Effective date: July 22, 2026
Last updated: July 22, 2026
Velora is operated by Joii Luxx. This Privacy Policy explains what information the app collects, how it is used, when it may be shared, how long it may be retained, and the choices available to users.
By using Velora, you acknowledge the practices described in this Privacy Policy.
When you create or use an account, we may process:
Email address and authentication-provider information.
Display name and profile image, when provided.
Account settings and preferences.
Age, birth date, sex, height, weight, activity level, fitness goals, nutrition goals, and similar information that you choose to provide.
Trainer/client relationship information when those features are used.
The app may process information you enter or generate, including:
Food logs and meal history.
Recipes and meal templates.
Calories, macronutrients, and available micronutrients.
Water intake.
Weight and body-composition records.
Nutrition and fitness goals.
Check-ins, notes, and progress information.
Food-search and nutrition information may be obtained through FatSecret. Search terms, barcode identifiers, and serving selections may be processed as necessary to return food and nutrition information.
The app may process:
Workout templates and planned targets.
Completed exercises, sets, repetitions, weight, duration, and other workout details.
Activity type, start and end time, duration, steps, calories, heart rate, distance, pace, and related session information.
Outdoor activity route and location information when route tracking is enabled and location permission has been granted.
Wear OS exercise and sensor information during supported activities.
With your permission, the app may read or write specific health and fitness data through Health Connect for user-facing features such as activity, nutrition, body measurements, and related trends.
We request only the Health Connect permissions needed for features that the user chooses to use. Health Connect permissions can be reviewed or revoked through Android or Health Connect settings.
When you choose to upload a profile image, progress photo, or another supported protected file, that file may be stored using Firebase Storage.
When you intentionally connect with a trainer or client, selected information may be shared according to the permissions and relationship features you enable.
Trainer access is scoped and revocable. Client-owned consumed food logs, completed workout history, water, weight, and other historical records remain client-owned. Plans, suggestions, and check-ins remain separate from completed user history unless the user accepts or records them.
To operate and secure the app, we may process limited technical information such as:
App version and device type.
Authentication and App Check integrity signals.
Notification token and notification preferences.
Date and time of service requests.
Error categories and diagnostic information.
Security-rule or deletion-operation outcomes.
Limited network and service metadata processed by Firebase and Google Cloud.
If you contact us, we may retain your message, contact information, verification status, and our response.
We use information to:
Create and authenticate accounts.
Provide nutrition, activity, workout, water, weight, and progress-tracking features.
Sync user-owned information across supported devices.
Provide Health Connect and Wear OS integration.
Return FatSecret food-search and nutrition results.
Provide trainer/client features selected by users.
Send requested reminders and service notifications.
Respond to support and account-deletion requests.
Protect accounts and prevent unauthorized access.
Diagnose errors and maintain the service.
Comply with applicable legal obligations.
Joii Luxx does not currently sell personal or sensitive information. Velora does not currently use personal or sensitive health, nutrition, activity, precise location, route, workout, body-measurement, or trainer/client information for targeted advertising.
In the future, Velora may use aggregated or appropriately de-identified trends—such as foods logged, activity categories, and general public places where people commonly hike, run, or walk—to improve services, measure broad interests, support advertising, recommend products, or market and sell Joii Luxx products or services. These future uses will not be designed to identify a particular person, reveal an individual’s precise or historical route, or create an advertising profile tied to a specific user.
Joii Luxx will not attempt to re-identify aggregated or de-identified information and will require service providers or recipients to prohibit re-identification. Velora will not sell personal or sensitive user data. Before any material new advertising, product-marketing, or data-sharing use begins, Joii Luxx will update this policy and applicable store disclosures and provide notice, consent, or choices when required by law or platform policy.
Service providers may process information as necessary to operate, secure, maintain, and support Velora, subject to their applicable terms, privacy obligations, and the limits described in this policy.
We may share or allow processing of information in the following limited circumstances.
We use service providers that support the app, including Google Firebase services for authentication, cloud storage, database synchronization, server functions, app integrity, and notifications.
These providers process information on our behalf according to their service terms and privacy practices.
Health Connect and Wear OS process health and fitness information according to permissions controlled by the user and the applicable device or Google account settings.
FatSecret processes food-search, barcode, serving, and nutrition requests needed to provide food information within the app.
Information is shared with a connected trainer or client only through the app’s relationship and permission features or when the user otherwise directs the sharing.
We may disclose limited information when reasonably necessary to:
Comply with applicable law or a valid legal request.
Protect users, the public, or the service.
