above is read from the same constant the index is declared with, so the promise and the mechanism cannot drift apart.
What changes it · The first security review that requires one is when we start one, and it will be named here.
A data-retention commitment from the company that routes our model requests.
We send a task only the material it needs — never another deal of yours. What we do not have is a signed undertaking about what the gateway itself keeps, and our own configuration sets no retention policy on those requests. Anyone who tells you otherwise about a service this size is guessing.
What changes it · Named on the subprocessors page the day one is signed.
Any statement about where our servers are.
Silence, in the one place on a page like this that normally says “hosted in the EU”. The arrangement is changing, and a claim about it is worth nothing until it is one we can hold to. Silence you can see beats a claim you cannot check.
What changes it · Stated here, plainly, once the move is done.
Nobody is paying us to look at your calls
Every large tool in this category sells a manager a view of what their reps did. That is the product, and it is why the recording has to survive: somebody other than you has to be able to open it later. The incentive runs against the rep before a single engineer makes a decision.
SalesWolf has no manager view, no team roll-up, no pipeline report and no CRM sync. There is nobody on the other side of your deal asking us for it, and no product we could build them without building a different company. This is not a temptation we are resisting — it is one we never created.
Sending this to your security team
This page is the one to forward. The binding versions are below — the same facts in the register a reviewer needs, with the clauses that are still open left visibly open.
A question none of them answers goes to [email protected], which reaches a person.