Privacy Policy
Local-first by design: your conversations and memory stay on your device.
Effective date: August 2, 2026 Version: 1.5
This Privacy Policy describes how Vodou Inc. ("Vodou," "we," "us") collects, uses, and shares information when you use our websites (vodou.ai, app.vodou.ai), create a Vodou account, use the Vodou software and hosted services, or use the Vodou Bridge browser extension (collectively, the "Service").
The short version: Vodou is local-first. Your conversations and memory stay on your own device by default. The optional Vodou Bridge browser extension can capture chats from supported AI websites and insert memories into them — captured content stays on your machine and is sent only to Vodou running locally (localhost), not to Vodou’s cloud. Memory you insert is a separate matter: it goes to the AI you put it into, by design. What we hold centrally is your account, billing, and usage metering — and prompt content only transits our servers when you choose to use the managed LLM tier.
1. Information We Collect
1.1. Information you provide
- Account information — name, email address, and password (stored as a salted hash; we never store plaintext passwords).
- Billing information — handled by our payment processor (Stripe). We receive subscription status, plan, and limited payment metadata (such as card brand and last four digits); we never receive or store full card numbers.
- Communications — emails and support requests you send us.
1.2. Information collected automatically
- Usage metering — to operate plans, quotas, and billing we record usage events: token counts, model identifiers, request timestamps, feature usage, and plan/quota state. This includes counting usage made with your own API keys (BYOK); for BYOK we meter counts and metadata, not the content of your requests.
- Service logs — standard server logs (IP address, user-agent, request timing) and diagnostic/error logs, used for security, abuse prevention, and debugging.
- Authentication tokens — issued when you connect the software to your account.
1.3. Content — and where it lives
- Local by default. Conversation history, memory databases, embeddings, schedules, and files created by the locally running Vodou software are stored on your device. We cannot access them.
- Managed LLM tier. If you use the managed tier, your prompts and the model responses transit our LLM proxy to the underlying model providers (for example Anthropic, OpenAI, or Fireworks). We process this content to route the request, enforce quotas, and prevent abuse. We do not sell it and do not use it to train foundation models. Transient operational logs, where kept for debugging or abuse prevention, are retained only for a limited period.
- BYOK. If you use your own API keys, request content flows from your device to your provider under your agreement with that provider.
- Third-party connections. When you connect third-party services (email, messaging, calendars, and other integrations), the software accesses them from your device using credentials you supply; that data is governed by your agreement with each provider.
1.4. Browser extension (Vodou Bridge)
The Vodou Bridge browser extension is an optional companion to Vodou running on your computer. Your conversations and memory are handled locally; the only thing it retrieves from us is a small public settings file, described under “Where that content goes” below.
What the extension may access (on your device):
- Supported AI chat websites you visit (for example ChatGPT, Claude, Gemini, and other sites listed in the extension). With your permission and settings, it may read conversation content on those pages so Vodou can save turns into local memory, and it may insert memory text you choose into the page’s composer.
- Browser storage on your device for preferences (for example gateway URL, enable/disable, pairing code, capture/inject settings).
- Cookies for listed AI sites only, when you use import features that replay your existing logged-in session on those sites (for example importing a ChatGPT conversation). The store edition of the extension does not use cookies to access arbitrary websites.
Where that content goes:
- Captured chat text and related memory stay in Vodou on your device. Your content travels over a localhost / 127.0.0.1 connection only — your machine.
- Vodou Inc. does not receive the content of pages or chats through the extension. The extension does not upload browsing history or chat content to Vodou’s cloud servers.
