Privacy policy
At a glance
- Pavelo is built local-first. Your stack, logs, notes, and reminders live on your phone. Optional sync keeps an encrypted server copy.
- No account needed. If you turn on sync, you sign in with Google and we keep an encrypted copy we cannot read. Nothing changes if you don't.
- The AI features are optional and ask first. Nothing is sent until you agree on the consent screen, and the screen tells you exactly what goes out.
- AI requests go through our server without forwarding your device's IP address to Anthropic. Content you choose to send may contain personal information.
- Usage statistics are off unless you turn them on. They are plain feature counts, with nothing in them about your supplements or your routine.
- We don't sell your data, and we don't use third-party tracking or ad SDKs.
- Uninstalling wipes the app's data from your phone, but it can't reach our server. If sync was on, delete the synced copy in the app first, and let any pending deletion of older linked statistics finish. Usage counts already added to a weekly total can't be pulled back out, because nothing ties them to your phone. Backup files you saved or sent somewhere stay where you put them.
What lives on your device
Everything that defines your day lives in the app's local database:
- Your supplement list, doses, schedules, and reminder times
- Daily check-offs
- How-you-felt check-ins and journal notes
- Settings and preferences
- Backups you keep on the phone (the app rotates the three most recent)
- A random app identifier used for AI request limits and subscription status. It is never sent with optional usage counts.
Nothing in this list ever leaves your phone unless you use one of the features below.
Sync and your account
Pavelo works fully without an account. Sync is optional: it keeps an encrypted copy of your data on our server so your other devices can pick it up.
- Off until you set it up. You sign in with Google and choose to turn it on. An app update never switches it on or off.
- What we can't read. Your records are encrypted on your phone before they leave, with a key only your devices hold.
- What we can see. Your Google account identifier, and housekeeping details of each record: type, size, when it changed, whether it was deleted. Not your email address, name or photo. Cloudflare, which hosts the service, sees your IP address, as with any internet request.
- Signing in. Google confirms it is you, under its own privacy policy. Your phone keeps a sign-in credential for up to 180 days, renewed while you use sync.
- Your recovery key. The app shows it the first time you turn sync on. Keep it safe, because we cannot recover it or read your copy. Supported Android phones also keep recovery material in the app's backup and in Google's Block Store, but that depends on your device and backup settings, so don't count on it. A phone that already syncs can show the key again.
- Deleting it. The copy stays until you delete it. Signing out or uninstalling does not remove it. Settings → Sync → Delete synced copy removes the encrypted records and keys, or you can ask by email (see Delete your account). Your phone keeps its own data. Our cloud provider's recovery copies can outlast the deletion for as long as its retention rules allow.
- Kept apart. Sync sends nothing to Coach or Anthropic. Pavelo Dev, the test build, uses its own separate sync and statistics storage.
What we send to a server, and why
Pavelo uses Claude (made by Anthropic) for a set of optional features. The first time you use one, the app asks for your permission and lists what will be sent. You can decline, and nothing goes out.
- Coach chat. Your message and a snapshot of your active stack are sent to Claude. The reply comes back the same way.
- Routine check. Your stack and the profile fields you chose to fill in are sent so the Coach can propose a tidier daily arrangement. As-needed supplements are only checked against a small on-device interaction table.
- Stack Map. The constellation chart is computed on your phone. With your permission, Coach's weekly read uses your active stack and summary routine numbers. Asking Coach about a supplement opens a conversation for you to review and send. Results of the weekly read are cached locally for the week.
- How you felt. The weekly read sends counts only: how many check-ins, how many were good or great, which weekday ran brightest. Never your notes, never day-by-day entries.
- Supplement deep-dives. Generating a chapter sends the supplement name and your stack context.
- Label scan. Barcode reading happens on your phone via Google ML Kit. The barcode number is checked against the public Open Food Facts database. If that doesn't identify the product, the label photo is sent to Claude to read the brand, dose, and ingredients.
- Doctor report. Drafting the printable overview sends your stack and summary routine statistics.
AI requests travel through our server. We do not forward your device's IP address, AI metering identifier or purchase token to Anthropic. The content itself can contain personal information, including anything you type into Coach or include in a photo. These requests are not guaranteed to be anonymous.
Saying no to AI stops those requests and nothing else. Version checks, crash reports, feedback you send, sync and usage statistics are separate, and each has its own section on this page. A version check carries no stack records.
Optional usage statistics
Usage statistics are off until you turn them on, in every country. The tracker works exactly the same either way.
- Only a yes counts. You say yes from an invitation in the app or in Settings. Signing in, turning on Sync, finishing setup or closing a message never counts. An update keeps your choice.
- What is counted. App opens, progress views, scans started, scan results shown, failed scans, scan results saved, plan views and share files prepared. A phone adds at most one app open and three of each of the others per UTC day.
