Veldt Privacy Policy

Effective 20 July 2026 · v1.0 · Last updated 20 July 2026
Operator: MEAI (Middle East Applied Intelligence) ("MEAI", "we", "us") operates Veldt — the Veldt mobile app, the Veldt web app, and the Veldt marketplace (together, "Veldt").
Reference law: UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), GDPR-informed. Plain English on purpose: this is what we actually collect and what we actually do with it.

1. What we collect

Account. Your email address and password. Sign-in is handled by Supabase Auth; we store a cryptographic hash of your password, never the password itself. Optionally: a username, display name, profile photo, short bio, language (English/Arabic), units preference, and a home region (GCC country level only — e.g. "UAE"; never a precise location).
Your field (content you create).
Photos you capture for identification, and photos attached to your assets.
Voice recordings you make (and the text transcriptions we produce from them).
Free-text entries, notes, and logs.
Records of your hobbies, assets, animals, plants, gear, vehicles, places, and skills — including their attributes and the links between them.
Approximate or precise capture location (latitude/longitude) only when it is present in the photo's EXIF data or your device provides it with the capture. Location sharing settings default to OFF.
Your chat messages with the Ask Veldt assistant.
Marketplace. Listings you create (title, description, price, condition, region), listing photos, inquiries you open on other people's listings, buyer–seller messages, and listings you save.
Reminders. Reminder title, schedule, and the item it relates to.
Device. A push-notification token if you enable notifications (iOS, Android, or web).
Settings. Notification preferences, privacy toggles (location sharing defaults OFF; feed visibility defaults private), and marketing opt-in (defaults OFF — we never pre-tick it).
First-party analytics. We record product events (e.g. "capture created") with identifiers, categories, and counts only — by rule, no free text, no email addresses, no precise location in analytics. We use no advertising networks and no third-party analytics or tracking SDKs.
What we do not collect: payment or card details (Veldt processes no payments), government IDs, contacts, or your device's photo library beyond the photos you explicitly submit.

2. Why we use it

To run Veldt: identify what you photograph or record, keep your field record, run the marketplace, deliver reminders and notifications.
To answer your questions in Ask Veldt using your own field data.
To keep the service safe: rate-limiting, abuse prevention, and enforcement of marketplace rules.
To improve the product using the PII-light analytics described above.
Marketing only if you opt in.
We do not sell your personal data. We do not show ads.

3. AI processing — what leaves our servers

Veldt's identification and assistant features send some of your content to third-party AI services for processing:
Google Gemini (Google servers). Photos you submit for identification, voice recordings (for transcription and interpretation), and your Ask Veldt chat messages (together with relevant context from your field record needed to answer) are sent to Google's Gemini API for processing.
Pl@ntNet and iNaturalist. Depending on what the photo appears to be (e.g. a plant or another living thing), the photo may also be sent to the Pl@ntNet identification API and/or the iNaturalist computer-vision API to improve species identification.
Google Search grounding. If you ask Ask Veldt a question that needs current, local information (e.g. "where can I buy a falcon hood near me"), we make one additional Gemini call that uses Google Search. That call sends your question, the last few messages of that chat conversation, and your home region name (if you set one). It never sends your field records, photos, or voice recordings.
These providers process the data on their own infrastructure under their own terms. We send only what the feature needs, and we do not send your email address or account identifiers with identification requests.

4. Where your data lives

Database and file storage: Supabase (PostgreSQL and private storage buckets), hosted in the Sydney, Australia region. All storage buckets are private; files are served only through short-lived signed links.
API: Vercel, Sydney (syd1) region.
Authentication: Supabase Auth (email + password).
This means your data is stored outside the UAE/GCC. We carry out this cross-border transfer under PDPL Articles 22–23 on the basis of your consent and appropriate contractual safeguards with our processors.

5. Retention

Account and field data: kept while your account exists. You can delete individual items (captures, entries, nodes, listings, reminders) at any time in the app.
Deleting your account (Section 6) permanently erases your data as described there.
Analytics events: on account deletion, the account identifier is removed from your analytics rows, leaving them anonymous.
Short-lived operational logs (error and request logs) expire on the hosting providers' standard schedules.

6. Your rights

Access and correction: view and edit your profile, settings, and content directly in the app.
Deletion: in the app, go to Me → Delete account, type DELETE to confirm. This permanently erases your profile, settings, subscription record, all field data (nodes, entries, edges, captures and their photos/recordings, identification results), your marketplace listings, inquiries, messages and saved listings, reminders, notifications, push tokens, and your login itself, and removes your files from all storage buckets. It also anonymizes community-improvement records you contributed to (Section 7) and your analytics rows. This is not reversible.
Portability / export: contact us (below) until self-serve export ships.
Objection / withdrawal of consent: turn off marketing at any time in settings; withdraw consent for optional processing by deleting the relevant content or your account.
Complaints: you may contact the UAE Data Office as the PDPL supervisory authority.

7. Community data

Veldt maintains a shared vocabulary of kinds and species names. If a new term you used is added to that shared vocabulary, the term itself (e.g. a species name) stays after you delete your account, but the link to you is removed (your user reference is set to null). No personal content travels with it.

8. Age requirement

You must be at least 18 years old to use Veldt. Veldt is not directed at children, and you may not create an account or use Veldt if you are under 18.

9. Changes

We will post changes to this policy on this page and, for material changes, notify you in the app before they take effect.

10. Contact

MEAI (Middle East Applied Intelligence) — hello@veldt.ae.