Privacy & Data
Privacy Policy
What information Veyda collects, how Sage uses it, who processes it on our behalf, and the rights and controls you have.
Effective date: July 8, 2026
Veyda, LLC ("Veyda," "we," "us") is a Los Angeles based health intelligence company. This policy explains what personal information we collect, how we use it, and the choices you have. It covers:
- the Veyda iOS app, including Sage, the personal health intelligence inside the app,
- Sage conversations you choose to continue over text messaging, and
- the veyda.com website.
Veyda is for adults. You must be 18 or older to use the app.
The most important points up front:
- We do not sell your personal information, and we never will sell your health information.
- We do not show third party advertising, and we do not use your information for advertising.
- We do not track you across other companies' apps or websites.
- Your content is not used to train the third party AI models that power Sage.
- We use your health information to provide and personalize Veyda for you, and only for the purposes described in this policy.
If you live in Washington or Nevada, our Consumer Health Data Privacy Policy also applies to your consumer health data and controls over this policy if the two ever conflict.
1. Who we are and what this policy covers
Veyda, LLC operates the Veyda iOS app and the veyda.com website. The app helps you understand and improve your health with the support of Sage, which personalizes its guidance using the health information you choose to share.
This policy applies to information we collect through the app, the Sage text messaging channel, the website, and your communications with us, such as member support. It does not apply to third party services you connect to Veyda or purchase through Veyda, which have their own privacy policies.
2. Information we collect
We collect information in three ways:
- Directly from you, such as your account details, the messages you send Sage, your onboarding answers, and anything you upload.
- From your device and connected services, with your permission, such as Apple Health and connected wearables, and, if you choose, your medical records.
- Automatically as you use the app or website, such as usage data, diagnostics, and device identifiers.
This information is linked to your identity as a Veyda account holder. None of it is used to track you across other companies' apps or websites. The categories we collect:
Contact information
Your name, email address, and phone number, collected when you create an account, verify your phone, activate Sage by text, or communicate with us.
Health and wellness information
This is the heart of Veyda, and we treat it with the greatest care. Depending on what you choose to share or connect, this may include:
- data from Apple Health and connected wearables or devices, such as activity, workouts, sleep, heart rate and other vitals, body measurements, and cycle tracking
- mood and state of mind entries you record
- lab results and biomarkers
- medical records you retrieve through our records connection feature (see section 5) or documents you upload, such as visit notes, imaging reports, and test results
- nutrition information, including foods you log and food photos you share for recognition
- workout activity and fitness assessments
- body composition results and progress photos you choose to add
- your health history, medications and supplements, and health goals
You control what health data you connect or upload. You can decline or revoke Apple Health permissions at any time in your device settings, and you can disconnect a wearable or records source at any time in the app.
Sensitive information
Some of the information above, including health information and any genetic information you choose to provide, is considered sensitive under privacy laws. We collect it only with your consent and use it only to provide and personalize the service, as described in this policy.
Content you create
- messages you send Sage in the app or over text, and your conversation history
- memories Sage keeps so it can be genuinely personal, which you can review, correct, and remove in the app under What Sage knows about you
- answers you give during onboarding, check ins, and surveys
- photos you choose to share, such as food photos and progress photos
- bug reports and feedback you submit, which may include screenshots and diagnostic logs shared with our support tooling solely to investigate the issue
- messages you send member support
Identifiers
An account ID, device identifiers, and push notification tokens, so the app works and we can deliver notifications you have enabled.
Purchase and order information
Your subscription status and transaction records, and, if you buy through the Veyda marketplace, your order details and shipping address. Section 10 explains what we do and do not receive about payments.
Usage information
How you interact with the app and website, such as screens viewed, features used, and actions taken, along with your IP address and the approximate location derived from it. Our analytics are configured to exclude your health measurements and the content of your Sage conversations (see section 3).
Diagnostics
Crash reports, performance data, and technical logs that help us find and fix problems.
Information about other people
Documents you upload, such as medical records, can contain information about other people, including family members. Please upload only information you are entitled to share. If you believe someone has shared your information with us without the right to do so, contact us and we will address it.
3. How we use your information
- To run the service. Creating and securing your account, syncing your data, delivering features, processing marketplace orders, and sending service communications such as verification codes and account notices. We use SMS for verification codes, service messages, and, if you activate it, Sage by text. You can stop any SMS by replying STOP.
