Privacy Policy
Local-first by design: your conversations and memory stay on your device.
Effective date: September 16, 2026 Version: 1.10
This Privacy Policy describes how Vodou Inc. ("Vodou," "we," "us") collects, uses, and shares information when you use our websites (vodou.ai, app.vodou.ai), create a Vodou account, use the Vodou software and hosted services, or use the Vodou Bridge browser extension (collectively, the "Service").
The short version: Vodou is local-first. Your conversations and memory stay on your own device by default. The optional Vodou Bridge browser extension can capture chats from supported AI websites, save a page or document you explicitly add (version 0.5.97.73 and later), and insert memories into your chats — all of that content stays on your machine and is sent only to Vodou running locally (localhost), not to Vodou’s cloud. Memory you insert is a separate matter: it goes to the AI you put it into, by design. What we hold centrally is your account, billing, and usage metering — and prompt content only transits our servers when you choose to use the managed LLM tier. Our websites use Google Analytics to measure visits: vodou.ai, and the signed-out pages of app.vodou.ai; it never runs while you are signed in. In the EEA, the UK and Switzerland it stays off unless you accept, and anywhere you can decline. It never receives your account details, conversations, or memory.
1. Information We Collect
1.1. Information you provide
- Account information — name, email address, and password (stored as a salted hash; we never store plaintext passwords).
- Sign-in with Google or GitHub (optional) — if you choose Continue with Google or Continue with GitHub, that provider tells us your name, your email address, whether the provider has verified that email address, and an identifier for your account with them (for GitHub, also your username). We use these only to create your Vodou account or sign you in to it. We request no other access (from Google, basic profile and email; from GitHub, read-only profile and email addresses), we never receive your Google or GitHub password, and we do not read or post anything else in those accounts. An account created this way has no Vodou password until you set one with Forgot password.
- Billing information — handled by our payment processor (Stripe). We receive subscription status, plan, and limited payment metadata (such as card brand and last four digits); we never receive or store full card numbers.
- Communications — emails and support requests you send us.
1.2. Information collected automatically
- Usage metering — to operate plans, quotas, and billing we record usage events: token counts, model identifiers, request timestamps, feature usage, and plan/quota state. This includes counting usage made with your own API keys (BYOK); for BYOK we meter counts and metadata, not the content of your requests.
- Service logs — standard server logs (IP address, user-agent, request timing) and diagnostic/error logs, used for security, abuse prevention, and debugging.
- Authentication tokens — issued when you connect the software to your account.
- Website analytics (vodou.ai and app.vodou.ai) — when analytics is allowed (see §1.5), Google Analytics records how our websites are used: pages viewed, time on page, referring site or campaign, approximate location (country and city, derived from your IP address), and device, browser, and screen information. On app.vodou.ai, our account site, it runs only on pages viewed while signed out (such as sign-in, registration, password reset, and these legal pages) and never while you are signed in, so it is not present on your dashboard, billing, or account pages. There, page addresses are recorded without their query strings (so one-time links such as password-reset and email-verification tokens are never sent), and we do not send your account ID, email address, or any account, billing, usage, or content data. Google Analytics is not used in the Vodou software or the browser extension.
1.3. Content — and where it lives
- Local by default. Conversation history, memory databases, embeddings, schedules, and files created by the locally running Vodou software are stored on your device. We cannot access them.
- Managed LLM tier. If you use the managed tier, your prompts and the model responses transit our LLM proxy to the underlying model providers (for example Anthropic, OpenAI, or Fireworks). We process this content to route the request, enforce quotas, and prevent abuse. We do not sell it and do not use it to train foundation models. Transient operational logs, where kept for debugging or abuse prevention, are retained only for a limited period.
- BYOK. If you use your own API keys, request content flows from your device to your provider under your agreement with that provider.
- Third-party connections. When you connect third-party services (email, messaging, calendars, and other integrations), the software accesses them from your device using credentials you supply; that data is governed by your agreement with each provider.
1.4. Browser extension (Vodou Bridge)
The Vodou Bridge browser extension is an optional companion to Vodou running on your computer. Your conversations and memory are handled locally; the only thing it retrieves from us is a small public settings file, described under “Where that content goes” below.
