Privacy

Privacy Policy

This policy explains how Velatura handles personal data for the website, accounts, billing, support, optional product analytics, and service-managed rendering features.

Published
17 July 2026
Controller
Velatura, Sweden
Contact
[email protected]

1. Who We Are

Velatura provides a macOS application and related online services for architectural visualization refinement. Velatura, Sweden is the controller for personal data processed through the website, account system, support channels, billing flows, and service-managed rendering features.

For questions about this policy or how personal data is handled, contact[email protected].

2. Personal Data We Process

We process the following categories of personal data when they are relevant to your use of Velatura:

  • Account and authentication data: email address, canonicalized email identity, password hash, session and verification records, account identifiers, trial and plan status, related account settings, and Google account identity data when you choose Google sign-in.
  • Billing data: selected plan, subscription status, billing portal events, payment status, Stripe customer identifiers, invoices, tax and transaction records, and payment metadata needed to keep your account licensed.
  • Managed rendering data: source images, prompts or instructions, selected workflow information, render job identifiers, cost estimates, temporary upload references, generated outputs, result URLs, and operational metadata needed to provide service-managed rendering.
  • Operational render-usage data: account and render-job identifiers, provider and model identifiers, operation and status, token and image counts, resolution tier, latency, provider request identifier, estimated service cost, render lineage, edit scope, plan snapshot, and low-cardinality mask/crop bands. This service telemetry is separate from optional product analytics.
  • Optional product analytics data: pseudonymous installation, project, session, and operation identifiers; allowlisted workflow event names; timestamps; app version; locale; low-cardinality context such as workspace mode, execution mode, workflow identifier, resolution band, status, failure category, and pseudonymous render-outcome correlation.
  • Dictation data: microphone audio processed through Apple Speech when you choose dictation, and the resulting transcript.
  • Website session data: tab-scoped billing access tokens, checkout and return state, campaign-attribution parameters included in a URL, page path, and local website interaction events.
  • Support and administration data: messages you send to us, support context, account lookup information, admin actions, audit records, and limited diagnostic details needed to resolve issues or protect the service.
  • Technical and security data: IP address or a keyed pseudonymous representation of it, email-domain reputation, request timestamps, device and browser information, app version, server logs, error information, authentication events, rate-limit counters, and security signals.

When you choose Google sign-in, Google sends Velatura an ID token. Velatura uses the Google account identifier, email address, email-verification status, and hosted-domain claim when present to authenticate you, create your Velatura account, or associate the Google identity with your account when that can be done safely. Velatura does not select or store the name or profile image claims from that token. Velatura also does not receive your Google password or request access to Google Drive, contacts, calendars, or other Google services.

To keep one account and trial per email identity, Velatura derives a canonical identity by lowercasing the address and removing the first plus-alias suffix. For Gmail and googlemail.com, dots in the local part are also ignored and googlemail.com is mapped to gmail.com. The submitted address remains the contact address. New public registrations may also be checked against a regularly updated public list of temporary-email domains; that list contains domains, not user data.

Velatura project files and local app content are primarily stored on your Mac. When you use managed rendering, only the data needed to provide that service is uploaded and processed by Velatura's service infrastructure. Managed-render uploads and results are service staging and are not canonical project storage.

If you use OpenRouter with your own API key, Velatura stores that key in an encrypted, app-controlled file on your Mac and sends the key only to OpenRouter. OpenRouter and the selected downstream model provider receive the final prompt, selected source or reference images, model, and resolution settings. Velatura does not enforce zero-data-retention on each request; retention and model-training treatment depend on your OpenRouter privacy settings and the selected provider. Velatura's server does not receive that key or render content. When you are signed in, the app may still send the operational render-usage data described above to Velatura for service administration and cost monitoring.

If you choose dictation and grant microphone and speech-recognition permission, Velatura uses Apple Speech to turn microphone audio into text. The current app does not require on-device recognition, so Apple may process the audio on its systems. Velatura does not persist the raw audio. The transcript stays in the app unless you submit it as part of a render prompt.

