Legal

Privacy Policy

Local-first by design: your conversations and memory stay on your device.

Effective date: September 16, 2026 Version: 1.10

This Privacy Policy describes how Vodou Inc. ("Vodou," "we," "us") collects, uses, and shares information when you use our websites (vodou.ai, app.vodou.ai), create a Vodou account, use the Vodou software and hosted services, or use the Vodou Bridge browser extension (collectively, the "Service").

The short version: Vodou is local-first. Your conversations and memory stay on your own device by default. The optional Vodou Bridge browser extension can capture chats from supported AI websites, save a page or document you explicitly add (version 0.5.97.73 and later), and insert memories into your chats — all of that content stays on your machine and is sent only to Vodou running locally (localhost), not to Vodou’s cloud. Memory you insert is a separate matter: it goes to the AI you put it into, by design. What we hold centrally is your account, billing, and usage metering — and prompt content only transits our servers when you choose to use the managed LLM tier. Our websites use Google Analytics to measure visits: vodou.ai, and the signed-out pages of app.vodou.ai; it never runs while you are signed in. In the EEA, the UK and Switzerland it stays off unless you accept, and anywhere you can decline. It never receives your account details, conversations, or memory.


1. Information We Collect

1.1. Information you provide

1.2. Information collected automatically

1.3. Content — and where it lives

1.4. Browser extension (Vodou Bridge)

The Vodou Bridge browser extension is an optional companion to Vodou running on your computer. Your conversations and memory are handled locally; the only thing it retrieves from us is a small public settings file, described under “Where that content goes” below.

What the extension may access (on your device):

Where that content goes:

Your controls:

Text you select on any site. The extension adds a right-click item, Send selection to Vodou memory, which saves a passage you have highlighted. It is available on any website, not only on listed AI sites, because a passage worth keeping can be anywhere. It runs only when you choose it, saves only the text you selected, and saves it to Vodou on your own computer. Two further right-click items, Add this page to Vodou Library and Add linked file to Vodou Library, are also available on any site and hand the address of that page or link to your local Vodou install, which fetches and files the document.

Page memory (version 0.5.97.73 and later, off unless you turn it on). The extension can show you what you already know about the page you are looking at — notes you made while you were on that page, and notes from elsewhere on the same site. To do this, while the side panel is open, it reads the address and title of the tab you are viewing, including tabs that are not listed AI sites, and sends them to Vodou on your own computer to look up your own memories. It is off until you turn it on, and we ask you before it runs for the first time. We do not build or keep a record of the pages you visit: nothing is recorded for a page you merely open, no browsing history is collected, stored, or transmitted to us, and none of this reaches Vodou's servers. With the same setting on, the panel can also suggest memories related to what you are typing: when you pause while writing in a text box on the page, the text you have typed so far (up to 500 characters) is sent to Vodou on your own computer to look up related memories, and the suggestions appear in the panel. This never runs in password, payment or one-time-code fields, nothing you type is stored by the extension, and the text goes nowhere but your own machine. Fill this form from Vodou *(0.5.97.75 and later)* is a right-click menu item / keyboard shortcut you invoke on a page: the extension then reads the labels, names and types of that page's form fields — never password, payment or one-time-code fields, and never what is already typed in them — and sends only that list to Vodou on your own computer, which proposes answers from your own memory. The proposals appear in the side panel; you review and edit them, and only the ones you tick are written into the fields. The form is never submitted by the extension. If you leave "Remember my answers on this page" ticked, the answers you accepted are stored in your local memory, tagged with the page, so the same form is pre-filled next time; nothing is remembered from a page where page memory is off or suggest-only. Enable Vodou on this site *(0.5.97.75 and later)*: on a site that is not a listed AI chat site, the side panel can offer to run Vodou's page script there automatically. Nothing is enabled at install; you click, Chrome shows its own permission prompt for that one site, and only if you accept does the extension's packaged script run there from then on — the same suggestions-while-typing, form-fill button and memory shortcuts as on the listed sites, without a right-click first. It never widens beyond the sites you chose, and you can turn a site off in the panel or in Chrome's extension settings, which removes the permission. On an enabled site there is a further, separate switch, "Also save what I write on this site" (off by default): with it on, text you submit in a text box on that site is saved to your local memory with the page recorded — like a right-click clip, automatically; never password, payment or one-time-code fields, and never sent to us. Turning the page-memory setting off stops all of the above — the extension reads neither your tab nor your typing. The same is true of the two features that predate this setting — the document match shown in the panel, and the address the panel uses to file a page you add to your Library — which likewise read only the tab you are viewing and only while you are using the panel.

Assembling a full conversation. When capture is on, and when you have asked Vodou to also remember conversations from before you installed it, the extension may ask the AI site you are on for the conversation you are viewing — signed in as you, exactly as that page itself would — so that the thread it saves is complete rather than partial. This is a request to that site, not to Vodou, and the result is saved to your own machine.

Permissions (summary): The extension requests permissions such as access to listed AI site hosts, localhost, policy.vodou.ai (to download the settings file described above), storage, tabs/scripting (to read and insert on those sites), alarms (to keep a local connection alive and to schedule that settings check), cookies (for optional import on allowlisted AI hosts), contextMenus (the three right-click items described above), sidePanel (the panel that is the extension's entire interface — there is no popup), notifications (to tell you a task you started has finished when you have navigated away), and — from version 0.5.97.73 — activeTab, which is what lets Add to Vodou Library work on a page that is not a listed AI site. activeTab is granted by your browser only at the moment you perform that action, applies only to the tab you performed it on, and lapses afterwards; it is requested *instead of* broader website access, not in addition to it. A separate full/developer build of the bridge may request broader capabilities for advanced features; the Chrome Web Store edition is limited as described above.

