Venoa — Privacy Policy
Effective date: 9 August 2026 Last updated: 9 August 2026
Plain-English summary. Venoa is a companion app for people using GLP‑1 medicines. You tell us about your doses, symptoms, weight, food and progress so the app can help you stay on track and learn about your treatment. Your health information is sensitive, and we treat it that way. We do not sell your data, and we do not use your identifiable data for advertising. You can export or delete your data at any time. This summary is for orientation only — the full policy below governs.
1. Who we are
If you have any questions, contact us at hello@venoa.health.
2. Where this policy applies
This policy applies wherever you use Venoa. Venoa is available globally, so depending on where you live, additional rights may apply to you:
- If you are in the UK, the UK GDPR and the Data Protection Act 2018 apply (see Sections 9–10).
- If you are in the EU/EEA, the EU GDPR applies (see Sections 9–10).
- If you are in the United States, US state privacy laws and consumer‑health‑data laws may apply (see Sections 11–12).
Where local law gives you stronger protection than this policy, that local law applies.
3. Key terms (in plain English)
- Personal data — any information that identifies you or relates to you, such as your email address, or a weight entry linked to your account.
- Health data — the health‑related information you enter into Venoa: for example your medication and doses, injection sites, side effects and symptoms, weight and body measurements, and food and hydration logs. Health data is a special category of personal data and receives extra protection.
- Sub-processor / service provider — a trusted third party that processes data on our behalf and under our instructions (for example, our cloud hosting provider), and only for the purposes we set.
- De‑identified / aggregated data — data that has been stripped of identifiers and combined so that it can no longer reasonably be linked back to you (for example, "average weekly weight change across all users").
4. A special note about your health data
Venoa is designed around sensitive health information, so we want to be clear up front:
- We collect your health data only to provide the Services to you — for example, to show your dose schedule, remind you about an injection, chart your progress, and surface relevant educational content.
- We process your health data on the basis of your explicit consent (in the UK/EU) and, where required, your opt‑in (in the US). You can withdraw consent at any time (see Section 10).
- We take deliberate steps to keep your health entries out of our analytics and marketing tooling. Our analytics record how features are used, not the content of your health entries.
- Venoa is not a healthcare provider and does not provide medical advice. Because of this, the information you provide through the Services is generally not "protected health information" under the US Health Insurance Portability and Accountability Act ("HIPAA"), and we are not a "covered entity" or "business associate" under HIPAA. This does not lessen our commitment to protecting your data — it simply describes the legal framework that applies.
5. What we collect, and why
We collect the following categories of data. Some are required to run the Services; most health entries are optional and entirely under your control.
| Category | Examples | Why we collect it |
|---|---|---|
| Account data | Email address, display name, password (stored only as a secure hash), sign‑in method (including Apple or Google Sign‑In identifiers) | To create and secure your account and let you sign in across devices |
| Health entries (special category) | GLP‑1 medication, dose and schedule, injection sites, missed‑dose events, side effects and symptoms, weight and body measurements, and food, nutrition and hydration logs | To provide the core tracking, reminders, insights and progress features you ask for |
| Preferences & settings | Units, reminder times, notification preferences, in‑app choices | To personalise how the app works for you |
| Device & technical data | Device model, operating system, app version, language, time zone, IP address, diagnostic and crash logs | To keep the app working, secure and stable, and to diagnose problems |
| Usage & analytics data | Screens viewed, features used, in‑app events (the content of your health entries is excluded) | To understand how the app is used and improve it |
| Subscription & billing metadata | Subscription status, plan, renewal and transaction identifiers from the App Store / Google Play | To manage your subscription and entitlements. We do not receive or store your full card details — payment is handled by the app stores (see the Terms) |
| Communications | Messages you send us, support tickets, feedback | To respond to you and improve the Services |
| Website cookies & similar | Cookie identifiers and analytics on our website (not the app) | See Section 13 |
We do not collect more than we need, and we do not ask for health data we do not use.
6. How we use your data
We use personal data to:
- provide, maintain and secure the Services and your account;
- deliver core features: dose tracking, reminders and missed‑dose guidance, symptom, weight, food and hydration logging, progress charts and insights;
- surface relevant educational content (our "stories" library);
- provide customer support and respond to your requests;
- keep the Services safe — prevent, detect and investigate fraud, abuse and security incidents;
- understand and improve the Services, including testing, research and product development, using de‑identified or aggregated data wherever practical;
- send you service communications (for example, security or billing notices), and — only with your consent where required — optional product updates you can opt out of at any time;
- comply with our legal obligations and enforce our Terms.
We do not sell your personal data. We do not use your identifiable data for targeted advertising. We do not use your health data to train advertising or third‑party AI models.
7. Legal bases for processing (UK/EU)
Where the UK or EU GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Creating and running your account; providing the features you request | Performance of a contract with you |
| Processing your health entries and connected‑source health data | Your explicit consent (Article 9) |
| Keeping the Services secure; preventing fraud and abuse; improving the Services using de‑identified data | Our legitimate interests (balanced against your rights) |
| Sending service‑critical communications | Performance of a contract / legitimate interests |
| Sending optional marketing (where used) | Your consent |
| Meeting legal, tax and regulatory obligations | Legal obligation |
You can withdraw consent at any time; doing so does not affect processing carried out before withdrawal, but some features may stop working without the underlying health data.
