Privacy Policy
Last updated: August 18, 2026.
I am one person running a small business, not a data company. I collect what I need to talk to you, book you, take payment, and do the work. This page says exactly what that is, who else sees it, how long I keep it, and how to get it back or get it deleted.
Who I am
This site and the AI consulting work on it are run by Noam Wolf, trading as Sunny Entertainment, in Los Angeles, California. The legal entity behind the business is AviNoam Productions Inc. Where this page says "I", "me" or "my", that is who it means.
"The site" means the pages at noamwolfmusic.com, including the AI consulting page at /ai/.
The way to reach me about anything on this page is by email: bookings@sunny-ent.com. I read it myself.
What I collect
There is no account on this site and nothing to log in to. I do not know who you are just because you read a page. Information reaches me in four ways.
1. The enquiry form
The form on the /ai/ page asks for your name, your email address, and a message about your business. It also has optional boxes for your phone number and your business name. That is the whole form. I get exactly what you type into it and nothing else.
One thing worth knowing, because it is unusual. The moment you press send, your message is saved in your own browser first, before anything is checked or sent anywhere. That is on purpose: if the send fails, your words are not lost and the page can offer to email them to me instead. That copy sits in your own browser's local storage, on your own device, under the name nw_ai_page_journal_v1. I cannot read it. It is deleted automatically once your message reaches me, and you can clear it yourself any time by clearing this site's data in your browser.
When your enquiry does reach me, it arrives as an email in my inbox, it is also written to a log file on my own server so a failed email can never lose it, and I get a copy as a message on Telegram so I see it quickly.
2. Booking a consultation
The booking calendar on the /ai/ page is Cal.com, shown inside a frame on the page. When you book, Cal.com collects your name, your email address, your time zone, the time slot you chose, and anything you type into the booking form's own boxes. All of that comes through to me.
3. Paying
The card is charged at the moment you book. Payment is handled by Stripe, through Cal.com. Your card details go straight to Stripe and never touch this site. I never see or hold your card number. What I see afterwards is what Stripe shows me: that a payment succeeded, the amount, the card brand, the last four digits, and the name and email on the payment.
4. The consultation call itself
The consultation is a live video call on Google Meet, one to one. During it you will show me real parts of your business: your inbox, your process, sometimes your clients' names on a screen.
The call is recorded and transcribed using Fathom, which also writes the notes. That is a deliverable, not surveillance: the recording and the notes are sent to you afterwards so you never have to remember what we did. I keep a copy too. If you would rather not be recorded, tell me at the start of the call and I will turn it off.
I treat everything I see in your session as confidential. I do not repeat it, publish it, or use it as an example anywhere without asking you first, and if I ever did ask, anything identifying would be taken out. The prompts and automations we build are yours, and they live in your account, not mine.
And the ordinary internet
Like every website, the servers that deliver these pages see the normal technical facts of a request: your IP address, your browser and device type, and which page you asked for. That is handled by Cloudflare, which serves the site and filters out attacks and bots. The enquiry form also counts recent submissions per IP address for a short while, so one machine cannot flood it. That count is not linked to you and is not kept.
These pages also count visits, so I can see how many people read them and which email or post sent them here. There is a section on it further down, under Analytics.
Why I have it
- To answer you. Your enquiry is how I write back with what I would build, how long it would take, and what it would cost.
- To hold your session and turn up to it. Your name, email and time zone are how the meeting exists and how the confirmation and reminders reach you.
- To take and refund payment. The card clears before the slot is held, and a cancellation two or more days ahead is refunded automatically, which needs the payment record to exist.
- To do the work well. What you tell me about your business is what I use to prepare for your session and to build the thing we build.
- To keep the books. Payment and invoice records are business records and have to be kept.
- To tell you about things I make later. This one is new, so it gets its own section below.
I may email you about my own work later
Please read this bit properly, because it is the part people usually find buried somewhere else.
If you send me an enquiry or book a session, I may email you later about other things I am offering: an online course, a presentation or workshop, digital products, that kind of thing. It is my own work only. I am not emailing you on anyone else's behalf.
You can stop it at any time. Email bookings@sunny-ent.com and say you do not want marketing email, or reply to any message I send you and say the same. I will take you off and it will not change how I treat you as a client.
I do not sell your information, and I do not trade it or share it for advertising. I do not give or sell your email address to anybody else to market to you.
Who else touches it
I use a small number of outside companies to run this. Each one only gets the part it needs to do its job, and each has its own privacy policy that governs what it does with it. This is the whole list.
- Cloudflare. Serves and protects the site. Sees the technical details of your request, including your IP address. It also runs the cookieless page counter described under Analytics below.
- Cal.com. The booking calendar. Gets your name, email, time zone, the slot you chose and your booking answers. It is also the piece that hands the payment to Stripe.
- Stripe. The payment processor. Gets your card details directly, plus the name and email on the payment. Stripe is the only one here that ever sees a card number, and I am not in that path at all.
- Google. Four separate parts of my setup. Gmail carries and stores my email, so your enquiry and our correspondence sit in a Google inbox. Google Meet hosts the consultation call. The typefaces on the site are loaded from Google's font servers, which means Google's servers see your IP address and browser when a page loads, with nothing you typed. And Google Analytics counts visits to the pages, described under Analytics below.
