Veilkin — Privacy Policy

Effective Date: 5 August 2026

1. Introduction and Who We Are

This Privacy Policy explains how Veilkin Ltd (“we”, “us”, “our”) collects, uses, stores, and shares your personal information when you use the Veilkin desktop application and associated web-based account management pages (together, the “Service”). Please read this policy carefully before using the Service.

Veilkin is a desktop AI application for Windows PC. It sits on your screen while you use your computer — primarily while gaming — and talks with you about what you are doing. The Service uses artificial intelligence to generate responses and can interact with you via text, microphone input, and screen viewing. Because the AI runs on our servers, an internet connection is required.

  • Business name: Veilkin Ltd

  • Registered address: Suite F2, Church House Business Centre, Church Street, Godalming, Surrey, GU7 1EW

  • Company number: 17213812

  • Country of incorporation: United Kingdom

  • Contact email for privacy matters: info@veilkin.gg

We are registered with the Information Commissioner’s Office (ICO) as a data controller. Our ICO registration reference is ZC145194.

2. Scope of This Policy

This Privacy Policy applies to all users of the Veilkin Service, wherever you are located.

Because we serve users across multiple jurisdictions, different legal rights and obligations may apply depending on where you live. Section 14 sets out jurisdiction-specific information. Where a jurisdiction-specific provision conflicts with the general provisions of this Policy, the jurisdiction-specific provision takes precedence for users in that jurisdiction.

This Policy does not apply to third-party websites, products, or services that we may link to. We encourage you to review the privacy policies of any third parties before sharing your information with them.

3. Age Restrictions and Children’s Privacy

The Service is intended for users aged 16 years and over. We do not knowingly collect personal information from anyone under the age of 16. Before creating an account, you must tick a box confirming that you are aged 16 or over. We do not collect a date of birth.

We are aware that the minimum age of digital consent varies between jurisdictions. We have set 16 as the global minimum age for Veilkin for consistency and to provide a higher level of protection for younger users across all markets.

If we become aware that a user is under the age of 16, we will promptly delete their account and all associated personal data. If you believe a person under 16 has registered for the Service, please contact us immediately at info@veilkin.gg.

4. Personal Data We Collect

We collect personal data in the following categories. Not all categories will apply to every user.

4.1 Account Data

When you create an account, we collect:

  • Your name

  • Email address

  • Password (stored in hashed form only — your actual password is never stored or accessible)

  • Age confirmation (a tick-box confirming you are aged 16 or over — we do not collect your date of birth)

This data is stored in a secure database hosted by Neon (neon.tech) on servers located in London, United Kingdom (Amazon Web Services EU West 2 region). Neon is SOC 2 compliant. This data is accessible to the business owner for operational and support purposes.

4.2 Subscription and Billing Data

If you purchase a trial, subscribe to a paid plan, or purchase pay-as-you-go credits, we collect:

  • Your plan (Trial, Plus, or Pro) or trial purchase record

  • Stripe customer ID and subscription ID

  • Subscription start and end dates

  • Usage data — the number of calls made during each billing period

  • Pay-as-you-go credit balances and expiry dates

  • A record of the purchase consent you gave at checkout, including the date and the version of the terms you accepted

Payment card details are never stored by us or in our database. All payment card data is collected and processed exclusively by Stripe, our payment processor, who is PCI DSS compliant. We receive only a token reference from Stripe.

4.3 Memory Data (AI Companion Memory)

The AI can remember things you share with it across sessions — for example, your gaming preferences, personal details you choose to share, and observations about your communication style.

Memory data is stored in our secure database (see 4.1) so that it is available to you across sessions. It is built automatically from your conversations — the AI saves useful facts and details rather than full transcripts — and is limited to a fixed set of categories, so only a small number of items is ever held.

We do not otherwise store the content of your conversations. Your chat history exists only within the app on your own device, is held in memory rather than written to disk, and is cleared when you sign out, after a period of inactivity, or when a new session begins.

You retain full control over your memory data at all times: you can view all stored memories, delete individual memories, or delete all memories at any time in the app’s settings.

4.4 Screen Capture Data

You may allow the AI to see your screen so that it can react to what you are doing. While the app is open and you have chosen to share a window, it takes periodic screenshots so it can respond to what is happening, and you can also prompt it to take a closer look on demand (the “watch this” feature). It only ever sees your screen while the app is open and you have actively chosen to share.

When screen viewing is active, screenshots are captured and sent to Anthropic’s API (our AI provider) so the AI can generate a response. We do not store screenshots. A screenshot is held in memory only for the length of a single request, sent to Anthropic to generate the reply, and then discarded — it is never written to disk, saved to a database, or written to a log. The screenshots taken by the “watch this” feature are handled the same way. You can stop the app seeing your screen at any time.

