← The Stellar Trinity

Privacy

Last updated 5 September 2026

This covers thestellartrinity.com and Vellum, the desktop tool. It is written to be read, not to be survived. Where it says the tool does not do something, that is a description of how it is built, and you can hold me to it.

The short version

Signing in with Patreon

Vellum's paid features are unlocked by signing in with Patreon. You are sent to Patreon's own page; I never see your Patreon password.

When Patreon confirms the sign-in, the server reads three things from your membership and nothing else:

Those become a signed licence file that is handed to your copy of Vellum and stored on your computer, not on the server. It is valid for 35 days; signing in again renews it. No email address, no payment details, no card number — Patreon handles payment and never passes any of that on.

Vellum shows the name from your Patreon profile in its own window, so you can see which account it is using. That is the only place it appears.

What the server keeps, and for how long

The licence server is a Cloudflare Worker with a small key-value store. It holds three kinds of entry:

There is no account database. If you have never redeemed a Creator key, nothing about you is stored on the server for longer than those fifteen minutes.

Checking for a new version

A few times a day Vellum asks the server whether a newer version exists. That request carries no parameters and no identity — not your licence, not your name, not a machine id. It is the same request for everyone, and the answer is cached at the edge, so most of the time it is not even seen by the server.

The answer is signed. Vellum checks the signature before it believes a word of it, and if it downloads an update it checks the file's SHA-256 against the one inside that signature before anything is installed.

What stays on your computer

Vellum works on files you already have. Mods, RaceMenu presets, meshes, textures, plugins, scripts and audio are read from your disk and written back to the folder you point it at. None of it is uploaded anywhere.

In %APPDATA%\Vellum it keeps:

The one exception: text-to-speech

If — and only if — you use the voice generation feature, the lines you asked to be spoken are sent to ElevenLabs with your own API key, because that is where they are turned into audio. What ElevenLabs does with them is governed by their privacy policy, not this one.

Importing audio you already recorded sends nothing anywhere. If you never enter an ElevenLabs key, this never happens.

The website

The site is static pages served by Cloudflare. There are no cookies for tracking and no third-party analytics. One cookie exists during a Patreon sign-in — it lasts fifteen minutes, holds a random value used to check that the reply came back from the same browser that started, and nothing else.

Cloudflare, as the host, sees the ordinary things any web server sees, such as IP addresses, and keeps them under its own privacy policy.

What I never do

Who is responsible, under the GDPR

The person who decides what happens to this data — the data controller — is Dari, who runs The Stellar Trinity from Lagos, Faro, Portugal. Because that is inside the European Union, the General Data Protection Regulation applies to everything on this page, wherever in the world you are.

Why the data is processed at all. The Patreon id, name and pledge amount exist for one reason: to work out which features your tier unlocks and to put that in a licence. That is performance of a contract — article 6(1)(b). The version check processes no personal data, so no basis is needed for it.

How long it is kept. The sign-in code, fifteen minutes. A Creator key record, until you ask for it to be deleted or the project ends. The licence itself is not kept by me at all — it lives on your computer and expires after 35 days.

Where it goes. The server runs on Cloudflare, whose network spans the world, and the sign-in itself happens at Patreon in the United States. Both operate under the standard contractual clauses the GDPR provides for transfers outside the EU. There are no other processors, and nothing is sold or shared.

Your rights

Under the GDPR you can ask me, at any time, to:

In practice there is very little to hand over — usually a Patreon id and a key code. I answer without undue delay and within one month, which is what the law asks; for a request that turns out to be complicated the law allows two months more, and I would have to tell you so inside that first month. Nothing is charged for any of it.

Requests reach me by Patreon message, and that is the address to use — it is the one I read. If you cannot reach me there, say so publicly on the Vellum page's comments and I will come and find you.

If you think I have handled your data badly, you can complain to the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (cnpd.pt), or to the authority in your own EU country.

Your choices

You can sign out of Vellum at any time, which deletes the licence from your computer. If you want the server side gone as well — the record of a Creator key you redeemed — ask, and it is deleted. There is nothing else to delete.

To revoke Vellum's access to your Patreon account entirely, remove it from your Patreon connected apps.

Changes, and how to reach me

If this policy changes in a way that matters, the date at the top changes and the change is mentioned on the Vellum page. Questions, corrections and deletion requests: message Dari on Patreon.