- One settings download. So that we can stop capture on a particular AI site quickly if that site asks us to, the extension downloads a small public settings file from
policy.vodou.aiwhen your browser starts and about twice a day. It lists which sites capture is currently permitted on. This request is a download only: it sends no cookies, no identifiers, and nothing about you, your device, or your conversations, and we do not log who requests it. If the download fails for any reason, the extension simply keeps using its last known settings. - Memory you insert goes to the AI you insert it into. That is what the feature is for. Text placed in a site’s message box and sent is received by that provider and handled under their terms and privacy policy, not ours. This is true whether you inserted it with the shortcut, picked it in the panel, or had auto-attach add it while sending. Vodou does not receive it; the AI provider does.
- If you later use the managed LLM tier inside Vodou, prompts you send through that tier are governed by §1.3 (Managed LLM tier) — that is separate from the extension’s localhost bridge.
Your controls:
- Capture is off unless you arm it. Arming turns it on for all of the supported AI sites at once; you can then untick individual sites in the extension’s side panel, under Settings, so capture never runs on those. You can turn capture off entirely in that same Settings tab or in Vodou’s Sources settings.
- Memory insert is separate from capture, and off unless you turn it on. By default nothing is added to a page unless you press the keyboard shortcut or use the memory picker in that moment. It has its own on/off switch and its own per-site ticks, independent of capture.
- Auto-attach is off by default, and it acts for you. There is an optional setting, off unless you switch it on and tick the sites you want it on: when it is on, pressing send pauses, appends relevant memory to the bottom of your message, and Vodou sends that message for you. With it on, memory reaches the AI provider as part of sending rather than as a step you confirm each time. With it off — the default — nothing is ever sent on your behalf.
- You can disconnect or disable the extension, clear local Vodou memory using in-product tools, or uninstall the extension at any time.
- Pairing with your local Vodou install may be required so only your machine’s Vodou instance can use the bridge.
Permissions (summary): The extension requests permissions such as access to listed AI site hosts, localhost, policy.vodou.ai (to download the settings file described above), storage, tabs/scripting (to read and insert on those sites), alarms (to keep a local connection alive and to schedule that settings check), and cookies (for optional import on allowlisted AI hosts). A separate full/developer build of the bridge may request broader capabilities for advanced features; the Chrome Web Store edition is limited as described above.
1.5. Cookies and similar technologies
app.vodou.ai uses essential cookies/local storage for sign-in sessions and security. Our websites do not use third-party advertising trackers. Because we use only essential storage, we do not respond differently to "Do Not Track" signals. The browser extension’s use of site cookies is described in §1.4 and is limited to features you initiate on allowlisted AI hosts.
2. How We Use Information
We use the information above to: provide and operate the Service (including optional local browser capture and memory insert via Vodou Bridge); authenticate you and your devices; meter usage and administer plans, quotas, and billing; secure the Service and prevent fraud and abuse; respond to support requests; analyze aggregate usage to improve the product; send service and account communications (and, with your consent or as permitted by law, product news you can opt out of); and comply with legal obligations.
Legal bases (EEA/UK users): performance of a contract (providing the Service), legitimate interests (security, abuse prevention, product improvement), consent (where required, e.g., optional marketing or optional browser capture features), and legal obligation (e.g., tax and accounting records).
3. How We Share Information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only with:
- Service providers / processors acting on our instructions — payment processing (Stripe), cloud hosting and infrastructure, email delivery — bound by contractual confidentiality and data-protection obligations.
- Model providers — solely to fulfill managed-tier requests you initiate (your prompt content is sent to the provider needed to generate the response).
- Legal and safety — when required by law, subpoena, or legal process, or where reasonably necessary to protect the rights, safety, or property of Vodou, our users, or the public.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, in which case this Policy continues to apply to the transferred information until amended.
Chat content handled by Vodou Bridge on your device is not shared with Vodou Inc. through the extension. Third-party AI websites you visit remain governed by those sites’ own terms and privacy policies.
4. Data Retention
We retain account information for as long as your account exists. Usage and billing records are retained as needed for billing integrity, dispute resolution, tax, and accounting requirements. Server and diagnostic logs are retained for limited periods. When you delete your account, we delete or de-identify your personal information within a reasonable period, except records we must keep by law. Local data never leaves your device through us — deleting it is in your control. Local memory created via the browser extension is retained on your device until you delete it in Vodou or remove the data yourself.