The app stores your account email, access and refresh tokens, and session-expiry information in its Application Support folder on your Mac so you can remain signed in. The packaged app also uses Sparkle to check velatura-ai.app automatically for signed updates; that request exposes ordinary connection data such as IP address, request time, and user-agent information to the website-delivery providers.

3. Purposes and Legal Bases

PurposeData involvedGDPR legal basis
Provide accounts, authentication, subscriptions, and licensed access.Account data, billing status, authentication events.Performance of a contract.
Run service-managed rendering, including upload handling, job execution, result delivery, cost estimates, and token accounting.Managed rendering data, technical data, account and license status.Performance of a contract; legitimate interests in operating and securing the service.
Measure provider usage, reconcile service cost, investigate render failures, and support account-level rendering.Operational render-usage data.Performance of a contract; legitimate interests in service reliability, cost control, and abuse prevention.
Process payments, invoices, subscriptions, refunds, disputes, tax records, and fraud checks.Billing data, Stripe identifiers, payment status, transaction metadata.Performance of a contract; legal obligations; legitimate interests in payment security and fraud prevention.
Provide support, investigate failures, and allow authorized admin access when needed.Support messages, account lookup data, render job references, logs, admin audit records.Performance of a contract; legitimate interests in customer support, service reliability, and abuse prevention.
Protect the service, enforce one-trial limits, prevent registration and rendering abuse, monitor availability, and maintain audit records.Canonical account identity, email-domain reputation, pseudonymous rate-limit buckets, technical and security data, admin actions, access logs.Legitimate interests; legal obligations where applicable.
Measure and improve onboarding, rendering workflows, feature adoption, and product reliability when you opt in.Optional product analytics data.Consent.
Convert speech into a prompt draft when you choose dictation.Microphone audio and transcript.Consent.
Send required account, billing, security, and service emails.Email address, account state, billing or security context.Performance of a contract; legal obligations; legitimate interests in keeping users informed.
Keep checkout, billing return, and campaign context available within the current browser tab.Website session data.Performance of a contract; legitimate interests in operating and understanding the website.

Where Velatura asks for consent for a specific optional activity, you may withdraw that consent at any time. Withdrawal does not affect processing that happened before consent was withdrawn.

4. Rendering Paths and Content

Managed rendering data is used only to provide and operate the managed rendering service: receiving uploads, preparing render requests, estimating and recording render cost, submitting jobs to rendering infrastructure, returning results, troubleshooting failed jobs, preventing abuse, and maintaining service integrity.

Velatura does not sell managed rendering inputs or outputs. Velatura itself does not use your managed rendering source images, prompts, or generated outputs to train general-purpose AI models. The model and infrastructure providers that process a request may apply their own terms and privacy notices. Access by Velatura is limited to the service flow and to authorized support or administrative access when needed for support, security, billing, abuse prevention, or legal compliance. Upload authorization currently expires after 15 minutes; this limits how long an upload may be started and does not itself delete a stored object. Velatura's Cloudflare R2 bucket lifecycle expires stored inputs, results, and related staging metadata seven days after they are created. Model and infrastructure providers may apply separate retention periods under their own terms.

5. Operational Render-Usage Data

Velatura records limited operational metadata for managed renders and, when you are signed in, for app-side OpenRouter renders. This includes provider and model identifiers, render and provider request identifiers, status, token and image counts, resolution tier, latency, and estimated cost. It does not include the provider API key, source images, generated images, masks, prompts, material descriptions, filenames, or filesystem paths.

This data is required service telemetry rather than optional product analytics. It is used to administer accounts, understand provider cost, support rendering, diagnose failures, and prevent abuse. Authorized administrators can review account-linked operational records for those purposes. Successful billing milestones may also be recorded as account-linked operational events independently of the optional app analytics setting.

