Privacy Policy
Last updated: 2026-09-28
This privacy policy explains what information Volo Health
([LEGAL ENTITY]; "we", "us") collects
when you use the Volo Health app, why we collect it, and how it's
protected.
What we collect
-
Account details from Google when you sign in: your
name, email address, profile picture, and your Google account ID. We
do not see or store your Google password.
-
Health data you enter: daily weight, meal logs
(amount + food groups), water and exercise check-ins, workout
completions, calories burned, and any free-form notes you write.
-
Settings you save: gender, height, age, weight-loss
goal, activity level, and your written goal and reason for it.
-
Recipes, workouts, and photos you add to the shared
banks — visible to every other member (see "What other members can
see" below).
-
Your weekly meal/workout plans — private to you, like
your health data above.
-
Billing information (once paid subscriptions
launch): handled by our payment processor, Stripe — see "Sub-processors"
below. We store your subscription status and billing dates, not your
card details.
-
Session cookie: a single secure, HTTP-only cookie
that keeps you signed in. See "Cookies and local storage" below.
How we use it
-
To operate the app — show you your data, calculate calorie / water
targets, process your subscription, and let you log progress.
-
To search food data on your behalf: when you search for an
ingredient, your search text (not your name, email, or account
identity) is sent through our server to USDA FoodData Central. See
"Sub-processors" below.
-
We do not sell your data, and we don't share it
with advertisers.
What other members can see
Your logged days, weight, weekly plan, goal and nutrition progress are
private to you — no other member can read them. The recipes and workouts
you add are the exception: those are shared banks, so every member can
see what you publish there, along with your name as the author and any
photos you attach. If you remove a recipe or workout that other members
are already using, it is retired — taken out of the bank so nobody new
can add it — but kept where they already use it, so their plans and
history aren't broken. One nobody uses is deleted outright.
Sub-processors and other third parties
We use the following services to run Volo Health. Each has its own
privacy practices, which we encourage you to review.
-
Google — sign-in (OAuth).
-
Neon — our managed PostgreSQL database, where your
account and app data is stored.
-
Vercel — hosts the app and its server functions.
-
Vercel Blob — stores recipe photos when configured.
Photos stored this way get a public URL: anyone with that exact URL
can view the image, even though we don't list or link it anywhere
outside the app.
-
Google Fonts — this page and every other page in the
app load fonts from
fonts.googleapis.com and
fonts.gstatic.com. Loading a font sends your browser's IP
address and standard request headers to Google, whether or not you're
signed in.
-
USDA FoodData Central — powers ingredient search. Your
search terms are sent to USDA through our server; we don't send your
account identity along with them.
-
Stripe (upcoming, once paid subscriptions launch) —
processes payments. Card details are entered directly on Stripe's
hosted checkout and customer-portal pages and never touch our servers.
Cookies and local storage
-
Session cookie: a single secure, HTTP-only cookie
that keeps you signed in. We don't use it for tracking or advertising,
and we don't use third-party tracking or advertising cookies. It stays
valid on a rolling basis as long as you use the app at least once
every 30 days; after 30 days of inactivity it expires. You can end a
session immediately by signing out.
-
Local storage: the shopping list screen remembers
which items you've checked off using your browser's local storage,
scoped to your device. That data stays on your device and is never
sent to our servers.
Data retention
We keep your account data for as long as your account is active.
Sessions that go 30 days without activity expire automatically and are
removed. When you delete your account (Settings → Delete my account),
your account and personal data are deleted immediately, in one step —
see Delete below for exactly what is removed and what
is kept for other members. Our database provider keeps point-in-time
history for a limited window for disaster recovery; deleted data ages
out of it automatically when that window passes.
Your rights
-
Access — your data is visible in the app at all
times.
-
Correct — you can edit or remove most entries
directly in the app.
-
Delete — go to Settings → Delete my account
and confirm. This immediately and permanently deletes your account,
your profile, settings and goal, logged days and weight, weekly plans,
meal and workout logs, nutrition progress, and the recipes, workouts
and categories you added that nobody else is using, and signs you out
on every device. Photos no longer shown on any recipe are deleted too.
Recipes, workouts and categories that other members have already
planned, logged, built on or tagged with are kept so their data isn't
broken: they are retired from the bank and credited to "Former
member" instead of your name. We keep a record that an account was
deleted and when, without your name or email.
-
Export — go to Settings → Export my data to
download a copy of your data (profile, settings, logged days and
weight, weekly plans, meal and workout logs, progress, and the
recipes and workouts you've written) as a JSON file, at any time.
Age requirement
Volo Health is intended for use by people age
[MINIMUM AGE] and older. We do not
knowingly collect information from anyone younger than that. If we
learn we've collected information from someone under that age, we will
delete it.
Changes to this policy
If we make material changes, we'll update the "Last updated" date
above. Continued use of the app after a change means you accept the
new policy.
Contact
Questions or requests:
hello@volo.one