Privacy Policy

30 July 2026

Vaelum is a personal AI assistant with a memory that persists between conversations. This policy explains what data the service handles, why, who else processes it, and what control you have. It covers vaelum.ai and any assistant you use through a messaging platform you connect.

1. Who operates Vaelum

Vaelum is operated by an independent developer rather than a registered company. For any privacy question, data request or complaint, write to info@vaelum.ai. We answer within 30 days.

2. What data we handle

  • Account data — your email address and display name, taken from the sign-in method you choose, along with your subscription plan and the identifiers linking your account to messaging platforms you connect.
  • Conversations — the messages you send to your assistant, its replies, and any files you attach.
  • Assistant memory — Vaelum is built around remembering you. It stores notes derived from your conversations: things you have told it, reminders, summaries of what happened, and the numeric representations used to search them later.
  • Data from connected services — content the assistant reads or writes on your behalf in services you connect, such as a calendar or a spreadsheet. Section 4 covers Google services specifically.
  • Access credentials — the tokens that let the assistant reach a connected service, encrypted before they are stored.
  • Technical data — request logs, timestamps and error diagnostics.
  • Payment status — subscriptions run through an external payment provider. We receive whether yours is active. Your card details never reach us.

3. Why we handle it

  • To provide the assistant you asked for — necessary to perform our agreement with you.
  • To keep its memory across sessions — the same basis. An assistant that forgets you is not the product you signed up for.
  • To reach a service you connect — your explicit consent, given separately for each service and withdrawable at any time.
  • To keep the service running and secure, and to diagnose failures — our legitimate interest in operating it.

We do not sell your data. We do not use it for advertising, and we do not build advertising profiles.

4. Google user data

This section describes how Vaelum handles data received from Google APIs, as required by the Google API Services User Data Policy.

PermissionWhy Vaelum asks for itWhat happens to the data
Sign-in (email, profile)To create your account and recognise you when you returnYour email address and display name are stored on your account
Calendar (events, read-only)So the assistant can tell you what is on your schedule, and create, move or cancel events when you askEvents in the period you ask about are read at the moment of the request; only the changes you ask for are written back
SpreadsheetsSo the assistant can build spreadsheets for you, and read or edit ones you point it atOnly spreadsheets you name or link, or that it created for you, are read or written
Drive (drive.file)To place the spreadsheets it creates and share them when you askLimited by Google to files Vaelum itself created. The rest of your Drive is never visible to it

Google data is read on demand, when a request needs it. It is not copied into our database wholesale: what the assistant retrieves lives for the length of that request and appears in the answer it gives you.

One thing is kept — a short list of spreadsheets, holding their Google id, title and link, for spreadsheets the assistant created for you or that you pointed it at. Without it the assistant could not find them again in a later conversation. Ask us and we will clear it.

Vaelum's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, information received from Google APIs is not used to develop, improve or train generalised artificial intelligence or machine learning models; it is not sold; and it is not used for advertising or for building advertising profiles.

To produce a reply, the content of your request — which can include data the assistant has just retrieved from a Google service — is sent to the AI processing providers described in section 5. They receive it solely to generate that reply, and their processing is configured so that this content is not used to train or improve their models.

You can withdraw access whenever you like: in Vaelum under Integrations → Disconnect, or from your Google Account at myaccount.google.com/permissions. Either one stops all further access immediately.

5. Who else processes your data

Vaelum relies on a small number of external processors. We do not sell your data to anyone, and we do not share it for advertising.

  • AI processing providers — they generate the assistant's replies. Your conversation, and anything retrieved from a connected service for that request, is sent to them for that purpose. Their processing is configured so that this content is not used to train or improve their models.
  • A payment provider — handles subscriptions and card data, which never reaches us.
  • Messaging platforms — if you choose to talk to your assistant through one, your messages pass through it under its own privacy policy.
  • A web search provider — receives the search terms, and only when you ask the assistant to look something up online.

6. Storage and security

  • Your data is stored in a database on infrastructure we operate ourselves, not on shared third-party application hosting.
  • Credentials for connected services are encrypted before they are written, with the keys held outside the database.
  • Access to production data is limited to the operator.

No service can promise perfect security and we will not pretend otherwise. If a breach affects your data, we will tell you.

7. How long we keep it

  • Conversations and assistant memory — until you delete them or ask us to close your account. A memory that expired on a schedule would defeat the point of the product.
  • Credentials for connected services — until you disconnect the service, at which point they are deleted.
  • Technical logs — kept for a limited period for diagnostics, then discarded.

To delete your account and everything attached to it, write to info@vaelum.ai. We action it within 30 days and confirm when it is done.

8. Your rights

You can ask us for a copy of your data, ask us to correct or delete it, or ask us to restrict what we do with it. You can withdraw consent for any connected service at any time without affecting the rest of the service. Write to info@vaelum.ai.

If you are in the European Economic Area or the United Kingdom, you also have the right to complain to your national data protection authority.

9. Children

Vaelum is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has an account, write to us and we will remove it.

10. Changes to this policy

If this policy changes we will update the date at the top of the page, and we will say so in the product when the change is material.

11. Contact

info@vaelum.ai