This policy explains how NAKA LABS S.L. processes the personal data of people who use the Vela app and this website, under Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
Vela processes health data, which is a special category. This policy says exactly which data, why, and on what legal basis. If any of it doesn't sit right with you, you can delete your whole account at any time, and all your data with it.
1. Data controller
- Controller: NAKA LABS S.L. (trading as NakaLabs)
- Tax ID (CIF): B75788034
- Registered address: Paseo de la Castellana 95, 28046 Madrid (España)
- Privacy contact: carlos@nakalabs.es
- Website: https://nakalabs.es
No data protection officer has been appointed: the processing does not meet the conditions of Article 37 GDPR. Requests are handled directly by the controller at the address above.
2. What this covers
The Vela app for iOS and Android, the API behind it, and this website, including the delete account and download data pages.
Vela is a wellbeing and personal organisation product. It is not a medical device, it does not diagnose, and it does not replace a health professional.
3. What data we process
Grouped the way the app store privacy labels declare it:
| Category | What it includes |
|---|---|
| Contact data | Your email address. It's all you need for an account: Vela has no passwords, you sign in with a one-time code or with Apple/Google. |
| Identifiers | Your internal account id, the identifier Apple or Google returns if you sign in with them, and the notification token of every device where you have Vela. |
| User content | Your check-in and day notes, the names you give blocks and quests, your recipes and lists, your profile photo and, if you use the fridge scan, the photos you take. |
| Health and fitness data | Hours of sleep, energy and mood, weight, workouts and minutes of activity, injuries or aches you declare, allergies and dietary preferences. |
| Usage data | Which days you log activity and how many minutes per area. It's what feeds your monthly brief; it is not used for advertising. |
| Technical data | IP address and minimal request data, to apply usage limits, prevent abuse, and record errors. |
Vela does not ask for your location, your contacts, or access to your other health apps. There are no advertising identifiers and no third-party tracking SDKs inside the app.
4. Health data: a special category
Sleep, weight, training, mood, injuries, allergies, and dietary preferences are data concerning health and are therefore a special category of personal data under Article 9(1) GDPR.
The legal basis for processing them is your explicit consent (Article 9(2)(a) GDPR), given when you enter them in the app after being informed by this policy. There is no other basis: without that consent those fields simply stay empty and Vela works with whatever is left.
You can withdraw consent at any time, without giving a reason, by deleting your account from the app (Me → Delete account) or from this site. Withdrawal deletes the health data along with the rest of the account, immediately and irreversibly. Withdrawing does not affect the lawfulness of processing before it.
This data is used only to build your plan and your monthly brief. It is not shared with insurers, employers, advertisers, or any third party beyond the processors listed below, which only host or transport it on the controller's behalf.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creating and maintaining your account and giving you access to the app. | Performance of a contract (Art. 6(1)(b) GDPR). |
| Sending the one-time code used to sign in. | Performance of a contract (Art. 6(1)(b) GDPR). |
| Building your day, your week, your meals, and your training from your check-ins. | Performance of a contract (Art. 6(1)(b)) and, for health data, explicit consent (Art. 9(2)(a) GDPR). |
| Writing your monthly brief in Memory. | Performance of a contract (Art. 6(1)(b)) and explicit consent for the health part (Art. 9(2)(a) GDPR). |
| Sending you notifications about your blocks, your check-in, or your grocery list. | Consent, managed from the app settings and your device settings (Art. 6(1)(a) GDPR). |
| Linking your account with your partner's when you redeem an invitation code. | Consent (Art. 6(1)(a) GDPR): you start the link and you can undo it. |
| Publishing one of your months on a page with an unlisted link when you tap share. | Consent (Art. 6(1)(a) GDPR), revocable from the app. |
| Generating your data export when you ask for it. | Legal obligation to serve the rights of access and portability (Art. 6(1)(c), Arts. 15 and 20 GDPR). |
| Applying usage limits, preventing abuse, and keeping the service secure. | Legitimate interest in the security of the service (Art. 6(1)(f) GDPR). |
| Recording errors so they can be fixed. | Legitimate interest in the service working correctly (Art. 6(1)(f) GDPR). |
| Answering your support requests. | Performance of a contract and legitimate interest in helping you (Art. 6(1)(b) and 6(1)(f) GDPR). |
| Meeting legal, accounting, and tax obligations. | Compliance with legal obligations (Art. 6(1)(c) GDPR). |
6. Processors and sub-processors
Vela does not sell data and does not share it with third parties for their own purposes. It does rely on providers that process data on the controller's behalf and on its instructions, under an Article 28 GDPR data processing agreement:
| Provider | What for | What it touches |
|---|---|---|
| MongoDB, Inc. (MongoDB Atlas) | The database where your account lives. | All account data, health data included. |
| Vercel Inc. | Hosting for the API and this website. | Data in transit on each request, and technical logs. |
| Cloudflare, Inc. (R2) | File storage: profile photo and exports. | Images you upload and the export ZIP. |
| Upstash, Inc. (Redis) | One-time codes with expiry, and usage limits. | Your email and the code, always stored hashed. |
| Google Ireland Limited (Gmail / Google Workspace) | Delivering the email with your code and account notices. | Your email address and the message content. |
| Functional Software, Inc. (Sentry) | Server error reporting. | Technical data about the error; your check-ins and notes are not sent. |
| Apple Inc. | Sign in with Apple and notification delivery on iOS. | Your Apple account identifier and the device token. |
| Google LLC | Sign in with Google and notification delivery on Android. | Your Google account identifier and the device token. |
| Expo (650 Industries, Inc.) | Push notification delivery service. | The device notification token. |
When you sign in with Apple or Google, those companies also act as independent controllers for the processing they do of your account with them, under their own policies.
