Vellum privacy policy
Vellum is a document reader made by Ayush Deolasee. Your library stays on your device or in the storage location you choose. Optional AI and read-later connections send data directly from Vellum to the service you select.
- Vellum has no developer-operated app account, advertising, or tracking service. Limited anonymous events measure downloads, first launches, and update checks.
- If you join the TestFlight waitlist, the developer stores your name and email only to manage beta invitations.
- Documents, notes, reading positions, and AI conversations are stored locally unless you choose a synced or external storage location.
- AI is optional. Vellum asks before it first sends document content to each AI provider.
- API keys and read-later tokens are stored in Apple Keychain.
- Deleting local data does not delete copies already held by a provider.
Contents
1. Scope
This policy covers the Vellum app for iPhone, iPad, and Mac, as well as the TestFlight signup form on vellum.work. It describes the data Vellum stores, the network requests the app makes, and the optional services a user can connect.
Vellum's developer does not operate a server that receives your documents, prompts, provider credentials, library, or reading activity. A connected provider still receives data directly from your device and handles it under its own terms and privacy policy.
This policy does not replace the policy of Apple, an AI provider, a website, Readwise, or Raindrop.io.
2. Data stored by Vellum
Vellum stores the information needed to provide its reading and annotation features. Depending on what you use, this can include:
- PDFs, saved webpages, document titles, file locations, and cached extracted text.
- Highlights, annotations, bookmarks, reading positions, Scratchpad notes, and attachments.
- AI conversations, references attached to a prompt, model settings, and usage totals. Full image pixels attached to an AI message are sent for that request but are not kept in the saved conversation.
- Readwise or Raindrop item metadata and optional offline copies.
- App preferences, recent files, workspace state, and cache-cleanup settings.
Vellum stores this data on the device and in the library location you choose. If an iCloud-enabled build and iCloud storage are selected, Apple processes the synced files under Apple's privacy policy. A custom folder may be managed by its filesystem or sync provider.
The app and its share and widget extensions may exchange the minimum data needed for capture and widget display through Apple's App Group container.
TestFlight signups
If you join the TestFlight waitlist on vellum.work, Vellum's developer receives your first name, last name, email address, signup date, and invitation status. This information is used only to manage beta invitations. It is not sold, used for advertising, or added to a marketing list.
Cloudflare processes the form submission, performs the security check, and stores the waitlist in Cloudflare D1 on the developer's behalf. When an invitation is available, the developer may provide your name and email address to Apple through App Store Connect so Apple can send the TestFlight invitation. Cloudflare and Apple handle that information under their own privacy policies.
Anonymous analytics
Vellum records anonymous events when someone selects a Mac download button, when the Mac app first opens successfully after analytics support is installed, and when the Mac app checks for updates. The app event contains only the event name, app version, and build number. Download events also contain the location of the selected button.
The analytics record does not contain a user, device, or installation identifier, document information, reading activity, credentials, or the request's IP address. Cloudflare necessarily receives ordinary network information while delivering the request, but Vellum does not add that information to the analytics event. Anonymous events are stored in Cloudflare D1.
3. Optional AI providers
AI features are off unless you add a provider credential. Before the first content-bearing request to each AI provider, Vellum shows a consent sheet naming the service and the categories of information that can be sent. Switching providers requires separate permission.
An AI request may include:
- Your prompt and recent AI conversation.
- The document title, current and visible page numbers, page text, and annotations.
- Selected text, highlights, quoted replies, images, page snapshots, and other references you attach.
- Excerpts and annotations from other pages, plus tool results, when you ask the assistant to search or act on the document.
- The selected provider, model, technical request information, and the API credential needed to authenticate.
The provider returns a reply to Vellum. Vellum stores the conversation in your library. Provider processing is necessary to supply the AI feature and is separate from Vellum's local storage.