- To personalize your experience. With your consent, Sage uses the health information and content you share to tailor its guidance, insights, and recommendations to you. This is the core of what Veyda does. Section 7 describes how AI processing works.
- For your safety. If a conversation suggests you may be in crisis, the app surfaces emergency and crisis resources.
- Analytics and product improvement. We analyze usage events, diagnostics, and identifiers to understand what is working and improve the product. Our general product analytics are configured to exclude health measurements, lab results, chat content, and food logs, and we do not use your health information to build analytics profiles. Any analysis of health information is limited to providing and improving the health features you actually use.
- Member support. Responding to your questions and investigating issues you report.
- Legal and security purposes. Preventing fraud and abuse, enforcing our terms, and meeting legal obligations.
We do not use your information for third party advertising, and we do not sell it. If we create de-identified or aggregated data, we maintain it in de-identified form, do not attempt to re-identify it, and require the same of anyone we share it with.
4. Apple Health and connected devices
We make these commitments about data from Apple Health, Motion and Fitness, and connected wearables:
- We never use it for advertising or marketing of any kind.
- We never sell it, and we never share it with data brokers.
- We never share it with third parties, except service providers who process it on our behalf and on our instructions to provide the app's features (see section 8).
- We read this data with your permission; the app does not write data back into Apple Health.
- We use it only to provide the health features you have asked for and, with your permission, to personalize your experience.
5. Medical records you connect
If you choose to connect your medical records, we retrieve them from your providers through a patient mediated records network, only after you verify your identity and give explicit consent in the connection flow. The consent screen describes exactly what will be retrieved and how it will be used. Key points, which match that consent:
- Records are retrieved for one purpose: powering your health insights and personalized information inside Veyda.
- Your consent expires after one year unless you renew it. You can revoke it at any time, through Veyda or through the records network's own portal, and revocation stops further retrieval.
- Retrieved records are stored in our systems with the safeguards described in section 12, and you can review and remove individual records.
- You can ask us to delete your retrieved records at any time, and account deletion removes them.
The records network acts at your direction under its own terms and privacy policy, which are presented to you in the connection flow. Once your records are delivered to Veyda, this policy governs them.
You can also upload records and documents yourself. Uploaded documents get the same protections.
6. Genetic information
If you choose to provide genetic information, for example by uploading a genetic test report or retrieving records that contain genetic results, we apply additional protections:
- We collect and use it only with your express consent, and only to provide the features you request and personalize your experience.
- We do not disclose it to any third party without your consent, except service providers processing it on our behalf as described in section 8. Any other transfer would require your separate, express consent. We have no plans to make such transfers.
- We will never share your genetic information with insurers or employers.
- You can withdraw consent and have your genetic information deleted at any time (see section 13).
7. Sage and AI processing
Sage is powered by third party AI service providers that process your messages and relevant health context to generate responses. Our commitments:
- Your content is not used to train the third party AI models that power Sage. Our agreements and configurations with these providers prohibit the use of your conversations, health context, memories, and other Sage content for model training.
- Our primary AI provider processes member conversations under a healthcare grade agreement with heightened confidentiality obligations and limited, time bound data retention. A backup provider may process conversations if the primary is unavailable, under agreements that prohibit training on your content.
- When Sage consults specialized clinical evidence services to ground an answer, your question is de-identified first. Direct identifiers are stripped before anything is sent.
- A limited number of authorized Veyda staff may review conversations in pseudonymized form, with identifiers masked and personal details redacted, to monitor quality and safety and to investigate issues.
- Sage's output is informational and educational. It is not medical advice, diagnosis, or treatment.
The full picture, including how Sage memories work and Sage's limitations, is in our Artificial Intelligence Disclosure.
8. How we share information
We do not sell personal information, and we do not share it for third party advertising. We share information only in these situations:
Service providers. We work with companies that process information on our behalf to run Veyda. Our primary AI provider operates under a healthcare grade agreement with heightened confidentiality obligations. Other providers operate under data processing agreements that limit their use of your information to providing services to us. By category:
- cloud infrastructure, database, and hosting providers
- AI service providers (section 7)
- wearable and device connectivity providers
- laboratory partners, if you order lab testing through Veyda
- nutrition recognition providers, which process the food photos and descriptions you log to identify foods, without your identity attached
- fitness content providers, which supply workout videos and programming
- commerce and fulfillment providers for the marketplace (section 10)
- payment and subscription platforms (section 10)
- communications providers that deliver push notifications, email, SMS, and Sage by text
- support, feedback, and diagnostics tooling providers
- analytics providers (section 3)
Service providers are contractually limited to using your information to provide services to us and are prohibited from using it for third party advertising or selling it. Some platforms may also process limited technical and transaction data for their own security, fraud prevention, and legal compliance as the law permits.
