Privacy Policy

Last Updated: December 24, 2025

Introduction

VeltoAI ("we," "our," or "us"), a sole proprietorship, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App").

Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the App.

We reserve the right to make changes to this Privacy Policy at any time. We will alert you about any changes by updating the "Last Updated" date of this Privacy Policy. You are encouraged to periodically review this Privacy Policy to stay informed of updates.

Table of Contents

1. Information We Collect

We collect information about you in various ways when you use our App. The information we collect falls into the following categories:

1.1 Information You Provide Directly

Account Information:

  • Email address (if you create an account)
  • Apple ID information (if you use Apple Sign-In on iOS)
  • Anonymous user ID (if you use the app without signing in)
  • Note: Google Sign-In is currently not available

Onboarding Information:

  • Age (date of birth)
  • Business interests and passions
  • Biggest business challenges
  • Past experiences and skills assessment
  • Existing assets and starting resources
  • Familiarity with business tools
  • Budget range and financial preferences
  • Geographic location (country)
  • Time commitment preferences (daily/weekly hours)
  • Business goals and motivation
  • Selected business idea and industry
  • Target audience information
  • Business stage (idea, launching, growing)

User-Generated Content:

  • Business name and description
  • Custom tasks, notes, and task feedback
  • Goals (monthly and yearly)
  • Daily tasks and completion status
  • Task difficulty ratings (easy/medium/hard)
  • Weekly journal entries (optional)
  • Progress notes and updates
  • Comments and feedback on generated content
  • Any other content you create within the App

Payment Information:

  • Subscription plan selected
  • Payment is processed through Apple App Store or Google Play Store
  • We do NOT directly collect or store credit card information
  • RevenueCat processes payment information on our behalf

Communications:

  • Customer support inquiries
  • Feedback and survey responses
  • Email correspondence with us

1.2 Information Collected Automatically

Device Information:

  • Device type and model (e.g., iPhone 14, Samsung Galaxy S23)
  • Operating system and version (e.g., iOS 17, Android 14)
  • Unique device identifiers (e.g., IDFA, Android Advertising ID)
  • Device settings and preferences
  • Mobile carrier
  • Screen resolution and device orientation

Usage Information:

  • App features you use and how you use them
  • Time spent on different screens
  • Interaction with buttons, tasks, and content
  • Navigation paths through the App
  • Session duration and frequency
  • Task completion rates and task feedback
  • Goal progress and achievements
  • Gamification metrics (streak count, flame status, XP points, level progression)
  • Task snoozing and pause feature usage
  • Onboarding completion status

Location Information:

  • Approximate location based on IP address
  • Country, region, and city-level location
  • We do NOT collect precise GPS location
  • Location data from onboarding (user-provided, not GPS)

Technical Information:

  • IP address
  • Browser type (for web features)
  • App version
  • Crash reports and error logs
  • Performance metrics
  • Network connection type

Analytics and Tracking:

  • App opens and session starts
  • Feature usage statistics
  • Screen views and navigation patterns
  • Task completion events and ratings
  • AI generation metrics (tokens used, generation type)
  • Subscription events (purchase, renewal, cancellation)
  • Error logs and crash reports (anonymized)
  • Performance metrics and app version tracking
  • Device information (model, OS version, platform)

1.3 Information from Third-Party Sources

Apple Sign-In (iOS only):

  • Apple ID
  • Email address (if you choose to share it)
  • Name (if you choose to share it)
  • User verification status

Payment Processors (Apple App Store / Google Play Store via RevenueCat):

  • Subscription status (active, trialing, expired, cancelled)
  • Payment success/failure events
  • Subscription plan (monthly/yearly)
  • Subscription renewal dates
  • Transaction IDs
  • Refund information
  • Platform (iOS/Android)

1.4 Cookies and Similar Technologies

We use cookies and similar tracking technologies to track activity on our App and store certain information. Technologies we use include:

Cookies:

  • Small data files stored on your device
  • Used to remember your preferences and login status
  • Enable certain features and functionality

Local Storage:

  • Data stored locally on your device
  • Used for caching and offline functionality
  • Includes user preferences and temporary data

SDKs and Tracking Pixels:

  • Mixpanel SDK (optional analytics on mobile devices)
  • RevenueCat SDK (subscription management)
  • Expo SDK (app framework and device APIs)
  • Used for analytics, crash reporting, and attribution
  • May collect device and usage information

You can instruct your device to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our App.