For App Store privacy disclosure, Vellum treats sent text as Other User Content and sent images as Photos or Videos. Both are used for app functionality, are not used by Vellum for tracking, and may be linked to the provider account because the request uses that account's API credential.
| Service | Routing | Important current rule |
|---|---|---|
| Google Gemini | Direct to Google | Unpaid and paid API projects have different training rules. |
| OpenAI API | Direct to OpenAI | API content is not used for training by default; default abuse logs may last up to 30 days. |
| OpenRouter | OpenRouter, then a model provider | The final provider can have its own retention and training rules. |
| OpenCode Zen or Go | OpenCode, then a model provider | Retention and training vary by gateway and selected model. |
Google Gemini Developer API
Vellum sends requests directly to Google's Gemini Developer API using the API key you provide. Google states that outside the EEA, Switzerland, and the UK, content sent through unpaid Gemini API quota may be reviewed by people and used to provide, improve, and develop Google products and machine-learning technologies. Google states that content sent through a paid API project is not used to improve its products, although it may retain content for abuse prevention and legal duties.
Optional logging, datasets, zero-data-retention approval, and certain API features have separate retention rules. Vellum cannot determine from a pasted key whether your project is paid or approved for stronger controls. Review the Gemini API terms, logging rules, and zero data retention guide.
Removing the key or revoking permission in Vellum stops future requests. It does not erase content Google already received.
OpenAI API
Vellum sends requests directly to the OpenAI API using the API key you provide. This is API use, not a ChatGPT consumer account connection. OpenAI states that it does not use API content to train its models by default unless the account holder opts in.
OpenAI's default abuse-monitoring logs may contain prompts, responses, and related metadata for up to 30 days. Legal, safety, endpoint, storage, Files, and approved retention-control rules can change that period. Review OpenAI's API data controls and privacy policy.
Deleting a Vellum conversation or revoking permission does not delete provider-held data or API objects. Use the applicable OpenAI account or API controls for those copies.
OpenRouter
Vellum sends a request to OpenRouter, which forwards it to the model provider selected for the request. OpenRouter states that it does not store prompt and response content by default. It does store request metadata such as model, provider, token counts, latency, and cost, and it anonymously categorizes a small sample of prompts. Prompt logging and product-improvement use are separate account options.
The receiving model provider may retain content or use it under its own terms. Blocking training, requiring a zero-data-retention endpoint, and disabling OpenRouter logging are separate controls. Bringing your own upstream key does not bypass OpenRouter because the request still passes through its service. Review OpenRouter's privacy policy, data collection guide, and provider logging guide.
Vellum cannot delete content already passed to an underlying model provider.
OpenCode Zen and OpenCode Go
Vellum connects to OpenCode's hosted Zen and Go gateways, not to a local OpenCode process or a user-defined server. OpenCode receives the request and routes it to the provider that hosts the selected model.
OpenCode says Zen models are hosted in the United States. Zen provider rules vary and some free models may use content for improvement. OpenCode's current Go table says listed Go models do not train on content, but retention varies by model from zero to 30 days. These lists and exceptions change. OpenCode's general privacy policy also describes prompt information as personal data and does not give one fixed gateway-retention period.
Review the current Zen model rules, Go model rules, and OpenCode privacy policy before sending sensitive material.
Removing a Zen or Go key or revoking permission stops future requests from Vellum. It does not erase content already received by OpenCode or an underlying model provider.
Provider terms and linked data-handling pages last checked 19 August 2026.
4. Read-later integrations
Readwise Reader and Raindrop.io are optional. Vellum connects only after you provide a token. It stores that token in Apple Keychain and sends it directly to the chosen service to authenticate.
Readwise Reader
Vellum may retrieve Reader item identifiers, titles, authors, summaries, tags, source links, saved and updated dates, locations, thumbnails, and available PDF or document content. If you move an item in Vellum, Vellum sends the item identifier and new location to Readwise.
Vellum currently uses a long-lived Readwise personal access token rather than a scoped OAuth grant. Treat it like a password. Readwise describes broad service-provider processing, international transfers, and purpose-based retention without one fixed deletion period. Review the Readwise privacy policy and Reader API documentation.
Raindrop.io
Vellum may retrieve bookmark identifiers, titles, excerpts, tags, collections, links, dates, thumbnails, and available file or PDF content. If you move a bookmark in Vellum, Vellum sends the bookmark identifier and destination collection to Raindrop.io.
Vellum currently uses a non-expiring Raindrop test token rather than normal expiring OAuth credentials. Treat it like a password. Raindrop.io states that its main data storage is on AWS in Germany, while its privacy policy permits processing and transfers in other countries. Review the Raindrop.io privacy policy, security information, and API documentation.