Legal requirements. We may disclose information if required by law or legal process, or to protect the rights, safety, or property of Veyda, our members, or others. Where it is lawful and practicable, we will notify you of a legal request for your information.
Business transfers. If Veyda is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
At your direction. If you ask us to share something, for example exporting a summary to hand your doctor, we share it as you direct. The medical records network in section 5 also operates this way: it retrieves your records because you authorized it to, under its own privacy policy shown in the connection flow.
9. Sage by text
You can choose to continue Sage conversations over text messaging. If you activate this:
- We collect and store your phone number to link your texts to your account, and we store the messages you exchange with Sage by text so your conversation stays continuous across the app and messages.
- Messages travel over standard messaging services operated by Apple, your carrier, and our messaging delivery provider. Message transport is handled by those services under their own terms, so treat texting as convenient rather than maximally private. For sensitive topics, Sage will guide you back into the app.
- Sage sends proactive check ins over text only if you turn that on, and you can turn it off at any time.
- You can deactivate Sage by text in the app at any time, and you can stop messages by replying STOP.
10. Marketplace, payments, and subscriptions
Subscriptions. Memberships are purchased through Apple's App Store. Apple processes the payment; we never receive your card number. We receive confirmation of your subscription status and transaction records, managed through a subscription management provider, so we can unlock your membership features.
Marketplace. If you buy products through the Veyda marketplace, our commerce platform processes your cart, checkout, and order records, including your shipping address. Payment is handled by the payment method you choose at checkout, such as Apple Pay; we do not receive full card numbers. Some products are fulfilled by independent vendors, and the vendor of record is shown on the product listing. Fulfillment partners receive only what they need to deliver your order.
We do not use your purchase history for third party advertising, and we do not sell it.
11. How long we keep your information
We keep your information while your account is active so Sage and the app can use it, then delete it when you delete your account, subject to the limits below.
- Contact information and identifiers: kept for the life of your account, then deleted, except where needed for legal or dispute purposes.
- Health and wellness information, records, and content you create: kept for the life of your account. Your conversation history stays available to you and to Sage so context is never lost, unless you delete your account or specific data.
- Sage memories: kept while relevant; you can correct or remove individual memories at any time in the app, and account deletion removes them all.
- Purchase records: kept as required by tax, accounting, and financial record keeping rules, which may extend past account deletion.
- Usage data and diagnostics: kept for the shorter operational periods needed to analyze and fix problems, then deleted or aggregated.
12. How we protect your information
We use administrative, technical, and physical safeguards designed to protect your information, including encryption in transit and at rest, access controls that limit who and what can read your data, member level data isolation, and monitoring. Your data is stored and processed in the United States on US region cloud infrastructure. No system is perfectly secure, but protecting your health information is a core obligation we take seriously.
A note on phishing: Veyda will never call you to ask for your password or ask you to text personal information to an unknown number. If someone claiming to be Veyda does this, it is not us. Please report it to us.
13. Your rights and choices
You can, at any time:
- Access the personal information we hold about you and receive a copy in a portable format.
- Correct information that is inaccurate, including individual Sage memories under What Sage knows about you.
- Delete your account and data. Settings, then Privacy and Data, then Delete Account permanently deletes your account and the personal information in our systems, with a reasonable period for deletion to propagate through backups. We also direct service providers that processed your information for us to delete it, as applicable law requires. Deleting your account does not cancel an active App Store subscription; manage that in your Apple subscription settings.
- Export your information by asking us for a copy.
- Withdraw consent to our use of your health or genetic information. Features that depend on that data will stop working.
- Disconnect any wearable, device, or records source in the app, and revoke Apple Health permissions in your device settings.
- Opt out of marketing communications using the unsubscribe link in any marketing email, control push notifications in your device settings, and stop SMS by replying STOP.
To exercise any of these rights, use the options in the app or email privacy@veyda.com from the email address on your account. We verify your identity before acting on sensitive requests, respond within 45 days (extendable once by 45 days for complex requests, with notice), and will not discriminate against you for exercising your rights. If we decline a request, you may appeal by replying to our response, and we will answer your appeal within the time your state's law requires.
