Our Privacy Principles
Adapted for public reading from Wolf Pak Strategies' internal Privacy Protection Constitution, Version 1.0, ratified June 2026.
We hold these to be non-negotiable: that users have a fundamental right to digital privacy, that their data belongs to them alone, and that software which respects its users is the minimum standard of integrity — not a premium feature.
This is a binding charter, not marketing copy. It governs every product decision, every infrastructure choice, and every third-party integration across Wolf Pak's products, including Tabella. When convenience conflicts with privacy, privacy wins. When growth conflicts with these principles, the principles win.
Identity sovereignty
Users are never required to authenticate through a third party that can surveil, monetize, or deny access to their identity. Tabella specifically operates its own authentication entirely, with no connection to any external identity provider — a permanent architectural decision protecting its privacy-first design. Password hashes use Argon2id. Refresh tokens are stored as hashes, never in plaintext, and are single-use.
The right to private communication
End-to-end encryption is the only mode Tabella operates in — not an opt-in feature. No plaintext message content is stored on the server; it holds ciphertext only. File attachments are encrypted client-side before upload.
Tabella's server operates in closed, non-federated mode and does not communicate with external servers on other networks — this prevents metadata from leaking to third parties. This is a permanent decision that cannot be quietly reversed; changing it requires a formal, public amendment to this charter (see below).
What we disclose rather than hide: push notifications via Apple and Google's services necessarily expose limited metadata — who received a message, in which conversation, and when — to those platforms, even though message content stays encrypted. This is disclosed before you send your first message, not buried in a terms-of-service update later.
Data residency
User data resides on infrastructure we control, in jurisdictions we've consciously chosen. The following categories of data are never transmitted to, processed by, or stored on any third-party system, under any circumstance:
- User credentials, password hashes, or authentication tokens, in any form.
- Plaintext message content, unencrypted file attachments, or decryption keys.
- Private cryptographic signing keys or any private key material.
- User behavioral profiles, usage analytics, or engagement metrics intended for external consumption.
- Personally identifiable information for the purpose of advertising targeting.
The third-party rule
We apply a presumption against third-party integrations and require an affirmative reason for each one. Before any third-party service is integrated, it must fail all three of these questions:
- Does it require the third party to see, process, or store user data in plaintext?
- Does it create a dependency that can't be replaced without changing the product experience?
- Does the third party use the data they receive to profile, advertise to, or monetize users?
A "yes" to any of these means the integration is prohibited, full stop — regardless of what the vendor's terms of service claim. Advertising networks, behavioral-analytics SDKs (the Google-Analytics/Mixpanel kind), and social-media tracking widgets are permanently excluded from every Wolf Pak product on this basis.
Metadata minimization
Even encrypted content leaks information through metadata — who talked to whom, when, how often. We commit to minimizing what we generate, retain, and expose:
| We do not collect | Unless |
|---|---|
| IP addresses, by default | Only if required for abuse prevention, and then anonymized and retained no more than 7 days |
| Device fingerprints or hardware identifiers | Never |
| Behavioral usage profiles (features used, session length, content viewed) | Only if anonymized, aggregated, never sent to a third party, and explicitly disclosed |
| Location data | Only when it's a core, disclosed feature requiring active consent each session |
Rejection of surveillance capitalism
We will never sell, license, or transfer user data for advertising or behavioral profiling; build advertising products into any Wolf Pak application; or accept investment on terms that require data-sharing. We generate revenue the way software has always earned it honestly: people pay for a product because it's worth paying for. Subscriptions, institutional licensing, and professional services are revenue we accept. Advertising, data brokerage, and pay-to-rank placement are revenue we categorically reject.
Transparency obligations
- Every product maintains an accurate, plain-language privacy document describing what's collected, where it's stored, who can access it, and how long it's kept.
- Known limitations are disclosed before you finish onboarding — not discovered later.
- If a data breach occurs, affected users are notified within 72 hours of discovery, in plain language, with what we're doing about it.
- You can request a full export of your data, or full deletion of your account and its data, and we commit to delivering either within 30 days. Deleting an account is never made harder than creating one.
How this charter can change
This charter can only be amended by Wolf Pak's Founder — not by a product team, not by an investor, not under a deadline. Any amendment requires a written proposal identifying exactly what's changing, a documented explanation of why it doesn't weaken user privacy, and a 30-day public review period before it takes effect. No amendment is made under time pressure, business urgency, or investor pressure.
Privacy is not a feature to be negotiated. It is the foundation on which we build.
Read the harder, less comfortable version of these questions on Hard Questions About Tabella, or how the encryption itself actually works on Encryption.
Create your account →