1. Data Vela accesses
Vela processes only data needed for its visible fitness-guidance features:
- Google Health: read-only sleep, steps, active minutes, active energy, resting heart rate, heart-rate variability and weight records.
- Hevy: workouts, exercises, sets, repetitions, load and session duration.
- Android Health Connect: owner-authorised menstrual period and flow records sent through an explicit foreground sync.
- Information entered directly into Vela: subjective check-ins and feedback about recommendations.
Vela requests read-only Google Health permissions. It does not use those permissions to modify Google Health records.
2. Why the data is used
Vela uses the data to provide features visible within the private application:
- daily sleep, recovery, activity, weight and training context;
- personal baselines and changes relative to those baselines;
- deterministic, evidence-linked fitness recommendations;
- completed-workout summaries, trends and weekly reviews; and
- evaluation of whether earlier recommendations were useful.
Vela does not use this information for advertising, credit decisions, insurance, medical diagnosis, regulated medical-device functions or human-subject research.
3. Storage and security
Normalised health and fitness records are stored in a private Google Cloud Firestore database in the London region. Provider responses are processed transiently and are not retained by default. OAuth credentials and API keys used by deployed import jobs are stored in Google Secret Manager rather than in application code or the database.
Data is encrypted in transit using HTTPS and encrypted at rest by the managed cloud services. The web application is protected by Google Identity-Aware Proxy and is restricted to the owner. Least-privilege service identities separate the web, API and ingestion boundaries.
4. Sharing and transfers
Vela does not sell personal or health data, use it for advertising or disclose it to data brokers. Google Cloud processes data only as the infrastructure provider used to operate the private application.
Google Health data is not currently sent to OpenAI. AI explanations remain disabled for live Google-derived evidence unless Vela first implements a separate, explicit and revocable consent flow. This policy will be updated before any such transfer is enabled.
Vela’s use of information received from Google Health APIs follows the Google Health API Developer and User Data Policy, including its Limited Use requirements.
5. Retention and deletion
Normalised provider records and Vela-created decision history are retained while they remain useful to the owner. Completed operational sync-run records expire after 90 days. Raw provider response bodies are not retained by default.
Revoking a provider connection stops future collection but does not automatically delete records already stored by Vela. Because Vela is single-user and has no public account-management interface, retained-data deletion is performed through a protected backend maintenance process. A deletion request can be made using the contact address below.
6. Owner controls
The owner can:
- review source freshness and connection status inside Vela;
- revoke Google access through the Google Account permissions page;
- revoke Hevy or Health Connect access at the provider or device; and
- request deletion of retained Vela data through the contact address below.
7. Public website
This public information website does not use analytics, advertising, cookies, forms or health-data APIs. It does not provide access to the private Vela application or its stored records.
8. Changes and contact
This policy will be updated when Vela materially changes its data access, use, storage, sharing or deletion behaviour. The effective date above identifies the current version.
Privacy questions and deletion requests: privacy@vela-fitness.com