Veldrun

Last updated 20 August 2026

Privacy policy

The short version: the current local archive path keeps readable documents, questions and answers on hardware you control. The website and account services still process the metadata listed below. Household sync is designed to send only application-encrypted artifacts whose household key we do not hold, but its production deployment and two-PC release validation are not complete.

What we collect

What we do not collect

Your content is never used for training

We do not use household documents, questions or answers from the current local product to train or fine-tune models. Any future optional hosted-model path would require separate disclosure and explicit consent; it is disabled in the current product.

Why we process what we do

We process a waitlist address with your consent, which you may withdraw at any time. We process account, device and security records as needed to provide an invited test and protect the service. If a paid product opens, its seller will publish the applicable contractual and legal bases before taking payment.

Who else is involved

The pre-release website and account infrastructure use hosting/content-delivery and email services. If sales open, the named merchant of record will process billing and tax. If managed storage opens, encrypted objects will use a disclosed storage processor. Each provider is limited to its function. We do not sell personal information or share it for cross-context behavioural advertising.

International processing

Website and email providers may process data in the United States and other countries. The final operator must document the providers, locations and applicable transfer mechanism before public launch; this pre-release notice does not claim a transfer arrangement that has not been recorded.

How long we keep it

Waitlist records are kept until you unsubscribe or ask for deletion. Invited-test account, device and security records are kept while needed to operate and protect that test. Exact production retention periods, including any encrypted relay deletion schedule, must be published before launch.

Your rights

Depending on where you live, you may have the right to access, correct, delete, port or restrict the personal data we hold, to object to processing, and to complain to your data protection authority. If you are in California you may also request disclosure of the categories of information collected and opt out of sale or sharing — though we do neither. We will not discriminate against you for exercising any of these rights.

To exercise them, email hello@veldrun.com. The applicable response period depends on your jurisdiction. Note that the current local archive path does not send us readable copies of your documents.

Security, stated honestly

Household sync artifacts are designed to be encrypted on-device with keys the relay does not hold. That is distinct from browser remote access through a tunnel, whose TLS terminates at the edge. Because we do not hold the household key, we cannot recover that encrypted archive if every authorized device and recovery copy is lost. This is a known gap, not a design goal. Organisation-held key escrow — where the customer, never Veldrun, holds a recovery key — is specified and not yet implemented; organisations with records-retention, legal-hold or emergency-access obligations should treat the current behaviour as unsuitable for those duties. Deployment, key rotation and real-machine recovery are still release gates.

Children

Veldrun is not directed at children under 13 and we do not knowingly collect their personal information. Household members are managed by the account holder.

Changes and contact

We post material changes to this page and, where they affect you meaningfully, notify you by email. Veldrun is currently a pre-release project, not a named incorporated seller. The legal operator/controller identity and service address must be published before public launch; we will not invent them here. Current privacy contact: hello@veldrun.com.