Privacy Policy
Effective Date: August 1, 2026 (Draft)
Last Updated: July 26, 2026 — drafts pending legal review
Velora is owned and operated by Havra LLC, a Florida limited liability company headquartered in Miami, Florida (“Havra,” “Velora,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you use the Velora app, our website at joinvelora.app, and related services (the “Service”).
Velora is an AI-powered fitness, nutrition, workout, run-tracking, body-progress, and coaching app. Velora is not a medical device, is not a HIPAA-covered entity, does not provide medical advice, and is intended only for users who are 18 years of age or older. See our separate Medical Disclaimer for details.
This Policy works together with three companion documents that go into more depth on specific topics — please read them too:
- Health Data Policy — our detailed handling of consumer health data, including menstrual cycle data.
- AI Processing Disclosure — exactly what we send to AI providers and what they do with it.
- Community Guidelines — what happens to information you choose to publish publicly.
Our key commitments, up front
- Encryption. Content you store is encrypted in transit (TLS) and at rest. Your progress photos, coach chats, nutrition history, GPS run routes, and other sensitive content are additionally encrypted on your device (AES-GCM-256) before upload, so our servers store only ciphertext they cannot read. See “Data Security.”
- Meal-scan photos are deleted. Photos you submit for AI meal scanning are deleted promptly after the AI returns your result and are not retained afterward.
- AI for responses, not training. We send data to our AI providers only to generate your result, and we contractually restrict those providers from using your data to train their own models. See the AI Processing Disclosure for the full, honest picture, including one item we cannot yet verify.
- No sale of personal information. We do not sell your personal information, and we do not use your health, fitness, nutrition, cycle, or run-route data for advertising. Our only advertising is optional rewarded video ads shown to free-tier users, described in “Advertising.”
- Run routes are never sold, shared, or used for advertising, and they are encrypted so that Velora’s own servers cannot read them. See “Run & Route Information” below.
Contact us at Havra LLC — [email protected].
Contents
- 1. Summary
- 2. Notice at Collection
- 3. Information We Collect
- 4. How We Use Information
- 5. Photos & Images We Process
- 6. Run & Route Information
- 7. Biometric Data — No Faceprints
- 8. AI Processing & Our AI Providers
- 9. Health, Fitness & Sensitive Data
- 10. Apple Health
- 11. Notifications
- 12. How We Share Information
- 13. Advertising (Free Tier Only)
- 14. Sale & Sharing of Personal Information
- 15. Data Retention
- 16. Your Privacy Rights & Appeals
- 17. California Privacy Notice
- 18. Other State Privacy Rights
- 19. Consumer Health Data
- 20. Community Content
- 21. Children & Age Requirement
- 22. Data Security
- 23. Data Breach Notification
- 24. International Users
- 25. Changes to This Policy
- 26. Contact
1. Summary
Velora collects information you provide to create your account, personalize your nutrition and workout plan, scan meals, log workouts, track a run with GPS, track body progress, optionally track your menstrual cycle, and sync certain data across devices.
We do not sell your personal information, and we do not use your health, fitness, nutrition, or run data for advertising. We show optional rewarded video ads to free-tier users only; those ads involve an advertising partner that receives your device’s advertising identifier (see “Advertising”).
We do not keep meal photos in permanent storage. We send data to our AI providers only to generate your response, and we contractually restrict them from using it to train their models — see the AI Processing Disclosure for the full picture, including an unresolved verification gap we are disclosing rather than hiding.
We do not provide medical advice. Nutrition, calorie, workout, recovery, run, BMI, cycle, and body-related estimates are informational only — see our Medical Disclaimer.
2. Notice at Collection
At or before the point we collect your information, this Notice at Collection tells you what we collect and why. We collect the categories of personal information described in this Policy, including sensitive personal information (your account credentials, your health and fitness data, and your run/location data). We use this information only for the business purposes described in this Policy, and we retain it only as described in our Data Retention schedule. We do not sell your personal information, and we do not use or disclose your sensitive personal information to infer characteristics about you. For free-tier users only, we share a mobile advertising identifier with our advertising partner to show rewarded ads; you can opt out (see “Advertising” and “Sale & Sharing”). You can exercise your privacy rights as described in “Your Privacy Rights & Appeals.”