More detail, including state specific disclosures and our notice at collection, is on the Your Member Rights page.
14. Washington, Nevada, and consumer health data
Washington's My Health My Data Act, Nevada's consumer health data law, and similar laws give consumers specific rights over consumer health data, including the rights to access it, withdraw consent, and have it deleted. We collect consumer health data only with your consent or as necessary to provide what you asked for, we obtain separate consent before sharing it in ways not described in our policies, and we do not and will not sell consumer health data.
The complete disclosure, including categories, sources, purposes, sharing, and how to exercise these rights, is in our Consumer Health Data Privacy Policy.
15. California privacy rights
If you are a California resident, the CCPA, as amended by the CPRA, gives you rights to know, access, correct, delete, and port your personal information, and to not be discriminated against for exercising them. These match the rights in section 13 and are exercised the same way. You may use an authorized agent, and we will verify the request as the law allows.
- We do not sell or share your personal information as those terms are defined by California law, including no sharing for cross context behavioral advertising. Because we do not sell or share personal information, there is no opt out to offer, and we treat any opt out request as confirmation that no such processing occurs.
- Sensitive personal information. Health information is sensitive personal information under California law. We use it only to provide and personalize the service you expect, and we do not use it to infer characteristics for advertising or other unrelated secondary purposes, so California's right to limit does not require a separate link.
- Notice at collection. The categories we collect are in section 2, our purposes in section 3, recipients in section 8, and retention criteria in section 11. A category by category notice at collection is on the Your Member Rights page.
- Shine the Light. We do not disclose personal information to third parties for their own direct marketing purposes.
- Medical and genetic information. California's Confidentiality of Medical Information Act protects medical information, and the Genetic Information Privacy Act protects genetic data. We maintain medical information in accordance with these laws, and our genetic information practices in section 6, including express consent for collection and separate consent for any transfer, are designed to meet them.
16. Other US state privacy rights
A growing number of states, including Colorado, Connecticut, Virginia, Texas, and Oregon, have comprehensive privacy laws. Where one applies to you:
- Sensitive data. These laws require opt in consent before processing sensitive data, which includes health information. We obtain your consent when you create your account and when you connect health data sources, as described in sections 2 through 6.
- Your rights to confirm, access, correct, delete, and port your data match section 13 and are exercised the same way.
- Opt outs. These laws let you opt out of targeted advertising, sale of personal data, and certain profiling that produces legal or similarly significant effects. We do not do any of these things. If you send an opt out request, we will honor it by confirming that no such processing occurs.
- Appeals. If we decline a request, you may appeal as described in section 13. If your appeal is unsuccessful, you may contact your state attorney general.
Because we do not sell or share personal information or use it for targeted advertising, there is nothing for a Global Privacy Control signal to switch off; where the law treats GPC as an opt out of sale or sharing, we honor it.
17. United States only
Veyda is offered in the United States. Your information is stored and processed in the United States. We do not offer Veyda in the European Economic Area or the United Kingdom. If you use Veyda while traveling, your information is still processed in the United States under this policy.
18. HIPAA and breach notification
Veyda is a direct to consumer service. We are not a healthcare provider, health plan, or healthcare clearinghouse, and we are not a covered entity under HIPAA, so HIPAA generally does not apply to the information you share with Veyda directly.
That does not mean your information is unprotected. We protect it through the commitments in this policy: a healthcare grade agreement with our primary AI provider, contractual limits on every service provider, the safeguards in section 12, no advertising use, no sale, and your deletion and export rights. In addition, the FTC's Health Breach Notification Rule applies to services like ours. If a breach of security affects your information, we will notify you and the appropriate regulators as the rule and other applicable laws require, without unreasonable delay and within the timelines the law sets.
19. Children
Veyda is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. Our onboarding requires you to confirm you are 18 or older. If we learn we have collected information from someone under 18, we will delete it.
20. Changes to this policy
We may update this policy as Veyda evolves. If we make material changes, we will notify you in the app or by email at least 30 days before they take effect. If a change would materially expand how we use health information we have already collected, we will ask for your consent rather than just notify you.
21. Contact us
Questions, requests, or concerns about privacy:
Veyda, LLC 9229 Sunset Boulevard, 8th Floor West Hollywood, CA 90069 Email: privacy@veyda.com
You can also reach us through member support in the app.