Privacy
Effective 26 August 2026.
This page will be expanded before public launch. For now, here is a plain description of what vela stores and does with your data today.
What we store
- Your Google account email address, so you can see which account is connected.
- Your Google refresh token, encrypted at rest (AES-256-GCM) and never accessible outside the backend.
- The ids of the Search Console properties and Analytics properties you choose to connect.
- The name of each MCP tool your agent calls (e.g.
gsc_search_analytics) — for rate limiting and abuse detection.
What we never store
- The arguments your agent passes to a tool call (site URLs, property ids, date ranges) or the results it gets back (your actual traffic and search data).
- Your Google password — we never see it; sign-in happens entirely on Google's side.
What we never do
- Sell your data.
- Train models on your data.
- Share your data with third parties.
Disconnecting and deleting your data
You can disconnect a Google account at any time from your account page. Self-serve data deletion hasn't shipped yet — until it does, email dev@william-laverty.com and we'll delete your account and all associated data.