Your words belong to you. Learn what Vellum keeps on your device and which actions make a network request.
Effective date: July 30, 2026
At a glance
- On-device first — Notes, images, and backups stay on your device by default.
- No tracking — No ads, no sale of personal data, and no cross-app tracking.
- You choose — Content reaches Notion only when you connect or send it.
01. Scope and core principle
This policy explains how the Vellum iOS app handles information created through your use of the app. Vellum is local-first and does not enable iCloud sync. The developer does not receive your library content except through the network features described here, files you deliberately export, or information you choose to send to support.
02. Information stored on your device
To provide capture, organization, search, recovery, and export, Vellum processes the following information in its app container, App Group, system settings, or Keychain:
- Library content: topics, titles, note text, supplementary notes, tags, images, creation and update times, and Trash status.
- Supporting data: preferences, drafts, rolling recovery backups, link-metadata caches, Notion credentials and export receipts, and pending shared items.
- System features: Spotlight indexes only titles, topics, tags, and snippets of up to 240 characters. On-device OCR processes photos or camera images without uploading them for recognition. Release builds create no capture diagnostics.
03. Network requests and support
Vellum has no advertising or behavioral analytics SDK and does not continuously upload usage records for profiling or marketing. The following actions make network requests when needed:
- Link previews: the system LinkPresentation framework may contact HTTP(S) sites in a note to obtain a title, canonical URL, and host name. The destination and its providers may receive ordinary network information such as an IP address. Vellum does not cache page contents.
- Support email: when you contact us, we receive the address, message, and attachments you choose to provide. We use them only to reply, investigate the issue, and meet necessary legal obligations. Do not send passwords, Notion access tokens, or unnecessary sensitive notes.
04. Notion integration and OAuth broker
Notion is an optional third-party service. Only after you connect it does Vellum store authorization credentials and workspace identifiers. Only when you choose Send to Notion does Vellum transmit the selected topic's title, rendered Markdown, tags, and timing information to Notion. Images are represented by a count; image files are not uploaded. Notion handles this content under your account settings, its terms, and its privacy policy.
To protect the Notion client secret, sign-in, refresh, and revocation pass through Vellum's OAuth broker running on Cloudflare. The authorization result is stored encrypted and deleted after one-time retrieval, for no longer than about five minutes. A hashed broker-session identifier plus workspace, owner, or bot identifiers may remain for up to 30 days. Hashed IP counters used to prevent abuse remain for about five minutes. The broker receives no Vellum notes or images and does not log tokens, authorization codes, or note content.
05. Sharing, advertising, and tracking
Vellum does not sell or rent personal data, show third-party ads, or combine in-app data with other companies' data for cross-app or cross-site tracking. Information is shared only as needed with Apple's system services, linked sites, Notion, Cloudflare OAuth infrastructure, or an export destination you choose, at your direction, unless disclosure is legally required.
06. Retention, security, and deletion
Vellum uses platform protections such as the iOS app sandbox, Keychain, and encrypted transport, but no storage or transmission method can be guaranteed absolutely secure. Notes moved to Trash remain until you empty it or delete them permanently. Disconnect Notion separately in integration settings. Delete exported files and content already sent to Notion at their respective destinations.
Local rolling backups, drafts, link caches, export receipts, pending shared items, and iOS-managed indexes or Keychain records may outlive deletion of an item until they are overwritten, consumed, expire, or are removed by the system. After permanent deletion of a note with images, unreferenced images may enter an app-internal quarantine and remain until later cleanup or removal of the app container by iOS. The current version has no separate control to purge that quarantine.
07. Your choices and rights
You can view, edit, export, and delete your library in the app; disable system permissions such as Spotlight or Camera; decline or disconnect Notion; and stop using Vellum by uninstalling it. Because your main library stays on your device, the developer generally cannot access, correct, or delete it for you. To ask about information involved in support email or the OAuth broker, or to exercise rights under applicable law, contact the address below. Reasonable verification may be required.
08. Children, changes, and contact
Vellum is a general-purpose personal note tool. It is not directed to children below the digital-consent age in their location and does not ask users to create an account or provide an age. Minors should use it with a parent or guardian's guidance. Contact us if you believe a child provided information through support or a network integration.
If a feature or data practice changes materially, we will update this policy and its effective date and provide notice through app release notes or another appropriate method. Review it again after significant updates.
For privacy questions, requests under applicable law, or support, contact yesiyang@outlook.com. Operator or contact: Yann.