4.5 Voice and Audio Data

You may speak to the AI using your microphone. When you use this feature, your audio is sent to Groq’s API for transcription into text. The resulting text is then processed as a standard text message.

We do not store your audio: it is held in memory only, sent for transcription, and discarded once the text is returned. Groq does not retain the audio either — we have enabled Zero Data Retention on our Groq account — and Groq does not use the data for training.

4.6 Technical and Usage Data

We collect limited technical and usage data to operate and protect the Service, including:

  • The number of calls made per billing period, to enforce usage limits

  • Subscription status and billing history, for financial record-keeping

Our servers keep standard operational logs recording the time, method, and path of requests and whether they succeeded, which we use to diagnose faults and protect the Service. These logs do not contain the content of your conversations, your screenshots, or your audio.

Our marketing website at veilkin.gg is built and hosted on Framer, which provides built-in visitor analytics. These analytics are privacy-first and cookieless: Framer counts page views and daily unique visitors by combining your IP address and browser type into a hash using a secret that is rotated and deleted every day. No cookies or persistent identifiers are used, and the result does not identify you. We see only aggregate counts — visitor numbers, popular pages, and where traffic came from.

Beyond this, we do not use advertising trackers or behavioural profiling, and we do not use analytics of any kind on the account pages at app.veilkin.gg. If we introduce further analytics in the future, we will update this Policy and notify you.

5. Lawful Basis for Processing (UK GDPR / EU GDPR)

Under UK GDPR and EU GDPR, we are required to identify a lawful basis for each type of personal data processing we carry out. Our lawful bases are as follows:

  • Account data (name, email, age confirmation): Contract — necessary to provide the Service you have signed up for and to verify your age.

  • Password: Contract — necessary to authenticate you and protect your account.

  • Subscription and billing data: Contract — necessary to process your payments and manage your subscription. Retention of billing records and purchase consents is also carried out to meet our Legal Obligations.

  • Usage data: Legitimate Interests — we process usage data to enforce fair usage limits and protect the Service from abuse. This is necessary for us to operate a sustainable service and does not override your interests or rights.

  • Memory data: Consent — you voluntarily share personal information with the AI companion. You may withdraw this consent at any time by deleting individual memories or all memories in the app’s settings.

  • Screen capture data: Consent — you actively choose to share your screen. You may withdraw consent at any time by stopping the screen share.

  • Audio data: Consent — you choose to use voice input. You may stop using this feature at any time.

For users outside the UK and EU, equivalent legal bases apply under the applicable laws of your jurisdiction. Please see Section 14.

6. How We Use Your Personal Data

We use your personal data only for the purposes described in this Policy. Specifically, we use your data to:

  • Create and manage your account

  • Provide and operate the Veilkin AI companion Service

  • Process your payments and manage your billing

  • Enforce the usage limits applicable to your plan

  • Enable the AI companion to respond to your text and voice inputs

  • Process screen capture data in real time when you share your screen

  • Communicate with you about your account, subscription, or billing

  • Respond to your data subject requests and privacy queries

  • Comply with our legal obligations

We do not use your data for advertising, marketing profiling, or sale to third parties. We do not use your data to train AI models. Conversation data sent to Anthropic and Groq is processed in accordance with their respective terms and is not used by those providers to train their models.

7. Third-Party Data Processors

We share your personal data with the following third-party processors who process data on our behalf. We have data processing agreements or equivalent safeguards in place with each of them.

Processor

Purpose

Data Shared

Location

Neon (neon.tech)

Database hosting

Name, email, subscription data, usage data, memory data

London, UK (AWS EU West 2)

Render (render.com)

Application and website hosting

Data passing through our servers in the course of running the Service

United States

Anthropic (anthropic.com)

AI response generation

Conversation messages, screenshots (if shared)

United States

Groq (groq.com)

Voice-to-text transcription

Audio recordings (transient)

United States

Stripe (stripe.com)

Payment processing

Name, email, payment card data (PCI compliant)

United States / EU

Framer (framer.com)

Marketing website hosting and cookieless visitor analytics

A daily-rotating hash of IP address and browser type; no personal data

Netherlands / EU

7.1 International Data Transfers

Anthropic, Groq, Render, and Stripe are based in or process data in the United States. When your data is sent to these providers, it is transferred outside the UK and EEA. We rely on the following safeguards for these transfers:

  • UK: International Data Transfer Agreements (IDTAs) or the UK Addendum to the EU Standard Contractual Clauses, as required under UK GDPR.

  • EU: Standard Contractual Clauses (SCCs) as approved by the European Commission, as required under EU GDPR.

