Effective date: June 2, 2026
1. Who we are
Velrae Method (“Velrae,” “we,” “us,” “our”) is a personalized food and personal-care scanner that grades products against the conditions and goals of the specific person using them. We are a small, independent project. Our contact email is velraemethod@gmail.com.
This policy covers the Velrae Method app (mobile + progressive web app), the website at velraemethod.com, and the purchase/license-activation flow.
2. Information stored only on your device
The following is stored in your device’s local storage and is never sent to a server we control:
- The conditions, goals, and diet protocols you set up
- Profile names and per-profile settings
- Scan history — products you scanned, the grades, and dates
- Meal logs and daily check-ins (energy, sleep, mood, symptoms, and any optional metrics like blood pressure, glucose, or weight)
- Patterns and insights the app generates
- Recipe and shopping lists, AIP phase data, and any doctor-PDF reports
You can erase all of it any time via Settings → Wipe all data. We have no way to access or recover it.
3. Information sent to outside services as you use the app
Some features need to talk to outside services. Here is the complete list.
AI features (Anthropic / Claude)
Velrae’s optional AI features — Smart Scan (reading a label photo), AI meal interpretation (“describe what you ate”), the AI day summary, and restaurant menu scanning — send the relevant input (the label or menu photo, or the text you provide) to our AI provider, Anthropic, to process it and return a result. These requests are not tied to your identity, and the data is not used to train models. If you never use these features, nothing is sent. Anthropic’s privacy policy: anthropic.com/legal/privacy.
Barcode lookups (OpenFoodFacts)
When you scan a barcode we don’t already recognize, the UPC — and nothing else — is sent to OpenFoodFacts, a public non-profit food database, to fetch the product name and ingredients. The request is anonymous. openfoodfacts.org/legal.
Community product database
When you resolve a product that was previously unknown, the app may anonymously contribute the record (UPC, product name, ingredients) so future scans resolve faster for everyone. This contains no information about you — no identifier, no device fingerprint, no conditions, no grade. You can opt out in Settings → Privacy.
Nothing else
In normal use the app sends no other data to any other server.
4. Information collected when you purchase
When you buy Velrae Method (a one-time $59 purchase, or an optional $29.99/year plan, with an optional Restaurant menu-scan add-on):
- Stripe, our payment processor, collects your payment-card details and email. Stripe is the only party that sees your card information — we never store it. Stripe keeps your email for receipts, refunds, and disputes. stripe.com/privacy.
- Our license backend (Supabase) holds your first name (the in-app license watermark), your email (so we can help if you change phones, lose your code, or reach out for support), and an anonymous device ID for each device you activate (to enforce the device limit). This is the only personal information on our own infrastructure. supabase.com/privacy.
- An anonymous device identifier is generated locally on each device and sent to our backend only to enforce the device limit. It is not derived from any personal information.
When you accept the in-app legal agreement, we store a record that you agreed (date + app version) and a one-way hashed version of your email — we cannot read the original from the hash.
5. Information we never collect
We do not collect or hold your diagnoses, symptom history, scan/meal logs, inferred health data, location, contacts, camera roll, biometrics, or any cross-site tracking data. There is no account system and no user database. The only “identity” we hold is the email + first name from your purchase.
6. Who we share information with
We share only with the services required to run the app and purchase flow:
| Service | What it sees | Why |
|---|---|---|
| Stripe | Payment details + email | Process your purchase; receipts, refunds, disputes |
| Supabase | First name, email, anonymous device IDs | Validate your unlock code; enforce the device limit |
| Anthropic (Claude) | Label/menu photo or text you submit to an AI feature | Process Smart Scan / AI summaries / menu scan and return a result |
| OpenFoodFacts | UPC barcodes (anonymous, only when needed) | Look up unknown products |
| Netlify | Infrastructure-level traffic (anonymous) | Host the app and site |
We do not share information with advertising networks, data brokers, or social platforms. We will disclose information only if legally compelled, and then only the minimum required, notifying you where legally permitted.
7. How long we keep information
- On your device: until you delete it (Settings → Wipe all data).
- Stripe: as long as required for tax/fraud/dispute purposes (governed by Stripe).
- Our license records (Supabase): while the license is active. On a deletion request, we delete the license record and device redemptions within 30 days.
- AI requests (Anthropic): handled per Anthropic’s retention policy; we do not keep a copy linked to you.
8. Your rights, including deleting your data
Velrae has no accounts and no login. Almost everything you track lives only on your phone, so you delete it yourself, instantly, with no request needed:
- Delete everything on your device — open the app and tap Settings → Wipe all data. This erases every scan, diary entry, condition, profile, list and report. We never had a copy, so once it’s gone it’s gone.
- Delete what we hold if you purchased — the only data we store off your device is a license record (first name, email, an anonymous device ID). Email velraemethod@gmail.com with “Delete my data” in the subject and we’ll remove your license record and free your device slots within 30 days. We cannot delete records Stripe is legally required to keep for payment/tax purposes.
- Know what we hold — email us and we’ll tell you (usually just your email, first name, and active license).
- Stop community contributions — toggle off in Settings → Privacy.
We respond to requests within 30 days. California (CCPA/CPRA) and EEA/UK/Switzerland (GDPR) residents have the additional rights granted under those laws (access, deletion, portability, objection, and — because we don’t sell or share personal information — opt-out is preserved by default). To exercise any right, email velraemethod@gmail.com with “Privacy” in the subject. For GDPR, our legal bases are contract (payments/licensing), legitimate interest (anonymous analytics), and consent (community contributions); Stripe and Supabase operate in the U.S. under Standard Contractual Clauses where applicable.
9. Children’s privacy
Velrae Method is intended for adults. We do not knowingly collect personal information from children. A caregiver may create a profile for a child in their care (for example, a parent managing a child’s type-1 diabetes); in that case the caregiver is the account holder and the child’s data lives only on the caregiver’s device, with no server-side record. If you believe a child provided us information, email us and we’ll delete it.
10. Security
We use TLS encryption for all communication between your device and our servers, and standard access controls on our infrastructure. No system is perfectly secure; we will notify affected users as quickly as legally permitted in the event of a breach affecting your information.
11. Changes to this policy
We may update this policy as our practices change. We’ll update the effective date above, and for material changes we’ll post a notice in the app and on the site. The current version always lives at this page.
12. Contact us
For any privacy question or request: velraemethod@gmail.com (put “Privacy” in the subject so it routes correctly). We answer most requests the same week.