Overrly
Velapp

Privacy Policy

Last updated: 2026-08-20 Effective date: 2026-08-20

This Privacy Policy explains how Velapp ("we", "our", "us") collects, uses, stores, and shares personal data when you use the Velapp mobile application ("the App"). We are committed to transparency and to compliance with the EU General Data Protection Regulation (GDPR), Polish data-protection law, and the privacy laws of any other jurisdiction where the App is available.

If you have questions about this policy, contact us at velapp.contact@gmail.com.


1. Who we are (Data Controller)

The controller of your personal data, within the meaning of Article 4(7) GDPR, is:

  • Legal name: Kamil Kamyszek IT Solutions
  • NIP (Polish tax ID): 5080100981
  • Data-protection contact: velapp.contact@gmail.com

We provide a postal address on request sent to the email above. It is also publicly available under the tax ID shown, in the Polish Central Register and Information on Economic Activity (CEIDG), and in the seller details published on the App Store and Google Play.

We have not appointed a Data Protection Officer. We do not carry out large-scale processing within the meaning of Article 37(1)(b) and (c) GDPR and we are not a public authority, so the obligation to appoint one does not apply to us. You can address any data-protection matter to the email above; we respond within the Article 12(3) deadline, that is without undue delay and at the latest within one month.

We have not designated a representative under Article 27 GDPR because we are established in the European Union.


2. What data we collect

2.1 Data you provide directly

  • Account data: email address, password (stored hashed, never in plain text), display name.
  • Profile data: age, gender, weight, height, running experience, available training days, target events, target finish times, injury notes you choose to share.
  • Run history (manual entries): distance, duration, pace, heart rate, cadence, elevation, perceived exertion, free-form notes.
  • AI conversation history: messages you send to "Veli" (the in-app AI coach) and Veli's replies — required so the coach can refer back to earlier exchanges within and across sessions.
  • Daily check-ins: sleep, legs, stress scores (1-5) and optional notes.

2.2 Data collected automatically

  • Device data: approximate location (only when you grant the permission, used for weather), platform (iOS / Android), app version. We do NOT collect precise GPS tracks of runs ourselves — those come from third-party providers (see §2.3) only if you connect them.
  • Push-notification token: an Expo / OS-generated identifier so we can deliver workout reminders and coaching nudges.
  • Advertising identifier (free tier only): if you use the ad-supported free tier, an advertising identifier may be processed by our ads SDK (Google AdMob) to serve ads. This is subject to your consent: on iOS we ask via Apple's App Tracking Transparency (ATT) prompt, and we use Google's User Messaging Platform (UMP) consent form for EEA/UK users. Pro (paid) subscribers do not see ads and no advertising identifier is processed for them.
  • Usage logs: error reports and performance metrics, retained for up to 30 days for debugging.

2.3 Data we receive from third parties (only after you opt in)

  • Apple HealthKit: when you grant permission, we read health and fitness data such as workouts and heart rate from Apple Health to enrich your training history. This is strictly opt-in and you can revoke access at any time in iOS Settings. HealthKit data is never used for advertising and is processed only to provide the coaching features you have asked for.
  • Google Health Connect (Android): when you grant permission, we read, on a read-only basis, your running workouts and related metrics — exercise/workout sessions, distance, heart rate, and calories burned — from Health Connect to enrich your training history. We never write data back to Health Connect. This is strictly opt-in; you can revoke access at any time in your device's Health Connect settings. Health Connect data is never used for advertising, is never sold, and is processed only to provide the coaching features you have asked for, consistent with the Google Health Connect Permissions policy, including its limited-use requirements.
  • Strava — integration switched off since 7 July 2026. The App no longer connects to Strava and pulls no new data from it. If you connected a Strava account before that date, the runs imported then remain in your activity history as your training data, and you can delete them individually or together with your account (§8). Strava-sourced data is not sent to the AI coach. Should we restore the integration in future, we will ask for fresh consent and update this policy.
  • Garmin Connect: when this integration launches, the same opt-in principle will apply and this policy will be updated.

We never receive your password for any connected provider.

2.4 Subscriptions and purchases

If you buy a Pro subscription, your purchase and subscription status (for example: whether the subscription is active, its renewal date, and the product purchased) is processed via RevenueCat and the Apple App Store or Google Play. Payment itself is handled entirely by the relevant app store — we do not receive or store your card or payment-card details. We use this information only to unlock Pro features and to validate that your entitlement is current.


3. Legal basis for processing

For every purpose we state the basis under Article 6(1) GDPR. Where we process health data, a further condition under Article 9(2) GDPR is required — in our case this is always your explicit consent. Both bases must be present together; details in §11.

