What VERA does with data about you, which is very close to nothing. This is our notice under the EU General Data Protection Regulation. We have tried to make it specific rather than reassuring, on the theory that specificity is what actually reassures.
The short, human version. The numbered sections below are the operative ones — but if the two ever seem to disagree, we would rather you had read this one.
1.1 Controller. For any personal data processed through the Service, the controller is Pointzone AB, a limited liability company registered in Sweden, reachable at hello@verapulse.app. We have not appointed a Data Protection Officer, as we are not required to.
1.2 Scope. This notice covers the VERA website at verapulse.app,
the installable web application served under /app, the VERA application for Android, and
the live shared-session service — together, the “Service”. It forms part of our
Terms of Service, and the definitions there apply here.
Your workout drafts, saved workouts, profile settings (display name, voice-cue, music and vibration
preferences), the in-progress run snapshot, and your analytics opt-in choice are stored
locally on your own device — in your browser's localStorage on the web,
and in the app's preference storage on Android. They are not uploaded to us, not backed up by us, and
not synchronised between your devices.
The practical consequence, in both directions: we cannot read them, and we cannot restore them. Clearing your browser data, using private browsing, or uninstalling the app deletes them permanently.
Health Connect (Android only, off unless you turn it on). The VERA app for Android can record each workout you finish into Health Connect, Google's health data store on your own phone, so that it appears in whichever health or fitness app you already use. This is off by default; you turn it on in My VERA, and Android then asks you separately for permission.
What is written is one exercise session per completed workout: the start and end time, the fact that it was interval training, the workout's name, and the timing of the work and rest intervals as they actually happened. Nothing else — no heart rate, no calorie estimate, no location.
Three things follow, and all three are deliberate:
Legal basis: your consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR), given twice over — once in VERA and once to Android — and withdrawable in either place.
The Service sends us nothing for analytics purposes unless you switch analytics on in My VERA. It is off out of the box.
If you turn it on, the app sends batched events describing product usage — for example that a workout was started or completed, that an invite link was shared, or that a session was hosted or joined — together with:
We do not collect or store: your name, email address, phone number, contacts, precise or coarse location, advertising identifiers, device fingerprints, or your IP address. We use no third-party analytics, advertising or tracking services, and we set no advertising cookies.
Legal basis: your consent (Art. 6(1)(a) GDPR), given by the toggle and withdrawable at any time by switching it off — which stops all further sending immediately, with no effect on the lawfulness of what came before.
Independently of the opt-in above, our web server keeps aggregate, non-identifying
counts of traffic so we can tell whether anyone is using this. Specifically: page-view
counts per path, a coarse platform bucket derived from the browser's User-Agent string, whether a
request looks like a bot, and the host name only of an external referrer (for
example news.ycombinator.com — never the full URL and never a query string).
We do not read, log or store IP addresses for this purpose, and these counts are not linked to any identifier, session or individual.
Legal basis: our legitimate interest in understanding and maintaining the Service (Art. 6(1)(f) GDPR). We consider the impact on you to be minimal precisely because the data cannot be traced back to you.
While you are in a live shared session, the server holds — in memory only — the session identifier, the connection identifiers of the participants, the workout configuration, the shared start time and each participant's chosen display name. This is deleted when the session ends (see Terms 6.4). It is never written to a database, because there isn't one.
Sessions are unauthenticated: anyone holding the link or the QR code can join and will see the display name you chose. If you would rather not be named, Keep me anonymous in My VERA is on by default and hides it.
Legal basis: performance of the service you asked for (Art. 6(1)(b) GDPR) — the feature is not possible without it.
Our hosting infrastructure may process connection metadata, including IP addresses, transiently as an unavoidable part of delivering an HTTP response and protecting against abuse. Where such logs exist, they are kept only briefly and are not used to build profiles or to identify individuals.
Legal basis: legitimate interest in the security and integrity of the Service (Art. 6(1)(f) GDPR).
VERA sets no cookies for advertising, tracking or analytics. The app uses your browser's local storage for the settings described in section 2, which is strictly necessary to provide the functionality you asked for and therefore does not require a consent banner. You are welcome to enjoy the absence of one.
There is one cookie on this website, and it is set only when you choose a language
using the picker in the footer. It is named vera.site.lang.v1, it contains a two-letter
language code (en, sv, de, es or fr)
and nothing else, and it lasts one year. Its only purpose is to remember your choice, so that the
site does not send you back to the language your browser asks for the next time you visit. It
identifies nobody, is never read by any third party, and is never sent anywhere but this site. Being
set by your own explicit action and doing only what you asked for, it is strictly necessary within
the meaning of the ePrivacy rules and needs no consent banner — please do not add one.
Background music tracks are streamed directly from Jamendo's servers to your device when music is enabled. That request is made by your browser or app to Jamendo, so Jamendo — like any host you fetch a file from — necessarily sees the request, including your IP address, and its own privacy policy applies to it. We receive nothing about your listening. If you would rather not make that request, switch music off in My VERA and no track is ever requested.
| Data | Where | Kept for |
|---|---|---|
| Workouts, profile, settings | Your device only | Until you delete them |
| Opt-in analytics events | Our server | Aggregated on receipt; raw events not retained long-term |
| Aggregate page counts | Our server | Indefinitely, in non-identifying aggregate form |
| Live session state | Server memory | Duration of the session only |
| Infrastructure logs | Hosting provider | Short-term, for security and diagnostics |
The Service is hosted in Sweden. Where any processing takes place outside the European Economic Area, we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses.
Under the GDPR you have the right to request access to, rectification of, or erasure of your personal data; to restrict or object to processing; to data portability; and to withdraw consent at any time.
We have to be honest about the shape of these rights here: because we do not hold any identifier that links to you as a person, we are in most cases genuinely unable to locate “your” data in order to act on such a request (Art. 11 GDPR). If you can supply information that lets us identify the relevant records, we will act on your request without undue delay and in any event within one month. In practice, deleting the app's data on your device removes everything that is actually about you.
You also have the right to lodge a complaint with a supervisory authority — in Sweden, the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, imy.se), or the authority in your country of residence.
We do not sell, rent, trade or share personal data with third parties for their own purposes, and we do not participate in advertising networks or data brokerage. Should we ever be legally compelled to disclose data, we will disclose only what is required, and will notify affected users where the law permits us to.
The Service is not directed at children under 13, and we do not knowingly process personal data of children under 13. Under Swedish law, a child aged 13 or over may consent to information-society services on their own behalf; below that age, a guardian's consent is required. See also Terms 3.4 on supervision.
We may update this notice. The version number at the top will change, and the current version will always be published at verapulse.app/privacy. For material changes — a new category of data, a new recipient, or a new purpose — we will give reasonable prior notice through the Service before they take effect.
Pointzone AB
Email: hello@verapulse.app
For privacy requests, please put “GDPR” in the subject line, and read section 11 first so you know what we can realistically do.