Privacy Policy
Last Updated: December 24, 2025
Introduction
VeltoAI ("we," "our," or "us"), a sole proprietorship, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App").
Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the App.
We reserve the right to make changes to this Privacy Policy at any time. We will alert you about any changes by updating the "Last Updated" date of this Privacy Policy. You are encouraged to periodically review this Privacy Policy to stay informed of updates.
Table of Contents
- Information We Collect
- How We Use Your Information
- How We Share Your Information
- Third-Party Services
- Data Security
- Data Retention
- Your Privacy Rights
- Children's Privacy
- California Privacy Rights
- Quebec Privacy Rights
- European Data Protection Rights
- International Data Transfers
- Do Not Track
- Changes to This Privacy Policy
- Contact Us
1. Information We Collect
We collect information about you in various ways when you use our App. The information we collect falls into the following categories:
1.1 Information You Provide Directly
Account Information:
- Email address (if you create an account)
- Apple ID information (if you use Apple Sign-In on iOS)
- Anonymous user ID (if you use the app without signing in)
- Note: Google Sign-In is currently not available
Onboarding Information:
- Age (date of birth)
- Business interests and passions
- Biggest business challenges
- Past experiences and skills assessment
- Existing assets and starting resources
- Familiarity with business tools
- Budget range and financial preferences
- Geographic location (country)
- Time commitment preferences (daily/weekly hours)
- Business goals and motivation
- Selected business idea and industry
- Target audience information
- Business stage (idea, launching, growing)
User-Generated Content:
- Business name and description
- Custom tasks, notes, and task feedback
- Goals (monthly and yearly)
- Daily tasks and completion status
- Task difficulty ratings (easy/medium/hard)
- Weekly journal entries (optional)
- Progress notes and updates
- Comments and feedback on generated content
- Any other content you create within the App
Payment Information:
- Subscription plan selected
- Payment is processed through Apple App Store or Google Play Store
- We do NOT directly collect or store credit card information
- RevenueCat processes payment information on our behalf
Communications:
- Customer support inquiries
- Feedback and survey responses
- Email correspondence with us
1.2 Information Collected Automatically
Device Information:
- Device type and model (e.g., iPhone 14, Samsung Galaxy S23)
- Operating system and version (e.g., iOS 17, Android 14)
- Unique device identifiers (e.g., IDFA, Android Advertising ID)
- Device settings and preferences
- Mobile carrier
- Screen resolution and device orientation
Usage Information:
- App features you use and how you use them
- Time spent on different screens
- Interaction with buttons, tasks, and content
- Navigation paths through the App
- Session duration and frequency
- Task completion rates and task feedback
- Goal progress and achievements
- Gamification metrics (streak count, flame status, XP points, level progression)
- Task snoozing and pause feature usage
- Onboarding completion status
Location Information:
- Approximate location based on IP address
- Country, region, and city-level location
- We do NOT collect precise GPS location
- Location data from onboarding (user-provided, not GPS)
Technical Information:
- IP address
- Browser type (for web features)
- App version
- Crash reports and error logs
- Performance metrics
- Network connection type
Analytics and Tracking:
- App opens and session starts
- Feature usage statistics
- Screen views and navigation patterns
- Task completion events and ratings
- AI generation metrics (tokens used, generation type)
- Subscription events (purchase, renewal, cancellation)
- Error logs and crash reports (anonymized)
- Performance metrics and app version tracking
- Device information (model, OS version, platform)
1.3 Information from Third-Party Sources
Apple Sign-In (iOS only):
- Apple ID
- Email address (if you choose to share it)
- Name (if you choose to share it)
- User verification status
Payment Processors (Apple App Store / Google Play Store via RevenueCat):
- Subscription status (active, trialing, expired, cancelled)
- Payment success/failure events
- Subscription plan (monthly/yearly)
- Subscription renewal dates
- Transaction IDs
- Refund information
- Platform (iOS/Android)
1.4 Cookies and Similar Technologies
We use cookies and similar tracking technologies to track activity on our App and store certain information. Technologies we use include:
Cookies:
- Small data files stored on your device
- Used to remember your preferences and login status
- Enable certain features and functionality
Local Storage:
- Data stored locally on your device
- Used for caching and offline functionality
- Includes user preferences and temporary data
SDKs and Tracking Pixels:
- Mixpanel SDK (optional analytics on mobile devices)
- RevenueCat SDK (subscription management)
- Expo SDK (app framework and device APIs)
- Used for analytics, crash reporting, and attribution
- May collect device and usage information
You can instruct your device to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our App.
