1. Who we are
Vela ("we", "us", "our") is operated by Vela AI Ltd, a private limited company registered in England and Wales (company number 17235407), with its registered office at 66 Paul Street, London EC2A 4NA, trading at tryvela.co. For the purposes of UK GDPR and the Data Protection Act 2018, we are the data controller of personal data processed through Vela.
For any privacy-related questions, requests, or complaints, contact us at:
Email: support@tryvela.co
Postal address: 66 Paul Street, London EC2A 4NA
If you are located in the European Union, our EU Representative under Article 27 EU GDPR is not yet appointed (pending — to be appointed before accepting EU users, or EU access restricted at launch).
You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk at any time. If you are in the EU, you may also complain to your local supervisory authority.
2. What this policy covers
This policy explains what personal data we collect when you use Vela, why we collect it, how we use it, who we share it with, how long we keep it, and what rights you have over it.
This policy applies to:
- The Vela platform at app.tryvela.co
- The Vela marketing website at tryvela.co
- Any other product, integration, or service we offer under the Vela name
This policy does not apply to third-party services you connect to Vela (such as Google Drive, Slack, or Stripe) — those services have their own privacy policies that apply to your use of them.
3. Who can use Vela
Vela is intended for use by adults aged 18 or over operating, founding, or working in business contexts. By creating an account, you confirm that you are at least 18 years old. We do not knowingly collect personal data from anyone under 18. If we discover that we have collected data from someone under 18, we will delete it promptly.
4. The data we collect
4.1 Account information
When you create an account, we collect:
- Your email address
- A password (which is stored only as a salted hash — we never store your password in plain text)
- Confirmation that you have accepted these terms
You verify your email address within 24 hours of signup. Unverified accounts may be deleted.
4.2 Onboarding information
During onboarding, you provide information about you and your business. This includes:
- Your name (as you wish to be addressed)
- Your company or project name
- The size of your company
- Your competitors (if you choose to share them)
- Your company's stage
- Any text, PDFs, or URLs you upload during onboarding
- Any additional context you provide before completing onboarding
This information is stored in your founder memory and used to give your AI team relevant context when they work for you.
4.3 Knowledge base uploads
You can upload URLs, PDF files, and documents to Vela's knowledge base. We store these uploads on our servers (hosted in the European Union via Supabase) and process them through our AI providers in order to make their content available to your agents. We do not currently accept image uploads to the knowledge base.
By uploading content, you confirm that you have all necessary rights to use it (see our Terms of Service for the full warranty).
4.4 Agent interaction data
When you interact with your AI agents in your boardroom or in direct messages, we collect and store:
- Message content and timestamps
- Behavioural patterns (such as response times, frequency of engagement, and which agents you interact with most)
- Sentiment and tone signals (used to help Vera coordinate the team around you)
- Vera's inferred state about how you are working (such as periods of higher pressure or distraction)
This data is used to make your team more useful to you specifically over time. We explain how this constitutes profiling under Section 5 below.
4.5 Integration data
If you connect third-party services to Vela, we collect data from those services as required to provide the integration. Specifically:
- Telegram: if you connect Telegram for notifications, we store your Telegram chat ID. We send Vela's outbound messages (briefings, notifications) to that chat ID. We do not read your other Telegram conversations.
- Calendar: we store calendar entries you create through Vela on our servers, including titles, descriptions, times, permission tiers, and statuses. Calendar entries created by Vela on your behalf are stored under the same model.
- Email: we use Resend to send transactional emails to you (welcome emails, briefings, trial reminders). We do not currently read your inbound emails or store your email content. If you connect Gmail or Microsoft 365 in future, our processing of those connections will be disclosed before activation.
- Other integrations: as you connect Google Drive, Slack, ad platforms, and other services, we will store credentials and access tokens needed to operate the integration. Tokens are stored in a credentials vault and used only as needed to fulfil tasks you have approved.
4.6 Finance tracker data
If you use the finance tracker feature, you enter your financial data manually. This includes revenue figures, costs, balances, and transactions you enter. We do not access your bank account, card details, or any financial institution directly. We do not handle Open Banking credentials. All financial data in the finance tracker is data you manually enter or approve.
Felix (your finance agent) may make observations about this data and suggest actions. Felix does not provide regulated financial advice. All observations are based on your data with your permission and should not be relied upon as professional financial guidance.
