Veery Privacy Policy
Effective date: September 9, 2026
Veery ("Veery," "we," "us") is a fitness and nutrition training app operated by Veery LLC. This policy explains what we collect, why, where it goes, and the controls you have. It is written to be read, not skimmed past — health data is the most personal thing you can give an app, and we treat it that way.
This policy covers the Veery mobile app, the Veery Apple Watch app, and the
Veery API at api.veery.fit.
The short version
- We collect the health and workout data you choose to share, and we use it to provide your training experience. If you separately allow session replay, limited workout details also help us diagnose and improve the app.
- We do not sell your data. We do not share health data with advertisers or ad networks — ever.
- Anything you share from Apple Health, your heart-rate data, and your GPS routes never go to our analytics or crash-reporting tools.
- You can delete your account and all its data from inside the app, at any time, without asking us.
What we collect
Account data. Your email address, your name (if you provide it or your sign-in provider shares it), and your sign-in credentials: a password (stored only as a salted hash) or your Google / Apple sign-in identity. If you sign in with Google or Apple, we receive the identifier and email those services share; we never see your Google or Apple password.
Profile data. Height, weight, age range, and biological sex — used to compute heart-rate training zones and calorie targets. During setup, with your permission, we pre-fill these from Apple Health so you don't have to type them.
Health and workout data (only with your explicit permission). If you connect Apple Health (or Health Connect on Android), Veery reads: sleep, heart rate (including resting heart rate and heart-rate recovery), weight, activity data, and workouts you complete outside Veery — including their heart rate, GPS route, energy burned, and running-form metrics (pace, power, stride length, ground contact time). Workouts you complete in Veery, including metrics streamed from your Apple Watch or a connected Bluetooth heart-rate monitor, are stored in your training history. With your permission Veery also writes your completed workouts back to Apple Health so they count toward your Activity rings.
Location. During an outdoor session you start (a run, a ride), Veery records your GPS route, distance, pace, and elevation — including while your screen is locked, for as long as the session is running. Veery does not track your location outside an active session and does not request "Always" location access.
Training content. The workout plans generated for you, the workouts, sets, and metrics you log, notes you write, and your interactions with plan generation.
Diagnostics and product analytics. We use Sentry for crash and error reports. Separately, PostHog helps us understand which screens and controls are used and which actions succeed or fail. Basic product events and sanitized diagnostic messages do not include sensitive workout content. Technical context includes device model, operating system, and app version. Signed-in records use an internal account identifier rather than your email address or name. That identifier still links records to your account; it does not make them anonymous.
Optional session replay. Session replay is off unless you explicitly allow it. With your permission, PostHog records app interactions to help us understand and fix problems. Recordings can show interface labels, catalog exercise names, workout structure, sets, repetitions, exercise weight, timers, and completion state. We mask names and contact details, personal photos, free-text notes and custom titles, chat, precise GPS routes, heart-rate readings, body measurements, and medical details. Nothing read from Apple Health / Health Connect goes to our analytics or crash-reporting tools. Replay permission does not expand what we include in basic product events or diagnostic messages.
Basic product analytics is on by default; session replay requires a separate opt-in. You can change either choice independently in Profile → Menu → Social & privacy. Turning either off pauses that collection on this device immediately. If you are offline, the app saves the choice to your account when connectivity returns; other devices adopt the saved choice when they next successfully refresh it. The app tells you if it cannot store or save your choice. Turning a choice on requires an online account save. Turning collection off does not delete previously collected records. Crash reporting and essential security and reliability diagnostics continue independently. After you sign out, subsequent basic product analytics use a fresh identifier that we do not link to your account; session replay stops and does not inherit your account's permission. Declining replay does not limit your use of Veery.
Push tokens. If you enable notifications, a device push token (routed through Expo's push service and Apple's/Google's push infrastructure).
What we use it for
- Generating and adapting your training plan — including AI-assisted plan generation (see "AI processing" below).
- Showing your history, trends, personal records, and progress.
- Computing personalization inputs (heart-rate zones, calorie targets, readiness signals like elevated resting heart rate + poor sleep).
- Account security: sign-in, email verification, password reset, and session revocation.
- Keeping the service working: crash diagnosis, error monitoring, and product analytics and replay subject to your account choice.
- Improving the Service using aggregate, de-identified data — stripped of anything that identifies you, and never including anything read from Apple Health / Health Connect.
Providing your data is voluntary, but the Service cannot work without the account basics, and the personalization features cannot work without the data that powers them — if you choose not to share something, the features that need it simply stay off.
We do not use your data for advertising. We do not sell it or rent it. We do not share health data with data brokers, advertisers, or ad networks, and Apple Health / Health Connect data is never used for marketing — this is both our policy and a platform rule we are bound by.
AI processing
Plan generation uses Google's Gemini models. When a plan is generated or adapted, relevant training context — your profile attributes, goals, training history, readiness signals, and notes you've written that inform your training (health notes, exercise cue notes, session journal entries) — is sent to Google's Gemini API to produce your plan. This data is sent under Google's API data-use terms, which do not permit Google to use it to train their models. We send what the feature needs, not your full account.
AI-generated plans are suggestions. You can edit, swap, skip, or ignore any part of them, and no decision with legal or similarly significant effects on you is made automatically.