- What is never sent. Supplement names, doses, schedules, check-offs, notes, photos, barcodes, Coach messages, account or payment details. Nothing from before you said yes.
- No identity. No installation ID, no session ID, nothing that follows a phone from day to day. A count carries its name, the day, a random one-time receipt, the policy version and an opt-in marker, then joins a weekly total. We can't tell from it how many people use Pavelo.
- How it travels. Counts go to our own service on Cloudflare, which sees an IP address as with any internet request, so we don't call this anonymous. We store no IP addresses, user agents, location or region, and request logging is off. A short-lived daily hash of the address limits abuse. Counts are never used for advertising.
- How long we keep it. Weekly totals stay up to 12 months, delivery receipts up to three days. Database recovery backups can hold older contents up to 30 days more. Counts waiting on your phone expire within two UTC days.
- Turning it off. Collection stops and anything not yet sent is cleared. A count already in a weekly total can't be taken back out, because nothing ties it to your phone.
- If you ran an earlier preview. One preview build kept usage history linked to an installation. The update first asks our server to delete it, and Settings shows a retry if that fails. Anything left, the deletion receipt included, is gone within 120 days.
Who processes data for us
These are the services that handle data for us, each only for the purpose listed. An AI request can contain details of your stack. A usage count never does.
- Anthropic (Claude). Processes the content sent for the AI feature you choose. Its standard API policy retains inputs and outputs for up to 30 days. Different contractual terms, certain services or models, safety enforcement and legal requirements can change or extend retention. We do not promise zero retention. Current policy: privacy.claude.com.
- Cloudflare. Routes requests and stores optional usage statistics. If you turn on sync, it also stores your encrypted copy; neither Cloudflare nor we hold the key to read that copy.
- Open Food Facts. Receives the barcode number during a label scan, nothing else.
- Sentry (EU region). Receives crash reports and feedback messages you submit.
- Google sign-in and Android backup services. Handle optional account sign-in and recovery material on supported Android devices.
- Google Play Billing. Handles your subscription if you upgrade to Pro. We never see your payment details.
Subscriptions
If you upgrade to Pavelo Pro, the purchase runs through Google Play Billing. Google notifies us whether your subscription is active. Subscription verification is separate from optional usage statistics.
Sharing from the app
When you share a Stack Map image or send a backup copy somewhere, Pavelo prepares the file on your phone and hands it to Android's share sheet. Where it goes from there is your choice, and we don't see it.
Crashes and feedback
If the app crashes, a sanitized report goes to Sentry: stack trace, app version, Android version, device model. Nothing else. We strip route slugs (a "Magnesium" page becomes /supplement/<redacted>), drop console logs, and disable session replay. We don't use Crashlytics.
Feedback messages from Settings → Send feedback go to Sentry too. The message and app version only. No name, email, identifiers, or stack data. Only when you tap Send.
What we never do
- No third-party tracking or advertising SDKs. No Google Analytics, Facebook SDK, ad networks, or data brokers.
- We never sell your data or share it for advertising. The service providers listed here process data for the purposes described in this policy.
- No location tracking.
- No access to your contacts, calendar, or photos beyond the specific label photo you scan.
- No device fingerprinting.
Permissions Pavelo asks for
Each permission is requested only when needed, never on first launch:
- Notifications. To send the supplement reminders you configure.
- Camera. To scan a supplement label, only when you tap the scan button.
- Exact alarm scheduling. So reminders fire at the exact times you set, even in battery-saver mode.
- Full-screen alarm. So a reminder you switch to Alarm can ring over the lock screen. Never used for regular reminders.
- Foreground service while ringing. Keeps the alarm sound playing until you answer. It runs during the ring and stops right after.
- Battery optimization exemption. So reminders fire reliably on aggressive battery savers. Optional but recommended.
Your data, your control
- Back up. Settings → Backups. Keep a backup on your phone, save or send a copy, and restore it in the app. Your statistics choice, counts waiting to send and the old deletion credential are left out of backups.
- Delete. Settings → Danger Zone → Reset all data removes the tracking data on your phone. Turning off Usage statistics stops counts. Totals already added can't be removed per phone, and older linked statistics have their own deletion request. If sync is on, Settings → Sync → Delete synced copy removes the encrypted server copy. Do these before you uninstall, because an uninstalled app can't send them.
- Decline AI. Tap "Not now" and that AI request is not sent. The app asks again the next time you open that feature. This choice has nothing to do with usage statistics, crash reporting or the other network services above.
Children
Pavelo is built for adults. The app is designed and listed for people 18 and over, and we don't knowingly collect data from anyone younger.
Changes to this policy
If we change the policy, the date at the top updates. The current version always lives at pavelo.app/privacy, and the app links to it from Settings.
Contact
Questions, concerns, or requests: support@pavelo.app.
Operator: Rudolf Arthur H., based in the Philippines.
See also: Terms of service.