Privacy Policy

Last updated August 1, 2026

Does my health data leave my phone?

Mostly no. Velisa has no account, no server, and no analytics of any kind. Everything you log is stored in a database inside the app's own private storage on your iPhone. Nothing leaves that phone unless you specifically connect something that needs it to:

Nothing here is ever used for advertising, sold, or shared with a data broker. There is nothing to sell it with — there is no server holding a copy of it.

What Velisa is

Velisa is an iOS app for tracking training, sleep, nutrition and recovery, built by a single independent developer. It is not backed by a company with a data team, a marketing department, or a reason to want your data for anything other than showing it back to you.

Where your data lives

Everything you log — workouts, food entries, weigh-ins, sleep sessions pulled in from a connected source, and every score Velisa computes from them — is written to a SQLite database inside Velisa's own private container on your iPhone. There is no Velisa server. This isn't a policy of minimizing what a server stores; there is no server component to this app at all, so there is nowhere else for that database to be.

Velisa does not use Apple's iCloud sync (CloudKit) to copy or share your data between devices — there is no code in the app that does this, and nothing about your data syncs anywhere on its own.

One honest nuance worth stating plainly: if you have iPhone Backup turned on in your iPhone's own Settings (to iCloud, or to a computer), your regular phone backup will include Velisa's local database — the same way it includes most other apps' local data on your phone. That is a feature of how iOS backs up your device generally, not something Velisa does on its own, and Velisa has no separate switch for it because it isn't a separate thing Velisa is doing. Apple Health data itself is different: Apple excludes the Health app's own store from iCloud backups automatically, independent of anything Velisa does.

Deleting the app deletes the local database immediately. A phone backup made before that, if you have one, still holds a copy until you overwrite it with a new backup or delete the old one yourself — the same as for any other app.

Apple Health

What Velisa reads (with your permission, granted per data type in the iOS permission screen): heart rate, resting heart rate, heart-rate variability, respiratory rate, blood oxygen, steps, active energy, VO₂ max, and sleep (duration, efficiency and stage). Read-only by default.

What Velisa can write, only if you turn it on: Settings has a toggle, off by default, for writing your logged workouts back to Apple Health. If you turn it on, a workout you finish in Velisa is written to Apple Health as a workout session, together with the active energy burned during it — but only when Velisa has a real, measured calorie figure for that session. If it doesn't, the workout is written without one rather than with a guessed number. Velisa's own computed scores — Recovery Score, Velisa Age, and everything else in Scoring — are never written to Apple Health; they stay inside Velisa.

Health data read through HealthKit is never used for advertising or marketing, never shared with a third party for those purposes, and never written to iCloud by Velisa.

Velisa does not access your location, your microphone, or your contacts. The camera is used only for the scanner (below).

Connected wearables — Whoop

If you choose to connect a Whoop account (Connected Sources in Settings), you sign in through Whoop's own login screen — Velisa never sees or stores your Whoop password. Whoop hands back an access token, which Velisa stores in your iPhone's Keychain and uses to pull your own recovery, sleep, workout, day-strain and body-measurement data, plus your Whoop profile name and email, from Whoop's API — so Velisa can show it next to everything else you log. Disconnecting removes the stored token immediately. This is a read connection: Velisa does not send data to Whoop, only the standard sign-in exchange.

Amazfit and other wearables

Amazfit Helio data reaches Velisa the same way Apple Watch data does — through Apple Health, once Zepp (Amazfit's own app) has written it there — subject to the same read-only rules above. A Bluetooth chest strap connects directly, phone to strap, with no server involved on either side.

There is also a direct-Bluetooth path to Whoop and Amazfit hardware that bypasses Apple Health and Whoop's own API entirely — but it only exists in the developer's own personal build (compiled with a flag named PERSONAL_BUILD), which by its own build rules is never distributed to TestFlight or the App Store. It has no bearing on the app anyone else installs, and is mentioned here only so this page stays complete rather than convenient.

The Coach (optional, off until you set it up)

The Coach needs your own Anthropic API key, which you create yourself at console.anthropic.com and paste into Settings. It is stored in your iPhone's Keychain at the strictest protection level available: unreadable while your phone is locked, excluded from iCloud Keychain sync, and never carried into a restore onto another device. Until a key is set, the Coach does nothing and sends nothing.

When you do ask the Coach something, a compact summary of your own numbers — not a raw data dump — is sent directly to Anthropic's API, using your own key. Precisely what that summary contains:

Explicitly not included: your name, any Velisa-internal or device identifier, raw minute-by-minute sensor readings, or any free-text notes you've typed. Before anything is sent, the Coach's own "What gets sent" screen shows you the literal payload — the same bytes, not a paraphrase — so this isn't a promise you have to take on faith.

