Privacy policy
This policy covers two very different kinds of visitor: firms evaluating our software, and people submitting a confidential report. The rules for reports are stricter, and they are stated separately below.
Last updated 26 July 2026
Who we are
WOLF AI is a software company building case-preparation tools for plaintiff-side False Claims Act litigation. We are not a law firm. We do not provide legal advice and we do not represent anyone.
The data controller is WOLF AI. Contact: contact@getwolf.ai.
1. Confidential reports submitted at /report
This is the most sensitive information we hold, and it is handled under its own rules.
What we collect
- What you tell us happened, in your own words.
- The organization and location you name, if you choose to name them.
- Your answers to the questions about government programs, timing, documents, and who else you have told.
- Your name, and an email address or phone number so we can respond.
- Any instructions you give us about how to contact you.
What we deliberately do not collect
- Your IP address and browser details are not stored with your report. Our other forms record them; this one does not, because on this form they are the fields that could identify you.
- We load no analytics, advertising, or third-party scripts on /report. Google Tag Manager, which runs elsewhere on this site, is switched off on that path, and a Content-Security-Policy blocks off-origin scripts from running there at all. One caveat we will not hide: this site is served through Cloudflare, and Cloudflare's edge can add its own telemetry to pages it serves independently of our code. We are switching that off for this path, and this sentence will be updated when it is confirmed gone.
- No cookies are set on /report, and nothing you type is written to your device. If you close the tab before the final step, the draft is gone, including from us.
Who can read it
Two people: Naveen and Joseph, the founders of WOLF AI. No employee, contractor, investor, or partner firm has access. Notification emails we send ourselves contain only a reference code, never the contents of your report, so that your disclosure does not also come to rest in a third-party mailbox.
Who we share it with
No one, unless you specifically tell us to. If your report describes something a qui tam attorney should see, we will tell you who we have in mind and ask you first. Your consent is per-firm and per-report. There is no blanket clause here permitting us to pass disclosures to partners, and we will not add one.
The one exception is legal compulsion: a court order, subpoena, or other binding legal process. If that ever happens we will tell you before complying, unless we are legally prohibited from doing so.
How long we keep it
Indefinitely, unless you ask us to delete it. Qui tam matters develop over years and a report that goes nowhere in 2026 may matter in 2031, so we do not auto-expire them. You can ask us to delete your report at any time, for any reason, and we will do it. Email us with your reference code.
2. Demo requests and firm enquiries
When a firm books a demo we collect the name, email, firm, phone, preferred time, and notes provided on the form, along with the IP address and browser user-agent of the submission. We use these to respond to the enquiry and to understand which firms are interested in the product. They are retained until the enquiry is closed and for a reasonable period afterwards for business records.
3. General website visitors
On the marketing pages of this site, meaning everything except /report, we use Google Tag Manager and the analytics it loads to understand traffic and which pages are read. This sets cookies and shares standard web-request data, including your IP address, with Google.
You can block this with any standard content blocker, and it does not run on /report under any circumstances.
4. Where the data lives
The site is hosted on Vercel. Data submitted through our forms is stored in a Neon PostgreSQL database. Transactional email is sent through Resend. All three are United States service providers, and data is transmitted over encrypted connections and encrypted at rest by those providers.
Like any site behind a CDN, Vercel's edge network processes request metadata including IP addresses in order to serve pages at all. We do not store that metadata against your report, but we also do not control our host's operational logs, which is precisely why this site describes reports as confidential rather than anonymous.
5. Your rights
You can ask us to:
- Tell you what we hold about you.
- Correct anything that is wrong.
- Delete it entirely.
- Stop contacting you.
Email contact@getwolf.ai. For a confidential report, include your reference code and nothing more. There is no need to restate the details over email. We aim to respond within 30 days. Depending on where you live you may have additional statutory rights, including under the GDPR or the CCPA, and we will honour those.
6. Changes
If we change this policy in a way that affects how reports are handled, we will change the "last updated" date and describe what changed. We will not retroactively broaden who can read a report you already submitted.
Questions about any of this go to contact@getwolf.ai. If your question is about a report you submitted, include your reference code and nothing else. Do not repeat the details in email.