5. Security
We use reasonable technical and organizational safeguards: encryption in transit (TLS), salted password hashing, tokenized payments, access controls, and least-privilege practices. The store edition of Vodou Bridge limits host access to listed AI sites and localhost and does not execute remote script code supplied over the network. No system is perfectly secure; please use a strong unique password and protect your devices and API keys. If we learn of a breach affecting your personal information, we will notify you as required by applicable law.
6. Your Rights
Depending on where you live, you may have rights to access, correct, delete, export, or restrict or object to the processing of your personal information, and to withdraw consent where processing is based on consent.
- EEA/UK (GDPR): all of the above, plus the right to lodge a complaint with your supervisory authority.
- California (CCPA/CPRA): the rights to know, delete, and correct; the right to opt out of "sale" or "sharing" (we do neither); and the right to non-discrimination for exercising your rights.
To exercise any right, email privacy@vodou.ai from your account email (or include information sufficient for us to verify your identity). We will respond within the time required by applicable law. Authorized agents may submit requests with proof of authorization. For local browser-captured memory, you can also delete or forget items in the Vodou product on your device.
7. International Transfers
We are based in the United States and process information there. If you use the Service from outside the U.S., you understand your information will be transferred to and processed in the U.S. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for transfers from the EEA/UK. Content that remains only on your device via local Vodou / Vodou Bridge is not transferred to Vodou Inc. by the extension.
8. Children
The Service is intended for adults and is not directed to children. We do not knowingly collect personal information from children under 13 (or the higher minimum age in your jurisdiction). If you believe a child has provided us personal information, contact us and we will delete it.
9. Changes to this Policy
We may update this Policy from time to time. We will post the updated version at https://app.vodou.ai/privacy.html with a new effective date, and we will provide additional notice of material changes (for example, by email or in-product notice). Changes apply prospectively.
Version history
- 1.5 — August 2, 2026. Added the optional auto-attach on send setting and corrected a statement it makes untrue. Version 1.3 said memory insert was “never automatic”; that was accurate when written and stops being accurate for anyone who switches auto-attach on, because with it on Vodou appends memory to the message and sends it. The setting is off by default and has its own per-site ticks. Also stated plainly something the policy had only implied: memory you insert is received by the AI provider you insert it into and handled under their terms — that has always been true of the insert feature, not just of auto-attach. No change to capture, and none to where captured content is stored.
- 1.4 — July 30, 2026. Corrected where the capture controls are found. Version 1.3 said the per-site ticks and the capture off switch were in "the extension popup"; the extension no longer has a popup, and those controls are in its side panel, under Settings. Nothing about what is collected, how it is used, or where it goes has changed — this corrects a description of the interface so that what the policy tells you to click matches what you see.
- 1.3 — July 29, 2026. Clarified the capture controls. "Off unless you arm it" was correct but read as though sites were armed one at a time; arming has always applied to all supported AI sites at once. The extension now also has per-site capture switches, so the policy describes both levels rather than only the master switch. Added a line separating memory *insert* from capture — insert is never automatic and has its own controls. No behaviour changed for capture; this corrects an understatement of the controls available.
- 1.2 — July 29, 2026. Disclosed the browser extension's one outbound request: a twice-daily download of a public settings file from
policy.vodou.ailisting which AI sites capture is permitted on, so capture can be stopped on a site quickly at that site's request. The request sends nothing about you and is not logged. Version 1.1 described the extension as communicating over localhost only, which was accurate when written and became incomplete when this capability was added. No change to how your conversations or memory are handled: those remain local to your device. - 1.1 — July 22, 2026. Prior version.
10. Contact Us
Vodou Inc. Privacy requests and questions: privacy@vodou.ai