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 To Provide and Improve Our Services
Core App Functionality:
- Create and manage your account
- Authenticate your identity
- Process your subscription and payments
- Provide customer support
- Send service-related notifications
AI-Powered Features:
- Generate personalized business ideas using Google Gemini API
- Create daily task recommendations
- Analyze your progress and provide insights
- Suggest goals based on your profile and behavior
- Optimize content recommendations
Gamification:
- Track XP, levels, and achievements
- Maintain streak tracking
- Calculate progress and statistics
- Generate performance insights
App Improvements:
- Analyze usage patterns to improve features
- Conduct A/B testing for new features
- Identify and fix bugs and technical issues
- Optimize app performance
- Develop new features based on user needs
2.2 To Personalize Your Experience
- Customize content and recommendations
- Remember your preferences and settings
- Adapt AI suggestions to your profile
- Provide relevant task recommendations
- Tailor notifications to your interests
2.3 To Communicate with You
Service Communications:
- Send confirmation emails for account creation
- Notify you of subscription changes
- Send payment receipts and invoices
- Alert you to terms or policy changes
- Provide important service updates
Marketing Communications (with your consent):
- Send promotional emails about new features
- Notify you of special offers or discounts
- Share tips and best practices
- Conduct surveys and request feedback
- Send newsletters (you can opt out anytime)
Push Notifications (with your permission):
- Daily task reminders
- Streak maintenance alerts
- Achievement unlocks
- Goal progress updates
- App update notifications
2.4 For Security and Fraud Prevention
- Detect and prevent fraudulent activity
- Monitor for security vulnerabilities
- Protect against spam and abuse
- Enforce our Terms of Service
- Verify your identity
- Investigate suspicious activity
2.5 For Legal Compliance
- Comply with applicable laws and regulations
- Respond to legal processes (subpoenas, court orders)
- Enforce our legal rights and agreements
- Protect our property and safety
- Defend against legal claims
2.6 For Analytics and Research
- Understand how users interact with the App
- Analyze trends and usage patterns
- Conduct research to improve AI models
- Generate anonymized statistics
- Create aggregated reports
- Benchmark performance
Anonymized Data:
We may anonymize your data and use it for industry research, AI model training, statistical analysis, and public sharing of aggregated trends. Once data is anonymized, it is no longer considered personal information and may be used without restriction.
4. Third-Party Services
Our App integrates with third-party services, each with their own privacy practices. We strongly advise you to review the privacy policy of every site or service you visit. We have no control over and assume no responsibility for third-party content or practices.
5. Data Security
5.1 Security Measures
We implement appropriate technical and organizational security measures, including:
- Encryption: Data in transit (TLS/HTTPS) and sensitive data at rest.
- Access Controls: Role-based access and multi-factor authentication for administrative access.
- Database Security: Row-level security policies in Supabase and regular audits.
- Application Security: Secure API key management and input validation.
- Monitoring: Real-time security monitoring and incident response plans.
5.2 Security Limitations
No method of transmission over the Internet is 100% secure. You are responsible for maintaining the confidentiality of your account credentials and reporting suspected security issues.
5.3 Data Breach Notification
In the event of a data breach, we will notify you within 72 hours and inform relevant authorities as required by law.
6. Data Retention
Active Accounts:
Account data and user content are retained while your account is active. Usage data is retained for up to 2 years.
Inactive Accounts:
Anonymous accounts are deleted after 30 days of inactivity. Authenticated accounts are deleted after 1 year of inactivity.
Deleted Accounts:
Most personal data is deleted within 30 days. Some data may be retained for legal compliance (e.g., tax purposes).
7. Your Privacy Rights
7.1 Access and Portability
You have the right to request a copy of your personal data and receive it in a structured, machine-readable format.
7.2 Correction and Deletion
You have the right to update inaccurate data or request deletion of your personal data through App Settings or by contacting us.
7.3 Opt-Out Rights
You can opt out of marketing communications, push notifications, personalized advertising, and certain analytics through App or device settings.
7.4 Automated Decision-Making
We use AI to generate suggestions. You have the right to understand how these are made and provide feedback. AI content is advisory only.
8. Children's Privacy
The App is intended for users aged 16 and older. We do not knowingly collect information from children under 16. If we discover a user is under 16, we will immediately delete their account and data.
Advisory for Users Aged 16-17:
We strongly recommend discussing your use of this App and any business decisions with a parent, guardian, or trusted adult.
9. California Privacy Rights
California residents have specific rights under the CCPA/CPRA, including the Right to Know, Right to Delete, Right to Opt-Out, and Right to Non-Discrimination. To exercise these rights, email veltoais@gmail.com with subject "California Privacy Request".
10. Quebec Privacy Rights
As a Quebec-based entity, we comply with Law 25. Residents have rights to access, rectification, withdrawal of consent, and portability. Contact us with subject "Quebec Privacy Request".
11. European Data Protection Rights
If you are in the EEA, UK, or Switzerland, you have rights under the GDPR, including access, rectification, erasure, and objection. We process data based on contract performance, legitimate interests, consent, and legal obligations.
12. International Data Transfers
Your information may be processed in countries other than your residence, primarily Canada and the United States. We ensure appropriate safeguards are in place for these transfers.
13. Do Not Track
Currently, we do not take action in response to Do Not Track signals. You can control tracking through device-level privacy settings and App settings.
14. Changes to This Privacy Policy
We may update this Privacy Policy. We will notify you of changes via email or in-app notification. Continued use constitutes acceptance of the updated terms.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:
VeltoAI
Sole Proprietorship (Quebec, Canada)
By using the VeltoAI App, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.
Version: 1.0 | Last Updated: September 30, 2025