What the extension may access (on your device):
- Supported AI chat websites you visit (for example ChatGPT, Claude, Gemini, and other sites listed in the extension). With your permission and settings, it may read conversation content on those pages so Vodou can save turns into local memory, and it may insert memory text you choose into the page’s composer.
- A page you explicitly add *(Vodou Bridge 0.5.97.73 and later)*. When you choose Add to Vodou Library — from the right-click menu or its keyboard shortcut — the extension reads that one page so Vodou can save it into your local library. This works on any page you are looking at, including ones that are not AI chat sites: a document, an article, a PDF your browser is displaying. It happens only on that action, only for the page you acted on, and the browser grants the access only because you performed the action. The extension does not read pages you have not added this way.
- The address and title of the tab you are on, while the side panel is open *(Vodou Bridge 0.5.97.73 and later)*. So the panel can tell you when you already have a document saved that relates to what you are reading, it compares the current tab's address and title against your own local library. It reads no page content to do this, and the comparison happens on your computer — the address and title go only to Vodou running locally, never to us. Close the panel and it stops.
- Browser storage on your device for preferences (for example gateway URL, enable/disable, pairing code, capture/inject settings).
- Cookies for listed AI sites only, when you use import features that replay your existing logged-in session on those sites (for example importing a ChatGPT conversation). The store edition of the extension does not use cookies to access arbitrary websites.
Where that content goes:
- Captured chat text and related memory stay in Vodou on your device. Your content travels over a localhost / 127.0.0.1 connection only — your machine.
- Vodou Inc. does not receive the content of pages or chats through the extension. The extension does not upload browsing history or chat content to Vodou’s cloud servers.
- One settings download. So that we can stop capture on a particular AI site quickly if that site asks us to, the extension downloads a small public settings file from
policy.vodou.aiwhen your browser starts and about twice a day. It lists which sites capture is currently permitted on. This request is a download only: it sends no cookies, no identifiers, and nothing about you, your device, or your conversations, and we do not log who requests it. If the download fails for any reason, the extension simply keeps using its last known settings. - Memory you insert goes to the AI you insert it into. That is what the feature is for. Text placed in a site’s message box and sent is received by that provider and handled under *their* terms and privacy policy, not ours. This is true whether you inserted it with the shortcut, picked it in the panel, or had auto-attach add it while sending. Vodou does not receive it; the AI provider does.
- If you later use the managed LLM tier inside Vodou, prompts you send through that tier are governed by §1.3 (Managed LLM tier) — that is separate from the extension’s localhost bridge.
Your controls:
- Capture is off unless you arm it. Arming turns it on for all of the supported AI sites at once; you can then untick individual sites in the extension’s side panel, under Settings, so capture never runs on those. You can turn capture off entirely in that same Settings tab or in Vodou’s Sources settings.
- Memory insert is separate from capture, and off unless you turn it on. By default nothing is added to a page unless you press the keyboard shortcut or use the memory picker in that moment. It has its own on/off switch and its own per-site ticks, independent of capture.
- Auto-attach is off by default, and it acts for you. There is an optional setting, off unless you switch it on and tick the sites you want it on: when it is on, pressing send pauses, appends relevant memory to the bottom of your message, and Vodou sends that message for you. With it on, memory reaches the AI provider as part of sending rather than as a step you confirm each time. With it off — the default — nothing is ever sent on your behalf.
- You can disconnect or disable the extension, clear local Vodou memory using in-product tools, or uninstall the extension at any time.
- Pairing with your local Vodou install may be required so only your machine’s Vodou instance can use the bridge.
Text you select on any site. The extension adds a right-click item, Send selection to Vodou memory, which saves a passage you have highlighted. It is available on any website, not only on listed AI sites, because a passage worth keeping can be anywhere. It runs only when you choose it, saves only the text you selected, and saves it to Vodou on your own computer. Two further right-click items, Add this page to Vodou Library and Add linked file to Vodou Library, are also available on any site and hand the address of that page or link to your local Vodou install, which fetches and files the document.
