Veery

Veery Privacy Policy

Effective date: September 9, 2026

Veery ("Veery," "we," "us") is a fitness and nutrition training app operated by Veery LLC. This policy explains what we collect, why, where it goes, and the controls you have. It is written to be read, not skimmed past — health data is the most personal thing you can give an app, and we treat it that way.

This policy covers the Veery mobile app, the Veery Apple Watch app, and the Veery API at api.veery.fit.

The short version

What we collect

Account data. Your email address, your name (if you provide it or your sign-in provider shares it), and your sign-in credentials: a password (stored only as a salted hash) or your Google / Apple sign-in identity. If you sign in with Google or Apple, we receive the identifier and email those services share; we never see your Google or Apple password.

Profile data. Height, weight, age range, and biological sex — used to compute heart-rate training zones and calorie targets. During setup, with your permission, we pre-fill these from Apple Health so you don't have to type them.

Health and workout data (only with your explicit permission). If you connect Apple Health (or Health Connect on Android), Veery reads: sleep, heart rate (including resting heart rate and heart-rate recovery), weight, activity data, and workouts you complete outside Veery — including their heart rate, GPS route, energy burned, and running-form metrics (pace, power, stride length, ground contact time). Workouts you complete in Veery, including metrics streamed from your Apple Watch or a connected Bluetooth heart-rate monitor, are stored in your training history. With your permission Veery also writes your completed workouts back to Apple Health so they count toward your Activity rings.

Location. During an outdoor session you start (a run, a ride), Veery records your GPS route, distance, pace, and elevation — including while your screen is locked, for as long as the session is running. Veery does not track your location outside an active session and does not request "Always" location access.

Training content. The workout plans generated for you, the workouts, sets, and metrics you log, notes you write, and your interactions with plan generation.

Diagnostics and product analytics. We use Sentry for crash and error reports. Separately, PostHog helps us understand which screens and controls are used and which actions succeed or fail. Basic product events and sanitized diagnostic messages do not include sensitive workout content. Technical context includes device model, operating system, and app version. Signed-in records use an internal account identifier rather than your email address or name. That identifier still links records to your account; it does not make them anonymous.

Optional session replay. Session replay is off unless you explicitly allow it. With your permission, PostHog records app interactions to help us understand and fix problems. Recordings can show interface labels, catalog exercise names, workout structure, sets, repetitions, exercise weight, timers, and completion state. We mask names and contact details, personal photos, free-text notes and custom titles, chat, precise GPS routes, heart-rate readings, body measurements, and medical details. Nothing read from Apple Health / Health Connect goes to our analytics or crash-reporting tools. Replay permission does not expand what we include in basic product events or diagnostic messages.

Basic product analytics is on by default; session replay requires a separate opt-in. You can change either choice independently in Profile → Menu → Social & privacy. Turning either off pauses that collection on this device immediately. If you are offline, the app saves the choice to your account when connectivity returns; other devices adopt the saved choice when they next successfully refresh it. The app tells you if it cannot store or save your choice. Turning a choice on requires an online account save. Turning collection off does not delete previously collected records. Crash reporting and essential security and reliability diagnostics continue independently. After you sign out, subsequent basic product analytics use a fresh identifier that we do not link to your account; session replay stops and does not inherit your account's permission. Declining replay does not limit your use of Veery.

Push tokens. If you enable notifications, a device push token (routed through Expo's push service and Apple's/Google's push infrastructure).

What we use it for

Providing your data is voluntary, but the Service cannot work without the account basics, and the personalization features cannot work without the data that powers them — if you choose not to share something, the features that need it simply stay off.

We do not use your data for advertising. We do not sell it or rent it. We do not share health data with data brokers, advertisers, or ad networks, and Apple Health / Health Connect data is never used for marketing — this is both our policy and a platform rule we are bound by.

AI processing

Plan generation uses Google's Gemini models. When a plan is generated or adapted, relevant training context — your profile attributes, goals, training history, readiness signals, and notes you've written that inform your training (health notes, exercise cue notes, session journal entries) — is sent to Google's Gemini API to produce your plan. This data is sent under Google's API data-use terms, which do not permit Google to use it to train their models. We send what the feature needs, not your full account.

AI-generated plans are suggestions. You can edit, swap, skip, or ignore any part of them, and no decision with legal or similarly significant effects on you is made automatically.

