Veery

Veery Privacy Policy

Effective date: [DATE — set when published]

Veery ("Veery," "we," "us") is a fitness and nutrition training app operated by [LEGAL ENTITY NAME — e.g. Veery Athletics, Inc.]. This policy explains what we collect, why, where it goes, and the controls you have. It is written to be read, not skimmed past — health data is the most personal thing you can give an app, and we treat it that way.

This policy covers the Veery mobile app, the Veery Apple Watch app, and the Veery API at api.veery.fit.

The short version

What we collect

Account data. Your email address, your name (if you provide it or your sign-in provider shares it), and your sign-in credentials: a password (stored only as a salted hash) or your Google / Apple sign-in identity. If you sign in with Google or Apple, we receive the identifier and email those services share; we never see your Google or Apple password.

Profile data. Height, weight, date of birth, and biological sex — used to compute heart-rate training zones and calorie targets. During setup, with your permission, we pre-fill these from Apple Health so you don't have to type them.

Health and workout data (only with your explicit permission). If you connect Apple Health (or Health Connect on Android), Veery reads: sleep, heart rate (including resting heart rate and heart-rate recovery), weight, activity data, and workouts you complete outside Veery — including their heart rate, GPS route, energy burned, and running-form metrics (pace, power, stride length, ground contact time). Workouts you complete in Veery, including metrics streamed from your Apple Watch or a connected Bluetooth heart-rate monitor, are stored in your training history. With your permission Veery also writes your completed workouts back to Apple Health so they count toward your Activity rings.

Location. During an outdoor session you start (a run, a ride), Veery records your GPS route, distance, pace, and elevation — including while your screen is locked, for as long as the session is running. Veery does not track your location outside an active session and does not request "Always" location access.

Training content. The workout plans generated for you, the workouts, sets, and metrics you log, notes you write, and your interactions with plan generation.

Diagnostics. Crash reports and errors (via Sentry) and product analytics events such as which screens are used (via PostHog, once analytics is enabled in production builds). These streams carry technical context (device model, OS version, app version) and may include summary measurements Veery itself computes about a workout you run in the app — for example a session's total distance and calorie figures — when needed to diagnose problems. The dividing line is the source: nothing read from Apple Health / Health Connect, no raw heart-rate data, and no GPS coordinates or routes ever go to diagnostics or analytics. No session replay or screen capture is enabled.

Push tokens. If you enable notifications, a device push token (routed through Expo's push service and Apple's/Google's push infrastructure).

What we use it for

Providing your data is voluntary, but the Service cannot work without the account basics, and the personalization features cannot work without the data that powers them — if you choose not to share something, the features that need it simply stay off.

We do not use your data for advertising. We do not sell it or rent it. We do not share health data with data brokers, advertisers, or ad networks, and Apple Health / Health Connect data is never used for marketing — this is both our policy and a platform rule we are bound by.

AI processing

Plan generation uses Google's Gemini models. When a plan is generated or adapted, relevant training context — your profile attributes, goals, training history, readiness signals, and notes you've written that inform your training (health notes, exercise cue notes, session journal entries) — is sent to Google's Gemini API to produce your plan. This data is sent under Google's API data-use terms, which do not permit Google to use it to train their models. We send what the feature needs, not your full account.

Legal bases (EU/UK users)

Where the GDPR (or UK GDPR) applies, we process each category on a legal basis:

Processing Legal basis
Account, profile, and training content — operating the Service Contract (Art. 6(1)(b))
Health data from Apple Health / Health Connect, heart-rate and GPS data Your explicit consent (Art. 9(2)(a)) — granted through the platform permission prompts, withdrawable there at any time
AI plan generation over your training context Contract (Art. 6(1)(b)); health-data inputs under your explicit consent
Security (verification, session revocation) Legitimate interest in securing accounts (Art. 6(1)(f))
Diagnostics and analytics Legitimate interest in a working product (Art. 6(1)(f))
Emails we're required to send (verification, security) Contract (Art. 6(1)(b))

You can withdraw a consent at any time without affecting the lawfulness of processing before withdrawal — health-data consent in your device's Health settings, and everything at once by deleting your account.

Who we share it with (processors)

We use a small set of service providers, each processing data only on our instructions:

Provider What Why
Google Cloud Platform (US) All server-side data Hosting, database, backups
Google (Gemini API) Training context during plan generation AI plan generation
Sentry Crash and error reports (no health data) Reliability
PostHog (when enabled) Product analytics events (no health data) Product improvement
Resend Your email address and the emails we send you Verification and account emails
Expo / Apple / Google push Device push token, notification content Notifications

We disclose data beyond this list only if required by law, to protect the rights and safety of users, or as part of a corporate transaction (merger, acquisition) — in which case this policy continues to apply to data collected under it and we will notify you of any successor.

Where your data lives and how long

Your data is stored on Google Cloud Platform in the United States (Iowa, us-central1). If you use Veery from outside the US, your data is processed in the US. For EU/UK users, our infrastructure providers (including Google Cloud) are certified under the EU-US Data Privacy Framework, and we use their standard contractual protections; [COUNSEL TO CONFIRM: the transfer mechanism applicable to Veery as a US controller collecting directly from EU users].

Deleting your account, and your other rights

Delete in-app: Profile → Menu → Delete Account. This permanently deletes your account and all associated data — profile, health and workout data, training history, plans, and push tokens — and, if you signed in with Apple, notifies Apple to revoke Veery's sign-in connection to your Apple ID. There is no retention period, no "soft delete," and no need to email us, though you can (below) and we'll do it for you.

Whatever your location, we honor these rights; some of them are guaranteed to you by law (GDPR in the EU/UK, CCPA/CPRA in California, and similar laws elsewhere):

To exercise any of these, email support@veeryathletics.com from the email on your account. We respond within 30 days. If you are in the EU/UK you may also lodge a complaint with your supervisory authority.

Consents you can withdraw at any time, in place: Apple Health / Health Connect access (in your device's Health settings), location (in device settings), notifications (in device settings). Veery keeps working with whatever you leave enabled.

Age

Veery is not directed to children. You must be at least 16 years old to create an account. We do not knowingly collect data from anyone under 16; if we learn we have, we delete it.

Security

Data is encrypted in transit (TLS everywhere, including between the app and our API) and encrypted at rest. The production database is on a private network with no public address. Access to production systems is restricted to [LEGAL ENTITY NAME]'s operator(s) with hardware-backed authentication. Passwords are stored only as salted hashes; password-reset and verification codes are stored only as peppered hashes. No system is perfectly secure — if a breach affects your data we will notify you as the law requires, and faster if we can.

Changes to this policy

We'll post changes here and update the effective date. For material changes — anything that expands what we collect or who we share it with — we'll notify you in the app or by email before the change takes effect.

Contact

[LEGAL ENTITY NAME] support@veeryathletics.com [POSTAL ADDRESS — required by GDPR Art. 13 and CAN-SPAM]