This page covers two things: this website (joining the waitlist or newsletter), and, in full below, The Veda Circle app itself.
What we collect
Your email address, only if you choose to join the waitlist or the newsletter. Nothing else is collected through this site.
Where it's stored
In a secure, EU-based database (Ireland).
What it's used for
To email you when we launch, and, only if you separately opt in, our newsletter. Nothing more.
Who sees it
Only us. We don't sell or share your email address with anyone else.
Third-party services this site uses
Loading this page requests fonts and code libraries from external servers (Google Fonts, jsDelivr), which means your device's IP address is visible to those services when the page loads. That's true of almost every website on the internet.
Your rights
You can ask us to delete your email address at any time by writing to hello@thevedacircle.com.
Sarah Lesley Hughes, trading as "The Veda Circle" ("The Veda Circle", "we", "us", "our"), a sole trader established in Malta and holding Malta VAT number 3303-1516 operating from Malta, publishes the The Veda Circle mobile application ("App").
This Privacy Policy explains what little personal data is involved in using the App, why, and the rights you have under the EU General Data Protection Regulation (GDPR) and the UK GDPR together with the Data Protection Act 2018.
Everything you log in the App: your cycle, symptoms, mood, sleep, journal entries, photos, medications, condition logs, and anything else you enter, stays on your device. It is never transmitted anywhere: not to us, not to any server, not to any cloud backup. There is no account or sign-up, so we have no way to identify you as a person from your use of the App.
The one exception is a narrow, specific check needed to confirm your subscription is active, described precisely in Section 3. That check never includes any health content, and is not tied to your name, email, or any identity we hold.
To offer paid subscriptions, the App uses RevenueCat, a third-party subscription-management service, to check whether your subscription is currently active. This check sends:
RevenueCat forwards the receipt to Apple's or Google's servers to validate it, and returns a yes/no "is this subscription active" result to the App. This is the only data that ever leaves your device, and the only reason it leaves. No cycle data, symptoms, moods, journal entries, photos, medications, condition logs, or any other content you log is ever included in this call, sent to RevenueCat, or sent anywhere else. The App has no network-sending code path for that data at all; the billing check is architecturally separate from everything else in the App.
We do not collect your name or email as part of this check. Separately, when you subscribe, Apple or Google handle your purchase and payment details directly as part of their own standard in-store checkout. That transaction is between you and Apple/Google, and we do not collect or see your payment details, name, or email through it.
Because the App never transmits anything you log, we never receive, store, view, or process your health and wellness data in any form. Any processing of that data such as creating it, editing it, deleting it, happens entirely on your device, under your control, using the App as a local tool. We do not act as a data controller or processor for that content, because it never reaches us.
This means the rights described in Section 7 (access, portability, erasure, and so on) are not something you need to ask us for when it comes to your logged health content: you already have full, direct, immediate control over it on your device. Deleting an entry, a photo, or the App itself removes it completely and irrecoverably, because no copy exists anywhere else.
If you choose to, and only with your explicit permission granted through your device's own permission system, the App can connect to Apple Health (iOS) or Health Connect (Android) to read your step count, sleep data, and exercise data, and display it alongside your logged content. This includes data from third-party wearables and devices such as smart rings, watches, or fitness trackers that sync into Apple Health or Health Connect on their own.
The App does not connect to any wearable, ring, or device manufacturer directly, and does not use any device maker's own API or cloud service; it only ever reads from the operating system's own health store, regardless of which device originally produced the data.
This data is read and stored only on your device.
Exactly like everything else you log in the App (see Section 2), it is never uploaded, transmitted, or sent anywhere: not to us, not to any server, not to Apple, and not to Google. This is not an exception to the App's on-device architecture; it is simply a new on-device data source the App can read from, at your instruction.
You control this feature entirely. The App will only request access to Apple Health or Health Connect if you actively choose to connect it, and you can disconnect it, or revoke the App's access, at any time through your device's Health app (iOS) or Health Connect settings (Android).
Disconnecting does not automatically delete data already read into the App on your device; like any other logged content, you can delete it within the App at any time.
The limited data described in Section 3 is processed on the basis of contractual necessity (GDPR Article 6(1)(b)) and is necessary to provide the paid Subscription you have chosen to purchase and to verify your entitlement to continued access.
Subject to conditions and exceptions under applicable law, you have the right to access, rectify, erase, restrict, or object to processing of any personal data we hold, to data portability, to withdraw consent, and to lodge a complaint with a supervisory authority. In practice, given Sections 4 and 5, this applies only to the narrow subscription-verification data described in Section 3.
Even that subscription-verification data is not linked to your identity on our side, so in most cases there is nothing further for us to look up, disclose, or delete beyond what RevenueCat itself may hold against the anonymous ID (contact RevenueCat directly, or ask us to make that request on your behalf, at hello@thevedacircle.com).
If you are in the EU, you have the right to lodge a complaint with the Malta Information and Data Protection Commissioner (IDPC), or with the supervisory authority of your EU member state of residence.
If you are in the UK, you have the right to complain to the Information Commissioner's Office (ICO).
Data read from Apple Health or Health Connect, where you choose to connect one of these sources, is not included in anything described in this section, it stays on your device and is not shared with us or with any third party. See Section 5.
We do not use analytics or advertising SDKs in the App.
Subscription-verification data described in Section 3 may be processed outside the EEA or UK by RevenueCat, Apple, or Google as follows:
We do not receive and therefore do not retain your logged health content. Subscription-verification data is retained by RevenueCat and the app stores under their own retention practices; we do not separately store a copy.
Because your health data never leaves your device, it is inherently protected from any breach of our systems, our infrastructure, or any third-party processor we use - there is nothing centrally stored to breach. Your device's own security (passcode, biometric lock, OS updates) is what protects your logged content, and we recommend keeping these enabled.
The App is not directed at children under the age of digital consent applicable in their country of residence. Because the App collects no personal information beyond the anonymous subscription check, and that check is not targeted at or informed by age, this risk is low; nonetheless, purchasing a paid subscription requires the legal capacity described in the Terms and Conditions.
In the unlikely event that RevenueCat or another processor notifies us of a personal data breach affecting the limited data described in Section 3 that poses a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it (GDPR Article 33), and notify affected users without undue delay where the breach is likely to result in a high risk (Article 34), to the extent we are able to identify and reach them.
We may update this Privacy Policy from time to time, in particular if the App's architecture changes to introduce any account system, sync, or additional network activity. We will notify you of material changes by in-app notice at least 14 days before they take effect.
For any questions about this Privacy Policy, contact us at hello@thevedacircle.com or in writing to [Sarah Lesley Hughes, trading as "The Veda Circle", Malta.