Vellichor — Privacy Policy

Last updated: 2026-06-09

Vellichor Privacy Policy

Effective date: TBD (date of v1.0 App Store launch) Last updated: 2026-06-09 (draft)

Introduction

Vellichor is a PDF utility app for Apple platforms (iPhone, iPad, Mac, Apple Watch) built on a single guarantee: your content is never sent to our servers or any cloud AI — we have none. Your documents may sync, at your option, only through your own encrypted iCloud (see §3). This Privacy Policy explains what data Vellichor handles, where it lives, and what we do — and do not do — with it.

If you do not agree with this policy, do not use Vellichor. Continued use indicates acceptance.


The short version


1. Data we do NOT collect

Vellichor does not collect, transmit, or store on our servers:

We don’t collect this because we don’t have servers. There is nowhere for it to go.


2. Data that stays on your device

These categories of data are stored exclusively on your Apple device:

2.1 Signatures

2.2 Forensic certification metadata

When you sign a PDF with Vellichor’s forensic certification enabled:

Important — what the metadata reveals when you share the PDF:

When you share the signed PDF, the recipient receives this metadata alongside whatever you’ve written in the document. If your name appears in the document itself, the metadata becomes associated with you in the recipient’s hands. Under GDPR Recital 26, this metadata is considered pseudonymous (not fully anonymous) — the device class + timestamp combined with document context could potentially be correlated with you.

You control this:

Important: Vellichor provides tamper-evident self-signing with biometric verification. We make NO eIDAS classification claim — Vellichor is NOT a Qualified Trust Service Provider (QTSP) and the signature is NOT a Qualified Electronic Signature (QES) under eIDAS. Some implementations of our forensic certification may meet criteria for an Advanced Electronic Signature (AES) under eIDAS Art. 26, but we make no certified AES claim. For legally binding signatures under EU law, UK law, US ESIGN Act, or equivalent regulations, use DocuSign, Adobe Sign, or similar certified providers.

2.3 Biometric authentication


3. Data that syncs via your iCloud

You control whether your documents sync across your Apple devices via iCloud. When sync is enabled:

3.1 What syncs

3.2 What does NOT sync

3.3 iCloud responsibility

3.4 Family Sharing

If you share Vellichor via Family Sharing:


4. AI Q&A and Apple Intelligence

Vellichor uses Apple Intelligence (Foundation Models framework) for on-device question answering, semantic search, and document summarization.

How Foundation Models works in Vellichor

Device requirements

On devices that don’t support Apple Intelligence, AI features are gracefully disabled with a clear message. We do not paywall or fake AI features on unsupported devices.


5. Forms and form-fill data

When you fill an interactive PDF form (AcroForm) using Vellichor:


6. Scanner and OCR

When you use Vellichor’s document scanner:

Camera, Photos, and microphone permissions are requested per Apple’s standard permission flow. You can revoke any time in iOS Settings.


7. Optional anonymous telemetry (v1.1+)

In a future version (v1.1+), Vellichor may offer optional anonymous usage telemetry powered by TelemetryDeck (a privacy-first analytics service).

If we enable this feature, it will be:

Until v1.1 ships with this opt-in feature documented here, Vellichor performs zero analytics.


8. Children and family use


9. App Store and payment processing


10. Data we may receive from Apple

Apple may share aggregated, anonymized App Store metrics with us (downloads, retention rates, etc.) via App Store Connect. This data:


11. Third-party services

Vellichor does NOT integrate with:

Your data goes nowhere except where you explicitly send it (e.g., the Share Sheet to email a PDF you control).


12. Your rights

For the full set of rights you have under GDPR (EU/EEA), the UK GDPR, Spain’s LOPDGDD, California’s CCPA/CPRA, other US states, and elsewhere — and the channels to exercise them — see KhassinX’s Privacy Rights Center. The rights are the same across every KhassinX app, so we maintain them in one place rather than duplicating them here.

In Vellichor specifically, you can exercise them directly — most without contacting anyone, because the data is already yours:

To make a formal request or lodge a question, email [email protected] — though we will likely respond “we don’t have it,” because we don’t.


13. Contact + EU representative

For privacy questions:

EU representative (GDPR Article 27)

KHASSINX LLC (a Florida limited liability company), the operator of Vellichor and a non-EU controller offering services to EU users, makes the following declaration:

Vellichor’s architecture is zero-collection on Vellichor’s side — no personal data is transmitted to KhassinX servers (because there are no KhassinX servers). The on-device hash + timestamp + biometric boolean + approximate device class processed during forensic certification is processed exclusively on the user’s Apple device, never reaches KhassinX systems, and falls outside the territorial scope clarifications of GDPR Art. 3(2) for “processing” by the controller.

However, to maximize defensibility and respect EU users’ rights:

Data Protection Officer / Brazilian Encarregado (LGPD)


14. Changes to this policy

We will update this policy when:

When we update, we’ll:


15. Standards alignment

Vellichor’s privacy practices align with:

This policy does NOT constitute legal advice. For jurisdiction-specific advice, consult a qualified attorney.


Vellichor is built by KhassinX. We respect your privacy because you trusted us with your documents. Thank you.