Vera Privacy
Effective 7 September 2026. This policy covers Vera for iPhone and iPad, bundle identifier com.d73.vera. Vera has no advertising, no cross-app tracking, and no sign-in account. We do not sell personal information.
Your choice before online processing
Before the app sends user content to Google or OpenAI, the app names the providers and the information they process and asks for your agreement. You can withdraw that agreement in Settings → About → Privacy & processing. The app then ends live activity and sends no further user content to those providers until you agree again.
What stays on your device
- Saved memories — names, notes, and reference images are encrypted with a key held in the device's Keychain. Matching starts on-device. With your AI-processing agreement, confirming a saved thing can use Google as described below. Saved people are matched only on-device.
- Saved-person recognition: the reference photos and face-recognition data used to match people stay on this device. They are not uploaded for cloud identification. Separately, camera frames or personal photos you choose for visual assistance can include people and are sent to Google; they are not automatically face-redacted. A locally matched person's saved name may be included in live conversation context or spoken-result text sent to a voice provider.
- On-device recognition models: SFace compares people you have chosen to save, and DINOv2 supports matching saved things. Both run locally and do not themselves make network requests. The separate cloud and voice processing described below may use selected thing reference images and result text. Their open-source notices are linked from the Terms page under Settings → About.
- Saved places and routes are encrypted on-device. The app does not upload your route history.
What is processed when you ask
- RevenueCat and Apple purchases: the app gives RevenueCat the same random installation identifier used with Vera's server, together with Apple product, transaction, subscription, and entitlement status. RevenueCat uses this information to show the available plan, complete and restore purchases, decide whether Vera Plus is active, support customers, and provide purchase analytics. RevenueCat does not receive your name, email address, Vera questions, camera frames, microphone audio, saved places, routes, readings, or memories from the app. Apple processes payment under your Apple Account; Vera never receives your full payment-card details.
- Google Gemini: a camera frame or selected personal photo, your question, page text, short conversation context, and optional measured distance are sent as needed for the visual or reading action you choose. Text for Vera's voice can also be sent to Google to generate speech. Vera's server does not retain this content after processing.
- Confirming a saved thing (Verify): when you press Capture and on-device matching is not enough, the captured view and up to two saved reference views of up to two saved things are sent through Vera's server to Google. The server retains none of those images or the descriptive verdict. Saved person memories and face-recognition data are excluded from this comparison; a thing view may still incidentally include people.
- Teaching a thing its words: after you save a thing, one saved view may be sent to Google to write a short description — its kind, colours, and a distinguishing mark. The saved description stays on-device with the memory, and may be used in later assistance or voice requests.
- OpenAI: microphone audio is sent while Keep Looking is live and unmuted, together with the live conversation context. Text is also sent to create Vera's speech. Speech text sent to OpenAI or Google can include an answer, a reading passage, or a saved name being spoken. Ending or muting the live session stops audio transmission.
- Google Maps Platform: when Places shows a Google map, resolves a search, or requests a walking route, the search text and the exact current and destination coordinates needed for that request pass through the app's server to Google. The request to Vera's server includes the random installation identifier for abuse prevention; that identifier is not forwarded to Google. The app's server does not retain the search text or coordinates.
- Apple Maps and Location Services: iOS supplies the current location and compass reading. Places sends typed search text to Apple for suggestions and selected place or address text for search resolution. Map and walking-distance fallbacks may provide current and destination coordinates to Apple's MapKit services under Apple's privacy terms.
- Location context: raw saved route breadcrumbs stay on-device. When you explicitly use a live assistant, the current location-derived context needed to answer may be provided to it. Location and depth data are used only for app functionality, never advertising, marketing, or data mining.
- Motion and step counts: during a walk to a saved place, Vera uses available device motion to calibrate step length and avoid treating a device lying flat as the direction you face. Counted steps are used only to estimate the final stretch. Motion and step-count data stay on-device and are not stored.
- Open Food Facts: a barcode decoded on-device may be looked up through the app's server. No camera image is sent to Open Food Facts.
- Device and diagnostics: a random installation identifier enforces limits and associates content-free events such as feature name, latency, error type, answer length, and confidence. It is not your name, email, Apple ID, advertising identifier, question, answer, transcript, or media.
Retention and provider handling
Vera's database retains minimal, content-free session metadata linked to the random installation identifier until you request deletion; these records have no automatic age-based expiry. Content-free operational diagnostics may also appear in service logs. The server does not retain camera frames, photos, audio, transcripts, questions, answers, or conversation context after request processing. Speech audio may be held in app memory during a listening session, but is not saved to the app's persistent voice cache.
To prevent an unfinished request from recreating a deleted diagnostic record, Vera temporarily retains a one-way hash of the retired random identifier, a random deletion-generation value, and an expiry time. This marker contains no media or other user content. It becomes eligible for removal after 10 minutes. Cleanup runs when the backend starts and every five minutes while it is running, in bounded batches; an outage or backlog can delay removal. This is not a guaranteed 10-minute deletion deadline.
Provider security systems may retain abuse-monitoring data under their terms. OpenAI documents a default period of up to 30 days for relevant API services, with longer retention where legally required. Google documents prompt-and-response abuse-monitoring logs for up to 55 days for Gemini API services. These provider records are not erased by Vera's own database deletion. Their practices can change; the links below are the controlling current terms.
The app does not use submitted content to train its own model. OpenAI states that API data is not used to train its models by default. Google states that paid Gemini API content is not used to improve its products. The app uses provider services for the requested app functionality, not advertising.
System permissions
Camera, microphone, speech recognition, photo library, motion, and location permissions are requested by iOS only when you use a feature that needs them. The app does not request Contacts access. You can deny or later change any permission in iOS Settings. The app does not use location in the background. Camera and microphone activity remains subject to Apple's system indicators, and the app also presents visible live-session controls.
Your choices
- Turn off online processing under Settings → About → Privacy & processing.
- Choose Restore purchases to ask Apple and RevenueCat for Vera Plus access already associated with your Apple Account.
- Choose Manage subscription to open Apple's subscription controls, where you can view or cancel renewal.
- Choose Delete my account to remove saved app data and preferences from this device, stop processing, retire the random installation identifier, erase its Vera database records, and request deletion of its RevenueCat customer record. The temporary deletion-protection marker described above remains until cleanup. RevenueCat may queue its deletion request rather than finish it immediately. Apple keeps its transaction record. Deleting Vera data does not cancel an Apple subscription; use Manage subscription for that.
- Change system permissions in iOS Settings.
Security and deletion
Network requests use HTTPS in App Store builds. On-device memories, readings, places, and routes are encrypted. No system is perfectly secure. If Vera's server cannot confirm its erase or RevenueCat cannot accept the deletion request, the app removes local data immediately and retains only the retired random identifier needed for that pending request. Reopen Vera with an internet connection to retry. A RevenueCat acknowledgement can mean deletion has been queued; it does not mean your Apple subscription was cancelled.
Children
The app is not directed at children and does not knowingly collect anything from them.
Contact and provider terms
Privacy questions or deletion help: Vera Support.