WoluTools

Privacy policy

How WoluTools handles personal data

This notice covers the public website, verified accounts, PayPal and Stripe checkout and every supported tool workflow. No advertising or behavioural tracking is used.

1. Controller

Wilhelm Machholz, Woluex, Versbacher Str. 229, 97078 Würzburg, Germany. Email: info@wolutools.com.

2. Website and security

IP address, request time, requested address, response status, browser information and security events are processed to deliver and protect the service under Article 6(1)(f) GDPR. Logs rotate and are retained only as operationally required.

3. Accounts and email

For registration and account operation WoluTools processes email address, password hash, verification and acceptance timestamps, session and CSRF hashes, credit balance, ledger and job ownership under Article 6(1)(b) GDPR. Login sessions expire after 14 days. IONOS provides business email. Account and correspondence data is retained while required for the relationship, legal duties or claims.

4. PayPal, Stripe and payment records

For checkout WoluTools sends the payment provider you choose (PayPal, or Stripe Payments Europe, Ltd., Dublin, Ireland, for card payments) the information necessary to create and settle the selected payment. Each provider processes payment and account information under its own privacy terms; card details are entered on the provider's page and never reach WoluTools. The legal basis is performance of the contract (Art. 6(1)(b) GDPR). Stripe may transfer data to the United States under the EU-US Data Privacy Framework and standard contractual clauses. WoluTools stores the provider order, capture and subscription references, buyer country, currency, net, tax and total amounts, purchased, applied or recurring-plan credits, status, refund or dispute events, and the versions and timestamps of required legal acknowledgements. These records are processed under Article 6(1)(b) and (c) GDPR and retained for statutory accounting and tax periods.

5. Uploaded files and results

Files, selected settings and generated findings are processed only to provide the requested tool under Article 6(1)(b) GDPR. Processing is local to WoluTools infrastructure unless a tool page expressly states otherwise. WoluTools does not train AI models on uploads. Users must have a lawful basis for any personal data they submit. Tool pages state the exact retention window; most drafts expire after two hours and most result packages after 24 hours. Price Compare results expire after seven days. Image and feed results expire after 24 hours. Earlier user deletion is available where shown.

6. Hosting, backups and recipients

The service is hosted on WoluTools-controlled netcup infrastructure in Vienna, Austria. Encrypted operational backups may contain account and job metadata and are retained up to 14 days. Recipients are limited to hosting, email and payment providers, professional advisers and authorities where legally required.

7. Cookies and measurement

Only essential session and CSRF cookies are used. Aggregate funnel counters do not use advertising identifiers and honour Global Privacy Control and Do Not Track. No advertising or behavioural analytics service is active.

8. Rights

Subject to legal requirements, you may request access, correction, deletion, restriction, portability or object to legitimate-interest processing. Contact info@wolutools.com. You may complain to the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.

Aggregate first-party usage counts

WoluTools may count a small fixed set of website events, such as a page view, prepared-demo run or tool-button click. The measurement stores only the date, event type, page path, tool key and an aggregate counter. It does not store an analytics cookie, visitor identifier, IP address, user agent or event-level history in the measurement table. Browser Global Privacy Control or Do Not Track signals suppress these aggregate events.

These counts are used only to understand which product pages are useful and where the customer journey needs improvement. They are not shared with an advertising or analytics provider and are not used to build individual profiles.

Image tool files and results

Verified users may upload static JPG, PNG, WebP and AVIF images to the Product Image Batch Editor or Target Size Image Compressor. Images, filenames, selected output settings, generated previews, ZIP files and manifests are processed only to perform the requested job. The image worker uses no external image or AI API and has no public internet access.

Original image uploads are deleted after success or failure. Generated image results and previews remain available to the account for 24 hours, are then blocked and are physically deleted in the next recurring cleanup cycle.

E-invoice files and technical reports

Verified users may upload structured invoice XML or a supported ZUGFeRD/Factur-X hybrid PDF. WoluTools processes encrypted files, filenames, detected invoice values, technical findings and explicitly confirmed transport-level repairs only to create the requested validation report. Processing uses pinned local validators and no external AI or document API.

Sources, readable findings, optional repaired copies and report packages remain available to the account for no longer than 24 hours and are then removed by the recurring cleanup process. A user can delete the complete validation earlier. Job history and dashboard data do not contain supplier names, invoice numbers, filenames or invoice contents.

Document comparison files and reports

Verified users may upload exactly two PDF, DOCX or plain-text document versions. WoluTools processes encrypted files, filenames, extracted document structure, optional alignment decisions and comparison findings only to create the requested redline and change package. Processing uses a local deterministic worker and no external AI or document API.

