By using the App, you consent to the data practices described in this Privacy Policy. This Policy should be read in conjunction with our Terms of Service. If you do not agree with this Privacy Policy, please do not use the App.
01 Information We Collect
We collect information in the following categories. Due to our encryption architecture, much of your most sensitive data is inaccessible to us even in its stored form.
1.1 Information You Provide Directly
| Data category | Specific data points | Encryption status |
|---|---|---|
| Account Data | Email address, display name, password (hashed by Firebase Auth), gender, relationship goal | Stored in plaintext on Firebase (except password, which is hashed). Protected by Firestore security rules. |
| Messages | Text messages, position suggestions between paired users | 🔒 End-to-end encrypted. Stored as ciphertext. Company cannot read. |
| Photographs | Photos shared between paired users, profile photos | 🔒 Shared photos: E2E encrypted, stored as ciphertext. Profile photos: stored in plaintext. |
| Health & Cycle Data | Last period date, average cycle length, cycle phase, fertility window estimates, cycle history | Stored locally on device via AsyncStorage. Period dates synced to Firebase calendar as encrypted events. |
| Intimacy Data | Intimacy dates, ratings, frequency, analytics data | Core dates stored locally via AsyncStorage. Calendar events synced to Firebase for partner visibility. |
| Mood Signals | "Go Time" / "Romance" / "Beware" mood status, initiator ID, timestamps | Stored in plaintext on Firebase. Auto-expires after 12 hours. |
| Fantasy Vault | Individual fantasy selections from categorized options | Stored on Firebase. Individual selections visible only to the selecting user; mutual matches revealed to both. |
| Love Languages | Assessment answers, calculated love language scores and results | Stored on Firebase. Results shared with paired partner. |
| Connection Points | Points totals, streaks, reef growth levels, milestones, relationship snapshots, activity history | Stored on Firebase. Shared between paired users. |
1.2 Information Collected Automatically
- Device Information: Device name, operating system (iOS/Android), platform identifier, stored via push notification registration.
- Push Notification Tokens: Expo Push Token, associated device name, token update timestamps, stored in your Firebase user profile for notification delivery.
- Usage Metadata: Message timestamps, conversation existence indicators, read receipts, last app open time, screenshot detection events and counts.
- Local Storage Data: The App stores certain data locally on your device via AsyncStorage, including: user PIN (optional), email/name cache for offline access, nudge settings and preferences, AI Concierge daily usage counters, cycle tracking data, and intimacy dates/ratings. This data does not leave your device unless specifically synced to Firebase as described above.
1.3 Information We Do NOT Collect
We want to be explicit about what we do not access: (a) the decrypted contents of your encrypted messages, photos, or position suggestions; (b) GPS location or geolocation data (location for AI Concierge is provided manually by the user, not tracked); (c) contacts, call logs, or SMS from your device; (d) browsing history; (e) data from other apps; (f) biometric data; or (g) financial or payment information (payments are handled entirely by Apple/Google).
02 How We Use Your Information
- Service Operation: To create and manage your Account, facilitate pairing with your partner, deliver encrypted messages and photos, process calendar events, compute cycle phases, manage mood signals, calculate connection points, and operate all App features.
- Notifications: To deliver push notifications for new messages, mood changes, calendar reminders, relationship nudges, and milestone celebrations using your Expo Push Token.
- AI Concierge: To process your prompts, partner name, specified location, and budget through third-party AI services for date planning and relationship advice. Conversation context is sent per-request and not stored by the Company beyond the request lifecycle.
- Google Places Integration: To search for venues, retrieve place details, and display photos through the Google Places API based on your manual location input.
- Screenshot Alerts: To detect and notify your partner when screenshots are taken of shared photos or self-destructing content, and to maintain screenshot count records.
- Service Improvement: To understand usage patterns in aggregate (not individual behavior) to improve App features and performance.
Consumer health data: how we handle cycle and intimacy data, and your rights over it, are set out in our Consumer Health Data Privacy Policy.
03 Our Encryption Architecture
Privacy is the foundational principle of Veluma. Our encryption architecture is designed so that the Company cannot access your most sensitive content, even if compelled.
3.1 How Encryption Works
- Device keys: Each device creates its own X25519 key pair. The private key is kept in the device's secure storage (iOS Keychain / Android Keystore) and never leaves the device; only the public key is uploaded.
- Couple key: When both partners are on a supported version of the App, one of your devices creates a random 256-bit couple key. It is shared with each of your and your partner's devices by sealing it to that device's public key (X25519 key agreement, HKDF-SHA-256, AES-256-GCM). Our servers store only these sealed copies, which only the intended device can open.
- What is encrypted: Text messages, position suggestions, shared photos, private calendar event details, Fantasy Vault selections and couple game entries are encrypted on the sending device with AES-256-GCM before they are uploaded, and decrypted only on your and your partner's devices.
- Upgrading from older versions: Earlier versions of the App used a key derived from account identifiers, which offered weaker protection. While one partner is still on an older version, the App continues to use that older method so your conversation keeps working; once both partners have updated, the App switches to end-to-end keys and re-encrypts your existing history in the background.
- New or replaced devices: A new device receives the couple key from one of your or your partner's existing devices the next time that device opens the App. If both partners lose all of their devices, encrypted history cannot be recovered — not even by us.
