Legal

Privacy Policy

Last updated: June 2026

1. What We Collect

We collect the minimum data needed to operate the service: Account data • Email address (required for account creation via AWS Cognito) • First and last name (optional, set in your profile) • Avatar photo (optional, uploaded by you) Usage data • Nutrition label photos and food photos you upload — stored in AWS S3 • Analysis records linked to your account — stored in AWS DynamoDB. If you share an analysis using its share link, anyone with that link can view that analysis. The link is unguessable but is not password-protected, so only share it with people you trust. • Journal entries you create: food notes, personal grades, and any photos you attach — stored in AWS S3 and DynamoDB Health and fitness data (optional) • If you connect Apple Health or Health Connect, we access the health categories you authorize — such as body weight, steps, exercise, active energy, basal metabolic rate, nutrition, and hydration. This is optional and off until you grant permission. See "Health and Fitness Data" below for the full breakdown of what we read, what we write, and how we handle it. Quiz data • Quiz responses are stored only in your browser's localStorage. We do not send quiz answers to our servers. Payment data • All payments are processed by a PCI-DSS compliant payment provider acting as our Merchant of Record. We receive only a customer ID and subscription status — we never see or store your card details. Analytics and error data • PostHog collects anonymised product usage events (pages visited, features used) to help us improve the product. • Sentry captures error reports that may include your email address in error context.

2. How We Use It

We use the data we collect to: • Provide and improve the Svelio service • Authenticate your account and manage your subscription • Process and display nutrition analysis results to you • Store your journal entries and make them available to you • Send transactional emails (account confirmation, password reset, billing receipts) • Monitor and fix errors and performance issues • Understand which features are most useful and where to invest next We do not sell your data. We do not use your uploaded photos or journal entries for advertising, model training, or any purpose beyond delivering the service to you.

3. Health and Fitness Data (Apple Health & Health Connect)

Svelio can connect to Apple Health (HealthKit) on iOS and Health Connect on Android. This connection is entirely optional and only activates after you grant permission through your device's system health-permission screen. You choose which categories to share, and you can change or revoke this access at any time in your device settings (iOS: Settings → Health → Data Access & Devices → Svelio; Android: Health Connect → App permissions → Svelio). Health data we read — only the categories you authorize • Body weight • Active energy / calories burned • Basal metabolic rate • Steps • Workouts and exercise We read these to show your activity and weight alongside your nutrition in the app, and to keep your Svelio dashboard in sync with what your phone already tracks. Health data we write — only the categories you authorize • Nutrition (calories and macronutrients from meals you log) • Hydration (water you log) • Body weight (weight entries you record in Svelio) We write these so the meals, water, and weight you log in Svelio appear in your phone's health platform and stay consistent with your other health and fitness apps. How we handle health and fitness data • We access health and fitness data only with your explicit, per-category permission, and only to provide the features described above. • Health and fitness data is never sold, never shared with third parties, and never used for advertising, marketing, or to train machine-learning models. Data accessed through Google Health Connect is used solely to provide in-app features and is handled in accordance with the Health Connect Permissions policy. • Weight, nutrition, and hydration values you log in Svelio are stored in your account (AWS DynamoDB, us-east-2 region) as part of your journal. Activity and weight values we read for display are not retained beyond what is needed to show them to you. • Revoking permission stops all future reads and writes immediately. Deleting your account removes the health-related entries stored in your Svelio account, as described in Data Retention.

4. Third-Party Services

Svelio uses the following third-party services to operate: AWS (Amazon Web Services) Storage and database infrastructure. Your uploaded files are stored in AWS S3 (us-east-2 region). Your profile and analysis records are stored in AWS DynamoDB. Authentication is handled by AWS Cognito, which stores your email and name. Payment processor (Merchant of Record) We use a PCI-DSS compliant payment provider acting as our Merchant of Record to process all subscriptions. The provider handles card data, tax collection, fraud screening, and compliance. We receive only subscription status and an opaque customer identifier. Card details are never transmitted to or stored by Svelio. The specific provider and their privacy policy are disclosed in your checkout flow at the time of purchase. PostHog Product analytics. We use PostHog to understand how the product is used — page views, feature clicks, and similar anonymised events. PostHog's privacy policy: posthog.com/privacy. Sentry Error monitoring. Sentry captures unhandled errors to help us diagnose bugs. Error reports may include your email address if you are logged in at the time of the error. Sentry's privacy policy: sentry.io/privacy. No other third parties receive your personal data as part of normal service operation.

5. Cookies

We use a minimal set of cookies: • Session cookie — an httpOnly cookie used to maintain your authenticated session. It contains no personal data, only a session reference. • Refresh cookie — an httpOnly cookie used to renew your session without requiring you to sign in again. We do not use advertising cookies or third-party tracking cookies. PostHog may set a first-party analytics cookie to distinguish unique sessions.

6. Data Retention

Your data is retained for as long as your account is active. If you delete your account, we will delete your profile, uploaded files, and journal entries within 30 days, except where we are required by law to retain records for longer. Our payment provider retains billing records independently for their own legal and compliance purposes. Error logs in Sentry are retained for 90 days.

7. Your Rights

Depending on your location, you may have the right to: • Access the personal data we hold about you • Correct inaccurate data • Request deletion of your data (right to erasure) • Export your data in a portable format • Object to or restrict certain processing • Lodge a complaint with a supervisory authority (EU/UK users: your national data protection authority) To exercise any of these rights, contact us at hello@svelio.io. We will respond within 30 days.

8. Contact

Questions about this Privacy Policy or how we handle your data? Email us at hello@svelio.io. Montebay Innovations LLC — svelio.io

Fact-check us with your AI

Open Svelio in your assistant of choice