Sources, extractions and report packages remain available to the account for no longer than 24 hours and are then removed by recurring cleanup. A user can delete the complete comparison earlier. Job history and dashboard data do not contain document names, parties or text excerpts.

PDF redaction drafts and verified exports

Verified users may upload one PDF for local analysis and confirmed redaction. WoluTools processes the encrypted filename, source, page previews, detected text locations, exact user terms and selected rectangles only to create the requested sharing copy and technical verification report. No external AI or document API receives the file.

Unfinished drafts and previews expire after two hours. The original and previews are deleted after completion, failure or cancellation. Confirmed encrypted settings and output packages expire after 24 hours. Dashboard and job-list metrics contain no filenames, document text, search terms or preview images.

PDF accessibility preflights and guided fixes

Verified users may upload one PDF for local PDF/UA preflight and optional confirmed safe fixes. WoluTools processes the encrypted filename, source, page previews, machine findings and user-supplied metadata, bookmark, alternative-text and form-label choices only to create the requested report and optional guided-fixed copy. No external AI or document API receives the file.

Unfinished drafts expire after two hours. Originals and previews are removed after completion, failure or cancellation. Encrypted reports and optional fixed copies expire after 24 hours. Dashboard metrics contain no filenames, document text, alternative text or screenshots.

Thumbnail images and export packages

Verified users may upload one JPG, PNG, WebP or AVIF background and optionally one foreground image, then provide headline, layout, crop, colour and output choices. WoluTools processes that material locally only to render the requested video thumbnail or Shorts cover package. Images and text are not sent to YouTube, an AI provider or another external design service.

Unfinished drafts expire after two hours. Both source images are removed after completion, failure or cancellation. Export packages and their settings manifests expire after 24 hours. Job lists and dashboard metrics contain no filename, headline, image preview or channel information.

YouTube audio loudness files and listening previews

Verified users may upload one supported video or audio file for local loudness measurement and optional deterministic audio processing. WoluTools records encrypted measurement details, confirmed targets and opaque storage paths. It does not send media, filenames, measurements or previews to YouTube, an AI provider or an external mastering service.

Encrypted upload parts and short before-and-after previews expire after two hours. Source parts and previews are removed after completion, failure or cancellation. Encrypted report and fixed-media packages expire after 24 hours. Dashboard and job-list metadata excludes filenames, audio samples and channel information.

YouTube caption files and optional timing media

Verified users may upload one SRT, WebVTT or SBV file and optionally one video or audio file for local timing review. WoluTools stores encrypted source parts, structural findings and explicitly confirmed repair choices only to create the requested clean captions and evidence package. It does not transcribe, translate or send captions or media to YouTube, an AI provider or an external subtitle service.

Encrypted analysis drafts and source parts expire after two hours and are removed after completion, failure or cancellation. Encrypted caption packages expire after 24 hours. Dashboard and job-list metadata excludes filenames, caption wording, media samples and channel information.

CSV cleaning files and validation reports

Verified users may upload one CSV or TSV file and confirm validation or cleaning rules. WoluTools processes the file, filename, detected structure, rules and issue locations locally only to create the requested cleaned exports and audit package. It does not send tabular data to an external AI, spreadsheet or data service.

Unfinished drafts expire after two hours. The source file is removed after completion, failure or cancellation. Cleaned exports and reports expire after 24 hours. Job lists and dashboard metrics contain no filenames, headers, cell values or issue excerpts.

Merchant feed files and audit results

Verified users may upload CSV, TSV, TXT, XML or XLSX product feeds. WoluTools processes the file, selected market, destination, column mapping and confirmed deterministic fixes only to create the requested audit. It does not connect to Google Merchant Center or send the feed to an external AI or product-data API.

The original feed is deleted after processing. The generated report package remains available to the account for 24 hours and is then blocked and physically removed during the next recurring cleanup.

Rental projects and tenant data

The protected landlord workflow is designed to store property, unit, tenancy, payment, meter and evidence data for the account user. Sensitive fields and source documents use application-level encryption. Local text extraction and OCR run in a dedicated worker without an external AI or document API; every extracted field must be reviewed and confirmed before it can affect a calculation.

Encrypted project data is intended to remain until the account user deletes it. Temporary cleartext is removed after worker processing and generated download packages expire after 24 hours. Verified accounts can use the protected workflow. Country-specific results remain technical guidance and require appropriate legal or tax review.