Privacy Policy
Privacy is the product. This policy explains exactly what Vellum collects, why, how long we keep it, and how you stay in control — including permanent deletion.
Last updated
1. Overview
Vellum (“we”, “us”) is a privacy-first, AI-moderated nearby dating service for adults aged 21 and over. This Privacy Policy describes how we handle personal data when you use our website and progressive web app (the “Service”). It should be read together with our Terms of Service. Vellum is the data controller for this processing; our servers are located in Germany (European Union).
Two principles drive our design: we collect the minimum needed to run a safe service, and you decide who can see you. You start invisible and become visible only when you choose.
2. Data we collect
We collect only the categories of data listed below.
We do not sell your personal data, and we do not collect data we do not need to operate the Service.
3. Location: approximate only
Location privacy is a core invariant of Vellum. We convert your location into a coarse geohash cell and a city label so we can show approximate distance and city. Your precise coordinates are never stored in your profile and are never shown to other members. A distance is only shown when enough members share a cell for it not to single you out, and you can hide distance entirely in your settings.
4. Online status & last seen
Your matches can see a green dot when you have Vellum open and the time you were last here; on Discover, members can see the dot only. You can turn this off with the single setting “Show my online status & last seen” in the Control Room. When it is off, others see only an approximate value — last seen recently, within a week, within a month, or a long time ago — and, in return, you see the same approximate values for everyone else. Read indicators (✓ sent, ✓✓ read) are always on, as in most messaging apps.
6. How we use your data
- Authenticate you and keep your account secure (one-time codes, rate-limiting, abuse prevention, duplicate-account detection).
- Operate core features: build your profile, show approximate distance, surface and filter requests, enable matches, chat, online status, and read indicators.
- Keep members safe: run AI moderation on messages and photos, verify identities, review reports, and enforce our Community & Safety Guidelines.
- Provide optional AI assistance you ask for: bio drafts, conversation suggestions, readiness feedback, and photo enhancement.
- Send communications you have enabled, such as new-request, new-message, and safety notifications.
- Improve the Service using aggregated product-analytics and campaign attribution.
- Comply with law and enforce our Terms.
7. Legal bases (GDPR)
Where the EU/UK General Data Protection Regulation applies, we rely on the following legal bases:
- Contract — to provide the Service you signed up for (account, profile, matching, chat, presence).
- Legitimate interests — to keep the platform safe, prevent fraud and abuse, detect duplicate accounts, and improve the Service, balanced against your rights.
- Consent — for the face signature created at selfie verification, for push notifications, for optional AI features you trigger, and — in the EU/EEA/UK/CH — for the attribution cookie and product-usage events (section 5); you can withdraw consent at any time.
- Legal obligation — to comply with applicable laws and lawful requests.
9. Retention
We keep personal data only as long as needed for the purposes above:
- Account, profile, photos, trust signals, settings — while your account exists.
- Messages, voice notes, chat photos, transcripts, read times — for the life of the match; a conversation is removed when either participant deletes their account.
- One-time codes — two minutes (SMS) or ten minutes (email). Live online status — refreshed while you are connected and cleared within 90 seconds of going offline; the last-seen time is kept while your account exists.
- Face signature — while your account exists.
- Reports, blocks, and moderation decisions — while your account exists, and longer only where we must keep a record to protect members or meet a legal obligation.
- AI-derived signals — refreshed at most daily and deleted with your account.
- Product-analytics events — retained without your profile after deletion, under an internal identifier that no longer maps to a person.
- Backups — daily backups are kept for 14 days and then overwritten; deleted data disappears from backups on that cycle.
When data is no longer needed, we delete or anonymise it.
10. Deletion & your rights
You can delete your account at any time from your account settings. Deletion is permanent and immediate: we remove your account and its database records — including your likes, passes, requests, matches, messages, reports, blocks, face signature, trust and AI signals, and settings — and we purge your media from storage: your photos and their blurred copies, your voice messages, and chat photos. A conversation you were part of is removed for both participants. Some limited records may be kept only where the law requires or to resolve disputes and enforce our agreements. Pausing your profile is the reversible alternative: you become invisible and keep your matches.
Depending on where you live, you may also have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate data;
- erase your data (“right to be forgotten”);
- restrict or object to certain processing;
- data portability;
- withdraw consent for consent-based processing at any time.
To exercise these rights, contact [email protected] from the number or address on your account. We will respond within one month, or sooner where the law requires.
11. Security
We use technical and organisational measures appropriate to the sensitivity of the data, including passwordless authentication, access controls, encryption in transit, media served only to members allowed to see it, and metadata stripped from uploaded photos. No system is perfectly secure, so we cannot guarantee absolute security; please help by keeping access to your sign-in number or inbox secure.
12. Where your data is processed
Our servers are located in Germany (European Union). Some processors are outside the EU — in particular the AI provider (United States) and SMS gateways in the countries we serve. Where personal data leaves the EU/UK we rely on the safeguards required by applicable law, such as the European Commission’s standard contractual clauses, and we send only the data the task needs.
13. Automated decisions
AI helps us moderate messages and photos, rank profiles, and flag risk, but no decision that significantly affects you — a restriction, a suspension, or a ban — is taken by an automated system alone: a member of our safety team reviews it, and you can ask for a human review by writing to [email protected]. Suggestions from the assistive AI are only ever suggestions.
14. No under-21s
Vellum is exclusively for adults aged 21 and over and is not directed to anyone under that age. We do not knowingly collect data from anyone under 21. If we learn that an underage person has created an account, we will remove it and delete the associated data. See the Age & Consent Policy.
15. Changes
We may update this Privacy Policy. When we make material changes we will update the “Last updated” date and, where appropriate, notify you in the Service.
16. Contact & complaints
For any privacy question or to exercise your rights, contact our privacy team at [email protected]. If you are in the EU/UK and believe we have not handled your data properly, you also have the right to lodge a complaint with your local data-protection authority.