PurposeBasis under Art. 6(1)Additionally Art. 9(2)
Creating and maintaining your account(b) performance of a contractnot applicable
Generating your training plan, zones and paces(b) performance of a contract(a) explicit consent (heart rate, injuries, check-ins)
AI coaching via Veli (Claude API, Anthropic)(b) performance of a contract(a) explicit consent to send health data to Anthropic
Reading Apple HealthKit data(a) consent, revocable at any time(a) explicit consent
Reading Google Health Connect data(a) consent, revocable at any time(a) explicit consent
Managing your Pro subscription(b) performance of a contractnot applicable
Personalised ads on the free tier(a) consent given through ATT (iOS) or the UMP form (EEA/UK)not applicable — health data never feeds advertising
Non-personalised ads where you do not consent(f) legitimate interest in funding the free tiernot applicable
Crash diagnostics and App reliability(f) legitimate interestnot applicable
Push notifications(a) consent, controlled by the in-app togglesnot applicable
Handling support requests(f) legitimate interest(a) if you describe a health matter to us yourself
Meeting accounting and tax obligations(c) legal obligationnot applicable

Where the basis is consent, giving it is voluntary, and refusing or withdrawing it carries no adverse consequence beyond losing the feature the consent covers.

Where the basis is legitimate interest, you have the right to object — see §7. We provide a copy of the balancing test on request.


4. How we use your data

We process your data to:

  1. Generate and adapt your training plan based on your profile, targets, and recent runs.
  2. Provide AI coaching — Veli reads a summary of your profile, recent activities, and the current chat history so its replies are contextual.
  3. Show progress and statistics in the Stats and Plan tabs.
  4. Send notifications you have enabled (morning greeting, workout reminders, weekly recap, milestone congratulations).
  5. Detect and prevent abuse of the AI service (rate-limiting, anomaly detection).
  6. Improve the App — aggregated, non-identifying usage signals help us prioritize features.

The free tier is supported by ads served via Google AdMob. With your consent (collected through Apple's App Tracking Transparency on iOS and Google's UMP consent form), the ads you see may be personalised; if you do not consent, you are shown non-personalised ads instead. You can change your ads consent at any time — see §12 for exactly where. Pro (paid) subscribers do not see ads.

We do not sell your personal data. We never use your health or fitness data (including Apple HealthKit data and heart-rate data) for advertising.


5. Third-party processors

The table below shows who we entrust your data to, in what role each provider acts, and where the data goes. The role matters legally: a processor (Art. 28 GDPR) acts only on our documented instructions, whereas a separate controller decides its own purposes and answers for them independently, under its own privacy policy.

ProviderWhat they doRoleLocationPrivacy info
Supabase (hosted Postgres + Edge Functions + Auth)Stores your account, profile, runs, AI conversationsProcessor (Art. 28)EU (eu-west-1)supabase.com/privacy
Anthropic PBC (Claude API)Powers the AI coach "Veli"Processor (Art. 28)USAprivacy.claude.com
Apple HealthKitOn-device source of health/fitness data (only if you opt in); data stays under Apple's Health permissionsOn-device (Apple)On-deviceapple.com/legal/privacy
Google Health ConnectOn-device source of health/fitness data on Android (only if you opt in); read-only, stays under Health Connect permissionsOn-device (Google)On-devicepolicies.google.com/privacy
Google AdMob (Google Ireland Ltd. / Google LLC)Serves ads on the free tierSeparate controller for its own advertising purposesEU / USApolicies.google.com/privacy
RevenueCatSubscription management and receipt validationProcessor (Art. 28)USArevenuecat.com/privacy
ResendTransactional email delivery (e.g. password reset)Processor (Art. 28)USA / EUresend.com/legal/privacy-policy
OpenWeatherMapWeather forecasts for the run-conditions feature; receives approximate coordinates only, with no user identifierProcessor (Art. 28)United Kingdom (adequacy decision)openweather.co.uk/privacy-policy
Expo (push notifications)Relays notifications to APNs / FCMProcessor (Art. 28)USAexpo.dev/privacy
Apple (App Store, APNs, HealthKit)App distribution, payments, OS-level notificationsSeparate controllerEU / USAapple.com/legal/privacy
Google (Google Play, FCM, Health Connect)App distribution, payments, OS-level notificationsSeparate controllerEU / USApolicies.google.com/privacy

We send each provider only the data it needs for its specific job (data minimisation). Transfer mechanisms outside the EEA are set out in §13.

