Vellum Privacy Policy
Updated: 7 September 2026
Pretty Boa Media Ltd., a company established in Israel, is responsible for the personal information described in this policy. This policy covers the Vellum app and its related services and takes precedence over our general app privacy notice for Vellum-specific processing. Contact us at support@prettyboamedia.com.
Photos, identification and saved results
Before you first send a photo for identification, the app asks for permission to send submitted photos and item details to the identification providers described below. Your choice applies to future scans. You can decline and keep the selected photo on your device, or withdraw permission under Settings → Manage privacy choices → AI identification. Withdrawing stops new scans; it does not recall information already sent, erase saved results or cancel your subscription. We store your permission choice, disclosure version and decision time on the device, and include the disclosure version and permission time with submitted scan requests.
When you request an identification, reduced copies of your selected photos are uploaded to our Firebase backend. We send those photos and relevant item information, including any mark notes and dimensions you provide, together with technical request identifiers, language, currency and valuation date, through OpenRouter to Google’s Gemini service to generate identification and estimated value information. We process scan records and results to deliver and recover your request, maintain saved results, and manage the scan allowance. Photos and results may therefore be stored on our servers as part of these features, as well as on your device.
For similar marketplace listings, a reduced photo may also be sent to eBay’s image-search service. Item descriptions and search terms may be sent to eBay and Etsy. These providers process requests under their applicable terms and privacy policies. Opening a marketplace link takes you to that provider’s service.
Provider information is available from the OpenRouter Privacy Policy. Google’s Cloud Data Processing Addendum describes processing of Customer Data under covered cloud-service agreements; its separate Cloud Privacy Notice covers Service Data, such as service-administration and operational information. We access the model through OpenRouter; these links do not describe a separate direct Vertex contract between you and Google. Our requests select a Google Vertex route through OpenRouter and request no provider training and zero data retention through the routing controls. These request settings do not mean that Vellum itself stores no photos or that every service keeps no operational metadata.
Optional Apple sign-in and collection sync
You can use scanning without signing in with Apple. The app uses an automatically generated Firebase identifier to operate server features. If you choose Sign in with Apple, we receive an Apple account identifier and, when supplied, your name and email address, which may be an Apple relay address. Firebase stores account information and synchronizes your collection, including item details, notes, photos and saved appraisals.
Settings → Account → Delete account initiates deletion of your Apple-linked Vellum account and synced cloud data. Fresh confirmation with Apple may be required. The app reports completion or a retryable failure. Your device’s local collection remains available; exported files and copies you have shared are separate. Deleting a Vellum account does not cancel a subscription billed by Apple. Manage billing in your Apple account’s subscription settings.
If you use Vellum without Apple sign-in, Settings → Manage privacy choices → Delete my scan data requests deletion of the guest account’s server-side scan history, uploads and usage counters. The app starts a new guest account after successful deletion. Photos and results saved on the device remain, and the action does not cancel your subscription. Analytics and advertising data have the separate deletion process described below; contact us if you need help with information associated with an earlier account.
Analytics and session replay
We use PostHog and Google Analytics for Firebase to understand how features are used and how the app performs. Events include screen visits, interactions, timing information, app/device characteristics and pseudonymous identifiers. Our product analytics events exclude scanned photos, item names, notes and valuations. An identifier can still relate activity to an installation or account; pseudonymous does not mean anonymous.
Where enabled, sampled PostHog session replay helps us understand how screens are used. The app configures typed text and images to be masked. Replay has a separate privacy control and depends on the app’s consent and sampling settings.
In the European Economic Area, United Kingdom, Switzerland, Brazil and South Korea, the app asks for a privacy choice before starting optional analytics and attribution. Elsewhere these features may be enabled by default subject to your settings and Apple’s tracking authorization. You can change analytics, replay and attribution choices in Settings → Manage privacy choices.
Advertising measurement
AppsFlyer, Meta and Apple’s advertising measurement systems help us understand which advertising leads to app use and purchases. Depending on your choices and platform permissions, this processing includes installation, device and campaign identifiers, selected app interactions and subscription events. RevenueCat receives attribution identifiers to connect subscription events with advertising measurement. Where our advertising measurement constitutes tracking under Apple’s rules, we request permission through Apple’s App Tracking Transparency prompt before that tracking occurs. Declining does not prevent use of the app’s core features.
Withdrawing attribution consent stops further attribution activity through the app’s privacy controls. It does not itself confirm that a partner has deleted information previously received. Technical network and device information, including IP addresses and approximate location derived from them, may also be processed by our service providers for security, service operation and permitted measurement. We also receive campaign and attribution information from measurement partners; the absence of a GPS permission does not mean no network-derived information is processed.
Purchases, diagnostics and support
Apple processes App Store payments. RevenueCat manages subscription and entitlement information using an app user identifier associated with the device’s Firebase identity. We do not receive your full payment-card details. App usage attributes are provided to RevenueCat only under the app’s analytics consent controls.
Firebase Crashlytics processes crash and device diagnostics to help us identify failures. Firebase App Check processes app/device attestation information to help verify that requests come from our app and protect server features from misuse. When you contact support using the app, the email may be prefilled with app/device information, a pseudonymous identifier, subscription status and technical diagnostics. You can review and remove this information before sending.