4.7 Billing information
Payment details (card numbers, billing addresses) are collected and processed by Stripe, our payment processor. We do not store your card details. We store the minimum information needed to manage your subscription, including your subscription tier and status, your billing email (if different from account email), and a reference to your Stripe customer record.
4.8 Usage and analytics data
We collect data about how you use Vela in order to improve the service. This includes:
- Pages visited, features used, time spent
- Events such as signup, onboarding completion, first agent interaction, subscription changes
- Device, browser, and operating system information
- Approximate location based on IP address (country and region only — we do not collect precise location)
This data is processed by PostHog (hosted in the EU, on eu.posthog.com) and Google Analytics 4. See our Cookie Policy for details on how this works and how to opt out.
Your choice. Product analytics only run if you accept analytics cookies on the banner shown on your first visit. You can decline — choosing “Reject non-essential” (or turning off the Analytics toggle under “Manage”) means we will not track your usage patterns. Core product features work exactly the same either way; nothing about your team, your boardroom, or your account depends on analytics being on.
Retention. Analytics events are retained for up to 12 months from collection. If you delete your account, we also delete your associated analytics history (your PostHog person and their events) within 30 days of the account deletion completing, alongside the rest of your data.
5. Profiling and automated decision-making
Vela performs personalisation and automated behavioural inference that constitutes profiling under Article 22 UK GDPR. We disclose this here because we believe in transparency.
What we infer
Your AI team uses your interaction history to:
- Adapt to your communication style (length, tone, frequency)
- Build a working model of your business context
- Anticipate which suggestions you are likely to find useful
- Identify periods when you appear under pressure (Vera coordinates the team accordingly)
- Recognise patterns in your decision-making over time
How you control it
This profiling is core to Vela's value — your team gets to know you and becomes more useful over time. We do not make solely-automated decisions that produce legal or similarly significant effects on you without your involvement. All significant agent actions require your approval unless you explicitly enable autonomous execution via the Freedom Dial.
You can control the profiling that happens in Vela:
- Settings → Agent Settings → Growth & Learning lets you control how each agent learns, including options to turn learning off entirely, limit learning to 30 days, or roll back an agent's development to a previous state.
- Settings → Freedom Dial lets you control how much autonomy agents have. The default is approval-required for all significant actions.
- Settings → Vera → Preferences lets you control what Vera infers and how she coordinates the team around you.
You have the right to object to profiling at any time. To object, contact us at support@tryvela.co or use the in-product controls above.
6. How Vela uses AI
Vela's service is delivered through a multi-provider AI routing system. We are transparent about this because it is uncommon and the implications matter.
How routing works
When you interact with agents, your messages and any necessary context are routed to the AI provider best suited to the specific task. This may be:
- Anthropic (Claude models) — primary provider for most tasks
- OpenAI (GPT models) — used for certain task types
- Google (Gemini models) — used for certain task types
- Brave Search — used when web search is needed
The response from the selected provider is then processed through Anthropic to ensure consistency with the agent's voice and personality before being shown to you.
Data minimisation
Each AI provider receives only the context necessary to complete the specific task. No provider receives more than is needed.
Provider data use
We use these providers via their API tiers, which contractually prohibit training their foundation models on user data. Anthropic, OpenAI, and Google Gemini do not use API-tier data for model training. Brave Search receives only search queries, not the broader conversation context.
How Vela's agents are improved
Vela's agents are continuously improved using behavioural patterns extracted from publicly-available business literature, podcasts, and articles. These patterns are paraphrased and attributed; no verbatim third-party content is reproduced. Your private data and conversations are never used to train cross-user behavioural patterns. Your data stays yours.
Vela's agent personality archetypes are abstracted from publicly-available business literature and operational patterns. They do not reproduce, endorse, or imply association with any specific individual.
Visibility
You can see exactly which AI provider processed any given message by tapping the (i) icon next to that message. You can view aggregate provider usage in Settings → Router. You can adjust routing behaviour (Best / Balanced / Economy modes) at any time.
7. How our AI provider list evolves
Vela continuously monitors the AI ecosystem for new tools and providers that could improve the service. Changes are categorised by data implication:
Within-provider improvements
When an existing AI provider releases a better or cheaper model, we may begin routing relevant tasks to that model automatically. This does not change which third parties have access to your data and requires no separate notice.
