VELA EV · VEHICLE APP PRIVACY
Vela EV Privacy Policy
Looking for the Vela Fox Protect and Parent privacy policy?
Effective August 28, 2026
Vela EV (formerly Vela Fox) is a local-first vehicle companion. 100% of Vela AI inference and Vela's processing of VIN scans, camera frames, trips, battery status, and vehicle telemetry occurs on the user's device. Vehicle commands and their cryptographic credentials are also handled locally. Vela Fox does not require a Vela server, remote vehicle backend, or third-party cloud AI service for these core functions, and does not send camera frames, AI prompts, vehicle data, or driving history to one for processing. Feature availability varies by device and release. The only app-originated data sent to Vela-operated services is the fixed product ID and Google Play purchase token required to verify paid access, plus an optional AI-response report that the user explicitly previews and submits. Neither path accepts vehicle or driving data.
Once any required on-device intelligence components are available, Vela's nearby controls, VIN recognition, supported AI inference, and stored-data analysis can operate without an internet connection. Live vehicle data requires an authenticated connection to the paired vehicle within Bluetooth range. Accurate new trip recording and the Drive HUD also require a usable device-location or GPS fix. Reviewing previously recorded data does not require the vehicle or GPS. Fresh street-map backgrounds, address labels, external navigation, app-store billing or entitlement restoration, and initial or updated intelligence-component downloads may still require internet access.
What Vela processes on the device
When the user enables the related feature, Vela may process:
- A vehicle identification number and a Vela-specific local vehicle-command key.
- Nearby vehicle status, including battery, charging, climate, closures, location, tire pressure, and other fields the vehicle makes available.
- Device location, speed, bearing, altitude, accuracy, motion, and acceleration for the HUD and user-enabled Drive Companion.
- Detailed trip traces, statistical route summaries, energy estimates, preferences, local rules, and—during the evaluation or with Pro—up to 40 post-drive recap memories.
- Typed or spoken requests and the local statistical context needed to answer them.
The VIN, local vehicle key, detailed trip history, and recap memories are encrypted at rest with AES-256-GCM keys protected by the device operating system's secure key store. Vela excludes its sensitive app data from operating-system backup and device-transfer mechanisms.
Camera, microphone, and on-device AI
Any camera frame Vela processes—including VIN OCR and supported camera intelligence—is processed entirely on the device. Frames are held only transiently in memory, are not added to trip history, and are discarded after processing. VIN recognition uses a text-recognition model bundled with the app and remains available without internet access. Manual VIN entry remains available. Road Lens is disabled in the current release, so active camera processing in this release is limited to VIN recognition.
Voice input is available only when the operating system provides an on-device speech service; typing remains available otherwise. Vela AI uses operating-system-managed on-device intelligence. Vela has no cloud AI account or third-party cloud AI provider that receives prompts or trip telemetry. The operating system or app store may download required intelligence components after the user requests them, under those services' own terms.
Google ML Kit and operating-system-managed on-device intelligence may send limited SDK operational diagnostics to Google over HTTPS, including device and app information, feature usage and events, errors, latency and performance, API configuration, and input/output sizes. Those diagnostics do not include prompts, camera images, recognized text, generated AI output, VINs, routes, or vehicle telemetry. Vela does not use this information for advertising or to build a remote driving profile.
Optional AI-response reports
Every displayed generative Vela AI response includes an in-app Report response action. Nothing is sent when a response is merely displayed. The user must choose a reason, review an exact preview, and separately tap Submit report.
A submitted report contains only a privacy-redacted copy of the selected AI response, the chosen reason, the response surface, the app version, and an optional user note. Vela removes recognizable VINs, coordinates, routes, addresses, telemetry measurements, vehicle names available to the app, vehicle keys, and device-like identifiers before the preview. The original prompt, trip record, map, vehicle state, account information, and device identifier are never included.
Reports are sent over HTTPS to Vela Fox, retained for up to 90 days for abuse, safety, and quality review, and then deleted. The Vela report database does not store an IP address or user agent. A successful submission displays a random report reference; contact support@velafox.comwith that reference to request earlier deletion.
