Privacy Policy
Last updated 13 September 2026
The short version. Vela reads a web page only at the moment you ask it something, and only the page you are looking at. It never runs in the background, never collects your browsing history, and never sells data. You can delete everything at any time by emailing us.
1. Who we are
Vela is a Chrome extension that provides an AI assistant in the browser side panel. This policy explains what the extension and its backend collect, why, and what you can do about it. Questions go to [email protected].
2. What we collect
| Data | When | Why |
|---|---|---|
| Page content — the readable text, title and URL of the tab you are viewing | Only when you send a message, press Listen, or run a context-menu action | So the assistant can answer about the page |
| Selected text | Only when you use a selection action | Same |
| PDF files you ask Vela to read | Only when you press Read PDF | Text extraction, so you can ask about the document |
| Your messages and the assistant's replies | When you chat | To produce answers, and to keep your five most recent conversations so you can reopen them |
| Account details — email address, display name, profile picture from your Google account | At sign-in | To identify your account and attach your credits to it |
| Usage records — which model, how many tokens, credits spent, timestamps | Every request | Billing, showing your balance, and fraud prevention |
| Purchase records — plan, order reference, amount, currency | When you buy | To grant credits and handle refunds |
3. What we do not collect
- Your browsing history. Vela has no access to it and does not record which sites you visit. A saved conversation keeps only the title and site name of the page it started on — never the full address or the page's text.
- Anything from pages you don't ask about. The extension does not run continuously on pages. It reads a page at the moment you act, and not before.
- Passwords, form inputs, or cookies. Vela extracts visible article text; it does not read form fields and does not transmit cookies or credentials.
- Payment card details. These go directly to our payment processor. We never see or store them.
Worth being explicit about: because Vela reads the page you are viewing, that can include pages you are signed in to — a webmail inbox, a dashboard, an internal document. It only happens when you ask a question on that page. If you would rather it did not, switch off Using page in the panel before asking, or revoke page access in Chrome's extension settings.
4. Who processes your data
We use a small number of providers to run the service. Each receives only what it needs.
| Provider | Receives | Purpose |
|---|---|---|
| Wiro AI | Your messages and the page text you attached | Runs the AI models, speech synthesis and PDF text extraction |
| Google Firebase (Google Cloud) | Account details, conversations, usage and credit records | Authentication, database, and the servers that run our backend |
| Creem | Your email address and purchase details | Payment processing as merchant of record |
| Cloudflare | Standard web request data for this website only | Hosting this site |
We do not train AI models on your data. Wiro AI, our model provider, retains a record of each API request — the text sent, the response, and any generated file such as narrated audio or extracted PDF text — as part of its service logs, and routes requests to the underlying model vendors (OpenAI, Google, Anthropic, ByteDance and others), each of which applies its own retention to API traffic. We send Wiro only what a request needs, never your account identity, and we do not use its conversation-memory features. We are not able to delete individual records from Wiro's systems ourselves; if you ask us to delete your data we will remove everything we hold and pass your request on to Wiro.
5. Where data is stored
Account, conversation and billing data is stored in Google Cloud data centres in the United States. Processing may take place in any region where our providers operate. Where transfers leave the European Economic Area or the United Kingdom, they rely on the European Commission's Standard Contractual Clauses.
6. How long we keep it
- Conversations — your five most recent only, stored as messages. Page text is never saved with them. Starting a new conversation when all five are used replaces the oldest, you can delete any of them from Recent chats in the extension, and all of them are removed if your account is deleted.
- Extracted PDF text — kept with the extraction job so it can be delivered to you, and removed when your account is deleted.
- Generated audio and extracted PDF text — not stored by us beyond what your conversation needs, but held by Wiro AI on its content network under Wiro's own retention.
- Usage and credit records — kept while your account exists, because they are the record of what you were charged.
- Purchase records — kept as long as tax and accounting law requires, typically seven years.
- Deleted accounts — removed from active systems within 30 days, and from backups within 90.
7. Legal basis
If you are in the EEA or the UK, we process your data on these bases: performance of a contract for everything needed to deliver the service you signed up for; legitimate interests for fraud prevention, abuse limits and service security; and legal obligation for tax and accounting records.
8. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to processing. If you are in Turkey, the equivalent rights under KVKK Article 11 apply. Email [email protected] and we will respond within 30 days. You also have the right to complain to your local data protection authority.
You can delete any saved conversation from Recent chats in the extension at any time, and revoke Vela's access to pages from Chrome's extension settings without deleting your account.
9. Children
Vela is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will remove it.
10. Security
All traffic is encrypted in transit with TLS. Access to production data is limited to those who need it to operate the service. Credentials for AI and payment providers are held in a managed secrets store and are never included in the extension, which is publicly downloadable.
11. Changes
If we change this policy in a way that materially affects you, we will tell you in the extension before the change takes effect. The date at the top always reflects the current version.
12. Contact
Email [email protected]. We aim to reply within three business days.