Page memory (version 0.5.97.73 and later, off unless you turn it on). The extension can show you what you already know about the page you are looking at — notes you made while you were on that page, and notes from elsewhere on the same site. To do this, while the side panel is open, it reads the address and title of the tab you are viewing, including tabs that are not listed AI sites, and sends them to Vodou on your own computer to look up your own memories. It is off until you turn it on, and we ask you before it runs for the first time. We do not build or keep a record of the pages you visit: nothing is recorded for a page you merely open, no browsing history is collected, stored, or transmitted to us, and none of this reaches Vodou's servers. With the same setting on, the panel can also suggest memories related to what you are typing: when you pause while writing in a text box on the page, the text you have typed so far (up to 500 characters) is sent to Vodou on your own computer to look up related memories, and the suggestions appear in the panel. This never runs in password, payment or one-time-code fields, nothing you type is stored by the extension, and the text goes nowhere but your own machine. Fill this form from Vodou *(0.5.97.75 and later)* is a right-click menu item / keyboard shortcut you invoke on a page: the extension then reads the labels, names and types of that page's form fields — never password, payment or one-time-code fields, and never what is already typed in them — and sends only that list to Vodou on your own computer, which proposes answers from your own memory. The proposals appear in the side panel; you review and edit them, and only the ones you tick are written into the fields. The form is never submitted by the extension. If you leave "Remember my answers on this page" ticked, the answers you accepted are stored in your local memory, tagged with the page, so the same form is pre-filled next time; nothing is remembered from a page where page memory is off or suggest-only. Enable Vodou on this site *(0.5.97.75 and later)*: on a site that is not a listed AI chat site, the side panel can offer to run Vodou's page script there automatically. Nothing is enabled at install; you click, Chrome shows its own permission prompt for that one site, and only if you accept does the extension's packaged script run there from then on — the same suggestions-while-typing, form-fill button and memory shortcuts as on the listed sites, without a right-click first. It never widens beyond the sites you chose, and you can turn a site off in the panel or in Chrome's extension settings, which removes the permission. On an enabled site there is a further, separate switch, "Also save what I write on this site" (off by default): with it on, text you submit in a text box on that site is saved to your local memory with the page recorded — like a right-click clip, automatically; never password, payment or one-time-code fields, and never sent to us. Turning the page-memory setting off stops all of the above — the extension reads neither your tab nor your typing. The same is true of the two features that predate this setting — the document match shown in the panel, and the address the panel uses to file a page you add to your Library — which likewise read only the tab you are viewing and only while you are using the panel.
Assembling a full conversation. When capture is on, and when you have asked Vodou to also remember conversations from before you installed it, the extension may ask the AI site you are on for the conversation you are viewing — signed in as you, exactly as that page itself would — so that the thread it saves is complete rather than partial. This is a request to that site, not to Vodou, and the result is saved to your own machine.
Permissions (summary): The extension requests permissions such as access to listed AI site hosts, localhost, policy.vodou.ai (to download the settings file described above), storage, tabs/scripting (to read and insert on those sites), alarms (to keep a local connection alive and to schedule that settings check), cookies (for optional import on allowlisted AI hosts), contextMenus (the three right-click items described above), sidePanel (the panel that is the extension's entire interface — there is no popup), notifications (to tell you a task you started has finished when you have navigated away), and — from version 0.5.97.73 — activeTab, which is what lets Add to Vodou Library work on a page that is not a listed AI site. activeTab is granted by your browser only at the moment you perform that action, applies only to the tab you performed it on, and lapses afterwards; it is requested *instead of* broader website access, not in addition to it. A separate full/developer build of the bridge may request broader capabilities for advanced features; the Chrome Web Store edition is limited as described above.
1.5. Cookies and similar technologies
app.vodou.ai uses essential cookies/local storage for sign-in sessions and security, which do not depend on the choice below.
vodou.ai (our marketing website) and the signed-out pages of app.vodou.ai (our account site) use Google Analytics 4, provided by Google LLC, to understand how visitors use them. Google Analytics is not loaded on app.vodou.ai while you are signed in. When analytics is allowed it sets first-party analytics cookies (_ga and _ga_<ID>) that let Google Analytics distinguish visits. We use it for measurement only: Google Signals and advertising features are off, neither site is linked to Google Ads, and advertising cookies and signals are denied for every visitor.