AI-specific note. When you chat with Veli, the context described in §11 is sent to Anthropic PBC to generate a reply. Under Anthropic's commercial terms for the API:

  • Anthropic does not train its models on your data;
  • inputs and generated outputs are automatically deleted within 30 days of receipt or generation;
  • content flagged by Anthropic's safety systems as violating its usage policy may be retained for up to 2 years, and the safety classification scores themselves for up to 7 years;
  • longer retention occurs only where required by law.

Current terms are published in the Anthropic Privacy Center. Independently of Anthropic's retention, the copy of the conversation stored with us is governed by §6 and you can delete it in the App.


6. Data retention

DataRetention
Account dataUntil you delete your account
Profile + run historyUntil you delete your account or the specific entries
AI conversations (our copy)Until you delete them via "Forget" in chat, or your account
AI conversations (Anthropic's copy)Automatically deleted within 30 days; up to 2 years for content flagged by safety systems, up to 7 years for the classification scores alone — see §5
Daily check-insUntil you delete your account
Subscription status (via RevenueCat)While your subscription is active and as required for receipt validation and accounting
Crash logs30 days, then deleted
Database backupsUp to 30 days, then overwritten

When you delete your account we erase your personal data within 30 days, except where we are legally required to keep records (e.g. accounting). Anonymised, aggregated statistics may remain.


7. Your rights (GDPR Art. 12-23)

You have the right to:

  • Access the personal data we hold about you.
  • Rectify data that is incorrect or out of date.
  • Erase ("right to be forgotten") your data — see §8.
  • Restrict processing while we look into an issue.
  • Data portability — request your data in a machine-readable format.
  • Object to processing based on legitimate interest.
  • Withdraw consent at any time for processing based on consent (e.g. revoke HealthKit or Health Connect access, withdraw ads consent, turn off notifications).
  • Lodge a complaint with a supervisory authority — in Poland this is the President of the Office for Personal Data Protection (Prezes Urzędu Ochrony Danych Osobowych — UODO, uodo.gov.pl).

To exercise any of these rights, email velapp.contact@gmail.com. We respond within 30 days.


8. How to delete your data

  • In-app: Profile → Account → "Delete account". This erases your account, profile, runs, AI conversations, and notification tokens.
  • By email: request to velapp.contact@gmail.com with the subject "Delete my account". We verify the request and erase within 30 days.

You can also delete specific items at any time:

  • Revoke Apple Health or Health Connect access in your device settings — we stop reading new data immediately.
  • Delete individual runs from the activity history.
  • Delete individual coaching notes ("Veli, zapomnij że…").

9. Children

The App is not directed at children and may not be used by anyone under 16 years of age.

Processing in Velapp rests in a key part on consent, including explicit consent to process health data (§11). Under Article 8 GDPR and Article 8 of the Polish Personal Data Protection Act, a person under 16 cannot give such consent on their own. For that reason we do not create accounts for anyone below that threshold, rather than relying on parental consent.

During sign-up we ask for your date of birth and block registration below the age threshold. If we nonetheless learn that an account belongs to someone under 16, we delete it together with all its data without undue delay. If you are a parent or guardian and believe your child has created an account, email velapp.contact@gmail.com and we will remove it.

In jurisdictions outside the EEA with a different age threshold, we apply the higher of the two.


10. Security

We protect your data with:

  • TLS 1.2+ for every connection to our servers.
  • Row-Level Security in Postgres so no user can read another user's data, even if our application code has a bug.
  • Hashed passwords (bcrypt or equivalent) — we never store plain passwords and cannot recover them; you reset them through email if forgotten.
  • Server-side secrets (Anthropic API key, Supabase service role) stored only in Supabase Edge Function environment variables, never in the mobile binary.
  • Logged access for our administrative actions.

No system is perfectly secure. If we discover a personal-data breach that is likely to result in risk to your rights, we notify you and the supervisory authority within 72 hours, as required by GDPR Art. 33-34.


11. Health data — special category (GDPR Art. 9)

Some of the data we process constitutes data concerning health within the meaning of Article 4(15) and Article 9(1) GDPR. This covers in particular:

  • heart rate: resting, maximum, and recorded during runs;
  • notes about injuries and complaints that you give us;
  • daily check-ins, that is your sleep, legs and stress scores;
  • training and health data imported from Apple Health or Google Health Connect;
  • the fitness inferences we compute from the above: VDOT, heart-rate zones, pace zones, predicted race times.

You do not have to disclose a specific medical condition for data to fall under this heightened protection. It is enough that the data supports inferences about your physical health. We therefore process it solely on the basis of your explicit consent (Art. 9(2)(a) GDPR), alongside the Article 6(1) basis set out in §3.