Legal bases (EU/UK users)
Where the GDPR (or UK GDPR) applies, we process each category on a legal basis:
| Processing | Legal basis |
|---|---|
| Account, profile, and training content — operating the Service | Contract (Art. 6(1)(b)) |
| Health data from Apple Health / Health Connect, heart-rate and GPS data | Your explicit consent (Art. 9(2)(a)) — granted through the platform permission prompts, withdrawable there at any time |
| AI plan generation over your training context | Contract (Art. 6(1)(b)); health-data inputs under your explicit consent |
| Security (verification, session revocation) | Legitimate interest in securing accounts (Art. 6(1)(f)) |
| Essential diagnostics and basic product analytics | Legitimate interest in a working product (Art. 6(1)(f)), subject to applicable consent requirements |
| Optional session replay | Consent (Art. 6(1)(a)); explicit consent where health data requires it (Art. 9(2)(a)) |
| Emails we're required to send (verification, security) | Contract (Art. 6(1)(b)) |
You can withdraw a consent at any time without affecting the lawfulness of processing before withdrawal — health-data consent in your device's Health settings, replay permission in Social & privacy, and everything at once by deleting your account.
Who we share it with (processors)
We use a small set of service providers, each processing data only on our instructions:
| Provider | What | Why |
|---|---|---|
| Google Cloud Platform (US) | All server-side data | Hosting, database, backups |
| Google (Gemini API) | Training context during plan generation | AI plan generation |
| Sentry | Crash and error reports (no health data) | Reliability |
| PostHog | Basic product events, optional session replay with the permitted workout details above, and sanitized diagnostics | Product improvement and troubleshooting |
| Resend | Your email address and the emails we send you | Verification and account emails |
| Expo / Apple / Google push | Device push token, notification content | Notifications |
We disclose data beyond this list only if required by law, to protect the rights and safety of users, or as part of a corporate transaction (merger, acquisition) — in which case this policy continues to apply to data collected under it and we will notify you of any successor.
Where your data lives and how long
Your data is stored on Google Cloud Platform in the United States (Iowa,
us-central1). If you use Veery from outside the US, your data is processed
in the US, and by using the Service you provide it to us directly there.
Our infrastructure providers (including Google Cloud) are certified under
the EU-US Data Privacy Framework and its UK extension, and where a transfer
safeguard is required we rely on the European Commission's standard
contractual clauses. Veery is offered from the United States and is not
established in the EU or UK.
- Active account: we keep your data for as long as your account exists, so your training history works as a history.
- Backups: our database keeps automated daily backups (up to 30 retained) plus 7 days of point-in-time recovery logs, and a nightly encrypted export. When you delete your account, its active Veery database records are removed and backup copies age out through normal rotation — within about 35 days. External-provider cleanup is described below. Backups are used only for disaster recovery; we do not restore deleted accounts from them except as technically unavoidable in a disaster-recovery event, in which case re-deleted data is removed again.
- Diagnostics: crash and error events age out of Sentry per its retention window (90 days).
- Session replay: recordings are configured for 30-day retention. This recording setting does not set the retention of product-analytics events. Account-linked PostHog records are included in the cleanup requested when you delete your account.
- Deletion requests: we retain limited cleanup-request information while provider cleanup is unresolved. Once the provider has acknowledged event and recording cleanup and profile removal, and verified event deletion, we retain the request record for another 30 days, then remove it.
- De-identified data: aggregate statistics that no longer identify you (and never include Apple Health / Health Connect data) are not tied to your account and are not deleted with it — there is nothing in them to link back to you.
Deleting your account, and your other rights
Delete in-app: Profile → Menu → Delete Account. This permanently removes your active Veery account and its associated database records — profile, health and workout data, training history, plans, and push tokens. If you signed in with Apple, we also request revocation of Veery's sign-in connection to your Apple ID. There is no account recovery period or need to email us, though you can request deletion by email instead.
Cleanup of externally stored files and account-linked PostHog records runs in the background and is retried when a provider is unavailable. PostHog processes event and recording deletion asynchronously, so records and dashboards derived from them may take time to reflect deletion. A provider's acknowledgement of a request does not mean every copy has already been erased. Backup copies expire through the rotation described above. Statistics that are truly anonymous and can no longer be connected to you may remain; replacing your name with an internal account identifier does not meet that standard.
Whatever your location, we honor these rights; some of them are guaranteed to you by law (GDPR in the EU/UK, CCPA/CPRA in California, and similar laws elsewhere):
- Access / export — ask us for a copy of your data in a portable format.
- Correction — fix inaccurate profile data (most of it is editable in-app).
- Deletion — the in-app deletion above, or by request.
- Objection / restriction — object to a specific processing purpose.
- No sale or sharing — we do not sell or share personal data as those terms are defined in the CCPA, so there is nothing to opt out of.
- No discrimination — exercising these rights never degrades your service.
To exercise any of these, email support@veeryathletics.com from the email on your account. We respond within 30 days. If you are in the EU/UK you may also lodge a complaint with your supervisory authority.
Consents you can withdraw at any time, in place: Apple Health / Health Connect access (in your device's Health settings), location (in device settings), notifications (in device settings). Veery keeps working with whatever you leave enabled.
Age
Veery is not directed to children. You must be at least 16 years old to create an account. We do not knowingly collect data from anyone under 16; if we learn we have, we delete it.
Security
Data is encrypted in transit (TLS everywhere, including between the app and our API) and encrypted at rest. The production database is on a private network with no public address. Access to production systems is restricted to Veery LLC's operator(s) with hardware-backed authentication. Passwords are stored only as salted hashes; password-reset and verification codes are stored only as peppered hashes. No system is perfectly secure — if a breach affects your data we will notify you as the law requires, and faster if we can.
Changes to this policy
We'll post changes here and update the effective date. For material changes — anything that expands what we collect or who we share it with — we'll notify you in the app or by email before the change takes effect.
Contact
Veery LLC support@veeryathletics.com 8401 Mayland Dr Ste A, Richmond, VA 23294, USA