← Back to Vedra

Privacy Policy

Last updated: July 2026

1. Who we are

Vedra (“we”, “us”, “our”) is a personal health intelligence platform operated at vedra-health.com. We help you understand your health data — blood test results, DNA reports, body composition scans, and related health metrics.

2. Data we collect

  • Account data: email address, name (from Google sign-in)
  • Health data: blood biomarker results, DNA trait data, body composition measurements, Apple Health exports — all uploaded by you
  • Profile data: age, sex, height, weight, activity level (used to personalise reference ranges)
  • Usage data: pages visited, features used, error logs — collected anonymously via Sentry and via cookieless Cloudflare Web Analytics (no cookies, no cross-site tracking)
  • Acquisition data: the campaign tags in the link you first arrived through (UTM source, medium and campaign) and the referring site. This tells us which channels bring people to Vedra. It contains no health data. We store it on a first-touch basis under our legitimate interest in understanding how the product is found
  • Billing data: subscription status, payment method details — handled entirely by Stripe, we never see your card number

3. How we use your data

  • To provide the Vedra service — analysing and displaying your health data
  • To generate AI-powered insights using your biomarker data (processed via Anthropic’s Claude API)
  • To personalise reference ranges based on your health profile
  • To send transactional emails (account confirmation, password reset)
  • To improve the service based on anonymised usage patterns

We never sell your data, and we never send your health data, or any personal identifier, into an advertising platform. Where we measure paid-ad performance (see section 7), the only signals shared are generic, non-medical funnel events such as a sign-up, with no health context.

4. Data storage and security

Your health data is stored in Supabase (PostgreSQL) hosted in the EU. Sensitive fields — including journal notes — are encrypted at rest using AES-256. All data is transmitted over HTTPS.

AI processing: when you use the AI assistant, your biomarker data is sent to Anthropic’s API to generate responses. Anthropic does not train models on API data. See Anthropic’s privacy policy.

5. Your rights (GDPR)

If you are in the UK or EU, you have the right to:

  • Access your data — export it from the Profile page at any time
  • Delete your data — use the “Delete account” option in Profile, which permanently removes all your health data
  • Rectify incorrect data — edit your health profile at any time
  • Portability — download your data as CSV or PDF from the app

To exercise any right or for data enquiries, contact us at james@vedra-health.com.

6. Third-party services

  • Supabase — database and authentication (EU-hosted)
  • Anthropic — AI analysis (US-based, GDPR-compliant)
  • Stripe — payment processing (does not receive health data)
  • Railway — application hosting (EU region)
  • Sentry — error monitoring, anonymised (EU DSN)
  • Cloudflare Web Analytics — cookieless traffic analytics (no cookies, no personal data)
  • Meta (Facebook) and Microsoft (Bing) — advertising-performance measurement, loaded only after you opt in (see section 7). They never receive health data or personal identifiers from us

7. Cookies and advertising pixels

Essential cookies. We use a session cookie to keep you signed in. This is strictly necessary for the service to work and does not require consent.

Cookieless analytics. Our traffic analytics (Cloudflare Web Analytics) set no cookies and do not track you across sites, so they also fall outside consent.

Advertising cookies (consent required). When we run paid advertising, we use the Meta (Facebook and Instagram) Pixel and the Microsoft (Bing) UET tag to measure whether an advert led to a sign-up. These set advertising cookies. Under UK PECR and UK GDPR they load only after you opt in through our cookie banner, and they stay completely inert until then. The only events we send are generic, non-medical funnel signals such as a sign-up. We never send health data, your name, your email or any other identifier into these pixels.

Withdrawing consent. You can change or withdraw your choice at any time using the “Cookie settings” link in the footer. Withdrawing is as easy as giving consent, and it stops the pixels loading on future visits.

8. Medical disclaimer

Vedra is a personal health tracking tool, not a medical device. Nothing on Vedra constitutes medical advice, diagnosis, or treatment. Always consult a qualified healthcare professional for medical decisions.

9. Changes to this policy

We may update this policy. Significant changes will be notified by email. Continued use of Vedra after changes constitutes acceptance.

10. Contact

Questions about privacy: james@vedra-health.com