Privacy
Privacy policy.
Effective May 16, 2026
Veto is a small independent team building a dining decision app for groups. We try to write privacy policies the way we'd want to read them — plain language, no dark patterns, no padding. If anything here is unclear, email hello@theveto.app and we'll explain.
What we collect
From this website. When you sign up for the beta we store the email address you provide, the page that referred you (if any), and your browser's user-agent string. That's it. We use Cloudflare to serve the site; Cloudflare may log standard request metadata (IP address, timestamp) for security and performance.
From the iOS app (when it ships). The app uses your device's location only while you're actively using it to find nearby restaurants — we do not track you in the background. Account information (email, sign-in token) is stored to keep you logged in. Your veto choices in group sessions are private to you; the host only sees aggregate results, never who voted what.
What we don't collect. We don't run third-party ad networks. We don't sell your data. We don't fingerprint your device. We don't track you across other apps or websites.
How we use it
- To send you a TestFlight invite and occasional product updates.
- To run the app's features (finding restaurants, group sessions, results).
- To keep the service secure and to debug problems.
- To understand how the product is used in aggregate — never tied to your identity for marketing purposes.
Where it lives
Account and signup data is stored in Supabase, which runs on AWS infrastructure. Restaurant data is provided by Google's Places API and is subject to Google's terms when you query it. Authentication is handled by Supabase Auth and (optionally) Apple's Sign in with Apple or Google's OAuth.
Your rights
You can ask us at any time to:
- See what data we have on you.
- Correct or update anything that's wrong.
- Delete your account and associated data.
- Stop sending you product emails (the unsubscribe link in any email also works).
Email hello@theveto.app for any of the above. We'll respond within 30 days, usually much faster. If you're in the EU/UK or California you have additional rights under GDPR and CCPA respectively — those laws apply whether or not we've spelled them out here.
Cookies and tracking
The marketing site currently uses no cookies and no analytics. If we add analytics later we'll use a privacy-preserving option (likely Cloudflare Web Analytics) that doesn't drop cookies or identify individual visitors. If that changes we'll update this page first.
Children
Veto isn't directed at children. We don't knowingly collect data from anyone under 13 (or under 16 in the EU). If you believe a child has signed up, email us and we'll delete the account.
Changes
If we change this policy in any way that matters, we'll update the effective date at the top and — for material changes — email beta participants. Continued use of Veto after the new date means you accept the changes.
Contact
Email hello@theveto.app. A human reads it.