Privacy policy
At a glance
- Pavelo is built local-first. Your stack, logs, notes, and reminders live on your phone, not on our servers.
- We don't run a user database. There's no account, no email login, no profile.
- The AI features are optional and ask first. Nothing is sent until you agree on the consent screen, and the screen tells you exactly what goes out.
- AI requests carry no identity. There's no account behind them, no name attached, and your IP address never reaches Anthropic.
- We don't run analytics. We don't sell data. There's nothing to sell.
- Uninstalling the app deletes your data. Backup files you saved or sent elsewhere are yours and stay where you put them.
What lives on your device
Everything that defines your day lives in the app's local database:
- Your supplement list, doses, schedules, and reminder times
- Daily check-offs
- How-you-felt check-ins and journal notes
- Settings and preferences
- Backups you keep on the phone (the app rotates the three most recent)
- A random anonymous identifier created on first launch. Used only to talk to our AI service. Not tied to your name, email, or any identity.
Nothing in this list ever leaves your phone unless you use one of the features below.
What we send to a server, and why
Pavelo uses Claude (made by Anthropic) for a set of optional features. The first time you use one, the app asks for your permission and lists what will be sent. You can decline, and nothing goes out.
- Coach chat. Your message and a snapshot of your active stack are sent to Claude. The reply comes back the same way.
- Routine check. Your stack and the profile fields you chose to fill in are sent so the Coach can propose a tidier daily arrangement. As-needed supplements are only checked against a small on-device interaction table.
- Stack Map. The constellation chart is computed on your phone. If AI is on, two short calls write the weekly story and the Coach's take. Each sends your active stack and last week's routine numbers. Results are cached locally for the week.
- How you felt. The weekly read sends counts only: how many check-ins, how many were good or great, which weekday ran brightest. Never your notes, never day-by-day entries.
- Supplement deep-dives. Generating a chapter sends the supplement name and your stack context.
- Label scan. Barcode reading happens on your phone via Google ML Kit. The barcode number is checked against the public Open Food Facts database. If that doesn't identify the product, the label photo is sent to Claude to read the brand, dose, and ingredients.
- Doctor report. Drafting the printable overview sends your stack and summary routine statistics.
Every request in this list goes out anonymously. There's no account, so no name or email is attached. Requests travel through our server, so Anthropic never sees your IP address. The app's anonymous identifier stops with us too: our server uses it to count requests, then strips it before anything goes to Claude. Anthropic can read what a request contains, but can't tie it to a person.
Skip these features and nothing leaves your phone. Separately, the app makes one small non-personal request: a version check against our server so it can tell you when an update exists. It carries no data about you or your stack.
Who processes data for us
A small number of services see fragments of your data when the optional features run. None see your whole history or your identity.
- Anthropic (Claude). Receives the specific request you triggered, with no name, no identifier, and no IP address attached. Anthropic doesn't train its models on this data and doesn't store the content of these requests by default. Content flagged by their safety systems can be held longer. Full policy: privacy.claude.com.
- Cloudflare. Routes the requests. Doesn't store their contents.
- Open Food Facts. Receives the barcode number during a label scan, nothing else.
- Sentry (EU region). Receives crash reports and feedback messages you submit.
- Google Play Billing. Handles your subscription if you upgrade to Pro. We never see your payment details.
Subscriptions
If you upgrade to Pavelo Pro, the purchase runs through Google Play Billing. Google notifies us whether your subscription is active. Your Pro status lives on your phone, tied only to the anonymous identifier.
Sharing from the app
When you share a Stack Map image or send a backup copy somewhere, Pavelo prepares the file on your phone and hands it to Android's share sheet. Where it goes from there is your choice, and we don't see it.
Crashes and feedback
If the app crashes, a sanitized report goes to Sentry: stack trace, app version, Android version, device model. Nothing else. We strip route slugs (a "Magnesium" page becomes /supplement/<redacted>), drop console logs, and disable session replay. We don't use Crashlytics.
Feedback messages from Settings → Send feedback go to Sentry too. The message and app version only. No name, email, identifiers, or stack data. Only when you tap Send.
What we never do
- No behavioural analytics. No PostHog, Mixpanel, Google Analytics, Facebook SDK, funnel tracking, or A/B test SDKs.
- No selling or sharing data with advertisers or data brokers.
- No location tracking.
- No access to your contacts, calendar, or photos beyond the specific label photo you scan.
- No device fingerprinting.
Permissions Pavelo asks for
Each permission is requested only when needed, never on first launch:
- Notifications. To send the supplement reminders you configure.
- Camera. To scan a supplement label, only when you tap the scan button.
- Exact alarm scheduling. So reminders fire at the exact times you set, even in battery-saver mode.
- Battery optimization exemption. So reminders fire reliably on aggressive battery savers. Optional.
Your data, your control
- Back up. Settings → Backups. Keep a backup on your phone, save or send a copy anywhere you like, and restore the latest in one tap. The file is a complete copy of everything.
- Delete. Settings → Danger Zone → Reset all data. Or just uninstall the app.
- Decline AI. Tap "Not now" on the consent screen and nothing is sent. The app will simply ask again the next time you open one of those features; agreeing once covers that feature from then on. The rest of the app never needs the network.
Children
Pavelo is built for adults. The app is designed and listed for people 18 and over, and we don't knowingly collect data from anyone younger.
Changes to this policy
If we change the policy, the date at the top updates. The current version always lives at pavelo.app/privacy, and the app links to it from Settings.
Contact
Questions, concerns, or requests: [email protected].
Operator: Rudolf Arthur H., based in the Philippines.
See also: Terms of service.