Your choice. Each site asks with a small cookie notice and remembers your answer in your browser's local storage for that site, so vodou.ai and app.vodou.ai each ask once:
- EEA, United Kingdom, and Switzerland: analytics cookies are off by default and are set only if you click Accept.
- Everywhere else: analytics is on by default, and you can click Decline.
- You can change your answer at any time with Cookie settings in the site footer. Declining stops analytics cookies from being set and deletes the Google Analytics cookies already stored for that site.
- You can also use Google's Analytics opt-out browser add-on, which applies on every site that uses Google Analytics.
While analytics cookies are declined, the sites use Google's Consent Mode, under which Google may still receive limited, cookieless signals (for example, that a page was loaded) that are not tied to an analytics cookie, and advertising data is redacted.
Our websites do not use third-party advertising trackers. We do not respond differently to "Do Not Track" browser signals; use the cookie notice or Cookie settings to control analytics. The browser extension's use of site cookies is described in §1.4 and is limited to features you initiate on allowlisted AI hosts.
2. How We Use Information
We use the information above to: provide and operate the Service (including optional local browser capture and memory insert via Vodou Bridge); authenticate you and your devices (including, if you choose it, through Google or GitHub sign-in, which we link to an existing Vodou account only when the provider has verified that it is the same email address); meter usage and administer plans, quotas, and billing; secure the Service and prevent fraud and abuse; respond to support requests; analyze aggregate usage to improve the product; send service and account communications (and, with your consent or as permitted by law, product news you can opt out of); and comply with legal obligations.
Legal bases (EEA/UK users): performance of a contract (providing the Service), legitimate interests (security, abuse prevention, product improvement, and website analytics outside the EEA/UK), consent (where required, e.g., website analytics cookies in the EEA/UK, optional marketing, or optional browser capture features), and legal obligation (e.g., tax and accounting records).
3. How We Share Information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only with:
- Service providers / processors acting on our instructions — payment processing (Stripe), cloud hosting and infrastructure, email delivery, and website analytics for vodou.ai and app.vodou.ai (Google Analytics, see §1.5) — bound by contractual confidentiality and data-protection obligations.
- Model providers — solely to fulfill managed-tier requests you initiate (your prompt content is sent to the provider needed to generate the response).
- Legal and safety — when required by law, subpoena, or legal process, or where reasonably necessary to protect the rights, safety, or property of Vodou, our users, or the public.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, in which case this Policy continues to apply to the transferred information until amended.
Chat content handled by Vodou Bridge on your device is not shared with Vodou Inc. through the extension. Third-party AI websites you visit remain governed by those sites’ own terms and privacy policies.
Google and GitHub sign-in. When you choose to continue with Google or GitHub, you are sent to that provider to sign in. The provider handles that step under its own privacy policy and learns that you are signing in to Vodou. We do not send your Vodou data to them.
3.1. Limited Use of Google user data
Vodou's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Data Retention
We retain account information for as long as your account exists. Usage and billing records are retained as needed for billing integrity, dispute resolution, tax, and accounting requirements. Server and diagnostic logs are retained for limited periods. If you use Google or GitHub sign-in, the link between that account and your Vodou account (the provider, its account identifier and the email address it reported) is kept for as long as your Vodou account exists; the one-time records used to complete a sign-in expire within minutes, cannot be used after that, and are periodically deleted. Google Analytics data about website visits is retained for no longer than 14 months, then deleted by Google Analytics. When you delete your account, we delete or de-identify your personal information within a reasonable period, except records we must keep by law. Local data never leaves your device through us — deleting it is in your control. Local memory created via the browser extension is retained on your device until you delete it in Vodou or remove the data yourself.
5. Security
We use reasonable technical and organizational safeguards: encryption in transit (TLS), salted password hashing, tokenized payments, access controls, and least-privilege practices. The store edition of Vodou Bridge limits its standing host access to listed AI sites, localhost, and policy.vodou.ai (the public settings download described in §1.2 and §1.4), and does not execute remote script code supplied over the network. From version 0.5.97.73 the one way it reaches any other page is activeTab, described in §1.4: your browser grants it only when you choose Add to Vodou Library on the page you are looking at, for that tab and that action alone. Earlier versions have no such capability at all. No system is perfectly secure; please use a strong unique password and protect your devices and API keys. If we learn of a breach affecting your personal information, we will notify you as required by applicable law.