When we collect this consent. During sign-up, on a dedicated consent screen, before you enter any training data. The consent is separate from accepting the Terms of Service and expressly covers sending this data to Anthropic PBC (Claude API) so the AI coach can work — see §5 and §13.

What is sent to the AI. When you chat with Veli, the current context of your training profile is sent to Anthropic: name, age, gender, weight, height, maximum and resting heart rate, reported injuries, experience level, today's check-in (sleep, legs, stress), a summary of your recent runs, your records, and the computed paces and zones. We do not send your email address, password, or payment data.

You can withdraw this consent at any time by emailing velapp.contact@gmail.com or by deleting your account in the App (Profile → Account → "Delete account"). Withdrawal does not affect the lawfulness of processing carried out before it. Because health data is necessary to compute your plan, zones and paces, withdrawing consent means we can no longer provide the coaching features — in practice it is equivalent to ending your use of the App.

What we do not do with this data. We do not use it for advertising or for marketing profiling, we do not sell it, we do not share it with data brokers, and we do not combine it with an advertising identifier. Apple HealthKit and Google Health Connect data is additionally subject to the restrictions those platforms' policies impose.

Veli is not a doctor. The AI coach does not diagnose, does not recommend medication, and directs you to a qualified professional for medical matters. The App is not a medical device within the meaning of Regulation (EU) 2017/745 and is not intended for the diagnosis, prevention, monitoring or treatment of disease.


12. Cookies and similar technologies

The mobile App does not use HTTP cookies. We use local on-device storage (AsyncStorage on iOS/Android) to remember your language preference, your auth session, and your last-known location for weather.

On the free tier the App embeds the Google AdMob SDK, which may use the device advertising identifier. Pro subscribers see no ads and no advertising identifier is used for them.

How we collect your ads consent and how you change it:

  • In the EEA and the UK we show Google's User Messaging Platform (UMP) consent form on first launch. You can change your choice at any time in the App: Profile → Settings → Ads privacy. The same screen lets you withdraw consent entirely.
  • On iOS Apple's App Tracking Transparency (ATT) prompt applies in addition. That choice is changed in System Settings → Privacy & Security → Tracking, because Apple does not let an app change it.
  • Without consent we serve non-personalised ads only.
  • Health data (§11) never feeds advertising and is never combined with an advertising identifier.

13. International transfers

Your account, profile, run history and Veli conversations are stored in the European Union (Supabase, region eu-west-1, Ireland). Only the data listed below leaves the EEA.

ProviderCountryWhat leaves the EEATransfer mechanism
Anthropic PBCUSAThe training context described in §11 and the content of your chats with Veli, including health dataStandard Contractual Clauses (module 2) under Anthropic's DPA
RevenueCatUSAUser identifier and subscription status. No health dataStandard Contractual Clauses
ResendUSAEmail address and the content of the transactional message. No health dataStandard Contractual Clauses
ExpoUSANotification token and notification contentStandard Contractual Clauses
Google (AdMob, FCM)USAAdvertising identifier and technical device data, on the free tier only and only with your consent. Never health dataEU-U.S. Data Privacy Framework (Google LLC is certified) and Standard Contractual Clauses
AppleUSAData related to App distribution and paymentsEU-U.S. Data Privacy Framework and Standard Contractual Clauses

What this means for you. US law does not provide protection identical to the GDPR, and US public authorities may in defined circumstances demand access to data. Accordingly:

  • health data is transferred to Anthropic solely on the basis of your explicit consent (§11), and no transfer happens if you do not use the AI coach;
  • we send no health data whatsoever to advertising or payment providers;
  • we apply additional safeguards to every transfer: encryption in transit (TLS 1.2+), minimisation of the data sent, and contractual purpose limitation.

You can request a copy of the relevant Standard Contractual Clauses by emailing velapp.contact@gmail.com.


14. Changes to this policy

When we change this policy materially, we:

  1. Bump the "Last updated" date at the top.
  2. Show an in-app notice the first time you open the App after the change.
  3. For changes affecting legal basis or sub-processors, ask you to re-confirm consent.

Continuing to use the App after a material change means you accept the new policy. If you do not accept, delete your account.


15. Contact

For any privacy question, GDPR request, or breach report:

Email: velapp.contact@gmail.com NIP: 5080100981

If we do not resolve your concern, you can lodge a complaint with the President of UODO (Office for Personal Data Protection), ul. Stawki 2, 00-193 Warszawa, Poland — or the supervisory authority in your EU member state.