  • Other markets: Equivalent transfer mechanisms as required by applicable local law. See Section 14.

Neither Anthropic nor Groq uses your data to train AI models. Groq retains no audio, because we have enabled Zero Data Retention. Anthropic deletes conversation content within 30 days.

Neon, our database provider, stores your account, subscription, and memory data in London, UK (Amazon Web Services EU West 2), meaning that data does not leave the UK.

8. Data Retention

We retain your personal data only for as long as necessary for the purposes described in this Policy or as required by law.

  • Account data: Retained for the duration of your account. Following account deletion, account data is retained for up to 30 days to allow for error correction, after which it is permanently deleted.

  • Subscription and billing data: Retained for 7 years from the date of the relevant transaction, in accordance with UK tax and financial record-keeping obligations. This includes the record of the purchase consent you gave at checkout.

  • Memory data: Stored in our database for as long as your account is active, or until you delete it. You control your memory entirely — you can view or delete individual memories or all memories at any time in the app’s settings, and memory is deleted with your account.

  • Screen capture data: Not stored by us. Screenshots are held in memory for a single request, sent to Anthropic to generate a response, then discarded. Anthropic deletes conversation content within 30 days and does not use it to train its models. Content flagged for a usage-policy violation may be retained by Anthropic for longer where required to enforce its Usage Policy.

  • Audio data: Not stored by us, and not retained by Groq. Audio is transcribed and discarded; we have enabled Zero Data Retention on our Groq account, and Groq does not use the data for training.

  • Pay-as-you-go credits: Credit records are retained while the credits are valid and thereafter as part of our billing records. Credits expire 12 months from the date of purchase.

9. Cookies and Similar Technologies

The Veilkin desktop application does not use cookies.

The Veilkin account pages at app.veilkin.gg use a cookie set by our authentication provider to keep you signed in while you manage your account. This is a strictly necessary cookie and does not require your consent under applicable law.

The account pages also store one item in your browser’s local storage: a record that you have confirmed you are aged 16 or over, so that you are not asked again on every visit. This is not a cookie and is not transmitted to us or to any third party.

We do not use advertising cookies, third-party tracking pixels, or analytics cookies. Our marketing website at veilkin.gg uses Framer’s built-in analytics, which are cookieless and do not place anything on your device (see Section 4.6). If we introduce analytics or other non-essential cookies in the future, we will update this Policy, implement a cookie consent mechanism, and notify you in advance.

For full details, please see our Cookie Policy.

10. Artificial Intelligence — Disclosures

Veilkin is an AI-powered product. The following disclosures are important for you to understand:

  • AI-generated responses: The conversational responses you receive are generated by an artificial intelligence model provided by Anthropic (Claude). Responses are not authored by a human.

  • Accuracy: AI responses may not always be accurate, complete, or up to date. You should not rely on them as a substitute for professional advice.

  • Not a professional service: Veilkin is a social companion application. It is not a medical service, mental health service, legal service, financial service, or any other form of regulated professional service.

  • Screen content: If you share your screen, the content of your screen is processed by Anthropic. Please do not share your screen if it contains sensitive personal information you would not wish to be processed.

  • Voice transcription: Audio from the voice input feature is transcribed by Groq. The audio is not stored by us and, with Zero Data Retention enabled on our account, is not retained by Groq.

  • Memory: The AI builds a memory of you from your conversations, stored in our database and under your full control — you can view or delete it at any time. Within a session the AI also retains the recent conversation; this is cleared after a few hours of inactivity, when you sign out, or when a new session begins, while your saved memory persists.

If you are in crisis or experiencing a mental health emergency, please do not rely on the AI companion. Contact emergency services (999 in the UK, 112 in the EU, or your local equivalent) or a crisis support service immediately.

11. Data Security

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised access, loss, or disclosure. These include:

  • Passwords are stored using cryptographic hashing — your actual password is never stored in plain text

  • Database storage is provided by Neon, a SOC 2 compliant provider, in London, UK

  • Your session token is encrypted at rest on your own device using your operating system’s secure storage

  • Payment data is handled entirely by Stripe, who is PCI DSS compliant — we do not handle or store card data

  • Memory data is stored in our SOC 2 compliant database and is not accessible to advertisers or third parties

While we take all reasonable steps to protect your data, no system can be guaranteed to be completely secure. If we become aware of a data breach that affects your personal data, we will notify you and the relevant supervisory authority in accordance with our legal obligations.

12. Your Rights

Depending on where you live, you have rights in relation to your personal data. The following rights apply to UK and EU users under UK GDPR and EU GDPR. Equivalent rights exist for users in other jurisdictions — please see Section 14.