3. Information We Collect
Account information. Name; email address; password credentials (handled through Supabase Auth, Sign in with Apple, or Google Sign-In); date of birth; gender or body-calculation preference, where provided; profile photo, if you upload one; account status.
Fitness, nutrition, and body information. Height, weight, and target weight; fitness goals; activity level, training experience, available training days, equipment access, and preferred workout style; workout logs and history; personal records; meal logs; calories, macros, and other nutrition estimates; food library entries, saved foods, and barcodes; progress photos and workout photos, if you upload them.
Meal scan information. A compressed meal photo, meal context/notes, follow-up answers, a temporary scan job record, and AI-generated nutrition estimates. See “Photos & Images We Process.”
Run & route information. If you use GPS run tracking, we collect your run’s route (GPS coordinates), pace, splits, elevation, cadence, duration, and estimated calories. See “Run & Route Information” below — this is a significant, deliberate disclosure.
Barcode information. Barcode number, product lookup result, and saved barcode/product history. Barcode lookups send only the product barcode — not your identity or health data — to Open Food Facts, an independent third-party product database.
Photos and media. Profile photos, body-progress/workout photos, and meal-scan photos. See “Photos & Images We Process.”
Device, usage, and technical information. Device type and OS; app version; feature usage; approximate timestamps; the IP address received by our backend or hosting providers; notification preferences. We use this to improve reliability, performance, security, and fraud prevention.
Payment and subscription information. Processed by Apple and our subscription manager (RevenueCat) under their own privacy policies. We receive your subscription tier and entitlement status, and an internal account identifier — never your name or email — for subscription management.
Website and waitlist information. If you contact us through joinvelora.app, we may collect your email, name, and basic website usage information.
Menstrual cycle information (optional). If you use cycle tracking, we process the cycle data you enter (period dates, symptoms, notes) and the estimates we calculate. This data is stored only on your device by default. The app includes a cloud-sync setting for cycle data that defaults to off; as of this Policy’s effective date that setting is not connected to any server-side storage — cloud sync for cycle data has not shipped to users. If it ships, it will remain off by default, require your separate opt-in, use the same client-side encryption described in “Data Security,” and we will update this Policy and our Health Data Policy first. See the Health Data Policy for full detail.
Apple Health data (optional). If you connect Apple Health, we read a limited set of metrics (sleep, heart-rate variability, resting heart rate, respiratory rate, steps, energy burned, VO2 max, workouts) to compute on-device wellness scores. This data and those scores stay on your device — never uploaded, never shared with any third party or AI provider, never used for advertising, never sold.
Fraud-prevention identifiers. A device identifier that is immediately hashed (SHA-256) before use, so we never store the raw identifier; used to enforce usage limits and prevent abuse, including for guests who are not signed in.
4. How We Use Information
We use information to: create and manage your account; verify age eligibility; authenticate signups and logins; personalize calorie, macro, workout, run, cycle, and coaching recommendations; generate AI meal estimates; generate or recommend workouts; track meals, workouts, runs, body progress, recovery, and (if enabled) cycle; display trends and progress; sync data where supported; provide notifications and reminders; send account, security, verification, and product emails; improve accuracy, app performance, and reliability; debug errors and prevent abuse; enforce our Terms of Service; and comply with legal obligations. For free-tier users only, we use a mobile advertising identifier to show rewarded ads (see “Advertising”).
5. Photos and Images We Process
We process three categories of images, each for a single, limited purpose:
- Meal-scan photos — analyzed by an automated AI model solely to estimate the food, portion, and nutrition content of your meal. Ephemeral: deleted promptly after the AI returns your nutrition result, with a fallback cleanup sweep within roughly 48 hours if delivery is ever interrupted.
