Most privacy policies explain how carefully a company handles the copy of your data it holds. This one mostly explains why there isn't one.
Last updated 30 July 2026 · Singalang Technologies, Sarawak, Malaysia
We never see your documents. The app processes everything on your own machine and makes no network connection to do it.
We hold your email address and licence records, because that's how you sign in and prove what you bought.
This website has no analytics, no cookies and no third-party scripts. Nobody is counting your visit.
VellumDoc performs no network communication to process a document. Not for compression, conversion, OCR, editing or redaction. Files are read from where they sit on your disk and written back beside them.
We therefore hold no documents, no filenames, no page counts, no content and no record that you processed anything at all. There is no telemetry and no usage analytics in the application.
If we were compelled by a court to hand over everything we know about your document work, we would produce an empty folder. That isn't a promise about our conduct — it's a consequence of the architecture.
Professional and Team licences are issued to a specific machine, which requires exactly one message. When you activate, the app sends:
It receives your licence file in reply. After that, the app never contacts us again — licence checks happen on your machine against a signed file, offline, permanently.
Enterprise licences send nothing at all, ever. They are organisation-wide files deployed by your own tooling, suitable for air-gapped machines.
No analytics. No cookies. No tracking pixels, no advertising tags, no session recording, no third-party fonts or scripts of any kind. Every page loads only from our own server.
Our host keeps standard server logs (IP address, page requested, timestamp) for security and troubleshooting. We don't build profiles from them and they're not linked to any account.
If you send us a message through the contact form, we receive what you typed and your email address, and we use it only to reply.
If you buy a licence, we store:
All of it lives in a database in Singapore with row-level security enabled, reachable only by our own server. The browser cannot query it directly.
Payments are handled by Stripe. We never see or store your card number — Stripe tells us only that a payment succeeded, and for what.
Transactional email (your activation file, your licence, receipts) is sent through Resend. We don't run a newsletter, we don't sell or share your address, and we won't email you marketing you didn't ask for.
Under the Malaysian Personal Data Protection Act 2010 — and equivalently under GDPR if you're in the EU or UK — you can ask us to show you what we hold, correct it, or delete it. Ask us and we'll do it; no form, no fee.
We keep licence and order records for as long as your licence is valid, plus the period Malaysian tax law requires us to retain financial records. Contact messages are kept until the matter is closed. Deleting your account removes your personal data but leaves the anonymised financial record we're legally required to keep.
We do not sell personal data. We do not share it with anyone except the payment and email providers named above, who process it on our instructions.
If this policy changes we'll update the date at the top, and material changes will be emailed to licence holders. The controller of your data is Singalang Technologies, Sarawak, Malaysia — reach us through the contact page.