Privacy policy
Last updated: 16 August 2026
This is a convenience translation. The German version is the legally binding one.
The short version. Vaelo is a private workspace for exactly two people. What you write there is visible to the other person — and, technically, to the operator. Content is not end-to-end encrypted. Please don't put passwords, credentials or strictly confidential documents into it.
1. Who is responsible
The controller under the GDPR is:
Fabio Burmann
Lothstraße 17
80335 Munich
Germany
Email: privacy@vaelo.site
No data protection officer has been appointed; the thresholds of Art. 37 GDPR / § 38 BDSG are not met.
2. What we process
Vaelo has two parts: the marketing site vaelo.site and the application app.vaelo.site. The marketing site requires no sign-in and holds no accounts.
2.1 When you use the application
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Magic-link sign-in, inviting the second person, linking you to a workspace | Art. 6(1)(b) GDPR (contract) |
| Display name and seat (intern / manager) | Showing who is who in the shared workspace | Art. 6(1)(b) GDPR |
| Content: goals, milestones, notes, agenda items, to-dos, schedules, retrospectives and session history | Providing the actual service | Art. 6(1)(b) GDPR |
| Mood check-ins: a state (e.g. "calm", "stressed", "sad", "tired"), an optional free-text reason, and the date | Letting both of you see how the other is arriving at a conversation | Art. 9(2)(a) GDPR (explicit consent) — see section 3 |
| Login session in your browser (localStorage) | Keeping you signed in | Strictly necessary, § 25(2) no. 2 TDDDG |
vaelo_returning cookie |
Sending returning visitors straight to the app | Consent, § 25(1) TDDDG / Art. 6(1)(a) GDPR |
2.2 When you load the pages (server logs)
When you request vaelo.site or app.vaelo.site, our hosting providers process technically necessary connection data — in particular IP address, time of request, resource requested, referrer and browser identification. The purpose is delivering the page, operational security and troubleshooting. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure, reliable operation).
We use no analytics, tracking or advertising services. There is no Google Analytics, no pixels, no profiling. Fonts are served from our own server rather than Google Fonts, so loading a page makes no connection to Google.
3. Mood data and Art. 9 GDPR
A mood check-in can say something about how you are feeling. We therefore treat it, as a precaution, as a special category of personal data under Art. 9 GDPR and process it only on the basis of your explicit consent (Art. 9(2)(a) GDPR).
The feature is optional. You can use Vaelo fully without ever recording a mood, and you can withdraw your consent at any time with effect for the future — in the app, or by email to privacy@vaelo.site.
4. Recipients and processors
We use the following providers. A data processing agreement under Art. 28 GDPR is in place with each of them.
| Provider | Role | Processing location |
|---|---|---|
| Supabase (Supabase Inc.) | Database and authentication — this is where content lives | EU (Frankfurt/Ireland region) |
| Vercel (Vercel Inc.) | Hosting and page delivery | EU edge, company based in the USA |
| Resend (Resend Inc.) | Sending sign-in and invitation emails | EU region |
| INWX GmbH & Co. KG | Domain and DNS | Germany |
Where personal data is transferred to a third country, this is done on the basis of the EU Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). Your content is never passed on for advertising purposes.
5. Cookies and similar technologies
Vaelo gets by with very little:
- Login session (localStorage, set by Supabase): strictly necessary to keep you signed in. Sign-in does not work without it, so no consent is required.
-
vaelo_returning(cookie, domain.vaelo.site, one year): remembers that you have signed in on this browser before, so that vaelo.site can send you straight to the app instead of showing you the marketing page again. It contains no name, no identifier and no token — only the fact "yes". It is set only with your consent. - Your cookie choice (localStorage): necessary in order to honour your decision — including a refusal — and not ask you again.
You can withdraw your consent at any time in one click under "Cookie settings" in the app. Withdrawing is exactly as easy as giving.
6. Retention
- Account and content data are kept for as long as the workspace exists. If you delete your account in the app, the shared workspace with all its content and your access are deleted immediately and permanently.
- Server logs are deleted by our providers according to their own schedules, typically within days to weeks.
- Email delivery data at Resend is deleted after a short period.
- Cookie consent: until withdrawn, at most one year.
Important about deleting your account: the workspace belongs to both of you and its content cannot meaningfully be separated. Deleting your account therefore deletes the entire shared workspace — for the other person too. Their own login remains intact and they can start again afterwards.
7. Your rights
You have the following rights in relation to us:
- Access to the data we hold about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) — available to you directly in the app at any time
- Restriction of processing (Art. 18 GDPR)
- Data portability in a common format (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
An informal email to privacy@vaelo.site is enough for any of these. We reply within one month.
8. Right to complain to a supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18, 91522 Ansbach, Germany
www.lda.bayern.de
9. Security
All traffic is encrypted over HTTPS. The database is encrypted at rest and protected by row-level security: technically, each workspace can only be read by its two members. Sign-in is passwordless, via a one-time link sent by email.
In the interest of being straight with you: content is not end-to-end encrypted. The operator has administrative access to the database and could technically read content. He does not do so routinely — only where it is unavoidable for fixing a fault, or where we are legally required to.
10. No use by children
Vaelo is intended for people aged 16 and over. We do not knowingly collect data from anyone younger.
11. Changes to this policy
We update this policy when Vaelo's features or the legal position change. The version published here, with the date shown above, is the one that applies.