- Profile photos — stored only to display your own account profile to you.
- Body-progress and workout photos — stored only so you can view and compare your own self-selected progress over time. Never used for identification, recognition, or matching.
We do not use any of these images to identify you or anyone else, to perform facial recognition, or to train any recognition system. We encrypt images in transit and at rest; progress, workout, and profile photos are additionally encrypted on your device before upload so we store only ciphertext. Imported and captured images are re-encoded on-device before upload, which drops the original camera file’s embedded metadata (such as GPS/EXIF tags) — the original file is never uploaded.
6. Run & Route Information
Velora includes an optional GPS run tracker. This section corrects an earlier internal assumption that Velora requested no location permission — that assumption was wrong, and we are disclosing the actual, current behavior truthfully.
- What we request. When you start a tracked run, Velora requests iOS “When In Use” location access (never “Always”). Background tracking during an active run is enabled the way run-tracking apps commonly do this, using Apple’s standard mechanism for apps that begin tracking in the foreground and keep an active session running.
- What we collect. Your run’s GPS route (coordinates), splits, elevation profile, pace, cadence, duration, and precise start/end times.
- How it’s protected. Your full run record — coordinates, splits, elevation, timestamps, cadence, and pace — is encrypted on your device (AES-GCM-256) before it is ever uploaded, using a per-user encryption key that lives only in your device’s Keychain (synced via iCloud Keychain) and is never sent to our servers. Our servers store only ciphertext and cannot read your route. A small set of low-sensitivity summary numbers — the calendar date, total distance, total duration, and calories — are kept as plain, queryable numbers so we can show you a run history list without opening the encrypted route data; these summary numbers do not reveal your location or path.
- What we never do with it. We never sell your run or route data. We never share it with advertisers or use it for advertising. We never use it to train AI models. It is not sent to any AI provider.
- Community sharing. If you choose to share a run to Velora Community, only a stats card (distance, pace, duration, splits computed server-side from rounded numbers) is published — never your coordinates, route, or precise timestamps. The systems that store shared runs are structurally unable to hold location data.
- Deletion. Deleting a run deletes it from your device and, if synced, from our cloud storage. Deleting your account deletes all of your run and route data. Free-tier cloud copies of run history expire automatically after about 14 days; paid-tier copies persist until you delete them or your account.
7. Biometric Data — No Faceprints, No Facial Recognition
Velora does not collect, capture, or use biometric identifiers or biometric information — no faceprints, face templates, facial-geometry scans, hand/face geometry, retina or iris scans, voiceprints, fingerprints, or DNA — and does not perform facial recognition or any form of biometric matching. We do not use any photo you provide to identify you or any other person, or to build a biometric template.
As used here, “biometric identifier” has the meanings given in the Illinois Biometric Information Privacy Act, the Texas biometric statute, and Washington’s biometric-privacy statute. Photographs and information derived solely from photographs are expressly excluded from those definitions, and Velora derives no biometric template or geometry from any photograph. If we ever introduce a feature involving biometric identifiers, we will provide a separate written disclosure and obtain your separate, prior, written consent first.
8. AI Processing and Our AI Providers
Velora uses third-party AI providers to estimate meal nutrition, generate or assist with workout plans, and provide coaching-style guidance. We send only the information needed to perform each task, and — for a meal scan — a compressed, temporary image. Read the full, honest picture, including one representation we cannot currently verify against a provider’s public terms, in our AI Processing Disclosure.
In short: we use AI providers only for inference (generating your result), not to build our own models. We contractually restrict our AI providers from using your data to train their own models. Providers may retain limited data briefly under their own standard terms to operate the service and to detect abuse — we do not have a signed agreement with every provider guaranteeing immediate deletion, and we say so plainly rather than overclaiming.
AI outputs may be inaccurate or incomplete and are estimates only. See our Medical Disclaimer.