6. Optional Product Analytics

Product analytics is enabled by default when no preference is stored and can be disabled in Velatura. While collection is enabled, the app sends only allowlisted workflow events to Velatura's service. Uploads are authenticated and stored against your Velatura account identifier, so this dataset is pseudonymous rather than anonymous. You can turn analytics off at any time in Settings. Turning it off stops future app submissions and deletes events still queued on your Mac; it does not automatically delete events already received by Velatura. You may request their erasure as described in Section 13.

Product analytics events do not contain project images, generated outputs, thumbnails, masks, prompts, material descriptions, filenames, filesystem paths, API keys, email addresses, full provider responses, or diagnostic request bodies. Analytics records are used for aggregate product measurement and shadow analysis of render workflows. Shadow analysis compares hypothetical edit-credit policies; it does not change current billing, authorization, entitlements, or the credit ledger.

7. Website Storage and Third-Party Technologies

The public website stores campaign parameters such as UTM values in browser session storage for the current tab. Credit Pack checkout temporarily stores a Velatura access token in the same tab-scoped storage so the return page can confirm the Stripe session; the page removes it after confirmation, and browser session storage ordinarily ends with the tab session. Do not use a shared browser profile for billing if other people can access that tab.

The website emits local interaction events for links marked for measurement and can pass them to a browser data layer only if another script has initialized one. Velatura does not currently use third-party advertising cookies on the public website. Google and Stripe may use their own cookies or similar technologies when you choose Google sign-in or enter their hosted checkout and portal flows; their notices govern that separate processing.

8. Stripe and Payment Processing

Velatura uses Stripe to process payments, manage checkout sessions, subscriptions, customer portal sessions, invoices, refunds, disputes, and payment-related fraud checks. Stripe acts as an independent controller for some payment processing activities and as a processor or service provider for others, depending on the activity.

Velatura receives payment status, subscription status, Stripe customer identifiers, invoice references, and related billing metadata needed to provide licensed access and account support. Velatura does not receive or store full card numbers.

9. Support and Admin Access

Authorized Velatura personnel may access account, billing, support, technical, and managed rendering records only when necessary to answer a support request, investigate service failures, verify subscription or token-accounting issues, prevent abuse, maintain security, or comply with legal obligations.

Administrative access is restricted to authorized administrators and legitimate operational purposes. Relevant admin actions may be logged for audit, security, and accountability.

10. Service Providers and International Transfers

Velatura uses service providers to host and operate the API, database, website, temporary assets, and app downloads; process payments; provide optional Google account authentication; deliver transactional email; and perform managed rendering. Current core providers include Render for API, database, and admin hosting; Cloudflare for network and temporary object-storage services; GitHub for website and release distribution; Google for optional identity and managed rendering; and Stripe for billing. Apple provides optional speech recognition. Transactional email is delivered through the configured email provider. OpenRouter and its selected downstream model provider receive data directly from your app when you connect your OpenRouter account.

When you choose Google sign-in, Google's identity service may process browser, device, and interaction data needed to display and operate its sign-in flow. Google's processing is also governed by the Google Privacy Policy.

When managed rendering uses the Gemini API, Google receives the render prompt, source or reference images, and generated output. Google's published Gemini API abuse-monitoring terms state that this content may be retained for 55 days and that content flagged for policy review may be reviewed by authorized personnel, unless a different approved arrangement applies. See Google'sGemini API usage policies.

Apple's handling of speech-recognition data is governed by the permissions presented by macOS andApple's privacy information for dictation. OpenRouter and downstream model-provider retention and training practices vary by provider and by the privacy controls on your OpenRouter account.

Some providers may process personal data outside Sweden or the European Economic Area. Where GDPR transfer safeguards are required, an applicable adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism must apply. Contact Velatura for information about the provider, processing location, and safeguard relevant to a particular transfer.

Velatura does not sell personal data. Providers may act as processors, service providers, or independent controllers depending on their role and the service you choose.

