Vera Privacy

Effective 7 September 2026. This policy covers Vera for iPhone and iPad, bundle identifier com.d73.vera. Vera has no advertising, no cross-app tracking, and no sign-in account. We do not sell personal information.

Your choice before online processing

Before the app sends user content to Google or OpenAI, the app names the providers and the information they process and asks for your agreement. You can withdraw that agreement in Settings → About → Privacy & processing. The app then ends live activity and sends no further user content to those providers until you agree again.

What stays on your device

What is processed when you ask

Retention and provider handling

Vera's database retains minimal, content-free session metadata linked to the random installation identifier until you request deletion; these records have no automatic age-based expiry. Content-free operational diagnostics may also appear in service logs. The server does not retain camera frames, photos, audio, transcripts, questions, answers, or conversation context after request processing. Speech audio may be held in app memory during a listening session, but is not saved to the app's persistent voice cache.

To prevent an unfinished request from recreating a deleted diagnostic record, Vera temporarily retains a one-way hash of the retired random identifier, a random deletion-generation value, and an expiry time. This marker contains no media or other user content. It becomes eligible for removal after 10 minutes. Cleanup runs when the backend starts and every five minutes while it is running, in bounded batches; an outage or backlog can delay removal. This is not a guaranteed 10-minute deletion deadline.

Provider security systems may retain abuse-monitoring data under their terms. OpenAI documents a default period of up to 30 days for relevant API services, with longer retention where legally required. Google documents prompt-and-response abuse-monitoring logs for up to 55 days for Gemini API services. These provider records are not erased by Vera's own database deletion. Their practices can change; the links below are the controlling current terms.

The app does not use submitted content to train its own model. OpenAI states that API data is not used to train its models by default. Google states that paid Gemini API content is not used to improve its products. The app uses provider services for the requested app functionality, not advertising.

System permissions

Camera, microphone, speech recognition, photo library, motion, and location permissions are requested by iOS only when you use a feature that needs them. The app does not request Contacts access. You can deny or later change any permission in iOS Settings. The app does not use location in the background. Camera and microphone activity remains subject to Apple's system indicators, and the app also presents visible live-session controls.

Your choices

Security and deletion

Network requests use HTTPS in App Store builds. On-device memories, readings, places, and routes are encrypted. No system is perfectly secure. If Vera's server cannot confirm its erase or RevenueCat cannot accept the deletion request, the app removes local data immediately and retains only the retired random identifier needed for that pending request. Reopen Vera with an internet connection to retry. A RevenueCat acknowledgement can mean deletion has been queued; it does not mean your Apple subscription was cancelled.

Children

The app is not directed at children and does not knowingly collect anything from them.

Contact and provider terms

Privacy questions or deletion help: Vera Support.