Privacy Policy
Last updated Jul 27, 2026
Velum builds privacy-first tools for the AI era. Privacy is not a feature we add on top. It is the reason the products exist. This policy explains what data we do and do not collect, both in our software and on this website.
In short: the documents and text you process never leave your machine. We cannot read them, because they are never sent to us. This website collects only the minimum needed to operate, and we never sell your data.
The browser extension goes further and makes no network requests at all. The desktop app makes a small number, none of which carry your content: they are listed in full below, because a policy that claimed zero would be untrue and an untrue promise is worse than the requests themselves.
This policy applies to the Velum website (velumprivacy.com and its subdomains) and
to the Velum products: the browser extension, desktop application, and
command-line tool.
Our products: local by design
Velum's tools are built to run fully on your device.
- Velum browser extension detects and masks personal data before it reaches any large language model, then restores it in the reply. All detection runs locally using a model bundled inside the extension. The extension makes no network requests and contains no analytics or telemetry. Your text, your files, and the mapping that re-identifies masked data never leave your browser, and the mapping is cleared when the browser closes.
- Velum desktop and CLI process documents locally in the same way. Masking and unmasking never require a network connection and never send your content anywhere. The desktop app includes an optional, off-by-default local usage log to help you understand your own usage; those logs are written only to your machine and are never transmitted to Velum.
We do not receive, store, or have any access to the content you process with these tools. There is no account to create and no data to sync.
What the desktop app does send
The desktop app makes five kinds of outbound request. None of them carries your documents, your text, or the mapping that re-identifies masked data. You can see the same list inside the app at any time, in the protection receipt it can generate for you.
- An update check on launch, to our download host, so we can offer you a new version. It sends no identifier.
- A one-time model download, only when you choose to install the full detection model.
- A licence revocation list on launch, downloaded in full and checked on your machine. We deliberately do not send your licence to ask about it, so this request tells us nothing about you.
- A single activation report, sent only at the moment you enter a licence key, never repeated. It contains the licence identifier and a one-way hash of a random identifier belonging to that installation. It lets us see whether a key is in use on a handful of machines or hundreds. It contains no email, no key, and nothing derived from your hardware.
- A trial registration, sent once on first run, and not at all once you hold a purchased licence key. This is the one request that is derived from your hardware, so it deserves a plain explanation.
The trial registration, in plain terms
Velum desktop offers a 7-day trial. To stop that trial being restarted over and over on the same computer, the trial's start date is recorded on our licence service rather than on your machine, where it could simply be deleted.
What is sent: a one-way cryptographic hash of your computer's platform identifier, and nothing else. A one-way hash cannot be reversed, so we never learn the identifier itself, and it is salted separately from the activation report above so the two records cannot be matched to each other.
What is not sent: your name, your email address, your licence key, your IP address as an identifier, and no document data of any kind.
Why we keep it: the record is what makes the trial a real trial. It is retained for as long as the product exists, because deleting it would allow the same computer to start a new trial indefinitely, which is the situation it was created to prevent.
What it means for you: starting a trial requires being online once. Nothing else does. Once your trial is registered, or once you enter a purchased licence key, the app verifies your licence entirely on your own machine and no further licence request is ever made.
This website
When you visit velumprivacy.com, we process a limited amount of data to run the site
and respond to enquiries:
Analytics
We use a self-hosted, privacy-friendly analytics tool
(analytics.velumprivacy.com) to understand aggregate traffic: which pages are
viewed and roughly where visitors come from. It does not use tracking
cookies, does not fingerprint you, and does not follow you across other
websites. Data is aggregated and cannot be used to identify you.
Contact form
If you use the contact form, we collect the name, email address, and message you submit so we can reply. Submissions are delivered to our inbox through our email provider (Resend). To prevent spam, the form is protected by Cloudflare Turnstile, a privacy-respecting bot check that does not profile users. We use this information solely to respond to your enquiry and do not add you to any marketing list without your consent.
Server logs
Our hosting provider may keep standard, short-lived technical logs (such as IP address and request time) for security and reliability. These are not used to build profiles of visitors.
What we never do
- We do not sell, rent, or trade your personal data.
- We do not show third-party advertising or embed advertising trackers.
- We do not access the content you process in our local tools.
- We do not use your data to train AI models.
Third parties
We rely on a small number of service providers strictly to operate the website:
- Resend delivers contact-form emails and licence-key emails after a purchase.
- Cloudflare Turnstile provides spam and bot protection on the contact form.
- Cloudflare Workers and storage run our licence service, which issues licence keys and holds the trial and activation records described above.
- Paddle is the merchant of record for purchases and handles payment and tax. Payment details are given to Paddle, never to us.
- Our hosting and analytics infrastructure serves the site and aggregates anonymous traffic statistics.
Each processes data only as needed to provide its service.
Data retention
- Contact-form emails are kept for as long as needed to handle your enquiry and our records of it, then deleted.
- Aggregate analytics contain no personal data and are retained in anonymous form.
- Licence records are kept for as long as the licence may need to be reissued or supported.
- Trial and activation records are kept indefinitely, and deliberately so. Both are one-way hashes that cannot be reversed into a person or a machine, and deleting a trial record would let the same computer start an unlimited number of new trials.
- We retain personal data no longer than necessary for the purposes described here.
Your rights
Depending on where you live (for example, under the EU/UK GDPR), you may have the right to access, correct, delete, or restrict processing of your personal data, and to object to processing or request portability. Because our products send us none of your content, these rights mainly concern data you have sent us directly, such as a contact-form message or a purchase.
The trial and activation records are one-way hashes with no name, email, or account attached, so we have no way to look up which record belongs to you, and no way to hand one to you or delete "yours" on request. That is a consequence of building them so they identify nobody. If you have a purchase or a support thread with us, we can find and act on that. To exercise any of these rights, contact us at the address below.
Children
Our products and website are not directed to children under 16, and we do not knowingly collect personal data from them.
Changes to this policy
We may update this policy as our products and legal obligations evolve. Material changes will be reflected by the "Last updated" date above.
Contact
Questions about this policy or your data? Email support@velumprivacy.com.
Velum is maintained by the SU Engineering team (github.com/su-engineering).