Privacy Policy

Privacy Policy

Celevo Co., Ltd. ("we", "us") takes your privacy seriously. This policy explains what we collect, why, and the choices you have. We comply with the Google API Services User Data Policy.


1. Information We Collect

Required
  • Email address and name (provided by Google Sign-In, or entered by you when signing up with email)
  • Password (email sign-up only — stored as a one-way hash; we never store or see the plain text)
  • Year of birth and sex
Optional
  • Height, weight, and health goals
  • Sleep records (duration, condition, energy)
  • Exercise records (type, duration, intensity)
  • Supplement intake records
  • Alcohol and smoking records
  • Weight records (weight by date, notes, target weight)
  • Supplement label images (analyzed by AI and not retained)
  • Food photos for meal logging (optional — stored in private storage accessible only to you, and deleted with your account)
  • AI assistant conversations (what you ask the in-app coach and what it answers — kept so the next conversation has context; a turn flagged as a crisis conversation is stored without its text)
  • Health goals and facts you write for the assistant (saved only when you fill in the form — the assistant proposes but never writes to it on its own)
  • Community profile (handle, display name, and an optional profile photo — your real name and email are never shown)
  • Community posts, comments and attached photos (visible to members of the group you post in — see section 13)

Everything under "Optional" is collected only if you enter it. The app is usable without any of it.

2. Health Data

The records listed above describe your health and habits. We treat them as sensitive and handle them under the following rules.

Menstrual cycle tracking has been removed

The menstrual cycle feature was removed from the app on August 2, 2026 and is no longer offered anywhere. No cycle data is collected, transmitted, or stored on our servers. Records created before that date remain encrypted at rest and are deleted when you delete your account; you can also ask us to delete them at any time.

To be precise about what that encryption does and does not do: it is not end-to-end encryption. The key is held per account in our database, so someone with full database access could in principle combine them. It protects against storage-level exposure, not against us.

Apple Health (HealthKit) and Health Connect

Only if you turn on health integration yourself, we read the following activity data from Apple Health (iOS) or Health Connect (Android) on a read-only basis: step count, workouts, active energy, heart rate during workouts, and workout distance. On iOS, if you grant them, we also read sleep stages, cardio fitness (VO2 max) and resting heart rate.

3. Google Account Data (Google Sign-In)

Google user data we access

When you sign in with Google, we access the following.

  • Email address
  • Name and profile picture (where provided)
  • Google account identifier (ID)

The scopes we request are limited to openid, email, and profile — all non-sensitive scopes.

How we use it

This data is used only to (1) identify you and create/sign in to your account, (2) manage multiple profiles, and (3) synchronize your data across devices. We use it for no other purpose.

Sharing

We do not sell, rent, or share Google user data with third parties, and we do not use it for advertising or marketing. It is processed only by the service providers listed in Section 8, and only as needed to operate the service.

Policy compliance

Our access to, use, storage, and sharing of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.

4. How We Use Your Information

5. Data Storage and Security

6. Data Retention

7. We Do Not Sell Your Data

We do not sell your personal information or your health data, and we do not share it for cross-context behavioral advertising. We have never done so. If that ever changes, we will say so here before it takes effect and obtain any consent the law requires.

8. Sharing and Service Providers

We do not provide your data to third parties for their own purposes, except where required by law. We use the following service providers, who process data only on our behalf.

9. Where Your Data Is Stored

The records you sync — your account, health records, and photos — are stored on servers in Seoul, South Korea, operated on our behalf by Supabase Inc. Our API also runs in Seoul, hosted by Vercel Inc. (a U.S. company) and delivered over a global edge network, so your requests pass through the edge location nearest you. Sign-in, analytics, and AI analysis are handled by Google LLC in the United States. Wherever you use the app from, your information is transferred across these locations under appropriate safeguards.

10. Your Rights and Data Deletion

You can, at any time:

How to delete: In the app, go to [Profile → Delete account permanently] to immediately and permanently delete your account and all data, including information from your Google account. You can also email contact@vivledia.com and we will process the request promptly.

11. Children's Privacy

This app is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has provided us information, contact us at the address below and we will delete it.

12. Usage and Diagnostic Data

We collect usage statistics and error diagnostics to improve the app and fix crashes.

On our website (vivledia.com) — the marketing pages and the Insights blog — we use Google Analytics 4 to measure visits, and Microsoft Clarity to understand how the site is used.

The Insights blog uses the same banner and carries over the choice you made on the marketing pages. Separately, you can also block cookies in your browser settings or install the Google Analytics Opt-out Add-on.

Neither Google Analytics nor Microsoft Clarity runs inside the app. They load only when you visit vivledia.com in a web browser, never within the iOS or Android app.

Because this data can reveal that you used a health feature, it is also disclosed in our Consumer Health Data Privacy Policy.

13. Community (Group Sharing)

The community is optional. If you do not use it, nothing in this section applies and none of your records are visible to anyone else.

Who can see what

Attaching your records to a post

Deleting and leaving

Reporting, blocking and the rules

14. Contact

For any privacy question or request, contact us at contact@vivledia.com.

15. Changes to This Policy

If we change this policy we will give notice in the app or by email before the change takes effect.

VIVLEDIA Effective: June 1, 2026 · Last updated: September 6, 2026