Privacy Policy

Vela — Spending Companion

Last updated: April 18, 2026

This Privacy Policy describes how Vela ("Vela", "we", "our", or "us") collects, uses, and shares information about you when you use our mobile application and related services (collectively, the "Service"). Please read this policy carefully. By using Vela, you agree to the practices described here.

Vela is operated by an individual developer based in Alberta, Canada. For questions or concerns, contact us at admin@velaawareness.com.

1. Information We Collect

1.1 Account Information

When you create a Vela account, we collect your email address and a password (stored securely via Supabase authentication). You may optionally provide a display name. We do not collect your legal name, phone number, or home address unless you voluntarily provide them.

1.2 Financial and Transaction Data

Vela connects to your bank accounts through Plaid, a third-party financial data platform. When you choose to link a bank account, we receive and store:

  • Bank account names and institution names
  • Transaction history, including dates, amounts, merchant names, and spending categories
  • Account identifiers required to refresh your transaction data

We do not receive or store your full bank account numbers, login credentials, or card numbers. Plaid handles authentication with your financial institution directly. You can review Plaid's privacy practices at https://plaid.com/legal/.

1.3 Subscription Information

Vela uses RevenueCat to manage in-app subscriptions. When you subscribe, RevenueCat processes your payment through Apple or Google and provides us with your subscription status (active, expired, etc.) and a pseudonymous subscriber ID. We do not receive your full payment card details. RevenueCat's privacy policy is available at https://www.revenuecat.com/privacy/.

1.4 Usage and Diagnostic Data

We use Sentry, a crash reporting tool, to identify and fix technical errors in the app. Sentry may collect device information (device model, operating system version), error logs, and app state at the time of a crash. Before any data is sent to Sentry, we automatically remove sensitive financial information such as transaction amounts, account numbers, and merchant names.

1.5 Information You Provide Directly

If you contact us for support (e.g. by emailing admin@velaawareness.com), we will receive and retain your name, email address, and the contents of your message.

2. How We Use Your Information

We use the information we collect to:

  • Create and maintain your Vela account
  • Connect to your financial institutions via Plaid and sync your transaction data
  • Generate monthly spending summaries, categories, and insights within the app
  • Process and manage your subscription
  • Diagnose and fix crashes and technical errors
  • Respond to your support requests
  • Comply with applicable legal obligations

We do not use your financial data to make credit decisions, and we do not use it for advertising purposes.

3. How We Share Your Information

3.1 Service Providers

We share information with the following third-party service providers, each of which processes data only as necessary to provide their services to us:

3.2 Legal Requirements

We may disclose your information if we are required to do so by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect the rights or safety of any person.

3.3 No Sale of Personal Information

We do not sell, rent, or trade your personal information to third parties for their marketing or commercial purposes.

4. Data Storage and Security

Your data is stored on servers operated by Supabase. Supabase may host your data in the United States or other jurisdictions outside Canada. We use Row Level Security (RLS) policies to ensure that each user can only access their own data. Sensitive data such as Plaid access tokens are stored server-side and are never transmitted to the app client.

While we take reasonable technical and organizational measures to protect your information, no system is perfectly secure. We encourage you to use a strong, unique password and to contact us immediately if you suspect unauthorized access to your account.

5. Data Retention, Deletion, and Policy Review

5.1 Retention

We retain your personal information only for as long as necessary to provide the Service and fulfill the purposes described in this policy.

  • Account data (email address, display name, authentication credentials): retained for the lifetime of your active account.
  • Financial and transaction data retrieved via Plaid: retained for the lifetime of your active account, and used solely to power the spending summaries and category views within the app.
  • Subscription status records: retained for the lifetime of your active account and for a reasonable period thereafter as required for billing dispute resolution.
  • Support correspondence: retained for up to two (2) years from the date of the most recent message in the thread.
  • Crash and diagnostic reports (Sentry): subject to Sentry's own retention policies, typically 90 days. We do not control retention of data once transmitted to Sentry.

We do not retain financial transaction data for any purpose beyond providing the Service to you. We do not sell, license, or otherwise use retained data for secondary commercial purposes.

5.2 Account Deletion and Data Removal

You may request permanent deletion of your account and all associated data at any time. To do so, navigate to your Profile within the Vela app and select the account deletion option. The deletion process works as follows:

  • Your Plaid bank connections are immediately unlinked. All Plaid access tokens and item credentials stored in our system are revoked and deleted as part of this flow, using Plaid's item removal API. This prevents any further transaction syncing from your financial institution.
  • All transaction data, spending summaries, account identifiers, and user profile information stored in our database are permanently deleted.
  • Your Supabase authentication record is removed, invalidating all active sessions.
  • Your RevenueCat subscriber record is anonymized; we do not retain a link between your deleted account identity and any prior subscription history.

Deletion is permanent and cannot be undone. Following account deletion, residual copies of your data may persist in encrypted Supabase database backups for up to 30 days before those backups are rotated and purged. During this window your data is not accessible to us in the normal course of operations. After 30 days, no recoverable copy of your personal data will remain in our systems.

If you are unable to access the in-app deletion flow, you may also request deletion by emailing admin@velaawareness.com. We will process verified deletion requests within 30 days.

5.3 Policy Review

We review this Privacy Policy at least once per calendar year to ensure it accurately reflects our data practices. We also review and update this policy promptly whenever we make a material change to how we collect, use, or share personal information — for example, if we add a new data processor, introduce a new product feature that involves personal data, or change our retention practices.

The "Last Updated" date at the top of this policy reflects the date of the most recent review or revision. When we make material changes, we will notify you by updating that date and, where appropriate, by in-app notice or email. Your continued use of the Service after any update constitutes acceptance of the revised policy.

6. International Data Transfers

Vela is operated from Canada, but our service providers may process your data in other countries, including the United States. By using Vela, you consent to the transfer of your information to these jurisdictions, which may have different privacy laws than your home country. We take steps to ensure our service providers provide adequate protection for your data.

7. Your Rights

7.1 Canadian Users (PIPEDA / PIPA)

Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA), you have the right to access the personal information we hold about you, request corrections, and withdraw your consent to our use of your information (subject to legal and contractual restrictions). To exercise these rights, contact us at admin@velaawareness.com.

7.2 United States Users (CCPA / CPRA)

If you are a resident of California, you may have additional rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of your personal information. We do not sell personal information. To submit a request, contact us at admin@velaawareness.com.

7.3 General Rights

Regardless of your location, you may contact us at any time to access, correct, or delete your information, or to ask questions about how we handle your data.

8. Children's Privacy

Vela is intended for users who are 18 years of age or older. We do not knowingly collect personal information from children under 18. If we become aware that we have collected information from a child under 18 without appropriate consent, we will delete that information promptly. If you believe a child under 18 has provided us with personal information, please contact us at admin@velaawareness.com.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this policy and, where appropriate, notify you in the app or by email. Your continued use of Vela after changes are posted constitutes your acceptance of the updated policy.

10. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy, please contact us at:

Email: admin@velaawareness.com

We will respond to privacy-related inquiries within a reasonable timeframe, and no later than 30 days from receipt.