- What we can and cannot see: We cannot decrypt end-to-end encrypted content, and a request for it would yield only ciphertext. We can see the data listed in 3.2 and metadata such as when messages are sent and their type (text, photo, position). You can compare the safety code shown in the App with your partner's to confirm no one has interfered with your keys.
3.2 What Is NOT Encrypted
For transparency, the following data is stored in a readable format on Firebase servers: account profile information (name, email, gender, relationship goal), pair codes and pairing status, mood signals, the date of calendar events (used to sort them; the event type and notes are encrypted), connection points and gamification data, love language assessment results, heat-map and conflict-tool entries, cycle data you choose to sync, and push notification tokens. Push notifications never contain the text of your messages. This data is protected by Firebase Authentication and Firestore security rules that restrict access to authenticated users.
04 Data Storage and Security
4.1 Cloud Infrastructure
App data is stored on Google Firebase infrastructure (Firestore Database, Firebase Authentication). Firebase provides: encryption in transit (TLS/SSL), encryption at rest for stored data, SOC 1/2/3 and ISO 27001 certified data centers, and enterprise-grade physical and network security. For more information, see Google's security documentation at firebase.google.com/support/privacy.
4.2 Local Device Storage
The App stores certain data locally on your device using AsyncStorage and (where available) Expo SecureStore. Local data includes: optional app PIN, cached user credentials for session management, nudge preferences and settings, cycle tracking data, intimacy dates and ratings, and AI Concierge usage counters. Local data is subject to your device's own security measures (passcode, biometric lock, encryption).
4.3 Firestore Security Rules
Access to Firebase data is governed by Firestore security rules that enforce: (a) authentication requirements for all read/write operations; (b) user-level restrictions where users can only write to their own profile; (c) conversation data accessible only to authenticated participants; and (d) storage rules restricting photo access to conversation participants based on user ID matching.
06 Data Retention and Deletion
6.1 Retention Periods
- Account Data: Retained for as long as your Account is active.
- Encrypted Messages: Retained until manually deleted by a participant or until Account/pairing termination.
- Self-Destructing Content: Deleted from the database upon TTL expiration after viewing.
- Mood Signals: Auto-expire and are deleted after 12 hours.
- Push Notification Tokens: Updated upon each registration; old tokens are overwritten.
- Local Device Data: Retained on your device until the App is uninstalled or data is manually cleared.
6.2 Account Deletion
You may delete your Account and associated data at any time directly within the App, via Profile → Delete Account. You may also request deletion by contacting us at the email address provided below. Upon Account deletion: (a) your user profile will be removed from Firebase; (b) your pair code will be deactivated; (c) your pairing will be severed; (d) encrypted content associated with your conversations may remain in encrypted (and now permanently undecryptable) form until the conversation or paired partner's Account is also deleted; and (e) connection points, milestones, and gamification data will be deleted. We will process email deletion requests within thirty (30) days.
6.3 Unpairing Effects on Data
When you unpair from a partner: encryption keys derived from that pairing relationship become invalid, meaning previously encrypted content may become permanently unreadable. Connection points, streaks, and reef data are lost. Calendar events, mood data, and other shared data become inaccessible through the App.
07 Your Privacy Rights
Depending on your jurisdiction, you may have certain rights regarding your personal information:
- Right to Access: You may request a copy of the personal information we hold about you.
- Right to Rectification: You may update your profile information directly through the App at any time.
- Right to Deletion: You may delete your Account in the App, or request deletion as described in Section 6.2.
- Right to Data Portability: You may request an export of your data in a machine-readable format.
- Right to Withdraw Consent: You may withdraw consent for optional data processing (e.g., push notifications) at any time through your device settings.
- Right to Object: You may object to certain processing activities by contacting us.
To exercise any of these rights, please contact us using the information provided in Section 12. We will respond to your request within thirty (30) days.
08 California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA): (a) the right to know what personal information is collected, used, and shared; (b) the right to delete personal information; (c) the right to opt-out of the sale of personal information — we do not sell personal information; (d) the right to non-discrimination for exercising your privacy rights; and (e) the right to correct inaccurate personal information. California residents may submit requests by contacting us at the email below. We will verify your identity before processing any request.
09 Children's Privacy
The App is strictly intended for users aged 18 and older. We do not knowingly collect personal information from anyone under the age of 18. The App contains adult content that is inappropriate for minors. If we discover that a user under 18 has created an Account, we will promptly terminate that Account and delete all associated data. If you believe a minor has provided us with personal information, please contact us immediately.
10 International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence, specifically the United States where Firebase data centers are located. By using the App, you consent to the transfer of your information to the United States and other jurisdictions where our service providers operate. We ensure that appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.
11 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by: (a) posting the updated Privacy Policy in the App; (b) sending a push notification; and/or (c) emailing the address associated with your Account. The "Last Updated" date at the top of this Policy will be revised accordingly. Your continued use of the App after any changes constitutes acceptance of the updated Privacy Policy.
12 Contact Information
For questions, concerns, data access requests, or deletion requests regarding this Privacy Policy or our data practices, please contact us at:
- Company
- AA Innovation Group LLC (d/b/a Veluma)
- Privacy Inquiries
- privacy@velumaloveapp.com
- General Support
- support@velumaloveapp.com
- Data Deletion Requests
- privacy@velumaloveapp.com
- Website
- velumaloveapp.com