Skip to content

Privacy and data

Your data deserves a plain explanation.

This policy describes how Vunalto works today. It separates what stays only on your device from what has to be processed to offer an account, Vunalto Credits and AI analysis.

Last updated: September 11, 2026

1. Who looks after the data

Vunalto is operated by AxtroAI. For questions, requests or to exercise rights over personal data, write to contato@axtroai.com.

2. Data that stays on your device

By default the product is local-first. Your browser may store:

  • your goal, food preferences, allergies and foods you avoid;
  • meal history, goals, workout plans and fasts;
  • consents and, when the feature is enabled, records from the body module.

This data stays in your browser's local storage until you erase it, clear the site's data or lose the device's storage. It is not synced to your account automatically.

3. Data processed off the device

  • Account: email, protected credentials, user identifier, full name, WhatsApp number and the terms version recorded at sign-up.
  • Vunalto Credits: minimal habit events, balance, streak and issuing rules. The payload must not contain photos, foods, calories, weight or body measurements.
  • AI analysis: only when you send a real photo, the image and the profile needed to tailor the answer are transmitted to the server and to the AI provider.
  • Security: IP address, device identifier and minimal technical logs may be used to limit abuse and investigate faults.
  • Billing, when available: technical customer, subscription, price and payment-status identifiers. With Stripe, card details are sent to its hosted checkout. With Pagar.me, the card number, expiry and CVV go directly from your browser to the provider's tokenization endpoint; Vunalto receives only the temporary token and sends CPF and billing address to Pagar.me when you request a purchase.

Vunalto strips known metadata from the image on the client and again on the server. We do not store the meal photo in our database in the current flow. The answer may be saved locally in your browser.

4. Sign-up, WhatsApp and usage records

At sign-up we ask for your full name and a WhatsApp number. We use this data to identify you, provide support and send operational notices about the account: for example, about access, security or the trial period. The legal basis for this use is performance of the contract entered into when you create the account.

News and tips over WhatsApp are a separate matter: that kind of commercial message is only sent if you tick the specific consent, at sign-up or later. It is not a condition for using the app and can be withdrawn at any time on the Account and data page.

To run the service safely and keep costs under control, we also keep:

  • a per-user record of each AI analysis: the route used, the model, the number of tokens, the estimated cost and the approximate country derived from the network address at the time of use. The purposes are abuse prevention and cost management: this record keeps neither the photo nor the content of the meal;
  • internal support notes, when you talk to support, so conversations can pick up where they left off;
  • minimized product metrics: authenticated observations deduplicated by account and page type once per UTC day, without query parameters or identifiers present in the URL, plus activity linked only to the day to measure activation, retention and inactivity. The onboarding event records only whether the flow was quick or full, never answers, free text or health data.

Your name, WhatsApp number, consent, analysis records, support notes and user-linked daily activity are deleted with your account. Page metrics that were already aggregated are no longer attributable to an individual and may remain for historical product analysis.

5. What we use the data for

  • delivering the features you asked for, authenticating your account and keeping your balance;
  • tailoring the analysis to the context you declared;
  • protecting the service against fraud, abusive automation and unauthorized access;
  • complying with legal obligations and responding to valid requests.

We do not sell personal data and we do not use your health profile for behavioral advertising. Any feature that requires a new use of data will say so before collecting it.

6. Services that help us operate

We use providers for specific purposes:

  • Vercel, for hosting and delivering the app, cookie-free Web Analytics and Speed Insights performance metrics;
  • Supabase, for authentication and the database;
  • OpenRouter and the selected inference provider, to analyze an image when you request a real reading and, when AI support is enabled, classify only sanitized product signals from a closed list. The original support question is never sent to the provider.
  • Stripe, for hosted checkout, payments and the billing portal; and Pagar.me, for tokenization, fraud prevention and payments in Brazil, when each option is available.

These services may process data in other countries. We apply data minimization and technical controls, but each provider also has its own terms and retention practices.

7. Retention and deletion

Local data stays on the device until you erase it. Account data remains while the account is active or while it is needed for security, legal obligations and dispute resolution. User-linked daily activity is kept for no more than 45 days and is then removed automatically; page metrics that were already aggregated and have no individual link may remain for historical analysis. The Account and data option stops linked subscriptions before deleting the account. Stripe deletes the customer; with Pagar.me, wallet cards are removed and the mutable profile is anonymized because financial records may have separate regulatory retention. A technical barrier containing the pseudonymous identifier is marked to expire after 24 hours and is removed by the next automated cycle, provided no account, link or billing issue still requires reconciliation. Transaction records and backups may remain for periods required by law, tax, refunds or disputes.

8. Your rights

You can ask for confirmation of processing, access, correction, portability where applicable, information about sharing, withdrawal of consent and deletion. Some requests require identity verification to protect your account.

9. Security, children and changes

We use access controls, input validation, data minimization and encrypted connections. No system is infallible. Do not upload other people's data, and respect the age notices shown on sensitive features. Material changes to this policy will be presented with a new update date.