Vellum Search Regulations coveredPricingContactAnalysis ↗ Sign in

Privacy Policy

Last updated: 28 August 2026

This Privacy Policy explains how Vellum AI Group Ltd handles personal data in connection with Vellum Search at search.vellumintel.com, including its website, mobile applications, searchable database, accounts, subscriptions, application programming interface (“API”), Model Context Protocol interface (“MCP”), notifications and related services (together, the “Service”).

We do not use personal data for third-party advertising, cross-site tracking or marketing profiles.

1. Who we are

Vellum Search is operated by Vellum AI Group Ltd, a company registered in England and Wales under company number 17129362.

For data-protection purposes, Vellum AI Group Ltd is generally the controller of personal data processed in connection with the Service.

You can contact us about privacy matters at [email protected].

2. Scope and data-protection roles

This Policy covers:

Where a business customer submits personal data through a search query, API request or other Customer Content and determines why that data is processed, the customer may be the controller and Vellum may act as its processor. In those circumstances, the customer’s privacy policy applies to its processing, and we assist the customer in accordance with our contractual data-processing obligations.

Vellum remains a controller for account administration, billing, security, service operation and the selection and presentation of the public regulatory corpus.

3. Personal data we collect

The personal data we process depends on how you interact with the Service.

3.1 Account and organisation information

This may include:

We use email verification codes for authentication. We do not ask you to create a Vellum password.

3.2 Authentication, device and security information

This may include:

3.3 Subscription and billing information

This may include:

Payments are processed by Stripe. We do not ordinarily receive or store full payment-card details.

For metered API billing, we report the Stripe customer identifier and an aggregate number of billable requests for each UTC hour. We do not send query text, request content, record identifiers or API keys to Stripe for metering.

3.4 Service-use information

This may include:

We may create aggregated or anonymised statistics that no longer identify an individual.

To arrange your Feed, we keep a preference profile for your account built from the topics, ecosystems and Vellum agents you follow and from your “More like this” and “Less like this” reactions on Feed items. It records which ecosystems, sectors and themes you have reacted to, with a simple positive or negative weight for each, and it is used only to order your own Feed — placing likely-relevant items higher and de-emphasising items you asked to see less of. This profile is a feature of the Feed rather than product measurement: it is stored so the Feed can honour your choices, so turning off the “Disable usage analytics on this device” switch does not remove it. It is not shared, is not used for advertising or cross-site profiling, and does not make any decision that produces legal or similarly significant effects about you (see section 15). You can clear it by removing the relevant follows and reactions, and it is deleted with your account (section 10).

When first-party product measurement is enabled, the website or mobile app sends only a coarse allowlisted page path, an allowlisted interaction or feature name, a coarse outcome and, where relevant, a result position or export format. It does not send search text, record titles, saved-search names, labels, account identifiers, full URLs, referrers, error messages, your device make or model, precise location or any advertising identifier. This measurement writes no analytics identifier.

Each event may also carry a small amount of coarse context: whether it came from the website or the mobile app and, in the app, the app version. The operating-system family and its major version, the browser-engine major version, whether the device is a phone, tablet or desktop, and the interface language (the language only, such as English) are not read from your device by the page: where we record them, they are derived at the Service edge from the request headers your browser or the app already sends, as described below. We record, in broad bands rather than exact figures, when the website or app is opened and closed and for how long it was in use, and how long a record was open for reading. In the mobile app we also record how it was opened — from a link, a shared item, a home-screen shortcut or a system shortcut — and the category of app a shared item came from, such as mail, a messaging app or a browser; and, when you share something out of the app, the kind of destination you chose, such as mail, a messaging app or copying a link. Product measurement never includes the shared text or the link itself.

Separately from measurement, when you share a link into the mobile app, the app sends the link, together with a short excerpt of any title, subject line or message text that came with it, to the Service so that it can check whether that page is in Vellum Search. The Service uses them to answer that request, may keep its answer for up to ten minutes so that a repeated check is quicker, and otherwise handles them like any other request content under this section and section 9. If what you share into the app contains no link, the shared text (up to its first 200 characters) is run as a search, as if you had typed it.

If something goes wrong in the website or app, it may send an error report containing the category of error, the part of the Service it occurred in, a position in the code that failed and the same coarse context described above. An error report never contains the error message, a stack trace, what you were looking at or any content. Error reports are sent without your sign-in credential and are not linked to your account, and we limit them to a few reports a day from any one device.

