Legal
Privacy Policy
Effective date: May 12, 2026 · Applies to the Vela mobile app and startvela.fit
This Privacy Policy explains how Vela ("Vela," "we," "us," or "our") collects, uses, shares, retains, and protects information when you use the Vela mobile app, web app, websites, and related services (collectively, the "Service").
Vela is a consumer fitness, nutrition, and coaching service. It is not a medical provider, health plan, or healthcare clearinghouse. Unless we separately agree in writing, information you provide to Vela should not be assumed to be protected by HIPAA.
If you do not agree with this Privacy Policy, do not use the Service.
1Contact
Privacy questions, account deletion requests, and data rights requests can be sent to:
- Support, privacy, and data rights: support@startvela.fit
- Security disclosures: security@startvela.fit
2Information we collect
Account and authentication information
We collect information needed to create, secure, and manage your account, including:
- Name, email address, profile image, and authentication identifiers.
- Login provider information from Google, Apple, Microsoft, or another supported sign-in provider.
- Authentication events, session information, security signals, and password reset or multi-factor authentication records.
Authentication is handled with WorkOS and related sign-in providers.
Profile, demographic, and preference information
We collect information you provide or configure in the app, including:
- Birthday or age, gender, height, weight, unit preferences, locale, and theme preference.
- Experience level, coaching tone, training schedule, session length, training days, rest days, activities, modalities, and focus areas.
- Gym and equipment information, including home or gym equipment inventories and notes you choose to enter.
Fitness, training, and performance information
We collect information needed to generate and track workouts, including:
- Goals, goal priorities, goal notes, generated goal tags, and goal refinement metadata.
- Workout programs, workout sessions, scheduled dates, completed workouts, skipped workouts, and session status.
- Movement selections, sets, reps, loads, durations, distances, movement history, fatigue estimates, personal-record indicators, ratings, perceived difficulty, and session notes.
- Wearable or manually imported workout data if you choose to provide it, such as source, duration, distance, elevation, pace, heart rate, and calories.
Injury, limitation, and body-status information
The Service may collect sensitive health and fitness information that you provide so the app can adapt workouts, including:
- Body region, target body area, laterality, injury or limitation status, pain severity, recency, source, movement/session context, and notes.
- AI-generated injury enrichment, movement exclusion flags, selection flags, recommendations, rehab phase estimates, summaries, and related metadata.
Do not enter emergency medical information into the Service. If you may have a medical emergency, call emergency services immediately.
Nutrition and food information
If you use nutrition features, we collect information such as:
- Meal logs, meal names, meal categories, meal times, day keys, meal totals, foods, serving sizes, quantities, calories, protein, carbohydrates, and fat.
- Food search terms, barcodes, branded food details, nutrition labels, regional search settings, and food classification data.
- Food photos or nutrition label photos that you choose to capture or upload for analysis or gap detection.
Nutrition estimates are approximate and are not medical or dietary advice.
Apple Health / HealthKit data (iOS)
If you choose to connect Apple Health on iOS, we read the following data from HealthKit to personalize your experience and reduce onboarding friction:
- Demographics: Biological sex, date of birth, height, and weight — used to pre-fill onboarding screens so you don't re-enter information already stored in Apple Health.
- Activity (future): Steps, active energy burned, basal energy burned, and exercise minutes — planned for wearable-informed training context.
Apple Health data is read-only — Vela never writes data to HealthKit. We do not read nutrition, clinical, reproductive health, or workout records from HealthKit. Apple Health data is processed on-device and used only within the app to populate your profile. It is not shared with third parties, used for advertising, or sent to AI model providers.
Connection to Apple Health is optional and can be enabled or disabled at any time from Settings. If you decline or disconnect Apple Health, no HealthKit data is accessed.
Photos, camera, and media information
If you use photo-based food features, the app may request camera and photo library permissions. We use those permissions only for features you initiate, such as scanning a plate, selecting a food photo, or reviewing a nutrition label. We do not request microphone access for the core Service.
