Privacy policy

Last updated: 16 August 2026

This is a convenience translation. The German version is the legally binding one.

The short version. Vaelo is a private workspace for exactly two people. What you write there is visible to the other person — and, technically, to the operator. Content is not end-to-end encrypted. Please don't put passwords, credentials or strictly confidential documents into it.

1. Who is responsible

The controller under the GDPR is:

Fabio Burmann
Lothstraße 17
80335 Munich
Germany
Email: privacy@vaelo.site

No data protection officer has been appointed; the thresholds of Art. 37 GDPR / § 38 BDSG are not met.

2. What we process

Vaelo has two parts: the marketing site vaelo.site and the application app.vaelo.site. The marketing site requires no sign-in and holds no accounts.

2.1 When you use the application

DataPurposeLegal basis
Email address Magic-link sign-in, inviting the second person, linking you to a workspace Art. 6(1)(b) GDPR (contract)
Display name and seat (intern / manager) Showing who is who in the shared workspace Art. 6(1)(b) GDPR
Content: goals, milestones, notes, agenda items, to-dos, schedules, retrospectives and session history Providing the actual service Art. 6(1)(b) GDPR
Mood check-ins: a state (e.g. "calm", "stressed", "sad", "tired"), an optional free-text reason, and the date Letting both of you see how the other is arriving at a conversation Art. 9(2)(a) GDPR (explicit consent) — see section 3
Login session in your browser (localStorage) Keeping you signed in Strictly necessary, § 25(2) no. 2 TDDDG
vaelo_returning cookie Sending returning visitors straight to the app Consent, § 25(1) TDDDG / Art. 6(1)(a) GDPR

2.2 When you load the pages (server logs)

When you request vaelo.site or app.vaelo.site, our hosting providers process technically necessary connection data — in particular IP address, time of request, resource requested, referrer and browser identification. The purpose is delivering the page, operational security and troubleshooting. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, reliable operation).

We use no analytics, tracking or advertising services. There is no Google Analytics, no pixels, no profiling. Fonts are served from our own server rather than Google Fonts, so loading a page makes no connection to Google.

3. Mood data and Art. 9 GDPR

A mood check-in can say something about how you are feeling. We therefore treat it, as a precaution, as a special category of personal data under Art. 9 GDPR and process it only on the basis of your explicit consent (Art. 9(2)(a) GDPR).

The feature is optional. You can use Vaelo fully without ever recording a mood, and you can withdraw your consent at any time with effect for the future — in the app, or by email to privacy@vaelo.site.

4. Recipients and processors

We use the following providers. A data processing agreement under Art. 28 GDPR is in place with each of them.

ProviderRoleProcessing location
Supabase (Supabase Inc.) Database and authentication — this is where content lives EU (Frankfurt/Ireland region)
Vercel (Vercel Inc.) Hosting and page delivery EU edge, company based in the USA
Resend (Resend Inc.) Sending sign-in and invitation emails EU region
INWX GmbH & Co. KG Domain and DNS Germany

Where personal data is transferred to a third country, this is done on the basis of the EU Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). Your content is never passed on for advertising purposes.

5. Cookies and similar technologies

Vaelo gets by with very little:

You can withdraw your consent at any time in one click under "Cookie settings" in the app. Withdrawing is exactly as easy as giving.

6. Retention

Important about deleting your account: the workspace belongs to both of you and its content cannot meaningfully be separated. Deleting your account therefore deletes the entire shared workspace — for the other person too. Their own login remains intact and they can start again afterwards.

7. Your rights

You have the following rights in relation to us:

An informal email to privacy@vaelo.site is enough for any of these. We reply within one month.

8. Right to complain to a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de

9. Security

All traffic is encrypted over HTTPS. The database is encrypted at rest and protected by row-level security: technically, each workspace can only be read by its two members. Sign-in is passwordless, via a one-time link sent by email.

In the interest of being straight with you: content is not end-to-end encrypted. The operator has administrative access to the database and could technically read content. He does not do so routinely — only where it is unavoidable for fixing a fault, or where we are legally required to.

10. No use by children

Vaelo is intended for people aged 16 and over. We do not knowingly collect data from anyone younger.

11. Changes to this policy

We update this policy when Vaelo's features or the legal position change. The version published here, with the date shown above, is the one that applies.