← Back

Privacy Policy

Last updated: August 22, 2026

The short version

Valo stores everything on your machine. We don't collect ongoing in-app usage analytics — nothing about what you write, which files you open, or how you use the app. For Pro licensing, we handle your email address, license key, and machine identifier. A launch ping contains only the app version, platform, CPU architecture, a random install ID, the furthest first-run setup step reached, and the provider setup route taken. The last two are each one word from a fixed list, so we can see where a setup route is getting stuck.

What we collect

Email address — collected when you activate a Valo Pro license. Used solely for license validation and account communication. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).

License and install identifiers — a Pro activation sends the license key and a machine identifier for validation. A launch ping sends a random install ID with the app version, platform, CPU architecture, the furthest first-run setup step reached, and the provider setup route taken.

Setup step — one word from a fixed list, recording how far you got through first-run setup (for example, whether Valo stopped at installing Node.js or reached your first message). It is sent when you move to a later step, so we can find where new users get stuck. Legal basis: legitimate interest in fixing a broken setup experience (GDPR Art. 6(1)(f)).

Provider setup route — one word from the fixed list claude, codex, local, or skipped. It records only which first-run connection route was taken, so we can tell whether one route is failing before people reach a first message. It does not include an account, credential, model, prompt, or conversation.

We don't collect names or usage patterns, we don't track what you do inside the app, and we don't store IP addresses.

What stays on your machine

All of the following is stored locally and never sent to our servers:

  • Your code and project files
  • Conversation history with AI
  • Codebase indexes and search data
  • Application settings and preferences
  • Any files generated during sessions

Connections Valo makes

Valo makes two outgoing connections to our infrastructure:

  • updates.getvalo.dev — checks for app updates. No personal data is sent.
  • licensing.getvalo.dev — validates Pro license keys (sends your license key and machine identifier), and receives an anonymous ping at launch containing your app version, platform, CPU architecture, a random install ID, the furthest first-run setup step you reached, and the provider setup route taken. The last two are fixed-list words such as needs-node or first-message. The step is sent again when you advance and never goes backwards; the route updates only if you deliberately choose a different route. No names, no email, no file paths, no message content, no IP address stored.

Third-party services

Paddle — our payment processor and Merchant of Record. When you subscribe to Valo Pro, Paddle collects your payment information, billing address, and related data. Paddle's handling of your data is governed by Paddle's privacy policy.

Anthropic — Valo runs the Claude Code CLI underneath, which connects to Anthropic's servers using your own account. Your conversations with Claude are sent to Anthropic for AI inference. This connection is between you and Anthropic — Valo doesn't intercept, store, or relay this data through our servers. See Anthropic's privacy policy.

OpenAI — when you choose Codex, its CLI connects to OpenAI using your own account. Requests you send to Codex are processed by OpenAI and do not pass through Valo's servers. See OpenAI's privacy policy.

Z.AI — when you choose GLM, Valo's isolated GLM runtime connects to api.z.ai using the Z.AI key stored in your encrypted Keyguard vault. Requests are processed by Z.AI and do not pass through Valo's servers.

Local models — when local-model support is enabled, inference will run through Ollama on your computer without sending the request to an AI provider. This support is in active development.

Cookies and tracking

The Valo desktop application does not use cookies or tracking technologies. This website (getvalo.dev) uses no tracking cookies and no analytics scripts — only an anonymous count of visits to our own share links, with nothing that identifies you.

Your rights (GDPR)

If you're in the EU/EEA, you have the right to:

  • Access the personal data we hold about you
  • Request correction or deletion of your data
  • Object to or restrict processing
  • Request data portability
  • Withdraw consent at any time

To exercise any of these rights, contact us on Discord. We'll respond within 30 days.

Data retention

We retain your email address for as long as your Pro license is active. If you cancel, we delete your personal data within 30 days unless required by law to keep it longer. Paddle retains payment records according to their own retention policy.

Children

Valo is not intended for children under 13. We do not knowingly collect personal data from children.

Changes to this policy

We may update this policy from time to time. If we make significant changes, we'll notify you through the application or by email.

Contact

Questions about your privacy? Reach us on Discord.