Legal

Privacy Policy

Effective date: May 12, 2026 · Applies to the Vela mobile app and startvela.fit

This Privacy Policy explains how Vela ("Vela," "we," "us," or "our") collects, uses, shares, retains, and protects information when you use the Vela mobile app, web app, websites, and related services (collectively, the "Service").

Vela is a consumer fitness, nutrition, and coaching service. It is not a medical provider, health plan, or healthcare clearinghouse. Unless we separately agree in writing, information you provide to Vela should not be assumed to be protected by HIPAA.

If you do not agree with this Privacy Policy, do not use the Service.

On this page 1. Contact 2. Information we collect 3. How we use information 4. How we share information 5. Account deletion & data retention 6. Your choices & rights 7. Security 8. International processing 9. Children & age limit 10. Changes to this policy 11. Questions

1Contact

Privacy questions, account deletion requests, and data rights requests can be sent to:

2Information we collect

Account and authentication information

We collect information needed to create, secure, and manage your account, including:

Authentication is handled with WorkOS and related sign-in providers.

Profile, demographic, and preference information

We collect information you provide or configure in the app, including:

Fitness, training, and performance information

We collect information needed to generate and track workouts, including:

Injury, limitation, and body-status information

The Service may collect sensitive health and fitness information that you provide so the app can adapt workouts, including:

Do not enter emergency medical information into the Service. If you may have a medical emergency, call emergency services immediately.

Nutrition and food information

If you use nutrition features, we collect information such as:

Nutrition estimates are approximate and are not medical or dietary advice.

Apple Health / HealthKit data (iOS)

If you choose to connect Apple Health on iOS, we read the following data from HealthKit to personalize your experience and reduce onboarding friction:

Apple Health data is read-only — Vela never writes data to HealthKit. We do not read nutrition, clinical, reproductive health, or workout records from HealthKit. Apple Health data is processed on-device and used only within the app to populate your profile. It is not shared with third parties, used for advertising, or sent to AI model providers.

Connection to Apple Health is optional and can be enabled or disabled at any time from Settings. If you decline or disconnect Apple Health, no HealthKit data is accessed.

Photos, camera, and media information

If you use photo-based food features, the app may request camera and photo library permissions. We use those permissions only for features you initiate, such as scanning a plate, selecting a food photo, or reviewing a nutrition label. We do not request microphone access for the core Service.

Food images may be uploaded to Cloudflare R2 and processed by service providers such as Passio when you ask the app to analyze an image, save a meal, or help improve food detection coverage.

AI prompts, outputs, and generated content

The Service uses AI systems to help generate and refine workouts, goals, injury-aware recommendations, nutrition features, coaching summaries, and other product experiences. AI inputs may include profile, training, equipment, goal, injury, nutrition, and session context relevant to the requested feature.

We avoid sending direct account identifiers to AI providers when they are not needed, but AI providers may process content you submit or content generated from your account data to provide the requested feature.

Device, usage, diagnostics, and analytics information

We collect operational information such as:

Communications and support information

If you contact us, provide feedback, or send a data rights request, we collect the content of your message and related contact information.

3How we use information

We use information to:

We do not sell personal information. We do not use health, fitness, injury, or nutrition information for third-party advertising.

4How we share information

We share information with service providers that help us operate the Service. These providers may process information only for the purposes we authorize, subject to their terms and security practices.

Key service providers include:

We may also disclose information:

Service provider details

Provider Purpose Data categories that may be processed
Convex Backend database, serverless functions, real-time sync, HTTP actions Account IDs, profile, health and fitness data, injuries, goals, sessions, nutrition logs, equipment, app data, operational logs
WorkOS Authentication, OAuth, MFA, password reset, session management Name, email, profile details, authentication identifiers, sign-in events, security metadata
Google, Apple, Microsoft Social login providers and app platform services Login identity data, app store account data, platform telemetry controlled by those providers
Sentry Error monitoring, performance monitoring, crash reports, session replay Device data, crash logs, app events, navigation, screenshots or replay visuals, masked text/input depending on platform
OpenRouter, OpenAI, and routed model providers AI generation and structured-output processing Relevant profile, goal, injury, equipment, session, nutrition, prompt, and generated output context
Passio Food search, nutrition lookup, barcode lookup, food photo recognition, label extraction Food search terms, barcodes, food photos, nutrition label images, locale/region, nutrition results, request metadata
Tinybird Real-time operational analytics and AI/nutrition cost tracking User IDs or anonymized IDs, event timestamps, endpoint names, model names, token counts, costs, latency, nutrition gap events, barcodes or R2 keys for gap events
Cloudflare Workers and R2 Edge routing, upload workers, CORS, presigned upload flows, object storage Upload metadata, request metadata, food image payloads, video upload metadata, IP-derived network metadata, stored images/videos
Transloadit Video transcoding and thumbnail extraction Movement/trainer videos, video metadata, thumbnails, webhook metadata
Expo/EAS Mobile builds, OTA updates, app delivery, submission automation Build metadata, app version, update channel, device/update metadata controlled by Expo services
Vercel Web hosting Web requests, deployment metadata, web app traffic metadata
GitLab Source control, CI/CD, issue tracking Development metadata, CI logs, issue/MR data; not intended for consumer health records

5Account deletion & data retention

You can request account deletion from in-app Settings or by emailing support@startvela.fit.

Vela uses an anonymize-and-retain deletion model. When account deletion is processed, we remove or replace direct identifiers on your user account, including first name, last name, email, birthday, and WorkOS user ID. We also revoke or disable the authentication identity where supported.

We retain other product records in anonymized or de-identified form so the Service can preserve operational integrity, safety history, product analytics, and aggregate learning. Retained records may include sessions, goals, injury records, injury notes, nutrition logs, food records, training preferences, equipment, height, weight, and gender after direct identifiers are removed.

Do not include directly identifying information in free-text notes if you do not want that information retained in anonymized product records.

We may retain limited records as needed for security, fraud prevention, legal compliance, dispute resolution, backup integrity, and enforcement of our Terms. Backups are overwritten or deleted according to normal backup cycles.

If you want a specific saved food photo or nutrition label image removed, email support@startvela.fit with enough information for us to locate it.

6Your choices & rights

Depending on where you live, you may have rights to:

To exercise rights, contact support@startvela.fit. We may need to verify your identity before fulfilling a request.

7Security

We use administrative, technical, and organizational safeguards designed to protect information. These include encrypted network transport, access controls, environment-specific credentials, monitored error reporting, and limited access for personnel and service providers with a need to know.

No system can be guaranteed to be completely secure. You are responsible for maintaining the security of your device, email account, sign-in provider, and any credentials.

To report a security vulnerability or other security concern, contact security@startvela.fit.

8International processing

Vela is operated from the United States. Information may be processed in the United States and other countries where we or our service providers operate. Those countries may have data protection laws different from the laws where you live.

9Children & age limit

The Service is intended for users who are at least 18 years old. We do not knowingly collect personal information from children under 18. If you believe a child has provided information to us, contact support@startvela.fit.

10Changes to this policy

We may update this Privacy Policy as the Service changes. If we make material changes, we will update the effective date and provide additional notice when required by law or platform policy.

11Questions

Contact support@startvela.fit with privacy questions or requests. Security disclosures: security@startvela.fit.