Investigate unauthorized access, fraud, abuse, or security incidents.
Enforce applicable agreements.
We do not permit service providers or connected trainers to use private health and fitness information for unrelated advertising.
Location is used only for features that require it, such as recording an outdoor activity route.
The app does not create a GPS route for indoor activities. Route tracking depends on device permission, sensor availability, and the selected activity.
Users may disable location permission through Android settings. Disabling location may prevent route-based activity features from functioning.
User-owned app data may be stored locally on the device and synchronized through Firebase services.
We use reasonable technical safeguards, including authenticated access, Firebase Security Rules, App Check, encrypted network connections, owner-scoped databases, and protected storage controls.
No security system can guarantee absolute protection. Users should maintain control of their device, Google account, and login credentials.
Account information and user-created records are generally retained while the account remains active or until the user deletes specific records.
When an account-deletion request is successfully completed, app-owned account data is deleted according to the deletion process described below.
The following limited information may remain temporarily or outside the app’s direct control:
Completed deletion-processing locks remain until their security-expiration period and are removed during a scheduled cleanup.
Failed deletion-processing locks remain until the deletion is successfully retried or manually reconciled.
Application and service logs stored in the Google Cloud _Default log bucket are retained for 30 days.
Administrative and system audit logs stored in the provider-controlled _Required log bucket are retained for 400 days.
Account-deletion support correspondence may be retained for 90 days after the request is completed or closed.
When reasonably necessary to investigate abuse, unauthorized access, security incidents, or attempts to interfere with account deletion, we may retain limited security records for up to 12 months after the matter is resolved, unless a longer period is legally required.
Information required by applicable law, a valid legal request, or a legal hold is retained only for the legally required period.
Google Play transaction records are controlled by Google Play.
Health Connect data is controlled through Health Connect.
Files that a user exported or saved outside the app are controlled by the user.
We do not retain deleted user information merely for future advertising or profiling.
Users may request deletion through:
The in-app account-deletion option at Settings → Sync & Data → Delete account/data.
The public deletion-request page at https://www.joiiluxx.com/tracker-deletion-request.
The monitored support pathway at admin@joiiluxx.com.
Account deletion includes the Firebase Authentication account and associated app-owned data, including applicable profile, food, nutrition, recipe, water, weight, workout, activity, relationship, notification, and protected-file information.
When a trainer account is deleted, client-owned history may remain when necessary to preserve the client’s records. The former trainer’s identifying attribution is removed or replaced with non-identifying wording such as “Former trainer.”
Deleting the account does not automatically delete:
Health Connect information controlled through Health Connect.
Google Play transaction history.
An active Google Play subscription, when applicable.
Files exported or saved outside the app.
Information another user independently owns.
Requests submitted through the public support process require reasonable verification of account ownership.
Depending on the feature, users may:
Review and update account settings.
Add, edit, or delete supported logs.
Revoke trainer/client access.
Revoke Health Connect permissions.
Disable location, notification, camera, or other device permissions.
Export supported app data.
Request deletion of the account and associated data.
Contact us regarding access, correction, deletion, or privacy questions.
Revoking a permission may limit the related app feature.
Velora is intended for individuals who are at least 18 years old. We do not knowingly collect personal information from individuals under 18. If we learn that an individual under 18 has provided personal information through Velora, we will take reasonable steps to review and delete that information as appropriate. A parent or guardian who believes that a minor has provided information may contact Joii Luxx at admin@joiiluxx.com.
Our service providers may process information in locations outside the user’s state, province, or country. Those locations may have different data-protection laws.
We use service providers and safeguards intended to protect information consistently with this Privacy Policy.
This Privacy Policy is subject to change from time to time as Velora’s features, service providers, legal obligations, or data practices evolve. Updates apply prospectively unless applicable law and valid user consent permit otherwise.
The updated policy will show a revised “Last updated” date. Before applying a material change to previously collected personal or sensitive information, Joii Luxx will provide appropriate notice and obtain consent when required. A policy update by itself does not authorize an undisclosed or prohibited use of personal or sensitive information.
Material changes may also be communicated through the app, email, or another appropriate notice. Users may stop using Velora and request deletion of app-owned account data if they do not wish to continue under a prospective change.
For privacy questions or account-deletion requests, contact:
App: Velora
Developer/publisher: Joii Luxx
Email or request form: admin@joiiluxx.com
Privacy Policy: https://www.joiiluxx.com/tracker-privacy-policy
Account deletion: https://www.joiiluxx.com/tracker-deletion-request