Privacy Policy
Last updated: 11 August 2026
Velora ("we", "our", "the app") is a wellness companion for food, energy and consistency tracking. Because we handle deeply personal information, privacy is a structural part of how Velora is built, not an afterthought. This policy explains what we collect, why, where it goes, and how to delete it.
1. Data we collect
- Account data: your email address and authentication credentials, managed by Firebase Authentication (Google). If you sign in with a social provider, we receive the email and display name that provider shares.
- Profile data: name, age, gender, height, current and goal weight, activity level, health focus areas, dietary preferences and allergens. This is the information you enter during onboarding or in settings.
- Wellness logs: the food, exercise, hydration, weight and meditation entries you create, plus the daily summaries and scores derived from them.
- Photos you choose to analyze: if you use photo food logging, the image you take or select is sent for analysis (see section 3). Images are processed, not stored as a photo library.
- Purchase state: whether you have an active Velora Pro subscription, processed by Google Play Billing and RevenueCat. We never see your card details.
2. What we do NOT collect
- No advertising SDKs. Velora contains none, and your data is never used for advertising.
- No third-party product analytics (no Mixpanel, Amplitude or similar) receiving your health data.
- No precise location data.
- No contact list, no browsing history, no background microphone access.
3. AI processing
Velora's food analysis, meal suggestions and weekly insights are generated by Google's Gemini API. When you log a meal or request a recipe, the minimum required context is sent for processing. That means the text or photo you provided, your dietary preferences and allergens, your remaining daily targets, and your selected health focus areas.
- Your name, email address and exact location are never included in AI requests.
- AI requests are ephemeral. The app's architecture assumes zero persistence on the model side, and payloads are not used to train the underlying models under Google's API terms.
4. Where your data lives
Your data is stored in Google Firebase (Cloud Firestore), keyed to your private account ID, and protected by security rules that allow only your authenticated account to read or write it. All traffic between the app and our servers is encrypted with HTTPS/TLS; the app enforces HTTPS-only networking at the operating-system level.
5. Third parties we rely on
- Google Firebase: authentication, database, and crash reporting.
- Google Gemini API: AI analysis of the food text and photos you submit.
- RevenueCat & Google Play Billing: subscription management and purchase validation.
These processors receive only what they need to perform their function. We do not sell your data, ever.
6. Your rights & data deletion
You can view and edit your profile data in the app at any time, and export all of your data from Profile → Export My Data.
You can permanently delete your account and all associated data from Profile → Delete Account in the app, or by following the steps on our account deletion page. Deletion removes your profile, all logs, snapshots, insights and aggregates from our systems, then removes your authentication account. This is irreversible.
7. Children
Velora is not directed at children and is intended for users aged 16 and over.
8. Changes to this policy
If we make material changes, we will notify you in the app before they take effect. The "Last updated" date at the top always reflects the current version.
9. Contact
Questions or requests: support@veloracoach.com