- Fathom. Records and transcribes the consultation call and writes the notes.
- Meta. The Golden Prompts page, and only that page, carries a Meta pixel so I can tell whether an advert for that free download worked. See Analytics below.
- Telegram. I get a copy of new enquiries as a message on Telegram so I notice them quickly. That message contains what you typed into the form.
Your enquiry is also written to a log file on my own server, so nothing is lost if an email fails to send.
Beyond that, I share your information only when I genuinely have to: if the law requires it, or to protect against fraud or abuse.
Analytics: two visit counters
This site counts visits with two tools, on every page including this one. They are there so I can tell whether anybody is actually reading the pages, and which email, post or link sent them here. That is the entire reason they exist.
Cloudflare Web Analytics is the simple one. It counts that a page was loaded, which page it was, the address of the site that linked you here if you followed a link, the country the request came from, the broad type of browser and device you used, and how quickly the page loaded for you. It sets no cookies and saves nothing on your device, it does not give you an identifier, and it cannot recognise you on another website. Cloudflare already delivers this site, so it already handles the technical facts of your request described above; this adds the counting on top, under Cloudflare's own privacy policy. Cloudflare says it works out the country from your request and then discards your IP address rather than storing it, and that it does not track people across the sites it counts for.
Google Analytics is the second one, added in September 2026. It counts the same kind of thing, plus the campaign tag on the link you clicked, so that when I send an email I can see how many people it actually brought to the site. It does set cookies, in your browser and under my own domain, and it uses them to work out whether a visit is a new person or the same person coming back. Those cookies expire on their own. Google processes this under its own privacy policy, and I have not switched on advertising personalisation or any Google Ads link for it.
What comes back to me from both is totals and charts. I do not know your name from either one, I never upload your email address or anything you typed into them, and I am not trying to identify you.
One page, The Golden Prompts, also carries a Meta pixel, so that if I run an advert on Facebook or Instagram for that free download I can tell whether it worked. It is on that page only, not on this one and not on the rest of the site. It sets its own cookies under Meta's domain and Meta processes it under its own privacy policy. Blocking scripts, or blocking connect.facebook.net, switches it off, and the download works exactly the same.
If you would rather not be counted: any browser setting, privacy mode or extension that blocks scripts, or that blocks static.cloudflareinsights.com and googletagmanager.com, switches both off completely. Google also publishes an opt-out add-on at tools.google.com/dlpage/gaoptout. Nothing on the page breaks if you do any of that. The booking calendar and the enquiry form work exactly the same either way.
The booking frame belongs to Cal.com, and Stripe sits behind it. They do their own measuring inside their own frames, under their own policies.
Cookies
There is no advertising cookie here, and nothing that follows you to another website. The Cloudflare counter described above sets no cookies at all. Google Analytics does set one, on my own domain, purely to tell a returning visit from a new one.
Three things use your browser's storage:
- The Google Analytics cookie described above. It holds a random number, not your name, and it expires on its own. Blocking it changes nothing about how the site works for you.
- The unsent-message copy described above, saved in local storage on your own device so your words survive a failed send. It is not a cookie, it is never sent to anyone, and it is deleted once your message arrives.
- The Cal.com booking frame, and Stripe behind it, which set their own cookies and storage under their own domains in order to run the booking and take payment securely. Those are theirs, and I cannot switch them off and still take a booking.
Cloudflare may also set a security cookie to tell real visitors apart from bots. You can block or delete any of these in your browser settings, though blocking the booking frame's storage will stop the calendar working.
How long I keep it
Five years. Enquiries, booking records, our email threads, call recordings and call notes are kept for five years from our last contact, and then deleted. If you ask me to delete them sooner, I will.
Two things sit outside that. Payment and tax records are kept for as long as tax and accounting rules require, because they are business records and I do not get to delete them on request. The unsent copy of your message in your own browser is not mine at all: it is deleted the moment your message reaches me, and it never leaves your device before then.
What you can ask me for
You do not need a reason, and you will not be treated differently for asking.
- Ask what I have. I will tell you what information about you I hold and where it came from.
- Get a copy. I will send you the information you gave me.
- Have it corrected. If something about you is wrong, tell me and I will fix it.
- Have it deleted. I will delete what I hold, apart from records I am required to keep, such as payment and tax records, and I will tell you if that applies.
- Stop the marketing email described above, without stopping anything else.
- Send someone on your behalf. If you want somebody to make the request for you, that is fine. I will need to be able to confirm they are acting for you.
To use any of these, email bookings@sunny-ent.com and say what you want. I may need to check you are who you say you are, usually by replying from the address you originally used. I answer these personally.
Children
This is a service for people running businesses. It is not directed at children, and I do not knowingly collect information from anyone under 13. If you believe a child has sent me something, email me and I will delete it.
Changes to this page
If what I do with your information changes, I will change this page and move the date at the top. The date at the top is always the truth about when this was last accurate. If a change is a significant one, I will say what changed rather than quietly editing it.
Contact
Questions about any of this, or you want your information out of my hands: email bookings@sunny-ent.com. A real person reads these.