11. Retention

Velatura keeps personal data only for as long as needed for the purposes described in this policy, including providing the service, maintaining security, resolving disputes, complying with accounting and tax obligations, and enforcing agreements.

  • Account data is kept while the account is active. Velatura does not currently provide self-service account deletion; erasure requests are handled manually through the privacy contact and may be limited where data is still needed for security, disputes, or legal obligations.
  • Billing and tax records are retained for the periods required by Swedish and EU accounting, tax, and consumer-protection rules.
  • Managed rendering uploads and outputs are service staging rather than canonical project storage. Upload authorization currently expires after 15 minutes, while inputs, outputs, and related staging metadata in Velatura's Cloudflare R2 bucket expire seven days after creation. Provider copies follow the provider's own retention rules; Google currently describes a 55-day Gemini API abuse-monitoring period unless a different approved arrangement applies.
  • Operational render-usage data is retained while needed to administer the account, reconcile usage and provider cost, support rendering, investigate abuse or disputes, and meet legal obligations.
  • Optional product analytics events are retained for up to 90 days and then deleted. Disabling analytics deletes unsent events from your Mac immediately; account-linked events already received remain for the rest of that period unless erased earlier following a valid request or retained under another applicable legal basis.
  • Dictation audio is not persisted by Velatura. A transcript remains local unless you submit it as a render prompt. Apple's retention is governed by its own privacy terms.
  • Website session data remains in the current browser tab session unless it is cleared earlier by the billing flow or by you.
  • Support records are retained while the issue is active and then for a reasonable period to maintain service history and accountability.
  • Security and server logs are retained for limited periods based on operational, security, fraud-prevention, and audit needs.
  • Registration rate-limit buckets use a keyed pseudonymous IP value. Events older than 48 hours are excluded from rate calculations and are pruned when later registration activity runs; without later activity, an old row may remain longer. A keyed canonical-identity trial eligibility record may remain after other account data is erased for as long as the one-trial-per-identity rule is needed to prevent repeat claims and protect the service.

When data is no longer needed, Velatura deletes it, anonymizes it, or isolates it from active use when deletion is not immediately possible because of backups, legal holds, or mandatory records.

12. Automated Checks

Velatura uses automated rules to canonicalize email identities, reject known temporary-email domains, enforce short registration rate limits, and determine whether an identity has already received a trial. These checks can refuse a new registration or trial but are not used to make decisions that produce legal or similarly significant effects about you. If you believe a check is wrong, contact Velatura and request a human review.

13. Your GDPR Rights

If the GDPR applies to your personal data, you may have the right to request access, rectification, erasure, restriction, portability, or objection to processing. You may also withdraw consent where processing is based on consent.

To exercise these rights, contact [email protected]. We may need to verify your identity before acting on a request. Some requests may be limited where Velatura must keep data for legal obligations, security, fraud prevention, accounting, dispute resolution, or establishment, exercise, or defense of legal claims.

You also have the right to lodge a complaint with theSwedish Authority for Privacy Protection(Integritetsskyddsmyndigheten, IMY) or another competent EU/EEA supervisory authority.

14. Security

Velatura uses technical and organizational measures designed to protect personal data, including encryption in transit, password hashing, encrypted local provider-key storage, access controls, credential protection, restricted operational access, logging, and service monitoring.

No online service can guarantee absolute security. If Velatura becomes aware of a personal data breach that requires notification, Velatura will notify affected users and competent authorities as required by the GDPR.

15. Children

Velatura is intended for people aged 18 or older and is not directed to children. If you believe a child has provided personal data to Velatura, contact us so the situation can be reviewed and the data deleted where required.

16. Changes to This Policy

Velatura may update this policy to reflect service, legal, or operational changes. The published date at the top of the page shows when this version took effect. Material changes will be communicated through an appropriate channel, such as the website, the app, or account email.

17. Contact

For privacy requests or questions, contact Velatura at[email protected].

Velatura
Sweden