Last Updated: July 7, 2026

Victura ("Victura," "we," "us," or "our") operates the Victura mobile application and the website at victura.app (collectively, the "Service"). This Privacy Policy describes how we collect, use, disclose, and protect personal information when you use the Service.

This policy is based on our actual product implementation as of the date above. If a feature is not described here, we either do not collect related data or the feature is not yet available.

1. Who we are

Victura provides AI-assisted nutrition tracking, meal scanning, and wellness coaching tools. For privacy inquiries and general support, contact support@victura.app.

2. Information we collect

2.1 Information you provide

  • Account information: email address and password when you register. We do not offer Google or Apple sign-in in the current app.
  • Profile and onboarding data: name or nickname, nutrition goal, diet type, dietary restrictions, protein preferences, cooking style, age, gender, height, weight, and activity level.
  • Meal and nutrition data: meal photos, food items, portion notes, calories, macros, micronutrients, feedback on meals, and related logs you create in the app.
  • Referral information: optional referral code at signup and referral program participation data.
  • Communications: messages you send to support.

2.2 Information collected automatically

  • Device and app data: device identifier generated and stored on your device, app version, and platform (for example iOS or Android).
  • Authentication data: access and refresh tokens stored in your device's secure storage.
  • Push notification data: Firebase Cloud Messaging (FCM) token, notification preferences, and delivery diagnostics when you enable push notifications.
  • Usage and behavioral events: privacy-oriented event types sent to our API (for example app open, scan completed, notification interactions). Payloads are sanitized on the client before transmission.
  • Approximate location: with your permission, city, country, and coarse GPS coordinates from your device. Used for service personalization and aggregated analytics. You can decline — the app works without location.
  • Session security data: hashed device and IP-derived fingerprints used to protect refresh-token sessions on our servers.

2.3 Information from device permissions (processed locally or with consent)

With your permission, the app may read steps and active energy burned for the current day from Apple Health or Health Connect. This health data is used on your device to enrich your experience and is not uploaded to our servers in the current implementation.

The app may also access your camera and photo library to capture or select meal images for scanning.

With your permission, the app may access your approximate location (when-in-use only) to determine city and country. If you allow, we store this on our servers to personalize the Service and for internal analytics. You can decline location access; core features remain available.

2.4 Information we do not collect

Based on our current codebase:

  • We do not integrate Firebase Analytics or Firebase Crashlytics.
  • We do not use Google Sign-In or Sign in with Apple.
  • We do not collect payment card numbers in the app (in-app purchases and Stripe checkout are not live).
  • We do not operate social profiles, public feeds, or direct messaging between users.

3. How we use information

We use personal information to:

  • Create and secure your account and authenticate API requests.
  • Provide meal scanning, nutrition estimates, streaks, coaching, and personalization.
  • Store your meal history and preferences.
  • Send push notifications you have opted into (for example reminders and streak updates).
  • Operate the referral and wallet-credit program.
  • Understand where our users are located (city/country) to improve product decisions and personalization when you grant location permission.
  • Improve reliability, security, and product quality (including aggregated behavioral analytics).
  • Comply with law and enforce our Terms of Service.

4. AI processing

When you scan a meal, we transmit your meal image (and optional portion notes) to our servers. Our servers may send that image and relevant non-email profile context (such as diet type, goals, and macro targets) to:

  • Google Gemini (primary AI provider), and
  • An OpenAI-compatible fallback provider (Kimi) if Gemini is unavailable.

AI outputs are estimates for informational purposes. They are not medical advice. We use AI results to display nutrition information and coaching in the app. AI interaction logs may be stored for quality, safety, and debugging.

We do not use your meal photos to train public foundation models. Processing is limited to providing the Service, subject to our agreements with AI providers.

5. How we share information

We do not sell your personal information.

We share information only as follows:

  • Service providers that help us host infrastructure, deliver push notifications (Google Firebase), and run AI inference (Google and, when needed, our fallback AI vendor), under contractual confidentiality and data-processing terms.
  • Legal and safety when required by law, court order, or to protect rights, safety, and security.
  • Business transfers in connection with a merger, acquisition, or asset sale, with notice where required by law.

We do not share your Apple Health or Health Connect data with third parties because that data stays on your device.

6. International data transfers

Victura may process and store information in countries other than where you live (including where our servers or providers operate). Where required, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms.

7. Data retention

We retain personal information while your account is active and as needed to provide the Service. Approximate location (city, country, coordinates) is retained while your account is active and updated when you open the app with location permission granted. Certain behavioral and UX telemetry may be deleted automatically after defined retention periods (for example, UX events after approximately 30 days).

When you delete your account, we delete core account and meal data from our databases through our account-deletion API. Some residual data (such as security logs, backup snapshots, or orphaned media files) may persist for a limited period before automated or manual purge. See our Data Retention Policy.

8. Security

We use industry-standard measures including HTTPS transport, hashed passwords, secure token storage on devices, access controls, and rate limiting. No method of transmission or storage is completely secure.

9. Your rights and choices

Depending on your location, you may have the right to:

  • Access a copy of your personal information.
  • Correct inaccurate profile data (in the app or by contacting us).
  • Delete your account and associated data (in-app or via our Account Deletion page).
  • Export data where technically feasible (contact support@victura.app).
  • Opt out of push notifications in device and in-app settings.
  • Decline location in the system permission prompt or by choosing "Not now" in the in-app rationale — the app remains fully usable.
  • Withdraw consent where processing is consent-based, without affecting prior lawful processing.

European Economic Area (GDPR)

Our lawful bases include contract (providing the Service), legitimate interests (security, improvement, fraud prevention), and consent (where required, such as push notifications).

You may lodge a complaint with your local supervisory authority. Contact support@victura.app to exercise GDPR rights.

California (CCPA/CPRA)

We do not sell or share personal information for cross-context behavioral advertising. California residents may request access, correction, and deletion by emailing support@victura.app. We will verify requests as required by law.

10. Children's privacy

Victura is not directed to children under 13. Onboarding requires a minimum age of 13. We do not knowingly collect personal information from children under 13. See our Children's Privacy Policy.

11. Third-party links

The Service may link to third-party sites (for example app stores). Their privacy practices are governed by their own policies.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version at victura.app/privacy and update the "Last Updated" date. Material changes may be communicated through the app or by email where appropriate.

13. Contact

Victura
Email: support@victura.app
Web: https://victura.app/privacy