Privacy Policy.
This Privacy Policy explains how WolfAI ("WolfAI," "we," "us") collects, uses, shares, and protects information when you visit wolfai.io, use the application at app.wolfai.io, submit a fraud tip, book a demo, or otherwise interact with our services (collectively, the "Services").
WolfAI is an intake, organization, and analysis platform for potential fraud matters. We are not a law firm and do not provide legal advice. Use of the Services does not create an attorney-client relationship with WolfAI.
1. Summary
- We collect information you give us (account info, case intake details, documents you upload) and a small amount of technical information automatically (device, log, and product-analytics data).
- We use that information to operate the Services, analyze potential fraud matters at your direction, communicate with you, and improve the product.
- We share information with a limited set of sub-processors (hosting, email, analytics, AI model providers) listed below.
- We do not sell your personal information and we do not use your case content to train third-party models for purposes unrelated to your matter.
- You have rights to access, correct, delete, and export your information, described in Section 9.
2. Information We Collect
2.1 Information you provide
Account & contact information. Depending on how you use the Services, we may collect:
Email address, name, role (e.g., relator, lawyer, law-firm admin, client), and law-firm affiliation when you sign up, accept an invitation, or contact us.
Demo bookings. Name, email, organization, and selected meeting time when you book a demo through our marketing site.
Whistleblower / fraud-tip submissions. Email, fraud type, estimated scale, timeframe, evidence categories, and the narrative description you submit through our public intake form.
Onboarding details. For law firms, this includes firm name, address, and member information; for clients invited by a firm, this includes profile details required to participate in their case.
Case intake content. Information you enter into a case, including: relator details (name, email, phone, address), target-company information, defendant information (which may include names, addresses, phone numbers, and identifiers such as NPIs for healthcare matters), case narratives, dates, dollar amounts, jurisdictional information, and references to procedure or billing codes.
Documents you upload. Files you upload to your case (PDFs, Word documents, images, and archives), along with the text and structured data extracted from them. These documents may contain personal information, financial information, business records, communications, and — in healthcare matters — medical and billing records that may include protected health information (PHI). Please see Section 4 (Sensitive Information) before uploading.
Communications. Messages you send to us by email, through support channels, or through the in-product chat.
2.2 Information collected automatically
Log & device data. IP address, browser type, operating system, referring URLs, pages visited, timestamps, and similar diagnostic data generated when you use the Services.
Product analytics. Aggregated and event-level usage data (e.g., which pages you view, which steps of a flow you complete) collected through our analytics provider (PostHog) using cookies or browser storage. We use this in "identified" mode only after you have authenticated or voluntarily submitted contact information.
Cookies and similar technologies. Strictly necessary cookies (for example, to keep you signed in) and analytics storage as described above. We do not use cookies for third-party advertising.
2.3 Information from third parties
When you use certain features, we receive information from third-party sources at your direction or to verify data you have entered. For example:
- Address suggestions and validation from Google's Places and Address Validation APIs when you fill out address fields.
- Provider and procedure data from public U.S. government sources, including the NPI Registry (NPPES), the CMS Medicare datasets, the OIG LEIE exclusion database, and CMS Open Payments. These public lookups generally use identifiers (such as NPIs or CPT codes) and do not transmit your case content.
- Case-law and public-record results from CourtListener and similar public research services.
- Business and company information from research providers such as Exa.ai, when you initiate a research workflow.
3. How We Use Information
We use the information described above to:
- Provide, operate, secure, and improve the Services;
- Process documents and case content you submit, including running automated extraction, classification, and analysis workflows (described in Section 5);
- Authenticate you, manage roles and permissions, and prevent abuse;
- Communicate with you — for example, to send one-time passcodes, invitation emails, analysis-complete notifications, demo confirmations, and support responses;
- Generate aggregated, de-identified insights and analytics;
- Comply with legal obligations and enforce our terms;
- Develop new features and improve product quality and reliability.
Legal bases (where applicable). Where laws such as the GDPR or UK GDPR apply, we rely on your consent, the performance of a contract with you, our legitimate interests in operating and securing the Services, and compliance with legal obligations.
4. Sensitive Information
Case documents you upload may contain sensitive personal information, including health information, financial information, government identifiers, and information about third parties. Specifically:
Health information. Healthcare-fraud matters routinely involve billing records, claims data, and medical records that may constitute Protected Health Information (PHI). WolfAI is not a HIPAA-covered entity. If you are a HIPAA covered entity or business associate, you are responsible for ensuring that you have an appropriate legal basis to share PHI with us, that you de-identify materials where required, and that you do not upload PHI absent an applicable agreement.
Third-party information. Case content frequently includes information about defendants, providers, employees, and other third parties. You represent that you have the right to submit any information you upload.
