Velmira — Privacy Policy
Effective: 2026-08-16
Velmira is operated by Trelinx Pte Ltd (UEN 202601108H), a Singapore private limited company, at 60 Paya Lebar Road #06-28 Paya Lebar Square, Singapore 409051. Questions or requests: support@velmira.io.
1. What Velmira is
Velmira helps you keep track of lab results, supplements and medications, reminders, and notes about your health. It includes an educational AI assistant.
Velmira is an educational and wellness product. It is not a medical device, it does not diagnose, and it does not give medical advice. Nothing in it replaces your doctor or pharmacist. We are not a HIPAA-covered entity and we do not describe ourselves as one.
You must be 18 or over to use Velmira.
2. What we collect
Only what you give us, or what the app needs to work:
- Health information you enter or upload — lab reports (the photo or PDF, and the values read from it), supplements and medications with their schedules, doses you log, and your notes.
- A little about you — date of birth, sex at birth, and whether you prefer metric or imperial. We ask for date of birth because some lab reference ranges depend on age.
- Account information — how you sign in (today that is a Google account) and any recovery codes we have issued you.
- Assistant conversations — what you ask, and what it answers.
- Technical information — a push token so reminders can reach your phone, and app version and crash information so we can fix problems.
We do not collect your location, your contacts, or your browsing.
3. What the assistant remembers
On a paid plan, the assistant can remember a few durable things you tell it about yourself — a goal, a preference, something your clinician told you — so it still knows them when you start a new conversation.
It never remembers your lab values, your doses, or your schedules. Those are looked up fresh from your records every time, so it cannot repeat a number that has since changed. You can see everything it has remembered, and delete any of it, in the app under Profile → Assistant memory.
Conversations are sent to Amazon Web Services to generate a reply. They are not used to train anyone's models.
4. How we use your information
To run the app for you: show your data back to you, send the reminders you asked for, read your lab documents, answer your questions, keep your account secure, and fix problems.
We do not sell your information, and we do not use it for advertising.
5. Who else sees it
Only the services we need to run Velmira, and only for that:
- Amazon Web Services — hosting, storage, and the assistant's model.
- Google Firebase — delivering push notifications. Notification text never contains a medication name, a dose, or a value.
- RevenueCat and the app stores — your subscription. We never see your card details.
- Sentry and PostHog — crash and usage reporting, with health information removed before anything is sent.
We may also disclose information if the law requires it, or to protect someone's safety.
Velmira does not currently offer any way to share your health data with another person, including a doctor. If we add that, we will tell you first, and it will be something you turn on yourself.
6. How we protect it
Your data is encrypted on your device and encrypted again on our servers. Every request can only reach your own records — that separation is enforced by the database itself, not only by the app. Access to production systems is limited and logged.
No system is perfectly secure, and we won't pretend otherwise.
7. Deleting your account and data
You can delete your account from inside the app. When you do:
- It enters a 14-day grace period, so you can cancel by signing back in. This exists so an accidental — or coerced — deletion is recoverable.
- After that we permanently erase your health data, keeping only a receipt that the erasure happened — a receipt that contains no health information, so we can prove it and cannot quietly fail to do it. Live systems are erased within 16 days of your request.
- Encrypted backups then age out on their own schedule, so every remaining copy is gone within 55 days of your request. We state the outer bound rather than the typical one, because the typical one isn't a promise we can keep every time.
One honest limit: a small internal cache that makes offline syncing safe can hold recently written content for up to about 7 days beyond your last write, plus a short cleanup delay. No other user can read it, and it cannot be searched by account.
Deleting a note, or something the assistant remembered, removes it straight away. Ending a protocol stops its reminders but keeps the doses you already logged, because that history is part of your record — it goes when your account does. You cannot yet delete a single lab report from inside the app: write to support@velmira.io and we will delete it for you. Deleting the app from your phone does not delete your account.
8. Your rights
Write to support@velmira.io and we will help you access, correct, or delete your information, get a copy of it, or ask us to stop using it. Depending on where you live you may also have the right to complain to a data protection authority. We will not treat you differently for asking.
9. Where your data is processed
Velmira is operated from Singapore. Your data is stored and processed on servers in the United States.
10. Children
Velmira is not for anyone under 18, and we do not knowingly collect information from children. If you believe a child has given us information, write to us and we will delete it.
11. Changes
If we change this policy in a way that matters, we'll tell you in the app before it takes effect.