6. Your Rights
Depending on where you live, you may have rights to access, correct, delete, export, or restrict or object to the processing of your personal information, and to withdraw consent where processing is based on consent.
You can stop using Google or GitHub sign-in at any time: set a password with Forgot password and sign in with your email instead, and remove Vodou's access in your Google or GitHub account settings. To have the stored sign-in link deleted, email privacy@vodou.ai.
- EEA/UK (GDPR): all of the above, plus the right to lodge a complaint with your supervisory authority.
- California (CCPA/CPRA): the rights to know, delete, and correct; the right to opt out of "sale" or "sharing" (we do neither); and the right to non-discrimination for exercising your rights.
To exercise any right, email privacy@vodou.ai from your account email (or include information sufficient for us to verify your identity). We will respond within the time required by applicable law. Authorized agents may submit requests with proof of authorization. For local browser-captured memory, you can also delete or forget items in the Vodou product on your device.
7. International Transfers
We are based in the United States and process information there. If you use the Service from outside the U.S., you understand your information will be transferred to and processed in the U.S. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for transfers from the EEA/UK. Content that remains only on your device via local Vodou / Vodou Bridge is not transferred to Vodou Inc. by the extension.
8. Children
The Service is intended for adults and is not directed to children. We do not knowingly collect personal information from children under 13 (or the higher minimum age in your jurisdiction). If you believe a child has provided us personal information, contact us and we will delete it.
9. Changes to this Policy
We may update this Policy from time to time. We will post the updated version at https://app.vodou.ai/privacy.html with a new effective date, and we will provide additional notice of material changes (for example, by email or in-product notice). Changes apply prospectively.
Version history
- 1.10 — September 16, 2026. Added optional sign-in with Google or GitHub. §1.1 lists what those providers send us (name, email address, whether it is verified, an account identifier, and for GitHub a username), and states that we request no other access and never receive their passwords. §2 adds that sign-in and linking it to an existing account with the same verified email address. §3 notes that the provider handles the sign-in step under its own policy. §4 states how long the sign-in link and the one-time sign-in records are kept, and §6 explains how to stop using it. Nothing else changed.
- 1.9 — September 16, 2026. Extended website analytics to the signed-out pages of app.vodou.ai, our account site; it does not run while you are signed in. Version 1.8 said Google Analytics was used only on vodou.ai. §1.2 now covers both sites and states what is excluded on app.vodou.ai: page addresses are sent without query strings, so password-reset and email-verification links never reach Google Analytics, and no account ID, email address, or account, billing, usage, or content data is sent. §1.5 applies the same consent choices to both sites, each asked separately, with Cookie settings in each site's footer, and §3 names both sites. Also fixed how this version history is displayed: entries that spanned several lines had been shown as broken, out-of-place paragraphs, and entries were not in order. The wording of earlier entries is unchanged.
- 1.8 — September 16, 2026. Disclosed Google Analytics on vodou.ai, our marketing website. Version 1.7 said our websites use only essential cookies and storage; that became untrue when vodou.ai added analytics. §1.2 lists what website analytics records; §1.5 describes the analytics cookies, that Google Signals and advertising features are off, and how consent works: off by default in the EEA, UK, and Switzerland until you accept, on by default elsewhere with a Decline option, changeable at any time with Cookie settings in the website footer, plus Google's opt-out add-on. §2 adds the legal bases for analytics, §3 names Google Analytics as a service provider, and §4 states its retention. Nothing changed about app.vodou.ai, the Vodou software, the browser extension, or how your conversations and memory are handled.
- 1.7 — August 17, 2026. Disclosed page memory, a new optional feature (and, under the same setting, typing suggestions, Fill this form from Vodou, and per-site Enable Vodou on this site — Chrome's own per-site prompt, nothing at install, revocable — with its separate off-by-default "Also save what I write on this site" — an on-request read of a page's form field labels/names/types, never password/payment/one-time-code fields, never existing values; proposals reviewed in the panel; never submitted — what you have typed so far in a page's text box, sent only to Vodou on your machine, never in password/payment/one-time-code fields): with it on, the extension reads the address and title of the tab you are viewing — including tabs that are not listed AI sites — while the side panel is open, and sends them to Vodou on your own computer to look up your own notes about that page. It is off until you turn it on and you are asked before it runs. No browsing history is collected, stored, or sent to us, and nothing is recorded for a page you merely visit.