9. Health, Fitness, and Sensitive Data
Some information Velora processes is “sensitive personal information,” including your account credentials and your health and fitness information (body metrics, nutrition and meal logs, workout logs, run/route data, progress photos, cycle data, and Apple Health metrics). We use sensitive personal information only for purposes that are exempt from the right to limit under California law: to provide the services you request, to maintain security and prevent fraud, to debug and repair errors, and to ensure quality and safety. We do not use or disclose your sensitive personal information to infer characteristics about you, and we do not sell or share it.
Consent. We ask for your consent to process health and fitness data when you create your account and begin using Velora’s coaching, nutrition, run-tracking, body-progress, cycle, and workout features. Optional features that involve additional health data — Apple Health, cycle tracking, and GPS run tracking — require a separate, affirmative opt-in (the iOS permission prompt, for location and Health data) before any such data is processed. You may withdraw consent at any time by turning off the relevant feature, deleting the relevant data or your account, or contacting [email protected].
See our Health Data Policy for the full, dedicated treatment of consumer health data, including heightened protections for menstrual cycle data.
10. Apple Health
Velora includes an optional Apple Health integration. Velora requests your permission before reading Apple Health data, and reads a limited set of metrics (sleep, heart-rate variability, resting heart rate, respiratory rate, steps, energy burned, VO2 max, workouts) solely to compute your wellness scores on your device. Velora never writes to Apple Health. Apple Health data and the scores derived from it stay on your device — not uploaded to our servers, not shared with any third party or AI provider, never used for advertising, never sold, consistent with Apple’s platform rules for Health data.
11. Notifications
Velora may send local notifications for meal reminders, meal-scan completion, workout reminders, optional cycle reminders, and other app reminders you enable. Manage these in iOS Settings and, where available, inside Velora.
12. How We Share Information
We share personal data only with vendors that help us operate Velora, under contracts that require them to protect your data and use it only on our instructions:
- Supabase — authentication, database, and encrypted storage
- Render — application hosting
- Resend — transactional email
- Our AI/model inference providers (SiliconFlow; OpenRouter for certain server-side generation/translation workloads; a frontier provider for our top tier) — see the AI Processing Disclosure
- RevenueCat — subscription and entitlement management (an internal account identifier and purchase data only — no health, fitness, or content data)
- Open Food Facts — barcode lookups (barcode only)
- Cloudflare — website delivery and security (Cloudflare Pages hosts our marketing/policy site)
- Apple — in-app purchases and subscriptions, and Sign in with Apple
- Google — Google Sign-In, if you choose that sign-in method
- Start.io — mobile advertising partner, free-tier rewarded ads only (see “Advertising”)
We do not sell your personal information. We never share your health, fitness, meal, photo, run, cycle, or coaching data with advertisers. We may add, remove, or change service providers over time and will require comparable protections.
13. Advertising (Free Tier Only)
Velora shows optional rewarded video ads to free-tier users only. Paid subscribers never see ads, and our advertising software is not even initialized for them.
We use Start.io as our advertising partner. When a free-tier user watches a rewarded ad, Start.io’s software receives your device’s mobile advertising identifier (IDFA) — only if you allow tracking through Apple’s App Tracking Transparency prompt — along with device and ad-interaction data. We ask for App Tracking Transparency permission before the advertising software is initialized. We do not share your name, email, health, fitness, meal, photo, run, cycle, or coaching data with Start.io or any advertiser. Ads are rewarded video only — no banners or interstitials.
Sharing an advertising identifier for personalized advertising may be treated as “sharing” for cross-context behavioral advertising under some state privacy laws, and we treat it that way: you can decline Apple’s tracking prompt (or turn off “Allow Apps to Request to Track” in iOS Settings), and, on our website, we honor Global Privacy Control signals. You can also avoid ads entirely by subscribing to any paid tier.
14. Sale and Sharing of Personal Information
We do not sell your personal information. We do not “share” your personal information for cross-context behavioral advertising except the limited advertising-identifier sharing described in “Advertising.” That sharing never includes your health, fitness, run, or content data. We do not knowingly sell or share the personal information of anyone under 18 (Velora is limited to users 18 and older). If your browser or device sends an opt-out preference signal such as Global Privacy Control, we treat it as a valid request not to sell or share.