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1 To Provide and Improve Our Services

Core App Functionality:

  • Create and manage your account
  • Authenticate your identity
  • Process your subscription and payments
  • Provide customer support
  • Send service-related notifications

AI-Powered Features:

  • Generate personalized business ideas using Google Gemini API
  • Create daily task recommendations
  • Analyze your progress and provide insights
  • Suggest goals based on your profile and behavior
  • Optimize content recommendations

Gamification:

  • Track XP, levels, and achievements
  • Maintain streak tracking
  • Calculate progress and statistics
  • Generate performance insights

App Improvements:

  • Analyze usage patterns to improve features
  • Conduct A/B testing for new features
  • Identify and fix bugs and technical issues
  • Optimize app performance
  • Develop new features based on user needs

2.2 To Personalize Your Experience

  • Customize content and recommendations
  • Remember your preferences and settings
  • Adapt AI suggestions to your profile
  • Provide relevant task recommendations
  • Tailor notifications to your interests

2.3 To Communicate with You

Service Communications:

  • Send confirmation emails for account creation
  • Notify you of subscription changes
  • Send payment receipts and invoices
  • Alert you to terms or policy changes
  • Provide important service updates

Marketing Communications (with your consent):

  • Send promotional emails about new features
  • Notify you of special offers or discounts
  • Share tips and best practices
  • Conduct surveys and request feedback
  • Send newsletters (you can opt out anytime)

Push Notifications (with your permission):

  • Daily task reminders
  • Streak maintenance alerts
  • Achievement unlocks
  • Goal progress updates
  • App update notifications

2.4 For Security and Fraud Prevention

  • Detect and prevent fraudulent activity
  • Monitor for security vulnerabilities
  • Protect against spam and abuse
  • Enforce our Terms of Service
  • Verify your identity
  • Investigate suspicious activity

2.5 For Legal Compliance

  • Comply with applicable laws and regulations
  • Respond to legal processes (subpoenas, court orders)
  • Enforce our legal rights and agreements
  • Protect our property and safety
  • Defend against legal claims

2.6 For Analytics and Research

  • Understand how users interact with the App
  • Analyze trends and usage patterns
  • Conduct research to improve AI models
  • Generate anonymized statistics
  • Create aggregated reports
  • Benchmark performance

Anonymized Data:

We may anonymize your data and use it for industry research, AI model training, statistical analysis, and public sharing of aggregated trends. Once data is anonymized, it is no longer considered personal information and may be used without restriction.

3. How We Share Your Information

We do not sell your personal information. However, we may share your information in the following circumstances:

3.1 With Your Consent

We may share your information with third parties when you explicitly consent, such as sharing achievements on social media, connecting with other services you authorize, or participating in referral programs.

3.2 With Service Providers

We share information with third-party service providers who perform services on our behalf:

Supabase (Database and Authentication)

Stores user account data, tasks, goals, and app content. Provides authentication services.

Privacy Policy: https://supabase.com/privacy

Google Gemini API (AI Services via OpenRouter Proxy)

Processes profile data to generate business ideas and daily tasks. All requests are sent through secure Edge Functions.

Google Privacy: https://policies.google.com/privacyOpenRouter Privacy: https://openrouter.ai/privacy

RevenueCat (Payment Processing)

Manages subscription status and billing. Processes transactions via App Store/Google Play.

Privacy Policy: https://www.revenuecat.com/privacy

Expo Push Notifications (Notification Delivery)

Delivers push notifications and manages notification preferences.

