Privacy and GDPR

Your GLP-1 records stay on your iPhone

Most health apps ask you to hand over your data before they will hold it for you. Velto does not, because there is no account to hand it to. Your medication history, weight, symptoms, photos and notes are stored on your device. This page explains exactly what that means, including the parts that are less convenient to say.

No accountNo email requiredController based in Berlin

Three things that are structurally true

There is no account

You do not create a Velto account, and you never give us a name or an email address in order to track. Velto is not an account-based service.

There is no credential database to breach. It also means that if you ask us to delete your tracking data, we generally cannot identify it — which is why the privacy policy tells you to delete it yourself on your device.

Your health records live on your device

Medication, treatment dates, dosage, weight, progress photos, symptoms, mood, notes and nutrition are stored locally and protected by Apple's device data protection.

If you turn on sync, it runs through your own iCloud account using Apple CloudKit. That is your Apple account under your iCloud settings, not a Velto server holding a copy.

The controller is in Berlin

Velto is made by MoneyCoach, whose registered contact address is in Berlin, Germany. GDPR applies to this processing directly rather than by extension.

You can exercise your rights by emailing us, and you can lodge a complaint with a German data-protection supervisory authority if you are not satisfied with the response.

What Velto holds, and where

The distinction that matters is not what we promise but what is architecturally possible. Health records and product analytics are handled completely differently.

DataWhere it livesCan Velto see it?
Medication, doses, treatment datesYour device, optionally your iCloudNo
Weight, progress photos, body measurementsYour device, optionally your iCloudNo
Symptoms, mood, appetite, journal notesYour device, optionally your iCloudNo
Apple Health data (weight, steps, water, nutrition)Apple Health, only with your permissionNo, and you can revoke access any time
Subscription status and purchase receiptsApple and RevenueCatYes, as an anonymous app identifier
App events such as viewing a paywallRevenueCat, Meta App Events, Apple attributionYes, without health content
Website visits and page viewsVercel Web Analytics, self-hosted UmamiYes, in aggregate
Newsletter email addressMailchimp, only if you subscribeYes, until you unsubscribe

What does leave your device

Being honest about this is more useful than a privacy badge. Velto is not a zero-telemetry app, and here is the full list of what goes out.

Purchases and subscriptions
Handled by Apple through the App Store. We use RevenueCat to manage subscription status and restorations. We never receive your full payment-card details.
Product analytics and attribution
App events, app version, device and operating-system information, approximate region, technical diagnostics and an install identifier, via RevenueCat, Meta App Events and Apple's privacy-preserving attribution. This is not intended to contain medication entries, symptoms, weight, photos, journal notes or Apple Health records.
Website delivery and analytics
IP address, timestamps, requested URLs, referrer and browser information for delivery and security, plus page views through Vercel Web Analytics and a self-hosted Umami instance.
Contact and newsletter
If you email us or subscribe, we process what you send. Contact messages are delivered through Twilio SendGrid and newsletter subscriptions through Intuit Mailchimp.

The part most privacy pages leave out

Several of those providers are US companies, so some of that data is processed outside Germany and the European Economic Area. Where that happens we rely on an applicable transfer mechanism such as an adequacy decision or standard contractual clauses. We would rather write that plainly than imply everything stays inside Europe, because it does not. What does stay on your device is the part that matters most: the health record itself.

Your rights under GDPR

Depending on where you live and which law applies, you can ask us to do each of the following.

  • Access the personal data we hold about you
  • Have it corrected or deleted
  • Restrict how we process it
  • Receive data you provided in a portable format
  • Object to processing based on legitimate interests, or to direct marketing
  • Withdraw consent at any time for future processing
  • Lodge a complaint with a data-protection supervisory authority

Email info@veltoglp.com to exercise any of these. We may need information from you to verify the request. Because Velto has no accounts, tracking data stored on your device or in your private iCloud generally has to be deleted by you, through the app, your device settings, Apple Health or iCloud.

Who is responsible

The controller responsible for the processing described here is MoneyCoach. Privacy questions and requests go to info@veltoglp.com.

MoneyCoachc/o Volkssolidarität e. V.Alte Schönhauser Straße 1610119 Berlin, Germany
info@veltoglp.com

Full privacy policy

Questions worth asking any GLP-1 tracker

Whether or not you choose Velto, these are the questions that separate a genuine privacy position from a marketing one. Ask them of any app you are considering.

  • Do I have to create an account to use it?No
  • Where are my health records actually stored?On your device
  • Who is the data controller, and where are they based?MoneyCoach, Berlin
  • Is my health data sold or used for advertising?No
  • Can I get my data out in a portable format?Yes, CSV export
  • Does any data leave the EEA, and under what mechanism?Yes, disclosed above

Frequently asked questions

Is Velto GDPR compliant?
There is no such thing as a GDPR certificate, so treat any app claiming one with suspicion. What we can tell you is specific: the controller is established in Berlin, the privacy policy documents a legal basis for each processing activity, the full set of data subject rights is available by emailing info@veltoglp.com, and transfers outside the EEA rely on adequacy decisions or standard contractual clauses.
Can Velto staff read my medication or symptom entries?
No. Those records are stored on your device and, if you enable sync, in your own iCloud account through Apple CloudKit. They are not sent to a Velto server. This is also why we cannot delete them on your behalf.
Does my data leave the European Union?
Your health records do not leave your device unless you enable iCloud sync, which is governed by your Apple account. Some analytics, subscription and email data is processed by US-based providers including Apple, RevenueCat, Meta, Vercel, Twilio SendGrid and Intuit Mailchimp, under adequacy decisions or standard contractual clauses.
Do you sell my health data?
No. We do not sell personal health information, and we do not share it with third parties for their own health-based advertising. The analytics we do collect is not intended to contain health-record content at all.
What happens to my data if I delete the app?
Records stored locally are removed with the app and its data. Anything you synced through iCloud remains subject to your iCloud settings and Apple's retention practices, so delete it there as well if you want it gone.
Do I need to give an email address to use Velto?
No. You only give us an email address if you contact support or subscribe to the newsletter, both of which are optional and separate from tracking.

Velto is currently an iPhone app. This page describes the iOS app and veltoglp.com, and reflects the privacy policy last updated 19 July 2026.

Track your GLP-1 plan without handing over your identity

No account, no email, and a health record that stays on your iPhone. Read the full policy first if you would rather check the detail yourself.