New providers entirely
When a fundamentally new AI provider becomes available, we will not route user data to that provider until:
- We have signed a Data Processing Agreement with them, and
- We have updated this Privacy Policy to list them as a processor, and
- We have given users at least 14 days' notice via email and in-product notification of the change.
Runtime web use
Vela's agents may read publicly available information from websites and public APIs during their work (for example, when researching a competitor or looking up market data). They will not send your personal or business data to any service that is not listed as a processor in this Privacy Policy.
Your right to object
You can object to a new processor being added to your data processing. If you object, your account will continue to function but may have reduced capability while we work with you to find an alternative or honour your objection.
8. Why we process your data — legal bases
Under UK GDPR Article 6, we rely on the following legal bases for processing your personal data:
| Processing activity | Legal basis |
|---|---|
| Providing the Vela platform to you | Contract (Article 6(1)(b)) |
| Sending transactional emails (briefings, billing) | Contract (Article 6(1)(b)) |
| Processing payments via Stripe | Contract (Article 6(1)(b)) |
| Analytics and service improvement | Legitimate interests (Article 6(1)(f)) |
| Sending marketing emails (if you opt in) | Consent (Article 6(1)(a)) |
| Compliance with legal obligations (e.g. HMRC, ICO) | Legal obligation (Article 6(1)(c)) |
| Profiling for personalisation | Legitimate interests (Article 6(1)(f)) with right to object |
| Improving agents from public behavioural patterns | Legitimate interests (Article 6(1)(f)) — public sources, no user data |
| Security event logging and threat monitoring | Legitimate interests + legal obligation (Article 6(1)(f) and 6(1)(c)) |
We do not knowingly process special category data under Article 9 unless you voluntarily disclose it in conversation with an agent. In particular, if you disclose mental health information (such as stress, anxiety, or distress) in a conversation, Vera may use that disclosure to coordinate the team around you, but we do not store or process this in a clinical or medicalised category. Vela does not provide medical advice. If you are experiencing a mental health crisis, please contact your GP, NHS 111, or Samaritans on 116 123.
9. Third-party processors
We work with the following third-party processors. Each one has a Data Processing Agreement with us, and each processes your data only on our instructions and for the purposes set out below.
| Processor | Purpose | Location | DPA |
|---|---|---|---|
| Supabase | Database, authentication, file storage | EU (Frankfurt) | Yes |
| Railway | API hosting | United States (US West) | Yes |
| Vercel | Frontend hosting | EU (Frankfurt) | Yes |
| Anthropic | AI model provider | United States | Yes |
| OpenAI | AI model provider | United States | Yes |
| Google (Gemini) | AI model provider | United States / EU | Yes |
| Brave Search | Web search provider | United States | Yes |
| Stripe | Payment processing | UK / EU / US | Yes |
| Resend | Transactional email | United States | Yes |
| Telegram | Bot messaging (optional) | International | Yes |
| PostHog | Product analytics | EU (Frankfurt) | Yes |
| Google Analytics 4 | Marketing site analytics | United States | Yes |
| ElevenLabs (when wired) | Voice synthesis | United States | Yes |
This list is current as of the date at the top of this document and reflects the actual state of Vela's processor relationships. When this list changes materially, we update this Privacy Policy and notify users in advance as set out in Section 7.
10. International data transfers
Some of our processors are located outside the United Kingdom and European Economic Area. Specifically, AI providers and certain other services operate in the United States. When we transfer your personal data to these processors, we rely on the UK Information Commissioner's Office International Data Transfer Agreement (UK IDTA) or the UK Addendum to EU Standard Contractual Clauses to ensure your data remains protected to UK GDPR standards.
Specific transfer mechanisms in place:
- US-based processors: UK IDTA signed with each
- EU-based processors: no transfer mechanism required (data remains in EEA)
You can request a copy of our transfer agreements at support@tryvela.co.