Once a message reaches Anthropic, what happens to it there is governed by Anthropic's own privacy policy and terms (anthropic.com) — Velisa has no visibility into or control over their retention.

The photo scanner

Velisa's food scanner has three modes. Two never leave your phone: scanning a barcode and reading a printed nutrition panel are both decoded on-device using Apple's own Vision framework. The third mode — photographing the front of a pack so Velisa can figure out what product it is — does send a photo off the device, to Anthropic, using the same API key and connection as the Coach.

That photo is downscaled before it's sent (capped at roughly 1024 pixels on the long edge, well below a full photo's resolution — plenty to read a brand name off a box, nowhere near enough detail for much else) and is never saved anywhere by Velisa, before or after sending. It exists for the length of that one request and nowhere else.

The model is asked for identity only — brand, product name, variant, pack size, and a barcode if one happens to be legible — and is structurally unable to return a nutrition figure: the format it must answer in has no field to put one in. Every calorie and macro number you see always comes from a database lookup afterward (the bundled offline database, your own saved foods, or a live lookup), never from the photo-identification step itself.

Barcode lookups

Scanning a barcode first checks a nutrition database bundled inside the app, which works with no internet connection at all. If the product isn't in that bundled slice, Velisa sends the barcode number to Open Food Facts' public database — a plain, unauthenticated lookup, no account or key involved. Only the barcode number travels; nothing about you does.

Contributing scan data back (opt-in, off by default)

There is a separate setting, off by default, for offering to send a confirmed nutrition panel back to Open Food Facts when it didn't have a product you scanned. It only ever runs when all of these are true: you've turned the setting on, Open Food Facts genuinely didn't have the product, and you've then read the pack yourself and confirmed the numbers. You see the exact fields before anything is sent. What's included: the barcode, the numbers on the pack, the product name/brand/size, and Velisa's own app-identity fields (so a bad batch of submissions can be traced and reverted) — never your identity, and never a photo of the pack.

What Velisa does not collect

Payments

Handled entirely by Apple through the App Store's in-app purchase system. Velisa never sees a card number, a billing address, or any payment detail — Apple is the merchant of record and hands Velisa only a signed receipt saying whether this Apple Account currently holds an active subscription. There is nothing for Velisa to hold, and nothing it could leak, because it never touches your payment information at all. The app starts with a free 30-day trial that needs no card up front; a subscription is required to keep most of the app working after that, but exporting your own data stays free permanently, even if the app is otherwise locked.

Children

Velisa is not directed at, or marketed to, children. Using it meaningfully requires setting up your own training and nutrition profile, connecting your own wearable or health data, and — after a 30-day trial — a paid subscription, none of which describe a child user. Velisa does not knowingly collect data from children, and no part of the app is designed with a child audience in mind.

Your rights and choices

Because there is no separate copy of your data anywhere Velisa controls, most of what a privacy law asks for — see it, get a copy, delete it — is already true right now, on your own phone, under your own control:

The three services Velisa can send data to at your own direction — Whoop, Anthropic, and Open Food Facts — each hold and govern whatever you sent them under their own privacy policies. Velisa doesn't operate any of those services and can't delete data on your behalf from one of them; to have a copy removed from their side too, you'll need to go through that provider directly (for example, your own Whoop account settings, or your own Anthropic console).

Data retention

On your phone: for as long as you keep it there. Velisa doesn't age data out or delete it on a schedule — a fact you logged five years ago is still there unless you remove it or delete the app. There's nothing held anywhere else to retain, because there's nowhere else it goes on its own.

Security

Third-party credentials live in the iPhone Keychain, never in a plain settings file. The Anthropic key is stored at the strictest protection level Apple offers for this: unreadable while the phone is locked, excluded from iCloud Keychain sync, and never carried into a restore onto a different device. The Whoop token is also Keychain-protected and excluded from iCloud Keychain sync, though — unlike the Anthropic key — it can be included in an encrypted local backup you make of your own phone, the same as most apps' saved sign-in tokens; it is never synced automatically across your devices either way.

Changes to this policy

If what Velisa collects or sends changes, this page changes with it and the "last updated" date at the top moves. There's no mailing list to notify, so the date is the signal — check back here if you want to know what changed since you last read it.

Contact

Questions about this policy or how Velisa handles data can be sent to [email protected].


This policy describes exactly what the app's code does, checked against the source by the person who wrote it — it is not legal advice, and this is not a substitute for a lawyer's review if you need one for a specific question. The entity publishing this app is Behlaah Dossaji, and any dispute arising from it is governed by the laws of India, with jurisdiction in the courts of Karnataka.