1.5. Cookies and similar technologies

app.vodou.ai uses essential cookies/local storage for sign-in sessions and security, which do not depend on the choice below.

vodou.ai (our marketing website) and the signed-out pages of app.vodou.ai (our account site) use Google Analytics 4, provided by Google LLC, to understand how visitors use them. Google Analytics is not loaded on app.vodou.ai while you are signed in. When analytics is allowed it sets first-party analytics cookies (_ga and _ga_<ID>) that let Google Analytics distinguish visits. We use it for measurement only: Google Signals and advertising features are off, neither site is linked to Google Ads, and advertising cookies and signals are denied for every visitor.

Your choice. Each site asks with a small cookie notice and remembers your answer in your browser's local storage for that site, so vodou.ai and app.vodou.ai each ask once:

While analytics cookies are declined, the sites use Google's Consent Mode, under which Google may still receive limited, cookieless signals (for example, that a page was loaded) that are not tied to an analytics cookie, and advertising data is redacted.

Our websites do not use third-party advertising trackers. We do not respond differently to "Do Not Track" browser signals; use the cookie notice or Cookie settings to control analytics. The browser extension's use of site cookies is described in §1.4 and is limited to features you initiate on allowlisted AI hosts.

2. How We Use Information

We use the information above to: provide and operate the Service (including optional local browser capture and memory insert via Vodou Bridge); authenticate you and your devices (including, if you choose it, through Google or GitHub sign-in, which we link to an existing Vodou account only when the provider has verified that it is the same email address); meter usage and administer plans, quotas, and billing; secure the Service and prevent fraud and abuse; respond to support requests; analyze aggregate usage to improve the product; send service and account communications (and, with your consent or as permitted by law, product news you can opt out of); and comply with legal obligations.

Legal bases (EEA/UK users): performance of a contract (providing the Service), legitimate interests (security, abuse prevention, product improvement, and website analytics outside the EEA/UK), consent (where required, e.g., website analytics cookies in the EEA/UK, optional marketing, or optional browser capture features), and legal obligation (e.g., tax and accounting records).

3. How We Share Information

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only with:

Chat content handled by Vodou Bridge on your device is not shared with Vodou Inc. through the extension. Third-party AI websites you visit remain governed by those sites’ own terms and privacy policies.

Google and GitHub sign-in. When you choose to continue with Google or GitHub, you are sent to that provider to sign in. The provider handles that step under its own privacy policy and learns that you are signing in to Vodou. We do not send your Vodou data to them.

3.1. Limited Use of Google user data

Vodou's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Data Retention

We retain account information for as long as your account exists. Usage and billing records are retained as needed for billing integrity, dispute resolution, tax, and accounting requirements. Server and diagnostic logs are retained for limited periods. If you use Google or GitHub sign-in, the link between that account and your Vodou account (the provider, its account identifier and the email address it reported) is kept for as long as your Vodou account exists; the one-time records used to complete a sign-in expire within minutes, cannot be used after that, and are periodically deleted. Google Analytics data about website visits is retained for no longer than 14 months, then deleted by Google Analytics. When you delete your account, we delete or de-identify your personal information within a reasonable period, except records we must keep by law. Local data never leaves your device through us — deleting it is in your control. Local memory created via the browser extension is retained on your device until you delete it in Vodou or remove the data yourself.

5. Security

We use reasonable technical and organizational safeguards: encryption in transit (TLS), salted password hashing, tokenized payments, access controls, and least-privilege practices. The store edition of Vodou Bridge limits its standing host access to listed AI sites, localhost, and policy.vodou.ai (the public settings download described in §1.2 and §1.4), and does not execute remote script code supplied over the network. From version 0.5.97.73 the one way it reaches any other page is activeTab, described in §1.4: your browser grants it only when you choose Add to Vodou Library on the page you are looking at, for that tab and that action alone. Earlier versions have no such capability at all. No system is perfectly secure; please use a strong unique password and protect your devices and API keys. If we learn of a breach affecting your personal information, we will notify you as required by applicable law.

6. Your Rights

Depending on where you live, you may have rights to access, correct, delete, export, or restrict or object to the processing of your personal information, and to withdraw consent where processing is based on consent.

You can stop using Google or GitHub sign-in at any time: set a password with Forgot password and sign in with your email instead, and remove Vodou's access in your Google or GitHub account settings. To have the stored sign-in link deleted, email privacy@vodou.ai.

To exercise any right, email privacy@vodou.ai from your account email (or include information sufficient for us to verify your identity). We will respond within the time required by applicable law. Authorized agents may submit requests with proof of authorization. For local browser-captured memory, you can also delete or forget items in the Vodou product on your device.

7. International Transfers

We are based in the United States and process information there. If you use the Service from outside the U.S., you understand your information will be transferred to and processed in the U.S. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for transfers from the EEA/UK. Content that remains only on your device via local Vodou / Vodou Bridge is not transferred to Vodou Inc. by the extension.

8. Children

The Service is intended for adults and is not directed to children. We do not knowingly collect personal information from children under 13 (or the higher minimum age in your jurisdiction). If you believe a child has provided us personal information, contact us and we will delete it.

9. Changes to this Policy

We may update this Policy from time to time. We will post the updated version at https://app.vodou.ai/privacy.html with a new effective date, and we will provide additional notice of material changes (for example, by email or in-product notice). Changes apply prospectively.

Version history

10. Contact Us

Vodou Inc. Privacy requests and questions: privacy@vodou.ai