Background location and Bluetooth
Drive Companion is off by default. When the user explicitly enables it, Vela may use location and Bluetooth while the app is closed to reconnect to the nearby vehicle, validate motion, and record qualifying trips. Free keeps only the newest completed trip; the evaluation and Pro can retain the extended history described below. The app displays an ongoing system notification or indicator when required while this service runs. Turning Drive Companion off stops its Bluetooth and location work.
Evaluation, Free, and Pro access
After the first authenticated Tesla pairing, the app grants one 72-hour Pro evaluation. It does not require a payment method, does not enroll the user in a subscription, and does not auto-renew. The evaluation start, deadline, and anti-clock-rollback state are encrypted locally. Vela has no user account and the billing verifier does not receive or track evaluation state, so removing the app or clearing its storage can erase that local evaluation record; strict once-per-person enforcement therefore cannot be guaranteed.
When the evaluation ends, Free remains available with the Drive HUD, approved basic nearby controls, Phone Relay, and the newest completed trip. Once Google Play has authoritatively confirmed that Pro is inactive, older completed-trip history and Pro-only derived records are removed. An active recording may finish first, after which the newest completed trip is retained. A billing outage or unresolved pending purchase does not authorize destructive pruning.
App stores and user-directed services
Google Play processes checkout, payment, renewal, cancellation, refund, and offer eligibility for the optional monthly Vela Pro subscription and the separate non-consumable Watch standalone unlock. The apps receive purchase state and a purchase token needed to acknowledge, verify, and restore access; Vela never receives card details. The apps send only that token and a fixed product ID over HTTPS to Vela's billing-only verifier, which queries Google Play's Developer API. The raw token is handled transiently and is not written to the Vela database. The verifier caches only a SHA-256 token digest, fixed product ID, entitlement state, and verification timestamps for one minute when access is inactive or five minutes when active; an hourly cleanup removes expired records. The phone stores only short-lived entitlement state. The watch stores an encrypted ownership record containing purchase and verification times plus a SHA-256 token digest, not the raw purchase token. Vehicle keys, VINs, commands, trips, coordinates, and AI content are never sent to Vela for billing.
If the user installs the optional Wear OS companion, Vela sends a small, key-free display snapshot through Google Play services' Wear OS Data Layer. It may include the chosen vehicle name and model, phone and vehicle connection state, lock state, battery state, and current estimated drive metrics. It excludes the VIN, GPS coordinates, route, prompts, diagnostic logs, and Tesla vehicle key. The routine snapshot never places a VIN or vehicle credential in a durable Data Layer item. Transport can use the paired devices' Bluetooth or Wi-Fi connection and Google's connectivity infrastructure. Vela does not receive this snapshot on a Vela server.
Phone Relay sends an explicit watch command to the user-approved paired phone. The phone then communicates with the nearby vehicle using the encrypted vehicle key that remains on that phone. Vela stores a minimal local approved-device binding so an unexpected nearby Wear OS node cannot silently become the command relay. Resetting that binding requires the user to approve the new nearby device before commands resume.
The optional Standalone Watch Key is separate from Phone Relay. Phone Relay is free when the approved phone app is installed and nearby. The separate one-time Watch entitlement allows six explicit nearby Bluetooth commands without the phone: lock, unlock, climate start, climate stop, frunk, and trunk. During explicit setup, the watch generates its own P-256 Driver credential; it never copies the phone's Tesla key. The raw watch credential is encrypted at rest with AES-256-GCM under a separate, non-exportable operating-system Keystore AES key. Hardware-backed key storage depends on the watch and is not guaranteed. Setup requires a secure watch screen lock and approval with the user's physical Tesla key card.
