Legal
Privacy Policy
This policy explains what Woolly collects, why, and the choices you have. Woolly at woolly.run is run by Great Land of Gems.
1. What we collect
- Account information. When you sign up we use Clerk. Clerk stores your name, email, and login credentials. We receive your user ID, email, and basic profile. We never see or store your password.
- Payment information. When you pay we use Stripe. Stripe collects and processes your card and billing details. We do not store full card numbers. We keep a record of your payments, plan, and status.
- Your engine configuration. The topic, seed sites, settings, and branding you enter to build and run an engine.
- Search queries. When someone searches an engine you built, we process the terms they type in order to return results, keep the service working, and prevent abuse.
- Usage and analytics. Technical data such as pages viewed, actions taken, approximate location from IP, browser and device type, and log data like IP address and timestamps.
- Messages. If you email us or contact support, we keep what you send.
2. How we use it
- Build, host, and serve your engine.
- Process payments and prevent fraud.
- Improve ranking, relevance, and product quality.
- Keep the service secure and enforce our policies.
- Contact you about your account, changes, and support. We use Resend to send email.
- Meet legal and accounting obligations.
We do not sell your personal information.
3. Searches on engines you build
Queries typed into an engine are used to return results, protect against abuse, and improve quality. We aggregate and de-identify query data for analytics where we can. If you run an engine, you are responsible for telling your own users how their searches are handled, and for any ads you place on it.
4. Ads
If you monetize your engine with ads, the ad provider you choose may set its own cookies and collect data from your users. That relationship is between you, your users, and your ad provider. Configure and disclose it responsibly.
5. Sub-processors
We rely on a small set of providers to run Woolly. They process data on our behalf under their own terms.
- Clerk: accounts and authentication.
- Stripe: payments.
- Neon: Postgres database hosting, which stores your account and engine data.
- Render: application hosting and compute.
- xAI: model provider used to help generate and tune engine configuration.
- Resend: transactional email.
We may add or change sub-processors as the service evolves, and we will update this list when we do.
6. Where indexed content comes from
Woolly indexes publicly available web pages, through live crawling that respects robots.txt and through the public Common Crawl archive. That indexed content is third-party material, not personal data we collect about you. If a page on the open web contains personal information and you want it out of an engine, see the Copyright / DMCA and removal policy.
7. Retention
We keep account and engine data while your account is active, and for a reasonable period after, so we can meet legal, accounting, and security needs. We keep payment records for as long as the law requires. We keep logs and query data for a limited period for security and quality, then delete or de-identify them. When you delete your account, we delete or de-identify your data within a reasonable time, except what we must keep by law.
8. Your rights
Depending on where you live, you can ask to access, correct, export, or delete your personal information, and to object to or limit some uses. To make a request, email privacy@woolly.run. We will verify your request and respond within the time the law requires. You can also delete your account from the dashboard. Some data is handled by our providers: you can manage your login through Clerk and your payment details through Stripe.
If you are in the EEA or UK, our legal bases for processing are: performing our contract with you, our legitimate interests in running and securing the service, your consent where we ask for it, and compliance with law.
9. Cookies
Woolly uses cookies and similar storage that are needed to sign you in, keep your session, and run the app. We use limited analytics to understand usage. We do not use third-party advertising cookies on woolly.run. Engines you build, and any ads you add to them, may set their own cookies, which is under your control. You can block cookies in your browser, but the app may not work fully without the essential ones.
10. Security
We use reputable providers and standard measures to protect your data. No system is perfectly secure. Tell us right away if you think your account has been compromised.
11. Children
Woolly is for adults and is not directed to children under 13, or the minimum age where you live. We do not knowingly collect data from them. If you believe a child gave us personal information, contact us and we will delete it.
12. International transfers
Our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards for those transfers.
13. Changes
We may update this policy. We will announce material changes by email or in the app. The effective date at the top shows the latest version.
14. Contact
privacy@woolly.run, or [PLACEHOLDER: legal entity name], [PLACEHOLDER: mailing address].