Deleting analytics data and retention
Settings → Manage privacy choices → Delete my analytics data turns off the optional categories and requests erasure of associated usage data and advertising identifiers. It preserves your collection, purchases and subscription. A request saved only on the device has not yet reached our server. The receipt distinguishes delivery and processing status and identifies partner actions that cannot be confirmed.
The request starts processing by the available deletion integrations. A receipt records which requests have been delivered, accepted, completed, skipped or failed; these statuses have different meanings. A skipped or failed partner step does not confirm deletion. Contact support@prettyboamedia.com if a step remains incomplete or you need help exercising a privacy right.
Depending on the available integration and identifiers, partner actions include deleting the PostHog profile and associated events, clearing Vellum-set usage attributes and advertising identifiers from RevenueCat, and submitting Google Analytics and AppsFlyer deletion requests. Partner acceptance may precede completion. Meta and crash diagnostics do not have an equivalent per-user deletion route in this in-app process. You may contact us about previously sent data and applicable rights, including data not covered by the automated process.
How long information is kept
Retention depends on the type of information and the feature it supports. The criteria are:
- Temporary scan photos and processing records: our backend is configured to clean up temporary uploaded scan photos within a 24-hour processing window and to expire completed or failed scan-job records seven days after they finish. Scheduled cleanup can be delayed by processing backlogs or failures; these are configured cleanup periods, not a guarantee that every copy disappears at an exact moment. Saved collection content has a separate lifecycle. Deleting a local item alone does not necessarily delete its server processing record. You may request deletion of associated server data through the available account or guest controls, or by contacting us.
- Saved collections and account information: kept to provide your account and synchronization until the relevant cloud content or account is deleted. Local collections, exports and copies you share are separate from cloud-account deletion.
- Analytics and advertising measurement: kept for feature-usage trends, troubleshooting and campaign measurement, subject to the provider’s retention controls and applicable deletion requests. Turning a category off stops future collection through that control; previously collected data is handled through the deletion process described above.
- Session replay: our current PostHog project setting gives new recordings a 30-day retention period. Recordings made under an earlier setting keep that earlier period, and provider deletion processing can continue after a recording expires.
- Diagnostics and support: Firebase Crashlytics retains crash reports and associated installation identifiers for 90 days before beginning removal from its live and backup systems. Support correspondence is kept as needed to resolve your request and related security issues or disputes.
- Privacy-request records: kept to deliver and retry requests, record partner responses and demonstrate how a request was handled. An unfinished request may remain pending while a partner step needs attention.
- Purchase and legal records: kept as needed to operate entitlements, resolve billing disputes and satisfy applicable accounting, tax and other legal obligations.
Deletion from an active service and expiry of backup or security records may occur at different times. Legal preservation obligations may require particular records to be kept longer. Contact us for information about retention or a deletion request relating to your data.
International processing and provider safeguards
Vellum uses international service providers, and your information may be processed outside your country, including in the United States. OpenRouter’s published data-processing agreement describes US hosting. Google, our analytics and advertising providers, and RevenueCat also operate international infrastructure and support services; this policy does not promise storage exclusively in your country or in Europe.
The providers’ applicable data-processing terms describe confidentiality, security, restrictions on processing and international-transfer protections. For example, OpenRouter’s Data Processing Agreement incorporates EU Standard Contractual Clauses and a UK transfer addendum for covered transfers. Firebase’s data-processing terms, PostHog’s Data Processing Agreement and RevenueCat’s Data Processing Addendum describe their respective safeguards and the conditions under which they apply. These contractual mechanisms are intended to protect personal information when it is processed in a country with different privacy laws.
Contact support@prettyboamedia.com for details of the safeguards applicable to your information or to request a copy. Our responsibility to handle your privacy requests is not replaced by a provider’s policy. We use access controls and protected network connections to limit unauthorized access; no storage or transmission system can be guaranteed completely secure.
Legal bases and your rights
Where EU or UK data-protection law applies, we process information necessary to provide requested scans, account sync and purchases to perform our contract with you. We rely on legitimate interests in protecting the service, preventing misuse, diagnosing failures and answering general enquiries where those interests are not overridden by your rights. Support necessary to deliver the service is processed to perform our contract. We rely on consent for optional analytics, replay and advertising where required, and on legal obligations for responding to statutory privacy requests and keeping required records. The app separately requires your permission before sending photos for AI identification; choosing not to provide that permission prevents new AI scans while leaving locally saved content available.
Depending on applicable law, you may request access, correction, deletion, restriction or a portable copy of your personal information. You may withdraw consent at any time without affecting earlier lawful processing. Contact support@prettyboamedia.com to exercise these rights, including if an in-app request fails or available controls do not cover your request. You may also complain to your local data-protection authority, including the ICO in the UK.
Your right to object: where applicable law provides this right, you may object to processing based on our legitimate interests for reasons relating to your circumstances. You may object to processing for direct marketing at any time. Contact support@prettyboamedia.com; the app’s privacy controls also let you stop optional analytics, replay and attribution.
Changes to this policy
We may update this policy when our services or privacy practices change. The date above identifies the latest revision. Where a change requires a new notice or consent, we will provide it as required by applicable law.