This version also corrects three descriptions that had fallen behind the software, none of which changes what is collected. The permissions summary in §1.4 now namescontextMenus,sidePanelandnotifications, which were in use but unlisted. §1.4 now states that the right-click items — saving selected text, and adding a page or link to your Library — work on any site rather than only on listed AI sites; that has been true since they shipped and the policy implied otherwise. §5 now namespolicy.vodou.aiin the extension's standing host access, which §1.2 and §1.4 had disclosed since version 1.2 while §5 omitted it. Finally, §1.4 now describes the request the extension makes to an AI site to assemble a complete conversation when you have asked it to remember older chats; product copy had described that feature as making no additional requests, which was true when written and became wrong when the conversation-snapshot path was added. - 1.6 — August 11, 2026. Added the Vodou Library: you can now save a page or document you are looking at — a document, an article, a PDF — into your local Vodou memory, using the right-click menu or a keyboard shortcut. Version 1.5 described the extension as reading "supported AI chat websites you visit", which was accurate when written and became incomplete the moment the library shipped, because that list is no longer the boundary of what the extension can read. What has NOT changed is who sees it: a page you add is read once, on your action, and goes only to Vodou running on your own computer. Also disclosed the panel's document matching, which compares the address and title of the tab you are on against your own local library while the panel is open, so it can point at something you already saved; it reads no page content and sends nothing to us. Two other statements needed correcting for the same reason: the summary at the top described the extension only as capturing chats, and §7 said the store edition "limits host access to listed AI sites and localhost" — both were true of 1.5 and neither survived the library. §1.4's permissions summary now also names
activeTab, which is the permission that makes the feature possible and is granted by your browser only at the moment you use it. The new capabilities are marked *0.5.97.73 and later* on purpose: version 0.5.97.71 is in review as this is written and has none of them, so an unscoped disclosure would describe a feature that a reader's own extension does not have. This policy is intended to be accurate for whichever build you are running. - 1.5 — August 2, 2026. Added the optional auto-attach on send setting and corrected a statement it makes untrue. Version 1.3 said memory insert was "never automatic"; that was accurate when written and stops being accurate for anyone who switches auto-attach on, because with it on Vodou appends memory to the message and sends it. The setting is off by default and has its own per-site ticks. Also stated plainly something the policy had only implied: memory you insert is received by the AI provider you insert it into and handled under their terms — that has always been true of the insert feature, not just of auto-attach. No change to capture, and none to where captured content is stored.
- 1.4 — July 30, 2026. Corrected where the capture controls are found. Version 1.3 said the per-site ticks and the capture off switch were in "the extension popup"; the extension no longer has a popup, and those controls are in its side panel, under Settings. Nothing about what is collected, how it is used, or where it goes has changed — this corrects a description of the interface so that what the policy tells you to click matches what you see.
- 1.3 — July 29, 2026. Clarified the capture controls. "Off unless you arm it" was correct but read as though sites were armed one at a time; arming has always applied to all supported AI sites at once. The extension now also has per-site capture switches, so the policy describes both levels rather than only the master switch. Added a line separating memory *insert* from capture — insert is never automatic and has its own controls. No behaviour changed for capture; this corrects an understatement of the controls available.
- 1.2 — July 29, 2026. Disclosed the browser extension's one outbound request: a twice-daily download of a public settings file from
policy.vodou.ailisting which AI sites capture is permitted on, so capture can be stopped on a site quickly at that site's request. The request sends nothing about you and is not logged. Version 1.1 described the extension as communicating over localhost only, which was accurate when written and became incomplete when this capability was added. No change to how your conversations or memory are handled: those remain local to your device. - 1.1 — July 22, 2026. Prior version.
10. Contact Us
Vodou Inc. Privacy requests and questions: privacy@vodou.ai