Direct Watch Key setup can make a one-time request for the VIN from the explicitly approved nearby phone, or the user can enter the VIN manually. The one-time response is not written to the durable Data Layer snapshot, and no vehicle credential is transferred between phone and watch. After approval and purchase validation, those six manual nearby Bluetooth commands can operate without the phone or internet. Standalone Watch control does not provide NFC or Wallet key emulation, pillar tap, center-console tap, passive walk-up entry, drive authorization, phone-free driving, or remote internet commands. It also does not provide phone-free live trip, battery, or telemetry data. Users must keep a physical key available to enter and drive.
The device's system geocoder may process trip endpoints to provide best-effort place labels. Opening navigation sends selected coordinates to the maps app chosen by the user. Trip replay and Drive HUD load an OpenFreeMap background automatically. When a viewed area is not already cached, the app requests the visible style and map tiles over HTTPS. This reveals the visible map area and ordinary connection metadata to OpenFreeMap, but Vela does not attach a VIN, vehicle telemetry, saved route history, archive file, or AI content. MapLibre keeps a bounded cache of viewed resources; a compatible imported PMTiles region remains on the device and avoids those online requests when it fully covers the view. These system and third-party services operate under their own terms.
Export occurs only after a user request. A private dashboard export excludes the VIN, vehicle key, access tokens, and diagnostic logs. The optional browser dashboard reads the selected file in the current tab and does not upload it to Vela; refreshing or closing the tab clears the imported dashboard data. The dashboard's optional Street map is off by default. If the user turns it on, the browser requests map tiles from OpenFreeMap, which reveals the visible map area and network address to that provider but does not transmit the imported archive file.
Retention and deletion
Free retains exactly the newest completed trip across the local trip, insight, memory, and analytics stores. Evaluation and Pro retention limits are maximums, not guarantees; storage pressure, user deletion, or app removal can remove data sooner. When access changes to authoritatively confirmed Free during an active trip, that trip is allowed to finish and then becomes the single retained completed trip.
The in-app You → Privacy & local data → Delete data control stops Drive Companion and removes local trip history, statistics, Vela AI preferences, encrypted recaps, the VIN, and the Vela vehicle key from that phone. Operating-system-managed intelligence is a system component and is not an app-owned file. This phone-side action does not silently delete a separately created Watch Key.
Remove Watch Key deletes the local watch credential and its setup record. Reset bound phone removes the approved phone binding but deliberately preserves the Tesla Watch Key so the user can approve a replacement phone. Neither local action removes the corresponding key entry from the vehicle. To revoke vehicle authorization, the user must also remove the matching Vela phone or Vela Watch key in Tesla Controls → Locks. Uninstalling or resetting either app can remove its local records without revoking a key that remains listed by the vehicle.
Watch key management and local key removal remain available even when the standalone purchase is inactive, refunded, or revoked. After a successful Google Play inventory check reports that the Watch product is no longer owned, direct commands are disabled and the encrypted ownership cache is revoked. The user must separately remove the key from Tesla Controls → Locks to revoke the vehicle-side entry.
Collection, sharing, and advertising
Vela has no advertising SDK and does not sell personal information. It does not upload or share a user's vehicle history with a Vela developer server. The billing-only entitlement check and optional, user-initiated AI-response report described above are the limited app-originated service paths. Neither is used for advertising or vehicle profiling. Data processed solely on the device is not collected by Vela.
Security and limitations
Vela uses the device operating system's secure key store, authenticated encryption, encrypted Tesla Vehicle Command sessions, no cleartext network traffic, command allowlists, and explicit approval for AI-proposed vehicle actions. Standalone Watch Key additionally requires a secure watch screen lock, its separate Google Play entitlement, and explicit confirmation before unlock or closure-opening commands. Hardware backing for Keystore keys varies by device and is not guaranteed. No security control is infallible. Users should protect access to each device and revoke the corresponding Vela phone or Watch key in the vehicle if a device is lost, replaced, transferred, or no longer trusted.
Vela Fox is independent software and is not affiliated with or endorsed by Tesla, Inc. Tesla and related marks belong to their respective owner.
Children and policy changes
Vela is a vehicle companion intended for licensed drivers and is not directed to children. Material policy changes will be reflected by updating the effective date on this page.