Legal

Privacy Policy

We don't want your data. Here's exactly what we collect and why.

Last updated: 2026-06-15

This Privacy Policy describes how Team Veto ("Veto," "we," "us," or "our") collects, uses, and protects information when you use the Veto iOS app or web app at get-veto.app. By using Veto, you agree to the practices described here.

1. Data We Collect

We collect information you actively provide:

All data is stored in Google Firebase Firestore under your authenticated user ID.

2. AI Analysis

When you run a Gauntlet conversation, the following data is sent server-side to Anthropic's Claude API via Firebase Cloud Functions:

Your name and email address are never included in API calls. Anthropic processes these requests under its commercial API terms and does not train its models on API data. Your conversation data is not retained by Anthropic beyond the scope of the individual request.

3. Visual Scouting

If you use Visual Scouting, the item name is sent to Serper (a Google Image Search proxy operated by Serper LLC) to retrieve publicly available product images. The item name is the only data transmitted. Product images are then stored in Firebase Storage linked to your item record. Image analysis uses Anthropic Claude server-side.

4. Spending Pattern Detection

Veto automatically analyses your purchase history to detect recurring spending behaviours — for example, late-night impulse buying, stress-triggered purchases, or sale susceptibility. These patterns are stored in your profile and used solely to personalise your AI advisor's responses. They are never shared externally.

You can view and delete detected patterns from the Settings screen in the app. This constitutes automated profiling within the meaning of GDPR Art. 4(4); it does not produce any legal or similarly significant effects — it only adjusts the tone and focus of the advisor's questions.

5. Sharing

We do not sell, trade, or rent your personal information. We do not share data with advertisers, data brokers, or marketing platforms. Data is processed by the following third-party services:

We may disclose information if required by law or to protect the rights, property, or safety of Veto, its users, or the public.

6. In-App Purchases

Veto offers Veto Pro, an auto-renewable subscription managed through Apple's in-app purchase system. We do not store or have access to your payment card details. Purchases and entitlement status are processed and verified through RevenueCat, which receives a pseudonymous app user identifier (your Firebase user ID) and transaction data from Apple in order to confirm your subscription status. To manage or cancel your subscription, go to Settings → Apple ID → Subscriptions on your device.

7. Analytics & Crash Reporting

We use Sentry to collect crash reports and diagnostic information when the app encounters an error. Each report is associated with a pseudonymous account identifier (your Firebase user ID) so we can investigate and fix issues affecting specific users. Reports include device type, OS version, app version, and a stack trace. Your name, email address, item data, and conversation content are never included. No advertising SDKs are present in the app. We do not request the Advertising Identifier (IDFA). We do not track you across other apps or websites.

If you would like your Sentry diagnostic data deleted, contact us and we will submit the deletion request to Sentry on your behalf.

8. Legal Bases for Processing (GDPR)

If you are in the European Economic Area (EEA) or United Kingdom, we process your data under the following legal bases:

9. Data Retention

We retain data for as long as your account is active. Specific retention windows:

10. International Data Transfers

Your data is stored and processed in the United States by Google Firebase (region: us-central1). Serper and Expo are also US-based. If you are located in the EEA or UK, these transfers are made under appropriate safeguards:

11. Children

Veto is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If we learn that a child under 13 has provided personal information, we will delete it promptly. If you believe a child has submitted data, contact us via our support form.

12. Your Rights

Depending on your location, you may have the following rights regarding your personal data. To exercise any of them, use the in-app controls below or contact us — we will respond within 30 days.

California residents (CCPA): You have the right to know what personal information is collected (see Section 1), the right to delete (see Erasure above), the right to correct, and the right to opt out of the sale or sharing of your personal information. We do not sell or share personal information. To exercise your rights, contact us via our support form or at [email protected].

13. Changes to This Policy

We may update this policy as the app evolves. Material changes will be reflected in the "Last updated" date above. Continued use of Veto after changes are posted constitutes acceptance of the revised policy.

14. Contact

Questions about this policy or requests to exercise your rights:

A Data Protection Officer (DPO) is not currently designated. Under GDPR Article 37, a DPO is required only where: (a) processing is carried out by a public authority; (b) core activities consist of large-scale systematic monitoring of individuals; or (c) core activities consist of large-scale processing of special category data. None of these conditions currently apply to Veto. If the user base grows to a scale where condition (b) or (c) is triggered, or if features involving explicit medical data or systematic behavioural tracking are introduced, this policy will be updated and a DPO appointed accordingly.