← Back to Welo

Privacy Policy

Last updated: August 17, 2026

Welo ("we," "our," or "us") is operated by Super Big Company. This Privacy Policy explains how we collect, use, and protect information when you use the Welo iOS app and website (getwelo.app).

1. Information We Collect

Account information. Email address and authentication identifiers when you create an account with email and password, Sign in with Apple, or Google. Auth is provided by Clerk.

Family profiles. Child display name, age group, skin conditions, and allergen preferences you enter so grades can be personalized. Profiles are stored on your device and synced to our servers so they follow you across devices.

Scan and saved-product history. Product identifiers, names, grades, and related scan metadata you generate in the app. History can live on-device and sync to our servers when you are signed in.

Subscription status. When you subscribe to Welo Pro, Apple sends us a signed receipt / App Store Server Notification so we can unlock Pro features. We store subscription state (active, expired, refunded) tied to your account. We do not receive your full credit-card number.

Device and diagnostics. Device type, OS version, app version, and push-notification device tokens if you enable alerts. We use these to deliver notifications and debug failures.

Website. If you email us from the site, we receive whatever you send. We do not run a public waitlist.

2. How We Use Information

We do not sell personal information. We do not use your profiles or scan history to advertise third-party products.

3. Where Data Lives

The app keeps an on-device SQLite cache so scanning and saved items still work offline (Pro). Signed-in data is also stored on our hosted backend (Fly.io) in PostgreSQL (Neon). Traffic is encrypted in transit with TLS.

4. Third-Party Services

5. Children's Privacy

Welo is built for parents and caregivers, not for children under 13. We do not knowingly collect personal information directly from children under 13. Age group and skin-condition data you enter about a child is provided by you, the adult account holder.

6. Your Rights and Account Deletion

You can access and edit profiles in the app. To delete your account and server-side data: Account → Settings → Delete Account. That removes the auth record and purges associated server data (profiles, saved products, scan history, subscription linkage, device tokens). Local data is cleared from the device. Uninstalling the app without using Delete Account removes the on-device cache only.

Email [email protected] if you need help with access, correction, or deletion.

7. Retention

Account and synced data are kept until you delete the account. Subscription records needed for Apple compliance (refunds, renewals) may be retained as long as Apple requires. Diagnostic logs are kept only as long as needed to operate the service.

8. Changes

We may update this policy. The "Last updated" date at the top is the current version. Material changes will be noted in the app or by email.

9. Contact

Privacy questions: [email protected].