Data will also be disclosed where there is a legal obligation or a valid request from a competent authority.
7. International transfers
Some of the providers above are US companies and may process data outside the European Economic Area. In those cases the transfer relies on the safeguards of Article 46 GDPR — the European Commission's standard contractual clauses — or, where applicable, on the relevant adequacy framework, together with any additional measures required.
You can request a copy of the safeguards in place by writing to the privacy address.
8. Retention and deletion
- While your account exists, your data is kept so the service can be provided to you.
- When you delete the account, deletion is immediate and irreversible. No archive, no deactivated copy, no grace period: profile, days, weeks, meals, quests, Memory, files, and shared links all go.
- Data exports you generate are stored behind a private link that expires after 7 days, after which the file is deleted.
- Shared month links live until you revoke them or until you delete your account.
- One-time codes expire after 10 minutes and disappear as soon as they're used.
- Technical and error logs are kept for the minimum time needed to diagnose incidents and, where applicable, for any period the law requires.
Database backups may retain information for a short additional period for technical reasons; they are overwritten in their normal rotation and are not used to restore deleted accounts.
9. Sharing a month and exporting data
The two features that take data outside your account do it through unlisted links: a long, unguessable address that appears in no search engine and no index, but is not password protected. Anyone holding the link can open it.
- A shared month page carries neither your name nor your email, only the month's brief. You can revoke it at any time from the app.
- The export ZIP does contain all your data, health data included. Treat it as a sensitive document and don't forward it. It expires after 7 days.
10. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction, and portability at any time, and withdraw consent where the processing relies on it.
- Access and portability: download your data from the app (Me → Export data) or from this site.
- Erasure and withdrawal of consent: delete your account from the app (Me → Delete account) or from this site.
- Rectification: you can correct your profile and your records inside the app.
- Anything else: write to carlos@nakalabs.es. We may ask for reasonable information to verify your identity, and we answer within one month.
If you believe the processing does not comply with the law, you can lodge a complaint with the Spanish Data Protection Agency (AEPD) or with your local supervisory authority.
11. Minors
Vela is not directed at anyone under 16 and is not intended for their use. We do not knowingly collect data from children under that age. If we find an account belonging to someone under 16, we delete it. If you believe a minor in your care has created an account, write to us and we'll remove it.
12. What Vela does not do
- No advertising in the app or on this site, and no advertising identifiers.
- No selling or renting of personal data, and no sharing with data brokers.
- No automated decision-making or profiling with legal or similarly significant effects (Art. 22 GDPR). Vela trimming your afternoon because you slept badly is a suggestion inside the app, and the last word is always yours.
- No third-party analytics and no cross-site tracking.
13. Features that are not live today
Voice transcription and image recognition appear in the app but are not connected today: no audio is sent and no photos are analysed by any provider. When they are switched on, this policy will be updated beforehand, naming the provider and the legal basis.
14. Security
All traffic is encrypted (HTTPS). Access codes are stored hashed and with an expiry, never in clear text. Sessions are short-lived tokens, and on this website a technical cookie that lasts only 15 minutes. Database access is restricted and usage limits are applied to curb abuse.
No system is infallible. If a breach occurs that poses a risk to your rights, it will be notified to the supervisory authority and, where required, to the people affected, within the GDPR deadlines.
15. Changes to this policy
We may update this policy for legal, technical, or functional reasons. The version in force is always the one published on this page with its update date. If a change affects the processing of health data or widens the purposes, it will be announced inside the app and, where the law requires it, fresh consent will be asked for.
This document is an informative template and must be reviewed by a legal professional before final publication.