Privacy Policy: https://expo.dev/privacy

3.3 For Legal Reasons

We may disclose your information if required or permitted by law to comply with legal obligations, respond to government requests, enforce our Terms, or protect rights and safety.

3.4 In Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before this happens, and you will have the right to delete your data.

3.5 Anonymized and Aggregated Data

We may share anonymized and aggregated information that does not identify you for research, marketing, or industry statistics.

4. Third-Party Services

Our App integrates with third-party services, each with their own privacy practices. We strongly advise you to review the privacy policy of every site or service you visit. We have no control over and assume no responsibility for third-party content or practices.

5. Data Security

5.1 Security Measures

We implement appropriate technical and organizational security measures, including:

  • Encryption: Data in transit (TLS/HTTPS) and sensitive data at rest.
  • Access Controls: Role-based access and multi-factor authentication for administrative access.
  • Database Security: Row-level security policies in Supabase and regular audits.
  • Application Security: Secure API key management and input validation.
  • Monitoring: Real-time security monitoring and incident response plans.

5.2 Security Limitations

No method of transmission over the Internet is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and reporting suspected security issues.

5.3 Data Breach Notification

In the event of a data breach, we will notify you within 72 hours and inform relevant authorities as required by law.

6. Data Retention

Active Accounts:

Account data and user content are retained while your account is active. Usage data is retained for up to 2 years.

Inactive Accounts:

Anonymous accounts are deleted after 30 days of inactivity. Authenticated accounts are deleted after 1 year of inactivity.

Deleted Accounts:

Most personal data is deleted within 30 days. Some data may be retained for legal compliance (e.g., tax purposes).

7. Your Privacy Rights

7.1 Access and Portability

You have the right to request a copy of your personal data and receive it in a structured, machine-readable format.

7.2 Correction and Deletion

You have the right to update inaccurate data or request deletion of your personal data through App Settings or by contacting us.

7.3 Opt-Out Rights

You can opt out of marketing communications, push notifications, personalized advertising, and certain analytics through App or device settings.

7.4 Automated Decision-Making

We use AI to generate suggestions. You have the right to understand how these are made and provide feedback. AI content is advisory only.

8. Children's Privacy

The App is intended for users aged 16 and older. We do not knowingly collect information from children under 16. If we discover a user is under 16, we will immediately delete their account and data.

Advisory for Users Aged 16-17:

We strongly recommend discussing your use of this App and any business decisions with a parent, guardian, or trusted adult.

9. California Privacy Rights

California residents have specific rights under the CCPA/CPRA, including the Right to Know, Right to Delete, Right to Opt-Out, and Right to Non-Discrimination. To exercise these rights, email veltoais@gmail.com with subject "California Privacy Request".

10. Quebec Privacy Rights

As a Quebec-based entity, we comply with Law 25. Residents have rights to access, rectification, withdrawal of consent, and portability. Contact us with subject "Quebec Privacy Request".

11. European Data Protection Rights

If you are in the EEA, UK, or Switzerland, you have rights under the GDPR, including access, rectification, erasure, and objection. We process data based on contract performance, legitimate interests, consent, and legal obligations.

12. International Data Transfers

Your information may be processed in countries other than your residence, primarily Canada and the United States. We ensure appropriate safeguards are in place for these transfers.

13. Do Not Track

Currently, we do not take action in response to Do Not Track signals. You can control tracking through device-level privacy settings and App settings.

14. Changes to This Privacy Policy

We may update this Privacy Policy. We will notify you of changes via email or in-app notification. Continued use constitutes acceptance of the updated terms.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:

VeltoAI

Sole Proprietorship (Quebec, Canada)

Email: veltoais@gmail.com

Location: Quebec, Canada

Business Hours: Mon - Fri, 9:00 AM - 5:00 PM EST

By using the VeltoAI App, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.

Version: 1.0 | Last Updated: September 30, 2025