8. Who we share data with
We share personal data only in these limited circumstances, and never in exchange for money:
- Service providers (sub‑processors) who process data on our behalf under contract and only on our instructions, including:
- cloud hosting and database providers who store the app's data securely;
- crash‑reporting and analytics providers (configured so the content of your health entries is not sent to them);
- communications providers who deliver our emails and push notifications;
- customer‑support tools. We keep an up‑to‑date list of sub‑processors available on request at hello@venoa.health.
- App stores (Apple, Google) for subscription and payment processing — they act as independent controllers of your payment data under their own policies.
- Legal, safety and corporate reasons — where we are required by law, valid legal process, or to protect the rights, safety and property of Venoa, our users or the public; and, if Venoa is involved in a merger, acquisition or asset sale, as part of that transaction (we will notify you and this policy will continue to protect your data).
We may create and use de‑identified and aggregated data (which cannot reasonably identify you) to understand trends, improve the Services and for research.
9. Where your data is stored and how we protect it
Your account and health data are stored on secure cloud infrastructure operated by our hosting sub‑processors. We protect it using appropriate technical and organisational measures, including:
- encryption in transit (TLS) and encryption at rest;
- strict access controls and the principle of least privilege for our staff and processors;
- hashed password storage;
- logging, monitoring and regular review of our security practices.
No method of transmitting or storing data is completely secure, so we cannot guarantee absolute security — but we work hard to protect your data and to improve our safeguards over time. You also play a part: choose a strong password and keep your device and credentials secure.
10. International data transfers
Because Venoa operates globally, your data may be processed in countries other than your own, including outside the UK and EEA. Where we transfer personal data internationally, we use appropriate safeguards, such as:
- transfers to countries covered by a UK or EU adequacy decision; or
- Standard Contractual Clauses (EU) and the UK International Data Transfer Addendum, together with additional measures where needed.
You can request a copy of the relevant safeguards at hello@venoa.health.
11. How long we keep your data
We keep personal data only for as long as we need it:
| Data | Retention |
|---|---|
| Account and health data | For as long as your account is active. Deleted within [30] days of you deleting your account, except where we must keep limited records to meet legal obligations |
| Support communications | For as long as needed to handle your request and for a reasonable period afterwards for our records |
| Diagnostic / crash logs | A limited period, then deleted or aggregated |
| De‑identified / aggregated data | May be kept indefinitely, as it can no longer identify you |
| Billing metadata | As required by law (e.g. tax and accounting rules) |
You can export or delete your data at any time from within the app, or by contacting us (see Sections 14–16).
12. Your rights (UK/EU)
If the UK or EU GDPR applies to you, you have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten");
- restrict or object to certain processing;
- data portability — receive your data in a structured, machine‑readable format;
- withdraw consent at any time; and
- lodge a complaint with a supervisory authority.
Many of these you can exercise directly in the app (export and delete). For anything else, email hello@venoa.health; we will respond within the time limits set by law (generally one month). If we decline a request, we will explain why, and you can appeal by replying to our response.
You may complain to the UK Information Commissioner's Office (ICO) at ico.org.uk, or to your local EU/EEA data protection authority.
13. Your rights (United States)
Depending on your state, you may have rights to access, delete, correct and obtain a portable copy of your personal data, to opt out of any "sale" or "sharing" of personal data or targeted advertising, and to limit the use of sensitive personal data. We do not sell your personal data or share it for cross‑context behavioural advertising, and we do not use your sensitive data beyond the purposes described in this policy.
We will not discriminate against you for exercising these rights. To make a request, email hello@venoa.health; we may need to verify your identity. If we deny your request, residents of certain states may appeal by replying to our response, and may contact their state Attorney General.
Consumer health data (Washington, Nevada, Connecticut and similar)
If you live in a state with a consumer‑health‑data law (such as Washington's My Health My Data Act, Nevada, or Connecticut), the health information you enter into Venoa is consumer health data. We collect it only to provide the Services with your consent, we do not sell it, and you may withdraw consent and request deletion at hello@venoa.health.
14. Cookies and similar technologies
Our app does not use advertising cookies. Our website uses a small number of cookies:
- essential cookies needed for the site to work;
- functional cookies that remember your preferences; and
- analytics cookies that help us understand how the site is used.
You can control non‑essential cookies through the cookie banner and your browser settings. Our Services do not currently respond to "Do Not Track" browser signals, but we honour recognised opt‑out preference signals where legally required.
15. Children's privacy
Venoa is intended for adults and is not directed at anyone under 18. We do not knowingly collect personal data from under‑18s. If you believe a child has provided us with personal data, contact hello@venoa.health and we will delete it promptly.
16. Automated decision‑making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.
17. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you in the app, by email, or by other appropriate means before the changes take effect, and we will update the "Last updated" date above. Continuing to use the Services after changes take effect means you accept the updated policy.
18. Contact us
- Privacy / data protection: hello@venoa.health
- Data Protection Officer / EU‑UK representative: hello@venoa.health
- General support: hello@venoa.health