Privacy Policy
Last updated: September 26, 2026
This policy explains what data Vellum collects, why, and what we do with it. The short version: we collect the minimum, we don't sell it, and you can delete it whenever you want.
What we store
When you sign in: your name, email, and avatar URL (from GitHub or Google). We don’t store your password.
When you create documents: all document data (client info, line items, notes, terms, etc.) stored in Supabase (PostgreSQL) in the Mumbai, India region.
When someone views your document: a timestamp and a hashed IP address (truncated SHA-256, first 16 characters). We don’t store the full IP.
When you send an email: the recipient’s email address is passed to Resend. We don’t store sent emails.
What we do NOT do
We don’t sell your data. Ever. To anyone.
We don’t use your document content to train AI models.
We don’t run ads. We don’t have a tracking pixel. We don’t have a cookie consent banner because we don’t use third-party cookies.
We don’t share your data with third parties except: Supabase (hosting), Resend (email delivery), GitHub/Google (authentication).
Cookies
Vellum uses one session cookie (managed by Supabase Auth) to keep you logged in. That’s it. No analytics cookies. No marketing cookies. No ‘essential’ cookies that aren’t actually essential.
Data retention
Your documents are stored until you delete them or delete your account.
View tracking data (timestamps, IP hashes) is stored indefinitely and deleted when you delete the document.
If you delete your account, all associated data is permanently deleted within 30 days.
Your rights
Access: you can see all your data in the app.
Correction: edit your documents and profile in the app.
Deletion: Settings → Danger Zone → Delete all. Or email us.
Portability: use the CSV export (coming soon) or ask us.
If you’re in the EU/UK: you have rights under GDPR. Email Vellum@x0q.net.
Third-party services
Supabase (supabase.com/legal/privacy) — database hosting, authentication. Data stored in Mumbai, India.
Resend (resend.com/privacy) — email delivery. They process the recipient’s email address to deliver the message.
GitHub (github.com/site/terms) — authentication only. We receive your name, email, and avatar.
Google (policies.google.com) — authentication only. Same as GitHub.
Security
Data is encrypted in transit (TLS 1.3) and at rest (Supabase default encryption).
Database access is restricted by Row Level Security. Each user can only access their own data.
API keys are stored server-side only. The publishable key in your browser has limited permissions.
We don’t claim to be impenetrable. No system is. But we follow standard practices.
Changes
We may update this policy. Material changes will be announced in-app or by email. The ‘Last updated’ date above reflects the current version.
Contact
Data requests, questions, or concerns: Vellum@x0q.net
We respond within 7 days.