15. Data Retention
| Category | Retention |
|---|---|
| Account & profile information | While your account is active. On account deletion, we immediately delete your account and profile data. |
| Health & fitness data (body metrics, nutrition/meal logs, workout logs, barcode scans) | While your account is active; deleted immediately on account deletion, or sooner when you delete the entry. Free-tier cloud copies auto-expire after ~14 days; paid copies persist until deleted. |
| Run & route data | Same as above. Free-tier cloud copies auto-expire after ~14 days; paid copies persist until deleted. Deleted immediately on account deletion. |
| Menstrual cycle data | Stored only on your device; not uploaded (see Section 3). Deleted using the in-app “delete all cycle data” control, or when you delete the app. |
| Apple Health data & wellness scores | Stored only on your device. Cleared when you revoke Apple Health access or delete the app. |
| AI coaching chat history | While your account is active (free-tier cloud copies auto-expire after ~14 days; paid persist); deleted immediately on account deletion. You can delete individual conversations. |
| Meal-scan images | Transient — deleted promptly once the AI scan result is returned (fallback cleanup within ~48 hours if delivery is interrupted). |
| Profile, body-progress & workout photos | While your account is active; deleted on account deletion. Free-tier photos are stored only on your device. |
| Subscription status | While your account is active and as required for tax/financial recordkeeping. |
| Anonymous scan corrections | De-identified records with no user identifier, kept to improve accuracy; not linked to you. |
| Administrative audit logs | Our internal administrative audit log (records of administrative actions) is, by design, append-only and permanent — it cannot be altered, redacted, or deleted, even by us. It records the administrator, the action taken, and a reference to the affected account. It is access-restricted and used only for security and legal-compliance integrity. We are disclosing this honestly: this is not a time-limited log that gets purged or de-identified on a schedule — it is permanent. |
On account deletion, we delete your account, profile, health/fitness data, run data, chat history, and stored photos across our database and storage — this is an immediate, hard delete, not a 30-day grace-period process. Certain records may persist as required for legitimate purposes: de-identified analytics and abuse-prevention records (with your account identifier removed), anonymous scan corrections (which never contained an identifier), and the immutable administrative audit log described above. We may retain information longer where required by law or to establish, exercise, or defend legal claims.
16. Your Privacy Rights and Appeals
Depending on your state or country, you may have rights to: know/access the personal information we hold about you; delete it; correct inaccurate information; obtain a portable copy; withdraw consent where processing is based on consent; object to or restrict certain processing; opt out of any sale, sharing, or targeted advertising; and limit the use of sensitive personal information.
You can delete your account and data directly in the app (Profile → Delete Account), and turn off optional features (Apple Health, cycle tracking, run tracking) at any time. To exercise your other rights — access, correction, a portable copy, or a formal consent withdrawal — email [email protected]; we currently handle these requests manually (there is no automated in-app export tool yet). We will verify your identity before responding and will respond within 45 days (California) or within the timeframe your state or country’s law requires, extendable as permitted with notice. You may use an authorized agent. We will not discriminate or retaliate against you for exercising your rights.
Appeals. If we deny your request, you may appeal by replying to our decision or emailing [email protected] with “Appeal” in the subject line; we will respond within 60 days. If we deny your appeal, you may contact your state Attorney General.
17. California Privacy Notice
If you are a California resident, this section provides additional information under the CCPA/CPRA.
Categories of Personal Information Collected: Identifiers (name, email, account ID, hashed device identifier, mobile advertising identifier for free-tier ads); customer records; protected classification information (age/date of birth, gender where provided); commercial information (subscription status); internet/network activity (app usage); precise geolocation (only while actively tracking a run, and only if you grant location permission — see “Run & Route Information”); sensory/visual information (photos you upload); inferences (nutrition targets, workout recommendations, wellness insights); and sensitive personal information (health/fitness data, body metrics, cycle data, Apple Health metrics, run/route data, account credentials).
