Last updated: 2026-06-15
This Privacy Policy describes how Team Veto ("Veto," "we," "us," or "our") collects, uses, and protects information when you use the Veto iOS app or web app at get-veto.app. By using Veto, you agree to the practices described here.
1. Data We Collect
We collect information you actively provide:
- Account information: Email address and display name created at sign-up via Firebase Authentication.
- Purchase considerations: Item names, prices, descriptions, and photos you submit for analysis.
- Financial profile: Monthly discretionary budget, estimated income, hours worked per week, and birth year — entered optionally to personalise cost analysis. This data is never verified or linked to any financial account.
- Conversation history: Your Gauntlet conversations with the AI advisor, including messages, verdicts, and per-turn analysis.
- Spending patterns: Behavioural labels automatically detected from your purchase history (see Section 4).
- Preferences: Advisor tone, app theme, and notification settings.
- Device identifiers: Your Expo push notification token, stored to deliver reminders. On iOS, this is a pseudonymous device identifier managed by Apple.
- Support & feedback: When you contact us through the website form or the in-app feedback feature, we collect your name, email address, and message. In-app feedback also includes your account identifier, app version, and device OS version to help us diagnose issues.
All data is stored in Google Firebase Firestore under your authenticated user ID.
2. AI Analysis
When you run a Gauntlet conversation, the following data is sent server-side to Anthropic's Claude API via Firebase Cloud Functions:
- The item name, price, and conversation history.
- Your financial profile context: discretionary budget, monthly outgoings, approximate age (derived from birth year), and advisor tone preference. This allows the AI to tailor its assessment to your financial situation.
Your name and email address are never included in API calls. Anthropic processes these requests under its commercial API terms and does not train its models on API data. Your conversation data is not retained by Anthropic beyond the scope of the individual request.
3. Visual Scouting
If you use Visual Scouting, the item name is sent to Serper (a Google Image Search proxy operated by Serper LLC) to retrieve publicly available product images. The item name is the only data transmitted. Product images are then stored in Firebase Storage linked to your item record. Image analysis uses Anthropic Claude server-side.
4. Spending Pattern Detection
Veto automatically analyses your purchase history to detect recurring spending behaviours — for example, late-night impulse buying, stress-triggered purchases, or sale susceptibility. These patterns are stored in your profile and used solely to personalise your AI advisor's responses. They are never shared externally.
You can view and delete detected patterns from the Settings screen in the app. This constitutes automated profiling within the meaning of GDPR Art. 4(4); it does not produce any legal or similarly significant effects — it only adjusts the tone and focus of the advisor's questions.
5. Sharing
We do not sell, trade, or rent your personal information. We do not share data with advertisers, data brokers, or marketing platforms. Data is processed by the following third-party services:
- Google Firebase (Auth, Firestore, Storage, Cloud Functions, Cloud Run) — core infrastructure provider. Data is stored in the United States.
- Anthropic — AI analysis, server-side only, under commercial API terms (see Section 2).
- Serper — image search for Visual Scout product identification. Item names are transmitted as search queries (see Section 3).
- Expo — push notification delivery. Your device push token and notification content (item name and price) are transmitted to Expo's push service to send reminders.
- Sentry — crash reporting and diagnostics (see Section 7).
- Apple — in-app purchase processing and payment management (see Section 6).
- RevenueCat — subscription management and entitlement verification. We share a pseudonymous app user identifier (your Firebase user ID) and receive your subscription status; RevenueCat does not receive your payment card details (see Section 6).
- Cloudflare — operates the proxy that receives contact form and in-app feedback submissions, and hosts our website. Cloudflare receives the name, email address, and message you submit, and processes it under Cloudflare's Data Processing Addendum and Standard Contractual Clauses.
- Resend — delivers contact form and in-app feedback submissions to our support inbox by email. Resend receives the name, email address, and message you submit, processed under Resend's Data Processing Agreement and Standard Contractual Clauses.
We may disclose information if required by law or to protect the rights, property, or safety of Veto, its users, or the public.
6. In-App Purchases
Veto offers Veto Pro, an auto-renewable subscription managed through Apple's in-app purchase system. We do not store or have access to your payment card details. Purchases and entitlement status are processed and verified through RevenueCat, which receives a pseudonymous app user identifier (your Firebase user ID) and transaction data from Apple in order to confirm your subscription status. To manage or cancel your subscription, go to Settings → Apple ID → Subscriptions on your device.
