Privacy policy
Last updated 26 August 2026
Ovelle is a personal knowledge application. This policy describes what it collects, why, and what it does not do. It is written to match the behaviour of the software rather than to reserve rights the product does not use.
What Ovelle stores
- Your account: the name and email address you register with, and a salted scrypt hash of your password. The password itself is never stored or logged.
- Your content: collections, entries, structured documents, links you share into Ovelle, and files you attach. This is the material you deliberately put there.
- Voice recordings: a short clip is sent for transcription and the temporary audio is deleted immediately after the transcript is produced or the attempt fails. The transcript is kept as part of your content.
- Agent exchanges: messages you send to a connected agent, its replies and delivered work, and a record of changes it made.
- History: an append-only record of changes to your workspace, and protected recovery snapshots that let a change be undone.
- Sessions: an opaque, hashed, expiring cookie. Device records hold a label and platform you provide.
What Ovelle does not do
- It does not sell your data, and it carries no advertising.
- It does not use your content to train models.
- It does not read your ChatGPT, Claude, or Codex history. Only exchanges made through Ovelle are stored.
- Site analytics are aggregate only and receive no account identifier, email, entry title or body, transcript, message, or agent credential.
Agents and permissions
Connecting an agent authorises it, and nothing else, to use the collections you choose. Read access is granted per collection and is off by default. Write access is separate and never implies read access. An agent cannot list, read, restore or delete your protected backups, cannot approve a release, and cannot reach another agent's messages. Every change an agent makes is recorded with its identity and the state it replaced, and you can revoke a connection at any time.
Processors
- Cloudflare hosts the application, its databases, and file storage, and provides the transcription model. Transcription runs through a gateway configured not to retain request logs.
- Resend delivers password-reset email, and receives only the recipient address and the message.
Ovelle is operated from Australia. Data is stored on Cloudflare infrastructure, which may process it outside Australia.
Keeping and deleting
Your content is kept until you delete it or close your account. Deleted entries are recoverable from history for a period, which is what makes an accidental deletion survivable. Recovery snapshots are retained for up to thirty days. Ask at the address below to close your account and have its content deleted.
Your rights
You may request a copy of your data, ask for corrections, or ask for deletion. Export is a normal part of the product rather than a paid feature: your knowledge should be able to leave. Under the Australian Privacy Act you may also complain to the Office of the Australian Information Commissioner.
Honest limits
Revoking an agent's access, or a recipient's access to something you shared, prevents further access. It cannot erase a copy that was already exported by someone who was authorised at the time. Ovelle states this rather than implying a recall it cannot perform.
Contact
Questions or requests: privacy@ovelle.me.