Sources, Purposes, and Disclosure: We collect from you, your device, and the service providers listed in Section 12. We use it for app functionality, personalization, account security, customer support, debugging, fraud prevention, free-tier advertising, and legal compliance. In the preceding 12 months we disclosed personal information to the service providers listed in Section 12 for these business purposes. We did not sell personal information. We shared one category — a mobile advertising identifier — with our advertising partner for free-tier advertising (see “Advertising”); you may opt out as described there.
Right to Limit Sensitive Personal Information: Because we use sensitive personal information only for permitted business purposes and do not use it to infer characteristics, the right to limit is already satisfied by our practices; you may still contact [email protected] to confirm or direct us.
Shine the Light: We do not disclose your personal information to third parties for their own direct marketing.
18. Other State Privacy Rights
If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you have rights to access, correct, delete, and obtain a copy of your personal data; to opt out of sale, targeted advertising, and profiling; and to appeal a denied request. We process your health and fitness information based on the consent described in Section 9. To exercise your rights or appeal, contact [email protected].
19. Consumer Health Data
Some of the information we process — including body metrics, nutrition and meal logs, body-progress and workout photos, meal-scan photos, run/route data, menstrual cycle data, Apple Health metrics, and health-related inferences — is “consumer health data” under laws such as the Washington My Health My Data Act, Nevada SB370, and the Connecticut Data Privacy Act. Our detailed handling of consumer health data is described in our Health Data Policy, which controls for consumer health data if it conflicts with this Privacy Policy. Nothing in our Terms of Service waives any non-waivable statutory consumer-health-data right.
20. Community Content
If you choose to publish a workout, run summary, comment, or profile information to Velora Community, that content becomes public. See our Community Guidelines for what publishing means, what data a shared run does and does not include (never your route or coordinates), and how to report or block content.
21. Children and Age Requirement
Velora is intended for users 18 and older. When you sign up with email, we collect your date of birth and block accounts under 18. For sign-ups using Apple or Google, you agree in our Terms of Service that you are at least 18. We do not knowingly retain accounts or data of anyone under 18; if we learn that a person under 18 has created an account, we will delete or deactivate it. Velora is not directed to children.
22. Data Security
We use reasonable, industry-standard administrative, technical, and organizational safeguards, including encryption in transit (TLS) and at rest (provider-managed AES-256), plus client-side encryption (AES-GCM-256 on your device) for your progress/profile photos, coach chat history, nutrition history, and GPS run/route data, so our servers store only ciphertext they cannot read. The keys for that client-side encryption are stored only in your device’s Keychain and synced via iCloud Keychain; we never hold them. If you lose that key (for example, iCloud Keychain is disabled and your device is lost), your client-side-encrypted cloud data cannot be recovered by Velora — by design, because we never hold the key. We also use access controls, private storage buckets, row-level security, authentication, and multi-factor authentication for administrative access. Meal-scan photos are the one deliberate exception to client-side encryption — stored briefly, unencrypted, in a private, access-controlled bucket in a form our AI provider can read, and deleted promptly after processing. No method of transmission or storage is completely secure.
23. Data Breach Notification
If we discover a breach resulting in the unauthorized acquisition of your unsecured personal or health information, we will notify affected users without unreasonable delay and no later than required by applicable law, including (where applicable) the FTC Health Breach Notification Rule and state breach-notification laws.
24. International Users
Velora is operated from the United States. Our providers may process data in the United States or other countries where they operate — our primary AI meal-scan inference provider operates from Singapore. If you access Velora from outside the United States, your information may be processed in the United States or those countries.
25. Changes to This Policy
We may update this Privacy Policy and will post the updated version with a new “Last Updated” date. If we make a material change that would reduce the protections applied to personal data we already collected, we will not apply that change to your previously collected data unless we first obtain your affirmative consent. We will provide advance notice of material changes by email or in-app notice before they take effect.
