Veramir

Privacy Policy

Last updated: July 2, 2026

The short version

Your most sensitive health entries are encrypted on your own device before they reach us, with keys only you hold — we cannot read them, ever. Some profile and account information is stored readably so the app can work, and we spell out exactly which is which below. We don't sell data, we don't run ads, and we don't use tracking. You can download everything or delete everything, any time, in Settings.

Who we are

Veramir ("we", "us") is a self-tracking companion for people living with chronic illness, operated by Ooboogoo, based in Canada. Questions about this policy or your data: hello@veramir.app.

What we collect, and how it's protected

We treat your information in three distinct ways. This distinction is the heart of our privacy design:

1. Encrypted so we cannot read it. These entries are encrypted on your device before being sent to us, using keys derived from your passphrase that never leave your device. We store only unreadable ciphertext. No Veramir employee, contractor, or system can decrypt it — and neither can anyone who compromises our servers:

  • Your pain map (where and how much it hurts)
  • Symptoms you log (fatigue, brain fog, and the rest)
  • Check-in notes and "body wins"
  • Menstrual cycle dates
  • Medication names, doses, frequencies, and side effects
  • Your food journal (what you ate and how your body responded)
  • Messages to your future self

A consequence you should know: if you lose both your passphrase and your recovery code, this data is permanently unrecoverable. We cannot reset it for you, because we never have the keys. That is a feature, not a limitation — but it puts real responsibility on your recovery code.

2. Stored readably, with care. Some information must be readable by our systems for the app to work — for example, so we can filter recipes to your needs. This information is protected in transit and at rest, but it is not end-to-end encrypted:

  • Your display name and account email (managed through our sign-in provider)
  • The conditions you select (e.g. MS, fibromyalgia)
  • Dietary frameworks and your food profile (foods you always avoid, foods you'd rather avoid, histamine sensitivity)
  • Physical and cognitive abilities you share, and whether pregnancy mode is on
  • Check-in states expressed as simple categories (energy posture, weather-style mood, yesterday's effort) and their timestamps
  • Recipes you submit to share, including the contact email and credit name you provide
  • Recipe feedback you send (ratings, how you felt after, anything you write)
  • Adapted-recipe records, which include a snapshot of your food profile at that moment
  • Local weather readings and your city name. To fetch these, your device sends your approximate coordinates directly to our weather and location providers (Open-Meteo and BigDataCloud) — those coordinates go to those services, but never to Veramir, and we never receive or store them. Only your city name and the weather readings come back to us

3. Kept only on your device.Some preferences never reach our servers at all: which kinds of gentle ideas you want to see, which education cards you've viewed, and any passive experiments you've opted into. They live in your browser's local storage.

What we don't do

  • We do not sell, rent, or trade your information. Ever.
  • We do not show ads or share data with advertisers.
  • We do not use advertising or analytics cookies, and we run no marketing trackers. (We do use one error-monitoring service — see below — to find crashes.)
  • We do not connect to wearables or pull data you didn't enter yourself.
  • We never claim a recipe is safe for you — and we never use your health data for anything except showing you your own patterns.

Service providers we rely on

A small number of providers process data on our behalf, under their own security commitments: Clerk (sign-in and account management), Neon (database hosting), Vercel (application hosting), and Resend (sending email such as recipe-submission confirmations). These providers may process data in the United States or other regions. We share with them only what they need to provide their service — and your end-to-end-encrypted entries are unreadable to them just as they are to us.

Two more come into play only for the optional weather feature: when you use it, your device (not our servers) contacts Open-Meteo and BigDataCloud with your approximate coordinates to fetch local conditions and your city name. And we use Sentry for error monitoring — it helps us find and fix crashes. We configure Sentry to strip personal details and it never receives your encrypted health entries, but on a crash it may collect limited technical context.

Cookies and local storage

We use only essential cookies (keeping you signed in, protecting against abuse) and local storage for your on-device preferences and encryption keys. There are no advertising or analytics cookies.

Your rights and controls

  • Export: download everything we store about you, any time, from Settings.
  • Delete: permanently erase your account and all your data, any time, from Settings. This is immediate and irreversible.
  • Correct: your profile and entries can be changed in the app.
  • Ask: email hello@veramir.app for anything else — including questions, complaints, or requests under the privacy laws that apply to you (such as PIPEDA in Canada or the GDPR in Europe). You also have the right to complain to your local privacy regulator.

Retention

We keep your data while your account exists. When you delete your account, your data is deleted from our production database immediately. Residual copies in short-term database backups expire on the backup provider's rotation schedule.

Children

Veramir is not directed at children and is intended for people 16 or older.

If something goes wrong

If we ever learn of a breach affecting your personal information, we will notify affected users and the relevant authorities as required by law — and we will tell you plainly what happened, what was and wasn't readable (remembering that your encrypted entries are unreadable without your keys), and what we're doing about it.

Changes to this policy

If we change this policy in a way that matters, we'll tell you in the app before the change takes effect. The "last updated" date at the top always reflects the current version.

Back home