Your Right

What This Means

Right of Access

You may request a copy of all personal data we hold about you.

Right to Erasure

You may request deletion of your account and all associated personal data by emailing info@veilkin.gg from your registered address. We will action this within 30 days. Billing records and purchase consents are retained for 7 years as we are legally required to keep them.

Right to Rectification

You may correct your name at any time in your account settings, or contact us to correct any other detail.

Right to Portability

You may request your personal data in a commonly used, machine-readable format.

Right to Object

You may object to processing carried out on the basis of legitimate interests. We will cease unless we can demonstrate compelling grounds.

Right to Restrict Processing

In certain circumstances, you may request that we limit how we process your data.

Right to Withdraw Consent

Where processing is based on consent (for example memory data or screen sharing), you may withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at info@veilkin.gg. We will respond within one calendar month of receiving your request. We may need to verify your identity before processing your request.

If you are dissatisfied with our handling of your personal data or with our response to a rights request, you have the right to lodge a complaint with the relevant supervisory authority. For UK users, this is the Information Commissioner’s Office (ICO): ico.org.uk. For EU users, please contact the supervisory authority in your country of residence.

13. Billing, Subscriptions, and Pay-As-You-Go Credits

13.1 Trial Purchase

New users may purchase a trial of the Service for a one-off charge of 99p, giving 90 calls. The trial is a single prepaid purchase and does not auto-renew. We collect and retain your name, email address, Stripe customer ID, and payment record in connection with the trial purchase, in the same way as any other transaction.

The trial is available once per account only. A record of your trial purchase is retained even if you request a refund, to enforce the once-per-account restriction. This processing is carried out on the basis of our legitimate interests in preventing misuse of the trial offer.

13.2 Subscription Billing

Subscriptions are billed monthly on the anniversary of your initial subscription date, not on a fixed calendar date. Subscriptions renew automatically unless you cancel before your next billing date.

Your monthly usage allowance resets on each billing date. Unused allowance does not roll over to the next period.

13.3 Pay-As-You-Go Credit Expiry

Pay-as-you-go credit bundles can be purchased with or without a subscription. Credits carry over month to month, but expire 12 months from the date of purchase, regardless of whether they have been used. Expired credits are forfeited and are not refundable. This expiry period is disclosed clearly at the point of purchase.

13.4 Cancellation

You may cancel your subscription at any time. On cancellation, you retain access to your plan until the end of your current billing period, after which your account becomes inactive. Cancellation does not delete your account or your saved memory. Your personal data is retained in accordance with Section 8.

14. Jurisdiction-Specific Information

14.1 European Union Users (EU GDPR)

If you are located in the European Union, the General Data Protection Regulation applies to the processing of your personal data. All rights described in Section 12 apply to you in full. Our lawful bases are set out in Section 5. Where we transfer your data outside the European Economic Area, we rely on Standard Contractual Clauses approved by the European Commission.

You have the right to lodge a complaint with the supervisory authority in your country of residence. A list of EU supervisory authorities is available at edpb.europa.eu.

14.2 United Kingdom Users (UK GDPR)

If you are located in the United Kingdom, UK GDPR and the Data Protection Act 2018 apply. All rights described in Section 12 apply to you in full. You have the right to lodge a complaint with the Information Commissioner’s Office at ico.org.uk.

14.3 United States — California

If you are a California resident, the California Consumer Privacy Act (CCPA/CPRA) gives you the right to know what personal information we collect and how we use it, the right to request deletion, the right to correct inaccurate information, and the right not to be discriminated against for exercising your rights.

We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not use your personal information for cross-context behavioural advertising. To exercise your rights, contact us at info@veilkin.gg.

14.4 Canada

If you are located in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation apply. Quebec residents have additional rights under Law 25. You may request access to or correction of your personal information by contacting us at info@veilkin.gg, and may complain to the Office of the Privacy Commissioner of Canada.

14.5 Australia

If you are located in Australia, the Privacy Act 1988 and the Australian Privacy Principles apply. You may request access to or correction of your personal information by contacting us at info@veilkin.gg, and may complain to the Office of the Australian Information Commissioner.

14.6 Other Jurisdictions

If you are located elsewhere, the data protection laws of your jurisdiction apply alongside this Policy, and nothing in this Policy is intended to exclude or limit any right you have under them.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email to your registered address and by displaying a prominent notice within the Service. The version in force is the one published on our website at the time.

16. Contact Us

If you have any questions about this Privacy Policy or about how we handle your personal data, please contact us:

Email: info@veilkin.gg

Address: Veilkin Ltd, Suite F2, Church House Business Centre, Church Street, Godalming, Surrey, GU7 1EW

ICO registration reference: ZC145194