Vaunt: Privacy Policy
This Privacy Policy explains how Vaunt ("Vaunt", "we", "us", or "our") collects, uses, stores, and protects information when you use the Vaunt mobile application (the "App"). Vaunt is a private, self-directed self-improvement coach: you analyze only your own photos, build routines and a personalized roadmap, and track your own progress over time. There is no social feed, no leaderboard, and no way to view, rate, or share other people.
If you have any questions about this policy or your data, contact us at privacy@getvaunt.app.
1. Who we are (Data Controller)
The data controller responsible for your personal data is Nerion Systems, Bratislava, Slovakia (the operator of Vaunt), reachable at privacy@getvaunt.app. For users in the European Union / European Economic Area and the United Kingdom, this means we determine the purposes and means of processing your personal data as described below.
Registered address: Nerion Systems s. r. o., Landererova 7743/8, 811 09 Bratislava, Slovakia.
2. Important note about the AI baseline
The AI baseline in Vaunt (the category estimates and the short written summary) is an algorithmic estimate generated for self-improvement purposes only. It is not medical, psychological, dermatological, or professional advice, and it is not a diagnosis or assessment of your health. Do not rely on it as such. If you are struggling with how you feel about your appearance or your mental health, please seek support from a qualified professional or a helpline such as the one listed at findahelpline.com.
Vaunt is intended for adults only (see Section 11, Children's privacy).
3. What we collect
We only collect the data described below. We do not collect your contacts, your precise or approximate location, your web browsing history, your calendar, audio recordings, or any data about other people.
a. Account data
- Email address: used to create and secure your account, sign you in, confirm your email, and send essential account messages (such as password resets). Authentication uses email and password.
- Account identifier (User ID): a unique ID generated for your account, used to associate your data with you and to link your subscription.
b. Profile data (onboarding)
- Age / date of birth: collected at the 18+ age gate at sign-up and during onboarding, used to confirm you are an adult and to personalize your roadmap and guidance.
- Goal: for example glow-up, bulk, cut, or recomposition.
- Self-rating: a starting score (1–10) you give yourself during onboarding.
c. AI baseline data
- Baseline estimates and summary: the category estimates, your overall estimate, and the short text summary produced by the AI baseline. These are stored in your account so you can see your history and so the App can generate a tailored roadmap. (See Section 4 for how the underlying selfie is handled; it is not stored.)
d. Routines, check-ins, and roadmap data
- Routines and routine steps you create (for example a morning or evening routine and its steps).
- Daily check-ins: which steps you completed and on which day, used to power streaks and progress.
- Roadmap: your AI-generated 90-day glow-up roadmap and its weekly tasks, including which tasks you have checked off.
e. Progress photos (stored)
- Progress-tracker photos: when you use the weekly progress tracker, the photos you upload (for example front, side, and body shots) are stored so you can compare your progress over time. They are kept in a private, per-user storage area that is not publicly accessible and is protected so that only your account can read them (see Section 8, Security). Progress photos are optional; you can use the rest of the App without uploading them.
f. Purchase data
- Subscription and purchase history: your subscription status, plan, trial state, renewals, and refunds. This is managed through our subscription provider and the app store's billing system so we can give you access to premium features and manage your subscription.
- We do not collect or store your payment card details. Card and payment processing is handled entirely by the app store (for example Google Play), not by Vaunt.
g. Referral codes
- Creator referral code: if you arrive through a creator's referral link or you enter a creator code at the end of onboarding, we record that code and associate it with your account so we can attribute the referral and pay the creator. The code may be captured from the link you opened or, on first launch, from a one-time read of your device clipboard if a referral marker is present (the marker is then cleared). We do not read or retain other clipboard content.
We do not collect special categories of data such as race or ethnicity, political or religious beliefs, sexual orientation, or health records.
4. How rating selfies are handled (processed, then immediately discarded)
This is important, so we state it plainly:
- When you submit a selfie to be analyzed for your private baseline, the image is sent securely to our server function, which forwards it to our AI processor (Anthropic) for that single request only.
- The image is held only in memory for the duration of that request. It is not written to any database or storage bucket, is not logged, is not used to build a profile of you, and is not retained by us after the baseline is produced.
- Once the AI returns your estimates, only the numeric estimates and the text summary are saved to your account. The selfie itself is discarded.
By contrast, progress-tracker photos are different: those you choose to upload to the weekly progress tracker are stored long-term in your private storage area (Section 3e) so you can track change over time. If you want nothing stored at all, do not upload progress photos.
5. How we use your data and our lawful basis (GDPR)
We process your data only for the purposes below. For users in the EU/EEA and UK, the relevant lawful basis under the General Data Protection Regulation (GDPR) is shown for each purpose.
| Purpose | Data used | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Create and operate your account; sign you in; secure the App | Email, User ID, password | Performance of a contract (Art. 6(1)(b)) |
| Provide the core features: generate the AI baseline, build and store your roadmap, routines, check-ins, and progress photos | Profile data, baseline estimates/summary, routines, check-ins, roadmap, progress photos, and (transiently) the baseline selfie | Performance of a contract (Art. 6(1)(b)) |
| Confirm you are 18+ | Age / date of birth | Legal obligation and our legitimate interest in operating an adults-only service (Art. 6(1)(c) / 6(1)(f)) |
| Manage subscriptions, trials, renewals, and refunds | Purchase history, User ID | Performance of a contract (Art. 6(1)(b)) |
| Attribute creator referrals and calculate creator payouts | Referral code, User ID, purchase data | Legitimate interests in running our referral programme (Art. 6(1)(f)) |
| Keep the service secure and prevent abuse (for example rate limits) | Account/usage data | Legitimate interests in security and fraud prevention (Art. 6(1)(f)) |
| Send essential service messages (for example password reset, email confirmation) | Performance of a contract (Art. 6(1)(b)) |
Where you have enabled push notifications, your device's notification permission is used to deliver reminders; you can turn this off in your device settings at any time.
