Privacy Policy
Last updated: 2026-05-16
This Privacy Policy describes how Springhead, LLC ("Springhead," "we," "us") collects, uses, and protects your data when you use Vellum, our household-records service.
What we collect
When you use Vellum, we collect:
- Account information: your email address (from our authentication provider) and billing data (handled by Stripe; we do not store credit card numbers).
- Forwarded emails: Vellum gives you a private inbox address. Anything you forward to that address — order confirmations, warranty registrations, receipts, manuals, photos of model plates — is received by our service and stored on your behalf. We only receive what you explicitly forward; we never connect to or read from your personal email account.
- Extracted records: from the forwarded emails we extract structured product, warranty, receipt, and serial information (e.g. the appliance brand and model, the warranty length, the purchase date and price, the serial number). These extractions are stored alongside the original message for retrieval.
- Usage data: per-account counts of items processed, model spend in cents, and error logs (no personally identifying information beyond what appears in the forwarded messages themselves).
How we use your data
We use the data we collect to:
- Extract product, warranty, and receipt information from your forwarded emails (this is the product).
- Make your household records searchable and retrievable when something breaks.
- Monitor service health and usage patterns.
- Bill your subscription via Stripe.
We do not sell your data, and we do not use the content of your household records to train any machine-learning model.
Third parties
To operate Vellum, we share specific data with these processors:
- Anthropic (Claude API): we send the contents of forwarded emails to Anthropic's Claude API for extraction (parsing out the product name, model number, warranty length, purchase date, etc.). Per Anthropic's Commercial Terms, Anthropic does not use API-submitted data to train their models.
- Stripe: handles all payment processing. We never see your full card number.
- Supabase: hosts the database where your account data, forwarded messages, and extracted records are stored.
- Vercel: hosts our web infrastructure.
- Postmark: sends transactional emails (account, billing, system notifications) and receives the inbound forwarded mail you send to your private Vellum address.
Data retention and deletion
If you cancel your Vellum subscription:
- Your private inbox stops accepting new forwards immediately.
- We retain your data in a soft-deleted state for 30 days, in case you reactivate.
- After 30 days, we hard-delete all forwarded messages, extracted records, and account data.
You can request immediate deletion of your data at any time by emailing hello@vellum.house. You can also export your records at any time from your account settings.
Security
We protect your data with:
- Encrypted-at-rest storage of message contents and attachments (AES-256-GCM).
- Row-level security in our database, enforcing per-user data isolation.
- TLS for all data in transit.
- Service-role-only access to administrative data (e.g., aggregate usage and error logs).
Your rights
You have the right to access, correct, export, or delete your data. To exercise any of these rights, email hello@vellum.house.
Changes to this policy
If we materially change this policy, we'll notify subscribers via email at the address on file. Non-material updates are reflected by changing the "Last updated" date at the top.
Contact
Springhead, LLC
Arkansas, USA
hello@vellum.house