Disconnecting either service disables future requests and removes its token from Vellum. Vellum removes the synced metadata snapshot. You can choose whether to delete downloaded files. Disconnecting does not delete anything in the provider account. Use Readwise or Raindrop.io account controls for provider-held data.
5. Documents and webpages
Opening a local PDF does not send its contents to Vellum's developer. The operating system or storage provider may still process the file when it comes from iCloud Drive, another cloud filesystem, or a shared location.
When you add, open, or save a webpage, Vellum requests the URL from the website and may load related page resources. The website and its service providers can receive ordinary network information such as your IP address, request headers, cookies accepted by the web view, and the requested URL. Their policies apply.
Sharing a webpage to Vellum passes the URL or captured page content through the local App Group container so the main app can save it. Vellum may keep an offline archive and extracted text in your selected library location.
6. Credentials and security
Vellum stores AI API keys and Readwise or Raindrop tokens in Apple Keychain. It sends a credential only to authenticate a request to the selected service. The developer does not receive a copy.
No system is perfectly secure. Protect device access, provider accounts, API keys, and local or synced document folders. Revoke a credential at the provider if a device or token may be compromised.
7. Retention and deletion
Vellum keeps user-created library data until you delete it, replace the library, or remove the app and its data. This includes documents, annotations, Scratchpad notes, bookmarks, reading positions, and AI conversations.
Vellum can remove rebuildable offline webpages and cached extracted text for items that have not been opened during the storage-retention period and were never saved or annotated. The default period is six months. Settings offers 1, 3, 6, or 12 months, or Never.
Read-later cache retention is controlled separately. Disconnecting a read-later service removes its credential and synced metadata. The disconnect flow lets you decide whether downloaded files are also deleted.
Deleting a file, conversation, credential, or permission in Vellum affects Vellum's local or selected synced copy. It does not recall data already sent to an AI provider, website, Readwise, or Raindrop.io. Each external service controls its own logs, backups, legal holds, account data, and deletion process.
TestFlight waitlist information is deleted when the beta ends, when it is no longer needed to manage invitations, or 12 months after signup, whichever comes first. You can request earlier deletion using the contact address below. Apple controls information already submitted to App Store Connect.
Vellum deletes anonymous analytics events older than three months when a new analytics event arrives. Because the events have no user, device, or installation identifier, Vellum cannot retrieve or delete events for a particular person.
8. Your choices
- Use Vellum without connecting an AI or read-later service.
- Review the exact AI provider before sending, choose Not Now, or revoke all AI-sharing permissions in Settings.
- Remove an AI key to prevent that provider from being used.
- Disconnect Readwise or Raindrop.io and choose whether to remove downloaded files.
- Delete local documents, conversations, annotations, notes, and caches through Vellum or the selected storage location.
- Request access to, correction of, or deletion of your TestFlight waitlist information by emailing the contact address below.
Revoking AI permission stops future sharing. Vellum asks again before the next request to that provider. It does not delete earlier provider-held data.
For access, correction, portability, objection, or deletion rights concerning a provider's copy, contact that provider. For Vellum's local app data, use the app and the selected storage location because the developer has no server-side copy to retrieve. For TestFlight waitlist information, contact Vellum's developer.
9. International processing and children
Connected services may process data in countries different from yours. Their privacy policies describe their locations and transfer safeguards. OpenCode states that Zen models are hosted in the United States. Readwise operates from the United States. Raindrop.io describes German storage but permits broader international processing. AI gateways may send a request to another model provider.
Vellum is not designed to collect information from children through a developer-operated service. Because Vellum can open documents and websites and connect to external providers, a parent, guardian, school, or organization should decide whether those services and the selected content are appropriate.
10. Changes and contact
This policy may change when Vellum adds a feature, changes a provider, or learns that a provider's practices have changed. A new effective date will appear at the top. Vellum will ask for AI-sharing permission again if the purpose or categories of content sent change materially.
Privacy questions about Vellum can be sent to pypdeveloper@deolasee.org. Do not email documents, API keys, access tokens, or other sensitive content.