When you use Avelor, we collect:
Avelor uses AI to read supplement labels, answer your questions and read lab reports you upload. We send the request to OpenRouter, which passes it to the model that answers it.
What we send. So the answer fits you, the request includes the relevant parts of your profile. Depending on what you are doing that can include the photo of the label you scanned and the question you asked; your health conditions, allergies and sensitivities; your medications and whether you take a GLP-1; your age range, biological sex, and flags such as pregnancy; your supplement stack; your recent lab results with values and reference ranges; recent daily summaries from a connected device or Apple Health; and the text of any health document you upload. We do not send your name, your email address or your date of birth. We do send a random identifier for your account, which lets the answer come back to you.
When we send it. Scanning, asking and uploading are things you do, and nothing is sent until you do them.
Where the brief is available to you, Avelor also writes you a short brief when you open Today, Sleep, Nutrition, Workouts or Symptoms, and again on Today when the morning, afternoon or evening turns over while it is open. Where it is available, it is on, and you can turn it off under Privacy settings.
A brief is put together on our own servers, from readings we already hold. It does not go to an AI provider and no part of it leaves Avelor. It uses the readings for the screen you opened: on Today, that day's wearable readings, your supplement and medication names, whether you took them, and any symptoms you logged. On Sleep, your sleep stages, efficiency and breathing rate, with your own 21 day range and which device each reading came from. On Nutrition, your nutrient totals kept separate by whether a device or you recorded them, and what you logged. On Workouts, the workout and the day's other activity. On Symptoms, what you logged with how severe and when, your supplement and medication names, and any interaction already flagged.
A brief never uses your lab results, your date of birth, your name, your email, your address or your device identifiers. Opening your profile, your settings, the scanner or Ask does not generate a brief.
Turning it off. Where the brief is available to you, you can turn it off under Privacy settings. Turning it off stops briefs being generated. Scanning, asking and uploading still work and still send, because that is the product.
What happens to it there. Requests we send through OpenRouter are not retained by the provider that answers them, and are not used to train models. We have set our account so these requests only go to providers that do not store them.
One thing works differently, and it is the question itself. To find the research behind an answer we send your question text to OpenAI separately, which does not go through OpenRouter, so OpenAI's own policy applies. We also keep your question and its searchable form on our own servers for one hour so that asking the same thing twice does not repeat the work.
You can connect a device such as an Oura Ring, WHOOP, Garmin, Eight Sleep, Fitbit, Withings, Ultrahuman, Polar, Peloton, Zwift, Wahoo or Hammerhead, and a continuous glucose monitor such as Dexcom or FreeStyle Libre.
Most of these do not send data to us directly. They are connected through Vital, a service that handles the connection to each device maker on our behalf and passes the readings to us. WHOOP is the one exception and connects directly. When you connect a device through Vital, we send Vital an internal account identifier so it can associate the connection with you.
We store daily summary values for these devices. You can also upload a data file from Oura, WHOOP, Polar or Garmin instead of connecting.
Disconnecting a device stops new data arriving. It does not delete the readings we already hold. To have those deleted, contact us or delete your account.
If you connect Apple Health, Avelor reads the categories listed in the permission screen on your device and sends them to our servers. That is more than steps and sleep: our servers accept 63 categories of reading, including heart and breathing measurements, blood pressure, blood oxygen, glucose, body measurements, nutrients, and the symptoms and cycle entries you log.
We store the readings themselves, not only daily totals. We also record the names of the other apps that write to your Apple Health, so we can tell you which app a reading came from.
Avelor writes one thing back to Apple Health: caffeine you log in Avelor. It writes nothing else.
We do not store your Health data in iCloud, and we never use it for advertising or share it with advertisers. Saved workout routes and heart-rate samples stay on your device and are not uploaded.
Running the product: Vercel (hosting), Neon (database), Stripe (payments), Resend (email), Vital (connections to most devices), Oura and WHOOP (device data), Apple and Google (optional sign-in).
AI: OpenRouter, which passes each request to the model that answers it. Those models today are made by Anthropic, and we use a small OpenAI model to route each question and to search research.
Measuring the product: Google Analytics and PostHog, both on every page including for visitors who are not signed in, and Sentry for error monitoring.
Advertising: Meta, via the pixel described under Cookies.
Each service has its own privacy policy and processes only the data it needs for its role.
Your account data is retained as long as your account is active. You can delete your account and all associated data at any time from inside the app (Profile, then Delete account), or by emailing us. See Data deletion for exactly what is removed and the timeline.
Four cookies are set on your first visit, before you sign in or interact with the page.
We run the Meta advertising pixel. It loads on every page and reports page views and events such as starting a scan or subscribing.
We do not currently ask for your consent before setting these, and we do not offer an in-product way to turn them off. You can block cookies in your browser, use Google's opt-out add-on, and adjust ad settings in your Meta account.
For privacy questions or data deletion requests, contact us at support@askavelor.com.