Vellum Code
FeaturesPlansChangelogFAQ
Download

Privacy

Vellum Code runs on your computer. This page is about the small amount that does not, which is the website and the optional account behind it.

Last updated 13 September 2026

What never leaves your machine

Your source code, your files, your prompts and your chats are held on your own computer and are never sent to us. There is no server of ours in the path between you and a model: the app calls the provider directly with the API key you configured, and that request is between you and them under their terms.

Your API keys are stored using your operating system’s own encryption — DPAPI on Windows, the Keychain on macOS — and are never transmitted anywhere except to the provider they belong to.

What we store if you sign in

Signing in is optional and the app works identically without it. If you do sign in with Google, we receive and store only what Google returns for a basic profile:

  • Your name, email address and avatar URL.
  • A record of each device you connect: the computer name you gave it, its operating system, the app version, and when it was last seen. This is what the account page lists and what a revoke acts on.
  • Your plan, if you have a paid one.
  • A session cookie, so the site knows it is you on your next visit.

What we do not store

  • Nothing from your projects: no code, no file names, no prompts, no model responses.
  • No API keys. We never see them.
  • No analytics or advertising trackers on this website.
  • No Google data beyond the basic profile above. We request no other scope, and we do not call Google again after you sign in.

Crash and usage reports

The app can report crashes and basic usage, and it is switched off unless you switch it on in Settings → Privacy. When it is off, nothing is sent. Its audit log of model requests — which records metadata and a hash of the prompt, never the prompt — is written to your own computer and is never uploaded.

Deleting your data

Revoking a device on the account page stops it renewing its license. To delete the account itself and everything listed above, write to the address at the foot of this page from the address you signed up with, and it is removed.

Changes

If this page changes materially, the date above changes with it. The history of this file is public in the repository the site is built from.

Questions about this page: [email protected]
Vellum Code — MIT licensed, bring your own keys.
FeaturesChangelogPlansAccountFAQPrivacyTermsDownloadReleases