RESUMEN EJECUTIVO
Velis Software does not collect, process, sell, transmit, or monetize your personal information or media playback habits. Our revenue is derived exclusively from upfront software license purchases on the Apple App Store. There are no advertising identifiers, tracking pings, or telemetry daemons inside Velis.
Zero-Telemetry & Zero-Knowledge Architecture
Velis does not embed any third-party analytics frameworks, crash log aggregators, performance monitoring daemons, or user tracking libraries (e.g., zero Firebase Analytics, zero Mixpanel, zero Google Analytics, zero Sentry, zero adjust, and zero advertising SDKs).
- No Telemetry Pings: The application does not send periodic "heartbeat" pings, session duration statistics, button-click events, or feature usage counters.
- No IP Logging: Velis does not operate telemetry ingestion servers and therefore never records, stores, or inspects your IP address, geographic location, or Internet Service Provider (ISP).
- Crash Reporting: If the application encounters an unexpected exception, diagnostic crash reports are collected solely by Apple via native opt-in TestFlight and App Store diagnostics, completely governed by Apple's Privacy Policy.
Local Keychain & Credential Isolation
To aggregate your personal media sources, Velis requires authentication tokens and connection endpoints (such as Plex Auth Tokens, Jellyfin User API Keys, Emby Connect Tokens, WebDAV passwords, and SMB credentials).
• All server passwords and API tokens are written directly to native Apple Keychain Services.
• Encrypted with hardware-backed AES keys managed by the Apple Secure Enclave.
• Stored with access control flag: kSecAttrAccessibleAfterFirstUnlock.
• Tokens are never synced to public iCloud, never included in unredacted exports, and never accessible outside your authenticated hardware device.
On-Device Machine Learning (Vibe Search)
Velis features "Vibe Search", a semantic discovery engine that allows you to discover media by emotional mood, color palette, pacing, and visual style.
100% Local Inference: Vibe Search executes an embedded, quantized 384-dimensional BGE-Small CoreML model running directly on your Apple device's Neural Engine (ANE) and GPU.
Zero Cloud Vector Lookups: When Velis indexes your media library, plot summaries and genres are converted into vector embeddings stored entirely in local SQLite memory. When you enter a search query, vector calculation and cosine similarity matching occur entirely offline in <18 milliseconds. Zero search terms, vectors, or media titles are ever transmitted to cloud AI services.
Third-Party API Boundaries (Outbound Traffic Scope)
Velis communicates strictly and directly with the services you explicitly configure. Velis servers never act as a reverse proxy or intermediary for this traffic:
Apple iCloud Synchronization (CloudKit & KVS)
Velis synchronizes playback progress, favorites, and custom library tags across your macOS, iOS, iPadOS, and tvOS devices using Apple's native CloudKit Private Database and NSUbiquitousKeyValueStore (KVS).
- Zero Developer Visibility: Data stored in your CloudKit Private Database is cryptographically siloed to your personal Apple Account. Velis engineers have zero visibility, zero query access, and zero administrative decryption privileges to your CloudKit records.
- Encryption: Data is encrypted both in transit (TLS 1.3) and at rest on Apple's CloudKit infrastructure in accordance with Apple's iCloud security standards.
App Store Purchases & Payment Processing
All financial transactions for Velis Universal Purchases are executed exclusively by Apple through the official Mac App Store, iOS App Store, and tvOS App Store via StoreKit 2.
Velis Software never collects, inspects, receives, or stores credit card numbers, PayPal credentials, bank accounts, or billing addresses. All billing records and receipt validation are governed solely by Apple's Media Services Terms and Conditions.
User Data Rights (GDPR / CCPA / CPRA Compliance)
Because Velis stores zero personal data, account databases, or playback histories on remote servers, your statutory rights under the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA/CPRA) are satisfied directly on your physical hardware:
Settings > Storage & Cache > Reset App Data, or by simply uninstalling the application from your Apple device.
Operator Information & Legal Inquiries
Velis is developed and maintained by Velis Software. If you have inquiries regarding our cryptographic security design, architectural disclosures, or privacy commitments, please contact our privacy compliance team: