Data Security and Confidentiality
Last updated: June 26, 2026
We know that the information you put into Vellor often includes confidential client information, and that your duty of confidentiality extends to the vendors you use. This page explains how we handle that data. It is part of our Terms of Service.
Your data is yours
- You own the documents, client information, and content you submit ("Customer Data").
- We process Customer Data only to provide, maintain, secure, and support the Service, and on your instructions.
- We do not sell Customer Data.
- We do not use Customer Data to train our own or any third party's general-purpose AI models.
Confidentiality
- We treat Customer Data as confidential and limit access to personnel who need it to operate and support the Service, under confidentiality obligations.
Security measures
We use administrative, technical, and physical safeguards designed to protect Customer Data, including:
- Encryption in transit (TLS) and at rest;
- Access controls, authentication, and least-privilege access;
- Logging and monitoring;
- Secure, reputable cloud infrastructure (Vercel) and database hosting (Supabase);
- Regular backups and other measures. No system is perfectly secure, but we work to protect your data using industry-standard practices.
Sub-processors
We use a limited set of vetted providers to deliver the Service. Current sub-processors include:
- Stripe — payment processing.
- Vercel — application hosting and infrastructure.
- Supabase — database and storage.
- Anthropic — AI processing of the inputs you submit to generate output. Under Anthropic's commercial terms, it does not use these inputs or outputs to train its models. We currently use Anthropic and may add or change AI providers and models over time, updating this statement accordingly.
- Resend — transactional and account email. We will maintain this list and provide notice of material changes.
How AI processing works
When you use AI features, the inputs you provide are sent to our AI provider, currently Anthropic, to generate output, which is then returned to you. Anthropic processes these inputs to provide the service and, under its commercial terms, does not use them to train its models. We do not use your inputs or outputs to train any AI models.
Data retention and deletion
- Customer Data is retained while your account is active.
- On termination, we make Customer Data available for export for 30 days, then delete it within 90 days, unless a longer period is required by law or to resolve disputes. Backups are purged on a rolling basis, generally within 90 days.
- You may request deletion of specific Customer Data at support@ellisaitech.com.
Breach notification
If we become aware of a security incident affecting your Customer Data, we will notify you without undue delay and consistent with applicable law, and provide information to help you meet your own notification obligations.
Data Processing Addendum (DPA)
A Data Processing Addendum is available for customers who require one for their compliance and professional-responsibility obligations. Contact support@ellisaitech.com to request the DPA.
Your responsibilities
- Confirm you have the rights and client authorizations to submit Customer Data.
- Use strong, unique credentials and keep them confidential.
- Configure access for your personnel appropriately and supervise their use.
Contact
Ellis Tech LLC — 1125 West St., Ste. 581, Annapolis, MD 21401 — support@ellisaitech.com