Privacy policy
At a glance
- Pavelo is built local-first. Your stack, logs, notes, and reminders live on your phone, not on our servers.
- We don't run a user database. There's no account, no email login, no profile.
- AI features (Coach, Stack Map, label scan, deep-dives) send data to Anthropic. They're optional. Decline once and they stay off.
- We don't run analytics. We don't sell data. There's nothing to sell.
- Uninstalling the app deletes your data. Reinstalling starts fresh.
What lives on your device
Everything that defines your day lives in the app's local database:
- Your supplement list, doses, schedules, and reminder times
- Daily check-offs
- Mood entries and journal notes
- Settings and preferences
- A random anonymous identifier created on first launch. Used only to talk to our AI service. Not tied to your name, email, or any identity.
Nothing in this list ever leaves your phone unless you use one of the features below.
What we send to a server, and why
Pavelo uses Claude (made by Anthropic) for a handful of optional AI features. The first time you use one, the app asks for your permission. You can decline.
- Coach chat. Your message and a snapshot of your active stack are sent to Claude. The reply comes back the same way.
- Stack Map. The constellation chart is computed on your phone. If AI is on, two short calls write the weekly story and Coach's take recommendations when needed. Each call sends your active stack and last week's adherence. Results are cached locally for the week.
- Label scan. Barcode reading happens on your phone via Google ML Kit. If the barcode can't be identified, the label photo is sent to Claude to read the brand, dose, and ingredients.
- Supplement deep-dives. Tapping "Generate" sends the supplement name and your stack context to Claude to write a short chapter.
Skip these features and nothing leaves your phone.
Who processes data for us
A small number of services see fragments of your data when AI or feedback features run. None see your whole stack or your identity.
- Anthropic (Claude). Receives the specific request you triggered. Their commercial API deletes request and response data within 30 days. Full policy: privacy.anthropic.com.
- Cloudflare. Routes AI requests. Doesn't store request contents.
- Sentry (EU region). Receives crash reports and feedback messages you submit.
- Google Play Billing. Handles your subscription if you upgrade to Pro. We never see your payment details.
Subscriptions
If you upgrade to Pavelo Pro, the purchase runs through Google Play Billing. Google notifies us whether your subscription is active. Your Pro status lives on your phone, tied only to the anonymous identifier.
Sharing your Stack Map
When you tap share on the Stack Map, Pavelo renders an image of your constellation on your phone and hands it to Android's share sheet. We don't see what you share or where.
Crashes and feedback
If the app crashes, a sanitized report goes to Sentry: stack trace, app version, Android version, device model. Nothing else. We strip route slugs (a "Magnesium" page becomes /supplement/<redacted>), drop console logs, and disable session replay. We don't use Crashlytics.
Feedback messages from Settings → Send feedback go to Sentry too. The message and app version only. No name, email, identifiers, or stack data. Only when you tap Send.
What we never do
- No behavioural analytics. No PostHog, Mixpanel, Google Analytics, Facebook SDK, funnel tracking, or A/B test SDKs.
- No selling or sharing data with advertisers or data brokers.
- No location tracking.
- No access to your contacts, calendar, or photos beyond the specific label photo you scan.
- No device fingerprinting.
Permissions Pavelo asks for
Each permission is requested only when needed, never on first launch:
- Notifications. To send the supplement reminders you configure.
- Camera. To scan a supplement label, only when you tap the scan button.
- Exact alarm scheduling. So reminders fire at the exact times you set, even in battery-saver mode.
- Battery optimization exemption. So reminders fire reliably on aggressive battery savers. Optional but recommended.
Your data, your control
- Export. Settings → Backups & Sync → Export JSON. You get a complete copy of everything.
- Delete. Settings → Danger Zone → Reset all data. Or just uninstall the app.
- Decline AI features. Tap "Not now" on any AI consent prompt. The feature stays inactive; the rest of the app keeps working.
Children
Pavelo is built for adults. We don't design for children under 13 and we don't knowingly collect data from them.
Changes to this policy
If we change the policy, we'll update the date at the top and surface a one-screen notice on the next app launch after the change.
Contact
Questions, concerns, or requests: [email protected].
Operator: Rudolf Arthur H., based in the Philippines.
See also: Terms of service.