Skip to content
← Back to home

Privacy Policy

Last updated: August 30, 2026

This document describes how Velia works today and will be updated as the service evolves. The Spanish and English versions are the reference versions.

Velia was designed to care without intruding. Privacy isn't a promise we make: it's how the product is built. This document explains what is processed on the phone, what data travels to provide the service, and what is never stored.

01The principle: video is never stored

Continuous camera detection (on the Guardians) happens entirely inside the phone. No video is stored on our servers or in the cloud, and during normal monitoring no video leaves the phone. The two optional single-image exceptions are explained below.

When a family member asks to watch live, video and audio travel with end-to-end encryption (DTLS-SRTP) between the two phones — directly when the network allows it, or through a relay (TURN) that only sees encrypted packets it cannot read. In no case is it recorded.

02What does travel through the cloud

Routine traffic through our servers is text: events (for example, “activity detected” or “possible fall”), signals used to connect two phones, and status messages (heartbeats). It also includes care-related text: the first name of the person being cared for (if you set it), family push-notification identifiers and, where applicable, a brief AI-generated description. The optional images described in the next section are processed in memory for one specific request and are not stored; audio is never stored.

Velia does not ask for a personal account, email address, or password. The app creates a protected anonymous technical identity to authenticate the device and authorize access to each Home. Live video travels directly over the local network when possible; events, status and connection signaling still use the infrastructure described in this policy. A Home key is transferred by QR code and its fingerprint (hash) is used to authorize access.

Access to our infrastructure is protected with app verification (App Check), and the credentials for the video relay (TURN) are ephemeral.

03The two optional single-image features

During setup, after a family member confirms that the Guardian is in its final position, you may allow one image of the camera view to be analyzed to create an approximate floor map. The Guardian chooses the best of three frames locally, sends only that JPEG, and keeps only the resulting geometry. If you decline, setup continues with a fully local short walk.

For a critical event, and only if you enabled the second look, one image may be analyzed to add context before alerting the family. It is not used to identify people or make a medical decision.

In both cases the image is used only to service that real-time request: Velia does not write it to databases, files, logs, diagnostics, or analytics. The Google Cloud project processing these images must have confirmed zero retention, and Google does not use them to train models.

05Error and usage diagnostics

When the app fails, the error report travels to Sentry (servers in Germany) so we can fix it. That report carries the error type, the app version, the phone model and a trail of the last internal actions. It does NOT carry video, it does NOT carry screenshots — they are explicitly disabled — it carries neither your name nor your email, and your Home's key does not travel: only a fragment useful for grouping and useless for accessing anything.

We also measure usage anonymously and in aggregate with Firebase Analytics: how many people finish setup, how many respond to an alert, how many open the video. These are counters, not content: none of them include what the camera sees, who you are, or who you are with.

06What you send us by email

If you write to contact@velia.care — a question, a problem, a quote for a care home — we keep that email and what you tell us to reply, provide support and maintain a reasonable record of the conversation. We do not sell it or use it for third-party advertising. We delete it when it is no longer needed for those purposes, unless we must retain it by law or to resolve a dispute. You can ask us to delete it by writing to that same address.

07Launch waitlist and campaign measurement

If you join the launch waitlist, we store your email, language, consent date and, when present, campaign parameters (UTMs and fbclid) together with your entry path. We use them to send launch-related information and calculate registrations by campaign. We do not store your IP address or full user agent with that registration. We keep the record until you withdraw consent or the waitlist is no longer needed; every commercial message includes a simple way to unsubscribe.

Meta Pixel measurement is optional and has a separate checkbox. Only if you accept it and the Pixel is configured does the browser load Meta's script, record PageView, and send Lead after the registration is accepted. Those events do not include your name or email. Meta may use cookies or other identifiers under its own policy. You can join the waitlist without accepting this measurement.

08Velia Founders Program

If you apply to the Founders Program, we store the information needed to assess compatibility, contact you, support installation and operate the test: name, email, country, language, Viewer platform, availability of an Android Guardian, general relationship to the person being cared for, availability, consents, campaign attribution and, if you choose to provide it, a short goal without medical information. Operational program consent is separate from optional marketing consent.

We keep a status history and limited internal notes so important decisions are not overwritten. We do not send names, emails, open answers or personal identifiers to Google Analytics. Active applications are scheduled for deletion 365 days after creation or the latest relevant status update; withdrawn or declined applications 30 days after that status; and operational program messages 120 days after their scheduled send date. Automatic deletion may not be immediate and depends on our database retention policy. The private link in the receipt email lets you withdraw or delete the application and its associated communications earlier. Aggregated metrics, or records effectively disconnected from an individual, may be kept longer.

Operational emails confirm receipt, explain possible selection and support the test; they do not create a charge or imply acceptance. Private TestFlight or Google Play Testing links are not published on the website.

09Providers and international transfers

We use infrastructure services: Google Firebase for signaling, status and applications; Resend to deliver email when enabled; Google Cloud Vertex AI for the optional single-image features; and TURN relays for P2P video when a direct connection is not possible. Vertex processes the image only for the stated request under zero-retention configuration; relays see only encrypted packets. If you accept optional campaign measurement, we also use Meta Pixel. No provider receives stored video, because none exists.

These providers and their subprocessors may process data outside Australia, including in the United States and Germany, and in other countries where they operate. Velia Care Pty Ltd selects providers with appropriate contractual commitments and security measures, limits data to what is necessary, and takes reasonable steps to protect it under applicable law. You can request current information about these transfers at contact@velia.care.

10Cookies

Without your optional measurement consent, this website does not load Meta Pixel or advertising cookies. Internal waitlist attribution uses sessionStorage —which is cleared when the browser session ends— and is not shared with third parties. If you accept Meta Pixel, Meta may use cookies or other identifiers to measure the campaign.

11Telemetry

Diagnostic telemetry (to know whether the app is working well) is optional and anonymous. You can turn it off.

The app also sends crash reports to standard diagnostic services so we can fix errors; they contain technical device data, never video or care content.

12Access, correction, deletion and complaints

You can request access to, correction of, or deletion of your data, withdraw consent, or make a privacy complaint by writing to contact@velia.care. We may request reasonable information to verify your identity and protect other people's data. We do not charge you for making a request and will normally respond within 30 days.

Velia may be offered globally where local law permits. Rights and requirements may vary depending on your location.

We will first investigate the complaint and tell you the outcome. If it remains unresolved, you may complain to the Office of the Australian Information Commissioner (OAIC) or the data-protection authority that applies in your country. If you are in the European Economic Area, the United Kingdom, or another jurisdiction with additional rights, you may also request restriction, portability, or object to processing where applicable.

13Security and incidents

We use technical and organisational controls proportionate to risk, including restricted access, authentication, encryption in transit, ephemeral links and credentials, and data minimisation. No system is infallible. If an incident occurs, we will investigate it, limit its effects, and notify affected people and authorities when the law requires it.

14Service operator

Velia is operated by VELIA CARE PTY LTD (ACN 701 619 650, ABN 70 701 619 650), Australia, which is responsible for the service and processing described in this policy. Privacy contact: contact@velia.care.

15Minors and changes

Velia is not directed to minors and does not knowingly collect data from them.

If we change this policy, we will update the date above and, if the change is material, notify you. Questions: contact@velia.care.