Last updated: April 22, 2026
Veste Health, a brand of ProActive Solutions for Life, LLC ("we", "us", "our") operates VERA (Veste Evidence-Based Response Agent). This policy explains how we collect, use, and protect your information.
Pending full legal review with counsel. The sections below reflect our good-faith description of current practices.
1. Information We Collect
Information you provide: Name, email (if you create an account), age, sex, height, weight, health goals, daily check-in data (mood, sleep, stress, energy), lab results, supplement lists, meal logs, and any messages you send to VERA.
Information we do NOT collect: Social Security numbers, insurance information, medical record numbers, or any data from your healthcare providers.
2. How Your Data Is Stored
Device storage: If you choose "On this device only," your data is stored in your browser's localStorage. It never leaves your device. We cannot access it.
Cloud storage: If you choose cloud storage, your data is encrypted and stored via Supabase (hosted on AWS) with encryption at rest and in transit. Only you can access your data through your authenticated account.
File backup: If you choose file backup, data is exported as a JSON file that you save wherever you choose.
3. How We Use Your Information
Your health data is used solely to:
- Provide personalized wellness guidance and recommendations
- Calculate nutrition targets and track health trends
- Generate reports and health summaries at your request
- Improve VERA's responses within your conversation
We do NOT:
- Sell your data to third parties — ever
- Share your data with advertisers
- Use your data to train AI models
- Share your information with healthcare providers unless you explicitly export and send it yourself
4. AI Conversations and Deep Memory
When you chat with VERA, your messages are sent to Anthropic's Claude API via a secure server-side proxy (Supabase Edge Function). Your API key and messages never pass directly from your browser to Anthropic. Anthropic does not use API conversations to train their models.
Anthropic data retention: per Anthropic's published API policy, API request data is retained for up to 30 days for safety and abuse monitoring, then deleted. Anthropic acts as a data processor — they do not own your data and cannot use it for training, advertising, or any purpose beyond processing your request and safety review.
Lab PDFs and meal photos: when you upload a lab report PDF or meal photo, the file is sent to Anthropic's Claude Vision through the same secure proxy to extract structured values. The same 30-day Anthropic retention applies. A one-time consent notice appears before your first upload.
Deep Memory: VERA builds a persistent profile of key facts about you from your conversations (conditions, medications, preferences, goals). This profile is stored in your browser's localStorage and, if you use cloud sync, in your Supabase account. You can view, edit, or delete any item in Settings under "What VERA Knows About Me."
When you delete data, VERA also deletes any AI-generated summaries, synthesis reports, and learned profile items derived from that data.
Crisis content (messages related to self-harm, suicidal ideation, or medical emergencies) is never logged to any tracker, profile, or persistent storage. It is used only to display immediate crisis resources.
5. AI-Generated Reports
VERA generates weekly and monthly health reports ("synthesis") based on your data. These are AI-generated observations, not diagnoses. They are labeled accordingly and should be discussed with your healthcare provider.
6. Third-Party Services (Subprocessors)
These are the third parties that process your data on our behalf. We sign Data Processing Agreements with each of them. They cannot use your data for their own purposes.
- Supabase (United States): Cloud database, authentication, and server-side API proxy.
- Anthropic (United States): AI conversation and analysis processing via secure proxy. API request data retained up to 30 days for safety review, then deleted. Not used for training.
- OpenAI (United States): Voice synthesis (text-to-speech) for VERA's spoken replies. Voice text is sent to OpenAI only when you have voice replies enabled. Not used for training.
- Stripe (United States): Payment processing. We never see or store your card number.
- Resend (United States): Transactional email delivery (welcome, weekly synthesis, trial reminders, support).
- Cloudflare (United States): Web hosting, DNS, CDN, and bot-protection (Turnstile) for the signup page.
This list will be updated if we add or change subprocessors. For the current canonical list, email privacy@vestehealth.com.
7. Analytics
We collect basic usage analytics (features used, message count) stored in our own Supabase database — not with any third-party analytics provider. We do not use Google Analytics or any tracking service that could access your health data. Analytics help us understand which features are valuable and improve VERA.
8. Your Rights
You have the right to:
- Access all your stored data at any time
- Export your data as a JSON file
- Delete your data and account at any time
- Correct inaccurate information in your profile or the "What VERA Knows About Me" page
- Choose where your data is stored (device, cloud, or file)
- Withdraw consent for marketing communications at any time via Settings → Communication Preferences
California residents (CCPA/CPRA): you have additional rights, including the right to know what personal information we collect, the right to delete it, the right to correct it, and the right to opt out of any "sale" or "sharing" of it. We do not sell personal information and have not in the past 12 months. To exercise these rights, email privacy@vestehealth.com.
Washington residents (My Health My Data Act): you have the right to confirm whether we process your consumer health data, access that data, delete it, and withdraw consent for its collection or sharing. We do not share consumer health data with third parties for advertising or marketing. To exercise these rights, email privacy@vestehealth.com.
9. Data Retention
We retain your personal and health data for the life of your account. When you delete your account, we permanently delete all data within 30 days from both our primary database (Supabase) and any backup snapshots.
- Chat history: retained until you delete it or your account.
- Health logs, device data, labs: retained until you delete them or your account.
- Weekly and monthly synthesis reports: retained in your archive until you delete them or your account.
- AI processing logs at Anthropic: retained by Anthropic for up to 30 days per their API policy, then deleted.
- Consent receipts: retained for the life of the account as an audit trail, then deleted when the account is deleted.
- Analytics events: aggregated usage metrics retained indefinitely; personal identifiers removed after 90 days.
10. HIPAA Notice
VERA is a wellness and educational tool, not a healthcare provider. VERA is not a "covered entity" under HIPAA. The health information you voluntarily enter into VERA is not Protected Health Information (PHI) under HIPAA. If you have concerns about your health data, we recommend using device-only storage.
11. Children's Privacy
VERA is not intended for users under 13 years of age. We do not knowingly collect information from children under 13.
12. Accessibility
Veste Health, a brand of ProActive Solutions for Life, LLC is committed to ensuring digital accessibility for people with disabilities. VERA is designed and developed in conformance with the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA standards and the Americans with Disabilities Act (ADA). Our accessibility features include keyboard navigation, screen reader compatibility, ARIA landmarks and labels, sufficient color contrast, reduced-motion support, responsive design for all devices, and touch-friendly interface elements. If you experience any accessibility barriers while using VERA, please contact us at accessibility@vestehealth.com.
13. Changes to This Policy
We may update this policy from time to time. We will notify users of significant changes through the app.
14. Contact
Questions about this policy? Contact us at privacy@vestehealth.com