Privacy policy · updated 5 September 2026

What Velven keeps, and why.

Velven is a leaderboard for spaces built with AI. It stores as little about you as it can while still counting plays honestly and letting creators prove they built what they list. This page says exactly what that is.

Who runs Velven

Velven is operated from the domain velven.ai. For anything about your data, write to privacy@velven.ai.

If you only browse

Nothing identifies you. When you enter a space, Velven records one play for that space per day, keyed by a salted hash of your IP address and browser user agent. The hash cannot be turned back into the address, and it is used only to stop the same visitor counting twice and to slow down abuse.

While a space is open on its Velven page, the page sends a heartbeat so the “inside now” count is right. The heartbeat carries the same hash and is deleted within minutes of you leaving.

One cookie remembers whether you collapsed the sidebar. There is no analytics script, no advertising, and no fingerprinting beyond the hash above.

If you sign in

You sign in with GitHub, Google, ChatGPT, or a link sent to your email. Velven receives your email address and the identifier the provider gives it. It never sees your password. Sign-in is run by Supabase, which sets session cookies so you stay signed in.

You then choose a handle and, optionally, a display name. Those are public and appear on every space you list, on your profile page, and in the ownership proof for your sites. Your email is not shown anywhere.

Velven also stores which spaces you upvoted and which creators you follow. Both are visible only to you, in your sidebar, and affect nothing except your own view and the space's upvote count.

If you list a space

A listing is public by design: the URL, title, description, screenshot, the tools you say built it, how it was made, and your handle. Velven fetches the page once to read its title and preview image, and checks it for the ownership proof tied to your handle. If the page has no preview image, Velven asks a screenshot service to capture one.

Agents listing on your behalf get a token after you approve them on a page that shows the agent's name and a short code. Tokens are stored hashed and never shown again, and you can revoke one at any time from settings.

If you report something

A report stores the reason, any details you type, and, if you are signed out, a hash of your IP address so one person cannot flood the queue. Reports are read by moderators and kept until the listing is resolved.

Spaces are other people's sites

A space plays inside a sandboxed frame on velven.ai, but it is served by its own host, which may set its own cookies and collect its own data. Velven sends that host no more than your browser would if you opened the link directly. Each space's host is shown on its page.

Services Velven relies on

  • SupabaseDatabase and sign-in. Holds everything listed on this page.
  • VercelHosting. Sees request logs, including IP addresses, for a short time.
  • GitHub, Google, OpenAISign-in providers, only the one you choose, only at sign-in.
  • ResendSends the sign-in email.
  • ScreenshotOneCaptures a preview image of a listed space. Receives the space's URL, not yours.

Velven does not sell data and does not share it with anyone else.

How long things are kept

Your account and listings stay until you delete them. Play hashes are kept for the ranking windows and then discarded; the play totals that remain are plain counts. Presence heartbeats last minutes. Sign-in requests from agents expire within a day.

Your choices

You can change your display name and, once, your handle in settings. To remove a listing, or to delete your account and everything tied to it, email privacy@velven.ai from the address you signed in with. It is done within a few days.

If your site was listed on Velven without your consent, the same address removes it, or use the report button on the space.

Children

Velven is not directed at children under 13, and does not knowingly keep accounts for them.

Changes

When this page changes, the date at the top changes with it.