Privacy Policy
Effective Date: August 11, 2026
At Ventro Core, your mental well-being and privacy are our highest priorities. This Privacy Policy describes how ROJO O VERDE LLC ("we," "us," or "our") collects, uses, processes, and shares information when you use the Ventro Core mobile application and related services (the "Service").
By using the Service, you consent to the data practices described in this policy.
1. Privacy at a Glance
We believe you should understand our data practices without digging through legalese.
- Service providers: We use PostHog (analytics), Google Firebase (push notifications), Meta App Events (install and subscription measurement), and RevenueCat (subscriptions)—see Section 4.
- Journals and drawings: Your private reflections are synced to operate the Service. We do not sell this content to advertisers.
- Sign-in options: Email/password, Sign in with Apple, Google Sign-In, or a guest session.
- Microphone: Optional, for Zen Pet voice features only; Secrets audio stays on-device and is not uploaded.
2. Information We Collect
To provide a seamless wellness experience, we collect the following categories of information:
2.1 Account Information
When you create an account, we collect information such as your email address and password, or we receive sign-in credentials from Apple or Google when you use Sign in with Apple or Google Sign-In. We use this information to authenticate you, secure your account, and sync your data across devices.
2.2 Guest Sessions
If you choose "Continue as Guest," we create a temporary account on our servers so you can use the App without registering an email and password. You may later upgrade a guest account to a permanent account. Guest accounts are subject to the same security and retention practices described in this policy.
2.3 Wellness & Activity Data
We process information you generate or log when you use features such as journaling (including optional drawings), mood tracking, breath and Trataka (gazing) exercises, meditations, soundscapes, self-discovery quizzes, journey and routine content, growth statistics, reminders, goals, and Zen Pet sanctuary progress. This helps us sync your content across devices and personalize your experience.
2.4 Creative Content (User-Generated)
This includes your written journal entries and digital drawings. This content is sensitive. We treat it as "Private Content" (see Section 5) and do not sell it to advertisers or data brokers.
2.5 Photos and Profile Images
If you choose to add a profile photo or attach images in supported features, the App may access your photo library or camera through the system picker and upload the selected image to our servers for storage and sync.
2.6 Microphone (Optional)
With your permission, the App may access the device microphone for optional Zen Pet voice features. Pet Memories voice notes are stored on your device. Pet Secrets uses short, temporary recordings as part of an in-app ritual and does not upload that audio to our servers.
2.7 Subscription and Purchase Data
If you purchase a subscription, payment is processed by Apple (App Store) or Google (Google Play). We use RevenueCat to verify subscription status and entitlements in the App. RevenueCat and the stores may process purchase identifiers, product IDs, transaction status, and related billing metadata. We do not receive or store your full payment card number.
2.8 Usage and Device Data
We automatically collect limited technical and usage information, such as app interactions, feature usage, device type, operating system version, and diagnostic data needed to operate, secure, and improve the Service.
2.9 Analytics and Product Telemetry (PostHog)
When configured in the App build, we use PostHog (PostHog Inc.) to collect product analytics and event data—such as onboarding steps, paywall views, sign-in method, meditation and mood events, and app lifecycle events—to understand how the Service is used and to improve it. When you are signed in, PostHog events may be linked to your account user ID and may include properties such as your email address and name. PostHog is hosted at https://us.i.posthog.com (or another region configured at build time). See https://posthog.com/privacy.
2.10 Marketing and Attribution (Meta App Events)
We use the Meta (Facebook) App Events SDK to measure app installs, app opens, and successful subscriptions for analytics and advertising attribution. This may include device and app identifiers. On Android, the SDK may access the advertising ID where permitted by the platform and your device settings. We use this to understand marketing performance—not to sell your journals, mood entries, or other Private Content. See https://www.facebook.com/privacy/policy/.
2.11 Push Notifications (Firebase Cloud Messaging)
We use Google Firebase Cloud Messaging (FCM) to register your device for push notifications you enable in the App. Your device's FCM token may be sent to our servers so we can deliver notifications. Google processes certain device identifiers and message delivery data as described at https://firebase.google.com/support/privacy.
3. How We Use Your Information
We process your information to:
- Provide the Service: authenticate you, sync your wellness data, operate subscriptions and premium features, and deliver notifications you request.
- Improve the Service: analyze usage trends, fix bugs, and understand which wellness tools are most helpful.
- Measure subscriptions and marketing: confirm purchases, restore entitlements, and evaluate the effectiveness of our outreach (including through Meta App Events).
- Communicate: send essential service messages, security alerts, and customer support responses.
- Protect users and the Service: detect abuse, enforce our Terms, and maintain security.
4. Third-Party Service Providers
We rely on trusted service providers to operate the App. They process data on our behalf and under contractual obligations. Key providers include:
- PostHog — product analytics (https://posthog.com/privacy)
- Google Firebase — push notification delivery (https://firebase.google.com/support/privacy)
- Meta (Facebook) — app event and subscription attribution (https://www.facebook.com/privacy/policy/)
- RevenueCat — subscription and entitlement management (https://www.revenuecat.com/privacy)
- Apple and Google — Sign in with Apple, Google Sign-In, and in-app purchases through their respective stores
- Cloud infrastructure providers — hosting and storage for our API and synced account data
Our API is operated at api.ventro-core.cloud. Sign-in tokens and account data are processed on our servers to provide authentication and sync.
5. Data Security and Sharing
Because Ventro Core handles sensitive emotional data, we implement rigorous security measures:
- Transport security: Data transmitted between the App and our servers is protected using TLS (HTTPS).
- Stored data: We apply administrative, technical, and organizational safeguards designed to protect personal data processed and stored on our systems.
- Data minimization: We collect only what is reasonably necessary to provide and improve the Service.
- No sale of Private Content: We do not sell, rent, or trade your journals, mood entries, drawings, or other wellness reflections to third-party advertisers or data brokers.
We may share limited app event and account-related data with analytics and attribution partners (such as PostHog and Meta) strictly to operate, measure, and improve the Service and subscription performance. This sharing does not include the content of your private journal or mood entries for advertising purposes.
6. Data Storage and Retention
Cloud Infrastructure
We use industry-standard cloud service providers to host our API and store synced account data.
On-Device Data
Some features (such as certain Zen Pet memory and secret flows) store data locally on your device. Uninstalling the App may remove locally stored data that has not been synced to your account.
Retention
We retain your account data while your account is active. If you delete your account, your personal data will be purged from our active databases within 30 days, except where we must retain certain records for legal, security, or fraud-prevention purposes.
7. Your Rights and Controls
Depending on your location, you may have the following rights regarding your data:
- Access and portability: You may request a copy of the data we hold about you.
- Correction: You can update certain account information in the App settings.
- Deletion: You may delete your account from Profile → Account & Security → Delete Account, or contact us at contact@ventro-core.com.
- Push notifications: You can disable notifications in the App or in your device settings.
- Microphone and photos: You can deny or revoke camera, microphone, or photo access in your device settings; some optional features may not work without permission.
8. Children's Privacy
Ventro Core is not intended for children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children.
If we become aware that a child has provided us with personal information without parental consent, we will take steps to delete such information and terminate the account.
9. International Users
We are based in the United States. If you use the Service from outside the U.S., your information may be processed in the U.S. and other countries where our service providers operate, which may have different data protection laws than your country.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons. We will notify you of material changes by posting the updated policy in the App and updating the Effective Date at the top.
11. Contact Information
If you have questions or concerns regarding your privacy, please contact us at: