Legal
Privacy Policy
Effective 15 August 2026 · Last updated 17 August 2026
This Privacy Policy explains how Velho ("Velho", "we", "us") collects, uses, stores, shares, and protects information when you use Magic Wand (the "Service"), available at magicwand.velho.io. Magic Wand brings together the accounts you choose, builds a personal context base, reconstructs processes you participate in, and surfaces evidence-backed automation opportunities.
Magic Wand is read-only. It analyzes and recommends; it never sends messages, edits documents, or changes any connected system on your behalf.
1. Information we access
When you choose to connect a source, you authorize Magic Wand through that provider's standard OAuth consent screen, where the exact permissions are shown before you approve them. We request read-only access only.
Google Workspace data
| Scope | What it allows | How we use it |
|---|---|---|
gmail.readonly | Read Gmail messages and attachments | Extract activity, participants, and referenced artifacts to build the knowledge graph and process maps |
drive.readonly | Read Drive files and metadata | Extract the content of referenced documents as process evidence |
calendar.events.readonly, calendar.calendarlist.readonly | Read calendar events and calendar list | Reconstruct meetings, participants, and process timing |
openid, email, profile | Basic account identity | Identify your connected account and display your email in the app |
Other sources and data
- Slack: messages, thread replies, and files in channels the connected account and installed app can access.
- Notion: pages, databases, properties, and nested block content that you share with the read-only integration.
- GitHub: issue and pull-request conversations from repositories you explicitly select, only when the authorizing GitHub user authored, commented, reviewed, was assigned, mentioned, or requested for review. Magic Wand excludes source code, diffs, commits, and bot comments from background ingestion.
- Account & connection metadata: your Magic Wand account, workspace and spaces, connected account identifier, granted scopes, consent timestamps, and encrypted OAuth tokens.
- AI integration data: host/client identity, scopes, selected spaces/accounts, tool names, timestamps, result identifiers, and authorization decisions. Tool arguments and returned source content are not intentionally stored in MCP audit logs.
- Operational data: standard server logs (such as request metadata and error diagnostics) used to run and secure the Service.
2. How we use information
- Import the previous 12 months of activity and keep it current with incremental syncs.
- Build and maintain a personal context graph of people, systems, artifacts, meetings, decisions, and work you participate in.
- Reconstruct personal and collaborative process maps and generate advisory automation opportunities with supporting evidence.
- Provide read-only context to AI hosts you separately authorize, within the spaces, accounts, and scopes you grant.
- Operate, secure, debug, and improve the Service.
We do not use your data for advertising, and we do not sell it.
3. AI processing
To generate the knowledge graph, process maps, and opportunities, eligible source content and referenced artifacts may be sent to our configured third-party AI provider (currently OpenAI) through its API. Important boundaries:
- Your OAuth credentials and access tokens are never included in AI prompts.
- Source content is processed only to provide these features to you. It is not used to train generalized or non-personalized AI/ML models.
- Our AI provider processes API inputs to return results to the Service and, under its API terms, does not use them to train its models.
4. Google API Services — Limited Use disclosure
Magic Wand's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide and improve the user-facing features described in this policy.
- We do not transfer Google user data except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition.
- We do not use Google user data for advertising.
- We do not use Google user data to develop, improve, or train generalized or non-personalized AI and/or ML models.
- We do not allow humans to read Google user data unless (a) you gave specific consent, (b) it is necessary for security purposes or to comply with applicable law, or (c) the data has been aggregated and anonymized.
5. Storage, security, and retention
- Encryption. OAuth credentials and extracted artifacts are encrypted at rest. Traffic to the Service is served over HTTPS/TLS.
- GitHub token minimization. The GitHub user token is used only to verify the selected GitHub App installation and read the authorizing user's stable ID/login, then is discarded. Repository conversation reads use short-lived read-only installation tokens that are not retained.
- Hosting. The Service uses contracted cloud application, database, and object-storage infrastructure. Applicable deployment locations and contractual transfer safeguards must be confirmed for the environment offered to you.
- Retention. Evidence already received is retained to keep your context coherent; the 12-month window is an import boundary, not automatic deletion. You can export or delete your account from the Service. Disconnecting a source stops future access but does not itself delete retained evidence.
6. Sharing and subprocessors
We share data only with service providers that help us operate Magic Wand, under contractual confidentiality and data-protection obligations:
- OpenAI — AI processing of eligible content via API.
- Railway — application hosting and managed database in the EU.
We may also disclose information if required by law or to protect the rights, safety, and security of our users and the Service.
7. Your choices and rights
- Pause or disconnect an exact source account at any time from within the app to stop future collection from that account.
- Change Notion or GitHub access in the provider, and change the selected GitHub repository allowlist independently in Magic Wand.
- Revoke an AI-host grant independently to stop subsequent MCP access by that host.
- Export or delete your account from Privacy & settings. Deletion removes retained workspace data and invalidates active sessions.
- Revoke Google access directly at myaccount.google.com/permissions.
- Access, correct, or delete your data by contacting us at privacy@velho.io. Depending on your location, you may have rights under the GDPR or other privacy laws, including access, rectification, erasure, restriction, portability, and objection.
8. International transfers
Where data is transferred outside your region (for example, to a subprocessor), we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
9. Children
The Service is intended for professional use and is not directed to individuals under 16. We do not knowingly collect data from children.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, by additional notice.
11. Contact
Velho — Magic Wand
Privacy inquiries: privacy@velho.io