You can turn product measurement off at any time. On the website, use the product-measurement control in section 7; in the mobile app, use the “Disable usage analytics on this device” switch in Settings. Browser Do Not Track and Global Privacy Control signals are also respected. Turning measurement off stops every product-measurement event described in this section, including error reports, from that browser or device.

At the Service edge, we create a daily salted pseudonym from request network and browser information for same-day counting and abuse limits. Raw IP addresses and user-agent strings are not written to the analytics event; the coarse operating-system, browser-engine, device-class and interface-language values described above are derived from that information at the edge, and only those values are kept. For signed-in and API use, we use a separately keyed account pseudonym so we can measure account-level use and apply account deletion. A signed-in interaction request uses the existing short-lived sign-in credential only to resolve that pseudonym; the credential and underlying account identifier are not written to product analytics. Our internal reporting system may group events for the same pseudonym into a session when they are no more than 30 minutes apart; the browser does not create or store a session identifier, and the open-and-close events described above carry a duration band only, not an identifier. Search text is not stored in product analytics: a keyed one-way fingerprint is created in memory to group repeated searches without making the words available in reports. We may record a selected ecosystem from our fixed public catalogue, or that multiple ecosystems were selected; other filter values are reduced to presence-only flags. These identifiers are pseudonymous personal data, not anonymous data.

3.5 Communications

This may include:

3.6 Personal data in official public records

The corpus is not designed as a directory of individuals. However, official regulatory records may contain personal data, including:

Some official records may contain special-category or criminal-offence information. Where an additional legal condition is required to process such information, we process it only where an applicable condition under the UK GDPR and Data Protection Act 2018 is available.

4. Where personal data comes from

We obtain personal data:

Each corpus record is intended to retain provenance information or a link to its official source.

5. How and why we use personal data

We process personal data for the following purposes and lawful bases.

5.1 Providing the Service

We use personal data to:

Where the user is personally party to the subscription, the lawful basis is performance of a contract.

Where the customer is an organisation and the user is its employee, contractor or representative, the lawful basis is generally our legitimate interests in providing and administering a business service for that organisation.

5.2 Billing and financial administration

We use billing and transaction information to:

The lawful bases are performance of a contract, compliance with legal obligations and our legitimate interests in administering payments and protecting our financial position.

5.3 Security, fraud prevention and acceptable use

We use account, device, network and usage information to:

The lawful basis is our legitimate interests in operating a secure and reliable business service and protecting Vellum, its customers and third parties.

5.4 Operating and improving the Service

We use service-use and diagnostic information to:

The lawful bases are performance of a contract and our legitimate interests in maintaining and improving the Service.

We do not use this information for third-party advertising or cross-site behavioural profiling.

5.5 Communications and legal compliance

We use personal data to:

The lawful bases are performance of a contract, compliance with legal obligations and our legitimate interests in managing communications and protecting our legal rights.

5.6 The public regulatory corpus

We process personal data appearing in official public records to:

The lawful basis is our legitimate interests in operating a reliable regulatory-information service and enabling efficient access to official public material.

We consider this processing proportionate because:

We generally do not contact every person mentioned in an official record individually. Where providing individual notice would be impossible or involve disproportionate effort, and applicable law permits us to rely on that exception, we instead make this Policy publicly available and maintain provenance to the relevant official source.

6. Sharing personal data

We disclose personal data only where reasonably necessary for the purposes described in this Policy.

6.1 Service providers

We use service providers including:

These providers may process account, device, network, transaction or service-use information depending on the function they provide.

Some providers act as processors on our instructions. A provider may also act as an independent controller for certain activities it carries out for its own legal, security, fraud-prevention or service-administration purposes. Its own privacy policy applies to that independent processing.

6.2 Other recipients

We may also disclose personal data:

We do not sell personal data or disclose it to third parties for their own advertising.

7. Cookies and similar technologies

The Service uses cookies and similar storage or access technologies that are necessary to:

We do not currently use non-essential advertising cookies or cross-site behavioural trackers on the Service.

Our first-party product measurement does not write an analytics identifier to cookies, local storage or session storage. If you turn measurement off below, or with the “Disable usage analytics on this device” switch in the mobile app’s Settings, we store one first-party preference cookie so the Service can honour that choice for one year. In the mobile app the same choice is also recorded in the app’s own local storage, because the app is not served over https and a “secure” cookie cannot be stored there — without it the switch could not remember your choice at all. Both records hold nothing but the choice itself. To keep error reports to a few a day, the website or app also keeps a small daily counter in its local storage; it holds only the date and a count and identifies nothing.