Privileged or unlawfully obtained materials. Do not submit privileged, confidential, or unlawfully obtained materials unless directed by your attorney.
5. Automated Processing and AI
The Services use automated systems, including large language models, to extract text from documents, classify and tag content, and produce analyses and summaries of case material. These workflows run on our infrastructure and on the systems of model providers listed in Section 6.
Model providers process your case content solely to return results to WolfAI. We do not authorize them to use your case content to train their general-purpose models.
Automated outputs are not legal advice and may contain errors. They are intended to assist qualified professionals, not to replace their judgment.
6. How We Share Information
We share information only as described below. We do not sell personal information.
6.1 Sub-processors
We use the following sub-processors to operate the Services. Each is contractually limited to using information to provide services to WolfAI.
- Supabase — Authentication, database, file storage, edge functions (account info, case content, uploaded documents).
- Cloudflare — Application runtime (Workers), object storage (R2), CDN (uploaded documents, derived text, log data).
- Vercel — Hosting of marketing and web applications (log and request data).
- Resend — Transactional email: OTP codes, invitations, notifications (email address, message content).
- Google (Calendar, Places, Address Validation) — Demo booking and address lookup/validation (name, email, requested times, address inputs).
- PostHog — Product analytics and feature usage (usage events, device/log data, account identifiers after sign-in).
- Anthropic, Google (Gemini), OpenRouter — LLM-based document extraction and analysis (document text, case content provided to the model).
- Exa.ai — Company and public-source research workflows (search queries, e.g. company names you enter).
- CourtListener — Public case-law research (search queries; no case content uploaded).
6.2 Within your law firm or organization
If you are part of a law firm or client workspace, members of that workspace with appropriate roles can access cases and content shared in the workspace. Administrators can manage members and access.
6.3 Legal and safety
We may disclose information when we believe in good faith that disclosure is required to comply with applicable law, valid legal process, or government requests; to enforce our terms; to protect the rights, property, or safety of WolfAI, our users, or others; or in connection with investigating fraud or other wrongdoing. Where permitted, we will notify the affected user before disclosing.
6.4 Business transfers
If WolfAI is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to standard confidentiality protections.
7. International Data Transfers
WolfAI is operated from the United States. If you access the Services from outside the United States, your information will be transferred to, stored in, and processed in the United States and other countries where our sub-processors operate. Where required by law, we rely on appropriate transfer mechanisms, such as the European Commission's Standard Contractual Clauses.
8. Data Retention
We retain information for as long as it is needed to provide the Services, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. Specifically:
- Account data is retained for as long as your account is active and for a reasonable period afterward.
- Case content and uploaded documents are retained for as long as the workspace that owns the case maintains it, subject to deletion requests as described below.
- Whistleblower intake submissions are retained so that authorized counsel can review them; submitters may request deletion subject to legal-hold obligations.
- Logs and analytics data are retained on a rolling basis appropriate to the purpose (typically up to 24 months).
9. Your Rights and Choices
Depending on where you live, you may have rights under laws such as the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and similar U.S. state privacy laws. Subject to those laws, you may:
- Request access to the personal information we hold about you;
- Request correction of inaccurate or incomplete information;
- Request deletion of your personal information;
- Request a portable copy of certain information;
- Object to or restrict certain processing, including processing based on legitimate interests;
- Withdraw consent where we rely on consent;
- Lodge a complaint with your local data-protection authority.
We do not sell personal information and we do not "share" it for cross-context behavioral advertising as defined under California law.
If a law firm or client workspace administers a workspace that includes your information, please direct workspace-specific requests to that administrator; we will support them in responding.
To exercise any of these rights, contact us at support@wolfai.io. We will verify your identity before fulfilling a request.
10. Security
We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit, encryption at rest for primary data stores, role-based access controls, and audit logging. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
If we become aware of a security incident affecting your personal information, we will notify affected users and regulators as required by law.
11. Whistleblower and Case-Confidentiality Notes
We understand that fraud-tip and qui tam matters are sensitive. Submissions made through our intake flows are stored with access restricted to authorized WolfAI personnel and the law-firm workspace (where applicable) you have engaged. We do not publicly disclose the identity of a submitter except as required by law or as expressly directed by the submitter.
Submitting information to WolfAI does not, by itself, create an attorney-client relationship. If you intend to file a qui tam action or report suspected fraud to a government agency, please consult qualified counsel.
12. Children
The Services are not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
13. Third-Party Links
The Services may contain links to third-party websites and services. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting a notice on the Services or by email. Continued use after the effective date means you accept the revised policy.
15. Contact
For questions about this Privacy Policy, contact us at support@wolfai.io.