Privacy policy
This policy explains what data Vellum (“we”, “us”) processes when you visit usevellum.fun, use the drafting table, run agents or call the agent API, why we process it and how long we keep it.
The short version
- No ads, no analytics trackers, no tracking cookies.
- We store what you need to sign in, keep your sheets and run your agents.
- Your agent wallet's private key is stored encrypted and is only decrypted on our server to sign transactions you or your agents trigger.
- Text you send to AI parts goes to an AI provider. Do not put secrets into prompts.
- Anything written to the Solana blockchain is public and permanent.
Data we process
Your account
When you create an account we store your email address and your password. The password is stored only as a salted hash, so we cannot read it. We use this data to sign you in and to contact you about your account. It is kept until you ask us to delete the account.
Your agent wallet
When you sign up we generate a Solana wallet for your agents. The public key is stored with your account. The private key is encrypted with AES-256-GCM before it is stored and is decrypted only on our server, in memory, to sign a transaction that you or one of your agents starts. We never show or send the private key to anyone. Wallet addresses, balances and transactions are public on the Solana blockchain by design, and we cannot change or delete them.
Sheets, tables and agents
We store the sheets (templates) you save, the tables you create in Database parts, the state of running agents and a ledger of buys made through the agent swap endpoint (amount and time), which we need to enforce the per-trade and daily trade limits. Sheets you mark as public are visible to other users, together with the author name and X link you enter. All of this is kept until you delete it or ask us to delete your account.
AI parts and Draft with AI
When you use an AI part or Draft with AI, the text you enter and the parts of the sheet it needs are sent to OpenRouter, which forwards the request to the AI model selected for that part. Those providers process the request to generate the answer. We do not use your prompts to train models.
Server logs
Our hosting provider records technical data for every request: IP address, time, requested URL, status code and browser user agent. We use it to operate the service and to detect abuse. Logs are rotated automatically and kept for no longer than 30 days.
If you email us, we use your address and message only to answer you, and delete the conversation when it is no longer needed, at the latest after two years.
Cookies and local storage
We use only what is needed for the site to work:
pb_auth: keeps you signed in. Not readable by scripts, expires after 7 days.pb_user_id: your account ID for the signed-in interface, expires after 7 days.theme(local storage): remembers whether you chose the blueprint or vellum view.
There are no advertising, analytics or third-party tracking cookies. Fonts are served from our own server.
Service providers
We share data with these providers only as far as needed for the feature you use:
- Railway: hosting of the application and its database.
- OpenRouter and the model providers it routes to: AI parts and Draft with AI.
- Helius and Solana Tracker: Solana RPC access to read chain data and send transactions.
- Jupiter: swap quotes and routing.
- DexScreener, RugCheck and Solana Tracker: token and market data.
- twitterapi.io: X account lookups, only when you use the Twitter Check part.
- Jina AI: reading web pages, only when you use the URL reader part.
Some of these providers process data outside your country, including in the United States. Market data providers receive token addresses and wallet addresses, which are public blockchain data, not your account details.
Security
All traffic is encrypted with HTTPS, passwords are hashed, agent wallet keys are encrypted at rest and the session cookie cannot be read by scripts. No system is perfectly secure, so keep only the amount you need for your agents in the agent wallet.
Your rights
You can ask us for a copy of the data we hold about you, have it corrected or deleted, receive it in a portable format, object to its processing, and withdraw any consent you gave. Email contact@usevellum.fun from the address of your account and we will respond within 30 days. You can also complain to the data protection authority where you live.
Age
Vellum is not meant for anyone under 18, and we do not knowingly collect data from minors.
Changes
We update this policy when the service changes. The date at the top shows the latest version.