Vest ← Back to site

Privacy Policy

Last updated: 5 August 2026

Short version: we collect only what we need to run the app. We don't sell your data. The AI coach messages you send are used solely to generate a reply. They are never used to train any model. You can request deletion of your account and all associated data at any time.

This Privacy Policy explains how Vest ("we", "our", or "us") collects, uses, and protects information when you use the Vest mobile application and associated services.

1. Information we collect

Account information

When you create an account, we collect your email address and a hashed password (if you use email/password sign-in). If you sign in with Google or with Apple, we receive your email address and name from that provider. We do not receive or store your Google or Apple password. If you use Sign in with Apple and choose to hide your email, we only ever see the private relay address Apple generates for you, never your real one. We also store a unique user ID assigned by our authentication provider (Supabase).

Profile and in-app data

To provide the service, we store the data you create inside the app, including:

Coach messages

The AI coach is available to everyone, with a daily message limit on the free tier that a Coach+ subscription removes. Whichever tier you are on, the same thing happens to your data: your chat messages and the coach's replies are stored so you keep conversation history across sessions, and a summary of your in-app data (Value Score, domain scores, habits, recent journal activity) is sent alongside each message so the coach can give relevant advice. This data is used only to generate your reply and is never used to train any AI model.

Journal and habit text sent for rating

Two features send text to the same AI provider without you opening the Coach tab. When you save a journal entry, its text and the life area you filed it under are sent to be rated for effort, which is what lets a demanding day count for more than an easy one. When you create or edit a habit, its name is sent the same way so its difficulty can be judged. In both cases only that text and the life area are sent, never your score, and what comes back is a single number. We ask you first. Before anything is sent for the first time, the app shows you what this does and asks whether to turn it on; if you decline, nothing is sent and every action simply counts the same as it otherwise would. You can change your answer at any time under Settings, in the row called "AI effort rating". This applies to signed-in accounts only: in guest mode, and in the local-only mode used for people below the digital consent age, nothing is sent.

Health data

If you enable Apple Health or Google Health Connect integration, we read daily step count and sleep duration from your device. This data is processed on your device to generate a Health domain score and is not transmitted to our servers. It stays local to your device. We do not store raw health readings.

Waitlist and feedback

If you sign up for the waitlist or submit in-app feedback, we store your email address and the content of your submission.

Usage analytics

We use PostHog to collect product analytics: screens visited, features used, and key events (such as completing a habit or starting a trial). This helps us understand how the app is used and improve it.

Once you are signed in, these events are linked to your account by your Vest user ID, so they are pseudonymous rather than anonymous. Alongside them we keep a profile of usage attributes: your Value Score and tier, your subscription status and plan, your priority allocation, your chosen theme and reminder time, whether your profile is public, and counts of your habits, goals, journal entries, friends and badges. We do not send your name, email address, journal text or coach conversations to PostHog.

Analytics are not collected for users who are under the applicable consent age in their country (determined by the date of birth you provide during setup), or for users who use the app in local-only (offline) mode.

Technical data

Our infrastructure automatically records standard server logs including IP addresses, request timestamps, and error traces. These are used for security monitoring and debugging and are retained for up to 90 days.

2. How we use your information

3. Third-party services

We use the following third-party services to operate Vest. Each is bound by its own privacy policy.

Supabase

Our database, authentication, and server-side functions run on Supabase. All app data (scores, habits, journal, coach messages) is stored in a Supabase-managed Postgres database. Data is hosted in the US.

Anthropic

The AI coach is powered by Anthropic's Claude API. Your messages are sent to Anthropic's servers to generate a reply and are subject to Anthropic's API usage policy. Anthropic does not use API inputs to train its models by default.

PostHog

Usage analytics are collected by PostHog. Events are tied to your Vest user ID, a random identifier that is not your name or email address, which means they are linked to your account rather than anonymous. We do not send your email address, real name, journal entries or coach conversations to PostHog.

Resend

Transactional and marketing emails are sent via Resend. Your email address is transmitted to Resend to deliver emails you have requested or opted into.

Google (Sign-in)

If you choose to sign in with Google, your authentication is handled by Google. We receive only your email and name from Google. See Google's Privacy Policy.

Apple (Sign-in)

If you choose to sign in with Apple, your authentication is handled by Apple. We receive only your email and name from Apple, and if you choose to hide your email we receive a private relay address instead of your real one. See Apple's Privacy Policy.

4. Data retention

We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or fraud-prevention purposes (such as server logs, which are retained for up to 90 days).

5. Your rights

Depending on where you live, you may have the right to:

To exercise any of these rights, email us at support@getvest.app. We will respond within 30 days. You can also delete your account directly from the app (Profile → Settings → Account → Delete account).

6. Children's privacy

Vest is not directed at children under 13. In countries where a higher age of digital consent applies (for example, 16 in some EU member states), we apply that higher threshold. During setup, we ask for your date of birth and country; users below the applicable consent age are restricted to a local-only mode where no data is sent to our servers and no analytics are collected.

If you believe a child under the applicable age has created an account, please contact us at support@getvest.app and we will delete the account promptly.

7. Data security

We use row-level security on all database tables so users can only access their own data. Communication between the app and our servers is encrypted in transit (TLS). API keys and secrets are stored as server-side environment variables and are never included in the app binary.

No method of transmission or storage is 100% secure. If you become aware of a security issue, please disclose it responsibly to support@getvest.app.

8. International transfers

Our infrastructure is based in the United States. If you are located outside the US, your data will be transferred to and processed in the US. We rely on standard contractual mechanisms where required by applicable law.

9. Changes to this policy

We may update this policy from time to time. If we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or in-app notice. Continued use of the app after a change takes effect constitutes acceptance of the updated policy.

10. Contact

If you have questions about this Privacy Policy or how we handle your data, please contact us at support@getvest.app.