Food images may be uploaded to Cloudflare R2 and processed by service providers such as Passio when you ask the app to analyze an image, save a meal, or help improve food detection coverage.
AI prompts, outputs, and generated content
The Service uses AI systems to help generate and refine workouts, goals, injury-aware recommendations, nutrition features, coaching summaries, and other product experiences. AI inputs may include profile, training, equipment, goal, injury, nutrition, and session context relevant to the requested feature.
We avoid sending direct account identifiers to AI providers when they are not needed, but AI providers may process content you submit or content generated from your account data to provide the requested feature.
Device, usage, diagnostics, and analytics information
We collect operational information such as:
- App version, device type, operating system, feature usage, navigation events, performance data, crash data, error reports, and logs.
- API usage metadata, model names, token counts, latency, cost estimates, request status, and feature endpoint names.
- Sentry Session Replay data for debugging. Mobile replay masks all text but may include app images or visual layout. Web replay masks input fields but may include rendered screen content. Replay is sampled and used for debugging, performance, and reliability.
Communications and support information
If you contact us, provide feedback, or send a data rights request, we collect the content of your message and related contact information.
3How we use information
We use information to:
- Provide, operate, secure, and maintain the Service.
- Authenticate users, prevent unauthorized access, and protect accounts.
- Generate, personalize, schedule, and track workouts.
- Adapt sessions for injuries, limitations, equipment, goals, preferences, and training history.
- Provide nutrition logging, food lookup, photo analysis, barcode lookup, and macro estimates.
- Generate AI-assisted content, summaries, recommendations, and refinements.
- Save user preferences and improve product reliability.
- Debug errors, investigate crashes, monitor performance, and prevent abuse.
- Track AI and nutrition API costs and operational usage.
- Respond to support, privacy, security, and legal requests.
- Comply with legal obligations and enforce our Terms of Service.
We do not sell personal information. We do not use health, fitness, injury, or nutrition information for third-party advertising.
4How we share information
We share information with service providers that help us operate the Service. These providers may process information only for the purposes we authorize, subject to their terms and security practices.
Key service providers include:
- Convex for backend functions, database, and real-time sync.
- WorkOS for authentication, OAuth, MFA, password reset, and session management.
- Google, Apple, and Microsoft for supported social login flows.
- Sentry for error monitoring, performance monitoring, and session replay.
- OpenRouter, OpenAI, and model providers routed through OpenRouter for AI-assisted generation and analysis.
- Passio for food search, nutrition lookup, photo analysis, barcode lookup, and label extraction.
- Tinybird for operational analytics, AI cost tracking, and nutrition gap events.
- Cloudflare Workers and R2 for storage, edge routing, food image uploads, and video assets.
- Transloadit for video transcoding and thumbnail generation.
- Expo and EAS for mobile builds, updates, delivery, and app distribution infrastructure.
- Vercel for web hosting.
- GitLab for development, deployment, and issue tracking.
We may also disclose information:
- To comply with law, legal process, or enforceable government requests.
- To protect the rights, privacy, safety, integrity, or security of users, Vela, or others.
- In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate protections.
- With your direction or consent.