We use this measurement only to produce statistical information about how Vellum Search is used so we can improve the Service. It is not used for advertising, cross-service tracking, individual profiling or decisions about people.

Product-measurement preference

You can object free of charge. Turning measurement off stops browser and same-origin product-measurement events on this device. Do Not Track and Global Privacy Control signals are also respected. In the mobile app, the same choice is in Settings.

Stripe-hosted checkout or billing pages and Clerk authentication functions may use necessary cookies and similar technologies under their respective privacy and cookie policies.

Where a technology is strictly necessary to provide a function you request, consent is not required, but we still provide information about its use. If we introduce a technology for which consent is legally required, we will request consent before using it.

8. International transfers

Vellum is established in the United Kingdom. Our providers and their subprocessors may process personal data in the United Kingdom, European Economic Area, United States and other countries in which they operate.

Where personal data is transferred outside the United Kingdom to a country that is not covered by applicable UK adequacy regulations, we use an appropriate transfer mechanism where required, which may include:

We may also apply contractual, organisational and technical safeguards appropriate to the transfer.

You may contact us for further information about the safeguards relevant to a particular transfer.

9. Retention

We keep personal data only for as long as reasonably necessary for the purposes for which it was collected, including legal, accounting, security and dispute-resolution requirements.

Our general retention approach is:

We may retain limited information for longer where required by law, necessary for fraud or security prevention, or relevant to an actual or reasonably anticipated dispute.

10. Account deletion

You may delete your account through the account page or request deletion by emailing [email protected].

Deleting an account:

Deletion does not necessarily remove all information immediately. We may retain limited information where required for:

Stripe and other independent controllers may retain information under their own legal obligations and privacy policies.

Deleting an account does not remove an official public record from the corpus merely because the account holder previously accessed it.

11. Security

We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction.

These measures may include access controls, authentication, encryption in transit, restricted administrative access, logging, monitoring and provider security controls.

No online service can guarantee absolute security. You are responsible for maintaining control of your email account, devices and API credentials and for notifying us promptly if you suspect compromise.

12. Your rights

You can delete your account and its data from the Account page without making a separate request. To exercise another applicable data-protection right, including access or data portability, contact us using the details below.

Depending on the circumstances and the lawful basis we rely on, you may have the right to:

These rights are not absolute. For example, we may retain information where required by law or where necessary to establish, exercise or defend legal claims. We may also preserve an accurate official or historical public record where applicable law permits.

To exercise a right, email [email protected]. We may need to verify your identity and clarify your request.

We normally respond within one month, subject to any lawful extension for a complex request or multiple requests.

If personal data was submitted by an organisation that controls it, we may refer your request to that organisation or assist it in responding.

13. Corrections and objections concerning official records

If you believe that:

you may contact [email protected] and identify the relevant record and official source.

We will assess the request in context. Depending on the circumstances, we may:

We cannot alter the content held by the original public authority. Requests to amend the authoritative record may need to be made directly to that authority.

14. Privacy complaints

You may make a complaint about our handling of personal data by emailing [email protected] with “Privacy complaint” in the subject line.

We will:

You may also complain to the Information Commissioner’s Office, the United Kingdom’s data-protection supervisory authority.

We would appreciate the opportunity to address your concerns directly before you approach the ICO, but you are not required to contact us first.

15. Automated decisions

We do not use personal data to make solely automated decisions about Service users that produce legal effects or similarly significant effects.

Search ranking, metering, fraud signals and security controls may involve automated processing, but material account enforcement decisions are subject to appropriate review where required.

16. Children

The Service is intended for users aged 18 or over. It is not directed at children, and we do not knowingly create accounts for children.

If you believe that a child has provided personal data through the Service, contact us at [email protected].

17. Changes to this Policy

We may update this Policy to reflect changes to:

If a change materially affects how we use personal data, we will provide reasonable notice by email or through the Service where appropriate.

The date at the top shows when this Policy was last updated.

18. Contact

For privacy questions, rights requests, corrections or complaints:

Vellum AI Group Ltd
Email: [email protected]
Company number: 17129362
Registered in: England and Wales