Legal bases (EU/UK users)

Where the GDPR (or UK GDPR) applies, we process each category on a legal basis:

Processing Legal basis
Account, profile, and training content — operating the Service Contract (Art. 6(1)(b))
Health data from Apple Health / Health Connect, heart-rate and GPS data Your explicit consent (Art. 9(2)(a)) — granted through the platform permission prompts, withdrawable there at any time
AI plan generation over your training context Contract (Art. 6(1)(b)); health-data inputs under your explicit consent
Security (verification, session revocation) Legitimate interest in securing accounts (Art. 6(1)(f))
Essential diagnostics and basic product analytics Legitimate interest in a working product (Art. 6(1)(f)), subject to applicable consent requirements
Optional session replay Consent (Art. 6(1)(a)); explicit consent where health data requires it (Art. 9(2)(a))
Emails we're required to send (verification, security) Contract (Art. 6(1)(b))

You can withdraw a consent at any time without affecting the lawfulness of processing before withdrawal — health-data consent in your device's Health settings, replay permission in Social & privacy, and everything at once by deleting your account.

Who we share it with (processors)

We use a small set of service providers, each processing data only on our instructions:

Provider What Why
Google Cloud Platform (US) All server-side data Hosting, database, backups
Google (Gemini API) Training context during plan generation AI plan generation
Sentry Crash and error reports (no health data) Reliability
PostHog Basic product events, optional session replay with the permitted workout details above, and sanitized diagnostics Product improvement and troubleshooting
Resend Your email address and the emails we send you Verification and account emails
Expo / Apple / Google push Device push token, notification content Notifications

We disclose data beyond this list only if required by law, to protect the rights and safety of users, or as part of a corporate transaction (merger, acquisition) — in which case this policy continues to apply to data collected under it and we will notify you of any successor.

Where your data lives and how long

Your data is stored on Google Cloud Platform in the United States (Iowa, us-central1). If you use Veery from outside the US, your data is processed in the US, and by using the Service you provide it to us directly there. Our infrastructure providers (including Google Cloud) are certified under the EU-US Data Privacy Framework and its UK extension, and where a transfer safeguard is required we rely on the European Commission's standard contractual clauses. Veery is offered from the United States and is not established in the EU or UK.

Deleting your account, and your other rights

Delete in-app: Profile → Menu → Delete Account. This permanently removes your active Veery account and its associated database records — profile, health and workout data, training history, plans, and push tokens. If you signed in with Apple, we also request revocation of Veery's sign-in connection to your Apple ID. There is no account recovery period or need to email us, though you can request deletion by email instead.

Cleanup of externally stored files and account-linked PostHog records runs in the background and is retried when a provider is unavailable. PostHog processes event and recording deletion asynchronously, so records and dashboards derived from them may take time to reflect deletion. A provider's acknowledgement of a request does not mean every copy has already been erased. Backup copies expire through the rotation described above. Statistics that are truly anonymous and can no longer be connected to you may remain; replacing your name with an internal account identifier does not meet that standard.

Whatever your location, we honor these rights; some of them are guaranteed to you by law (GDPR in the EU/UK, CCPA/CPRA in California, and similar laws elsewhere):

To exercise any of these, email support@veeryathletics.com from the email on your account. We respond within 30 days. If you are in the EU/UK you may also lodge a complaint with your supervisory authority.

Consents you can withdraw at any time, in place: Apple Health / Health Connect access (in your device's Health settings), location (in device settings), notifications (in device settings). Veery keeps working with whatever you leave enabled.

Age

Veery is not directed to children. You must be at least 16 years old to create an account. We do not knowingly collect data from anyone under 16; if we learn we have, we delete it.

Security

Data is encrypted in transit (TLS everywhere, including between the app and our API) and encrypted at rest. The production database is on a private network with no public address. Access to production systems is restricted to Veery LLC's operator(s) with hardware-backed authentication. Passwords are stored only as salted hashes; password-reset and verification codes are stored only as peppered hashes. No system is perfectly secure — if a breach affects your data we will notify you as the law requires, and faster if we can.

Changes to this policy

We'll post changes here and update the effective date. For material changes — anything that expands what we collect or who we share it with — we'll notify you in the app or by email before the change takes effect.

Contact

Veery LLC support@veeryathletics.com 8401 Mayland Dr Ste A, Richmond, VA 23294, USA