11. How long we keep data
We keep your data only for as long as needed for the purposes set out in this policy. When you delete your account, we delete your data within 30 days unless we are required to keep specific records for longer to comply with a legal obligation.
| Data type | Retention while account active | After account deletion |
|---|---|---|
| Account information | For the life of the account | Deleted within 30 days |
| Onboarding information | For the life of the account | Deleted within 30 days |
| Knowledge base uploads | For the life of the account | Deleted within 30 days |
| Agent interaction data | For the life of the account | Deleted within 30 days |
| Agent memory and learned preferences | For the life of the account | Deleted within 30 days |
| Finance tracker data | For the life of the account | Deleted within 30 days |
| Generated content (websites, copy, posts) | For the life of the account | Deleted within 30 days |
| Subscription billing records | For the life of the account | Retained for 7 years to comply with HMRC tax obligations |
| Analytics events (PostHog, GA4) | Up to 12 months from collection | Pseudonymised; account-level deletion within 30 days |
| Backups | Up to 90 days, then permanently deleted | Up to 90 days, then permanently deleted |
Backups are technical-recovery copies only and are not used for any other purpose.
12. Your rights
Under UK GDPR, you have the following rights over your personal data:
- Right of access — you can request a copy of all personal data we hold about you
- Right to rectification — you can ask us to correct inaccurate or incomplete data
- Right to erasure — you can ask us to delete your data ("right to be forgotten")
- Right to restriction — you can ask us to limit how we process your data
- Right to portability — you can ask for your data in a portable, machine-readable format
- Right to object — you can object to processing based on legitimate interests, including profiling
- Right to withdraw consent — if processing is based on your consent, you can withdraw it at any time
- Right not to be subject to solely automated decision-making — see Section 5
How to exercise your rights
The fastest way to access or export your data is to use the self-service controls in Settings → Account → "Export all my data" and "Delete my account." For any request that cannot be self-served, contact us at support@tryvela.co.
We will respond to requests within one month. Complex or numerous requests may extend this to up to three months; if so we will tell you within the first month.
You also have the right to complain to the UK Information Commissioner's Office (ICO) at any time, without contacting us first.
13. Cookies and similar technologies
See our Cookie Policy for information on the cookies and similar technologies we use.
14. Marketing communications
If you have given us your consent to send you marketing emails, we will send occasional emails about new features, product updates, and Vela news. You can withdraw consent at any time by:
- Clicking the unsubscribe link in any marketing email
- Adjusting your preferences in Settings → Notifications
- Emailing support@tryvela.co
Withdrawing consent for marketing does not affect transactional emails (such as billing notifications, password resets, or agent briefings), which we send as part of providing the service.
15. Children
Vela is not directed at children under 18 and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us at support@tryvela.co and we will delete the data promptly.
16. Security
We take reasonable technical and organisational measures to protect your personal data, including:
- TLS/HTTPS encryption for all data in transit
- Encryption at rest for data stored in our database and file storage
- Industry-standard password hashing (bcrypt) for stored credentials
- Access controls limiting who can access production systems
- Daily automated backups with point-in-time recovery (via Supabase Pro)
- Continuous monitoring of access and unusual activity
Security event logging
Vela logs security events (failed authentication, anomalous patterns, blocked requests) for the purpose of protecting the platform and its users. These logs include IP address, endpoint accessed, and detection signal, but never message content. Logs are retained for 90 days then aged out. We rely on legitimate interests and our legal obligation to keep the service secure (Article 6(1)(f) and 6(1)(c) UK GDPR) as the bases for this processing.
Threat intelligence
Vela's security agent (Veil) ingests public threat intelligence feeds (CVE, GitHub Security Advisories, AI safety disclosures) to identify vulnerabilities affecting the platform. No user data is sent to these external feeds.
We do not currently maintain formal certifications such as SOC 2 or ISO 27001. As Vela grows we expect to obtain appropriate certifications.
No security measure is perfect. If we become aware of a personal data breach that poses a risk to your rights, we will notify you without undue delay and notify the ICO within 72 hours, as required by UK GDPR Article 33.
17. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes (changes that affect your rights or significantly change how we use your data), we will:
- Notify you by email at least 14 days before the change takes effect
- Display an in-product notification of the change
- Update the "Effective date" and "Last updated" dates at the top of this policy
For minor changes (clarifications, corrections), we will update the "Last updated" date but may not send a separate notification.
18. Contact
For any privacy-related questions, requests, or complaints:
Email: support@tryvela.co
Postal: 66 Paul Street, London EC2A 4NA
For our EU Representative (if you are in the EU): not yet appointed (pending — to be appointed before accepting EU users, or EU access restricted at launch)
For complaints to the UK regulator: Information Commissioner's Office