Service provider details
| Provider | Purpose | Data categories that may be processed |
|---|---|---|
| Convex | Backend database, serverless functions, real-time sync, HTTP actions | Account IDs, profile, health and fitness data, injuries, goals, sessions, nutrition logs, equipment, app data, operational logs |
| WorkOS | Authentication, OAuth, MFA, password reset, session management | Name, email, profile details, authentication identifiers, sign-in events, security metadata |
| Google, Apple, Microsoft | Social login providers and app platform services | Login identity data, app store account data, platform telemetry controlled by those providers |
| Sentry | Error monitoring, performance monitoring, crash reports, session replay | Device data, crash logs, app events, navigation, screenshots or replay visuals, masked text/input depending on platform |
| OpenRouter, OpenAI, and routed model providers | AI generation and structured-output processing | Relevant profile, goal, injury, equipment, session, nutrition, prompt, and generated output context |
| Passio | Food search, nutrition lookup, barcode lookup, food photo recognition, label extraction | Food search terms, barcodes, food photos, nutrition label images, locale/region, nutrition results, request metadata |
| Tinybird | Real-time operational analytics and AI/nutrition cost tracking | User IDs or anonymized IDs, event timestamps, endpoint names, model names, token counts, costs, latency, nutrition gap events, barcodes or R2 keys for gap events |
| Cloudflare Workers and R2 | Edge routing, upload workers, CORS, presigned upload flows, object storage | Upload metadata, request metadata, food image payloads, video upload metadata, IP-derived network metadata, stored images/videos |
| Transloadit | Video transcoding and thumbnail extraction | Movement/trainer videos, video metadata, thumbnails, webhook metadata |
| Expo/EAS | Mobile builds, OTA updates, app delivery, submission automation | Build metadata, app version, update channel, device/update metadata controlled by Expo services |
| Vercel | Web hosting | Web requests, deployment metadata, web app traffic metadata |
| GitLab | Source control, CI/CD, issue tracking | Development metadata, CI logs, issue/MR data; not intended for consumer health records |
5Account deletion & data retention
You can request account deletion from in-app Settings or by emailing support@startvela.fit.
Vela uses an anonymize-and-retain deletion model. When account deletion is processed, we remove or replace direct identifiers on your user account, including first name, last name, email, birthday, and WorkOS user ID. We also revoke or disable the authentication identity where supported.
We retain other product records in anonymized or de-identified form so the Service can preserve operational integrity, safety history, product analytics, and aggregate learning. Retained records may include sessions, goals, injury records, injury notes, nutrition logs, food records, training preferences, equipment, height, weight, and gender after direct identifiers are removed.
Do not include directly identifying information in free-text notes if you do not want that information retained in anonymized product records.
We may retain limited records as needed for security, fraud prevention, legal compliance, dispute resolution, backup integrity, and enforcement of our Terms. Backups are overwritten or deleted according to normal backup cycles.
If you want a specific saved food photo or nutrition label image removed, email support@startvela.fit with enough information for us to locate it.
6Your choices & rights
Depending on where you live, you may have rights to:
- Access, confirm, or receive a copy of personal information we maintain about you.
- Correct inaccurate personal information.
- Delete personal information, subject to retention described above.
- Object to or restrict certain processing.
- Request portability of certain information.
- Withdraw consent where processing is based on consent.
- Appeal a decision about a rights request where applicable.
- Opt out of sale or sharing of personal information. We do not sell personal information or share it for cross-context behavioral advertising.
To exercise rights, contact support@startvela.fit. We may need to verify your identity before fulfilling a request.
7Security
We use administrative, technical, and organizational safeguards designed to protect information. These include encrypted network transport, access controls, environment-specific credentials, monitored error reporting, and limited access for personnel and service providers with a need to know.
No system can be guaranteed to be completely secure. You are responsible for maintaining the security of your device, email account, sign-in provider, and any credentials.
To report a security vulnerability or other security concern, contact security@startvela.fit.
8International processing
Vela is operated from the United States. Information may be processed in the United States and other countries where we or our service providers operate. Those countries may have data protection laws different from the laws where you live.
9Children & age limit
The Service is intended for users who are at least 18 years old. We do not knowingly collect personal information from children under 18. If you believe a child has provided information to us, contact support@startvela.fit.
10Changes to this policy
We may update this Privacy Policy as the Service changes. If we make material changes, we will update the effective date and provide additional notice when required by law or platform policy.
11Questions
Contact support@startvela.fit with privacy questions or requests. Security disclosures: security@startvela.fit.