Privacy Policy
Last updated 10 August 2026
Who is responsible
Draftlabs is the data controller for Wobboo. You can reach us at hello@draftlabs.org for any question about your data, including a request to delete it.
What we collect
Three things, and nothing else:
- The photo you upload. You choose it. We never ask for a photo of a person, and you should not upload one of someone who has not agreed to it.
- Your email address, if you ask us to reveal a card. This is how we send you the sign-in link and how you get back to your Toybox later.
- How you arrived and what you clicked. If you came from a Google ad we store the ad click identifier (
gclid) and the campaign tags in the URL, so we can tell how many people who arrived went on to make something. We also record page views and a small set of product events, tied to a randomly generated identifier rather than to your name.
We do not ask for your real name, your address, your phone number, or any payment details. Wobboo takes no payments at all.
Where your photo goes
Your photo is uploaded to a private storage bucket. It is not published, it is not listed anywhere, and its address cannot be guessed — the file name carries a random tag derived from a key that only our server holds, and the bucket does not allow anyone to browse its contents.
To make your card, our server creates a temporary, expiring link to that file and sends it to our image provider, fal.ai. fal.ai reads the photo twice: once to generate the creature artwork, and once to read a few attributes from the image that inform the creature’s name and type. This is the one place your photo leaves our own storage, and it is what makes the product work.
The creature artwork that comes back is generated art. It is not your photo, and your photo is never shown on the card, on the site, or to anyone else.
So when we say elsewhere that your photo stays private, we mean exactly this: it is never published, never shown to other users, never sold, and never used to train a model. It is processed by the provider named above for the sole purpose of making your card.
Who else processes your data
We use a small number of services to run Wobboo. Each one only receives what it needs:
- Supabase — database, sign-in, and the private storage bucket your photo sits in.
- fal.ai — generates the creature artwork and reads attributes from your photo, as described above.
- PostHog — product analytics: page views and product events, under a random identifier. Your photo is never sent to it.
- Resend — sends your sign-in link and the email confirming a card is in your Toybox.
- Vercel — hosts the site and serves these pages.
We do not sell your data, and we do not share it with advertisers. The ad click identifier we store travels one way: it comes to us from the ad, it does not go back out.
How long we keep it
Wobboo is a short experiment. Your photo, the generated card, your email address and the associated records are kept for as long as the experiment runs, so that your Toybox still works when you come back to it. There is no automatic deletion schedule — we would rather tell you that plainly than promise a timetable the product does not implement.
When the experiment ends, the infrastructure holding this data is torn down and the data goes with it.
Deleting your data
Email hello@draftlabs.org from the address you signed up with and ask us to delete your data. We will remove your photo, your cards and your account record. You can also ask us for a copy of what we hold about you, or ask us to correct it.
Cookies and similar storage
We use only what the product needs to function: a sign-in session once you have used your email link, a short-lived token that ties an in-progress creature to your browser before you have signed in, and the analytics identifier described above. There are no advertising cookies and no third-party trackers beyond the analytics service named above.
Children
Wobboo is not intended for children. Do not use it if you are under 13, and do not upload a photo of a child.
Changes to this policy
Wobboo is being actively built, so this page will change as the product does. The date at the top is the last time it was revised, and it is revised when the behaviour changes — not on a schedule.