6. We do not sell your data and do not use it for third-party advertising
- We do not sell your personal data.
- We do not share your personal data with third parties for their own advertising or marketing.
- We do not use your photos or your text to train AI models.
- We do not run third-party advertising SDKs that profile you in the App.
7. Sub-processors (third parties that process data on our behalf)
We use a small number of trusted service providers ("sub-processors") who process data only on our instructions to provide the App. They act as processors, not independent controllers of your data, and they are contractually bound to protect it.
| Sub-processor | Role | What it receives |
|---|---|---|
| Supabase | Hosting, authentication, database, and file storage | Your account email and password (for authentication), your User ID, and all data you store in the App: profile, baseline estimates/summary, routines, check-ins, roadmap, stored progress photos (in a private bucket), and referral records. |
| Anthropic | AI processing of your photos and text to generate the baseline and roadmap | The image you submit for your baseline (processed in memory for that request only, then discarded; see Section 4) and the profile context used to generate your roadmap (such as age, goal, current estimate, and the text summary). Anthropic processes this to return a result and, under our terms, does not store it after the request and does not use it to train its models. |
| RevenueCat | Subscription management | An app user identifier (your account User ID), your subscription/purchase events and status, and, if you used a creator code, that referral code. RevenueCat acts as our processor for managing subscriptions. |
The app store's billing system (for example Google Play Billing) processes your actual payment to complete purchases; we do not receive your card details.
8. Security
We take reasonable and appropriate technical and organizational measures to protect your data, including:
- Encryption in transit: all communication between the App, our servers, and our sub-processors uses HTTPS/TLS.
- Row-Level Security (RLS): every record in our database is locked to its owner. Your data can only be read or written by your own authenticated account.
- Private storage: stored progress photos live in a non-public storage bucket, organized per user, so only your account can access your files. There are no public links to your photos.
- Server-side secrets: the AI provider's API key lives only on our server functions and is never present in the App.
- No long-term storage of baseline selfies: as described in Section 4, photos submitted for the AI baseline are not persisted.
No method of transmission or storage is ever completely secure, but we work to protect your data using the measures above.
9. Data retention
- We keep your account data, profile, baseline history, routines, check-ins, roadmap, stored progress photos, and referral records for as long as your account exists, so the App can show your history and progress.
- Baseline selfies are not retained: they exist only for the duration of a single request (Section 4).
- When you delete your account (Section 10), we delete your associated data, including your stored progress photos, as described there.
- We may retain limited records where we are required to by law (for example certain transaction or tax records related to purchases), and aggregated or anonymized information that does not identify you.
10. How to delete your account and data
You can delete your account and the personal data associated with it at any time. There are two ways:
a. In the App. Open the App and go to Settings → Delete account, then confirm. This removes your account and your associated data: your profile, baseline history, routines, check-ins, roadmap, and your stored progress photos.
b. By email. If you have uninstalled the App or prefer not to use the in-app option, email privacy@getvaunt.app from the email address tied to your account and ask us to delete your account and data. We will verify the request and act on it.
When your account is deleted, we delete the data tied to it across our systems, including the rows in our database and your stored progress photos in the private storage bucket, and we instruct our sub-processors to remove the associated data they hold on our behalf. Some records may be retained only where the law requires (see Section 9). Because baseline selfies are never stored, there is nothing to delete on that front.
A dedicated, publicly accessible deletion page is also available at getvaunt.app/delete-account.
11. Children's privacy
Vaunt is intended for adults aged 18 and over only. The App is not directed to children, and we do not knowingly collect personal data from anyone under 18. You must confirm you are 18 or older at sign-up. If you believe a person under 18 has provided us with personal data, contact privacy@getvaunt.app and we will delete it.
12. Your privacy rights (GDPR and others)
If you are in the EU/EEA or the UK, you have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: ask us to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): ask us to delete your data (see Section 10).
- Right to data portability: request your data in a structured, commonly used, machine-readable format.
- Right to restrict processing: ask us to limit how we use your data in certain circumstances.
- Right to object: object to processing based on our legitimate interests, including the referral programme.
- Right to withdraw consent: where processing is based on consent, withdraw it at any time (this does not affect prior lawful processing).
- Right to lodge a complaint: with your local data protection authority.
To exercise any of these rights, email privacy@getvaunt.app. We will respond within the time required by applicable law (generally within one month under the GDPR). We may need to verify your identity before acting on a request.
Depending on where you live, you may have similar rights under other laws (for example certain US state privacy laws). We honour applicable rights regardless of where you are located; contact us at the address above.
13. International data transfers
We are based in, and our sub-processors may operate from, locations including the United States. This means your personal data may be transferred to and processed in countries outside the EU/EEA and the UK, including the United States, which may have different data-protection laws.
Where we transfer personal data internationally, we rely on appropriate safeguards required by law, such as the European Commission's Standard Contractual Clauses (SCCs) (and the UK Addendum where applicable) with our sub-processors, to ensure your data receives an equivalent level of protection.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the App. Your continued use of the App after an update means you accept the revised policy.
15. Contact
For any privacy question, request, or complaint, contact us at:
privacy@getvaunt.app
Nerion Systems, Bratislava, Slovakia
Registered address: Nerion Systems s. r. o., Landererova 7743/8, 811 09 Bratislava, Slovakia.