7. Analytics & Crash Reporting
We use Sentry to collect crash reports and diagnostic information when the app encounters an error. Each report is associated with a pseudonymous account identifier (your Firebase user ID) so we can investigate and fix issues affecting specific users. Reports include device type, OS version, app version, and a stack trace. Your name, email address, item data, and conversation content are never included. No advertising SDKs are present in the app. We do not request the Advertising Identifier (IDFA). We do not track you across other apps or websites.
If you would like your Sentry diagnostic data deleted, contact us and we will submit the deletion request to Sentry on your behalf.
8. Legal Bases for Processing (GDPR)
If you are in the European Economic Area (EEA) or United Kingdom, we process your data under the following legal bases:
- Performance of contract (Art. 6(1)(b)): Account creation, storing purchase considerations, delivering AI analysis, sending reminders.
- Legitimate interests (Art. 6(1)(f)): Crash reporting and diagnostics (our interest: maintaining a stable and secure app); spending pattern detection (our interest: improving the relevance of AI advice). These interests do not override your rights — you can opt out of patterns in Settings and request Sentry data deletion.
- Consent (Art. 6(1)(a)): Push notifications (you grant permission through the iOS system prompt; you may withdraw at any time in your device Settings).
9. Data Retention
We retain data for as long as your account is active. Specific retention windows:
- Account data, purchase history, and conversations: Retained until you delete your account.
- Sentry crash reports: 90 days (Sentry's default retention period).
- Push notification logs: Approximately 30 days.
- AI feedback reports: If you use the in-app feature to report a poor AI response, that report is stored to help improve the advisor. It is automatically deleted when you delete your account.
- Support & feedback correspondence: Contact form and in-app feedback messages delivered to our support inbox are retained for up to 24 months, then deleted.
10. International Data Transfers
Your data is stored and processed in the United States by Google Firebase (region: us-central1). Serper and Expo are also US-based. If you are located in the EEA or UK, these transfers are made under appropriate safeguards:
- Google Firebase: Covered by Google's Standard Contractual Clauses (SCCs) and Google's Data Processing Addendum.
- Anthropic: Covered by Anthropic's Data Processing Agreement and SCCs.
- Serper and Expo: Transfers made on the basis of SCCs.
- Cloudflare and Resend: Transfers made on the basis of SCCs (see Section 5).
11. Children
Veto is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If we learn that a child under 13 has provided personal information, we will delete it promptly. If you believe a child has submitted data, contact us via our support form.
12. Your Rights
Depending on your location, you may have the following rights regarding your personal data. To exercise any of them, use the in-app controls below or contact us — we will respond within 30 days.
- Access (Art. 15): Request a copy of the data we hold about you, including the categories of data, processors involved, and retention periods.
- Rectification (Art. 16): Correct inaccurate data directly in Settings → Profile, or ask us to update it.
- Erasure (Art. 17): Delete your account and all associated data from Settings → Account → Delete Account. This removes your Firestore data and stored images immediately.
- Restriction (Art. 18): Ask us to pause processing of your data while a dispute is resolved.
- Portability (Art. 20): Export your purchase history and notifications as a JSON file from Settings → Export Data.
- Object (Art. 21): Object to processing based on legitimate interests (e.g., spending pattern detection). Contact us and we will disable it for your account.
- Withdraw consent: Disable push notifications at any time in your device Settings.
- Lodge a complaint: You have the right to lodge a complaint with your national data protection authority — for example, the ICO (UK), the CNIL (France), or the DPC (Ireland).
California residents (CCPA): You have the right to know what personal information is collected (see Section 1), the right to delete (see Erasure above), the right to correct, and the right to opt out of the sale or sharing of your personal information. We do not sell or share personal information. To exercise your rights, contact us via our support form or at [email protected].
13. Changes to This Policy
We may update this policy as the app evolves. Material changes will be reflected in the "Last updated" date above. Continued use of Veto after changes are posted constitutes acceptance of the revised policy.
14. Contact
Questions about this policy or requests to exercise your rights:
A Data Protection Officer (DPO) is not currently designated. Under
GDPR Article 37, a DPO is required only where: (a) processing is
carried out by a public authority; (b) core activities consist of
large-scale systematic monitoring of individuals; or (c) core
activities consist of large-scale processing of special category data.
None of these conditions currently apply to Veto. If the user base
grows to a scale where condition (b) or (c) is triggered, or if
features involving explicit medical data or systematic behavioural
tracking are introduced, this policy will be updated and a DPO
appointed accordingly.