Skip to content
Back to home

Privacy Policy

Last updated: August 3, 2026

Version: 2026-08-03

Effective: August 3, 2026

1. Controller and scope

The controller is Roberto Diaz, a self-employed sole trader established in Spain (Spanish tax ID 71655922C), with a professional address at Calle Vázquez de Mella 75, 33012 Oviedo, Asturias, Spain.

No Data Protection Officer has been appointed because, given the current scale and organisation, appointment is not considered mandatory under GDPR Article 37. This decision will be revisited if the scale, nature, or regular and systematic monitoring changes.

This Policy covers verxion.ai, the web and mobile apps, API, MCP servers, widgets, coaching, social profiles, waitlist, support, and connected apps operated by Verxion. Third-party products you choose—such as an identity provider, AI model, or MCP client—have their own policies where they act as independent controllers.

2. Data we process

Depending on the features you use, we process:

  • Account and authentication: email, name, provider image, Apple/Google identifiers, sessions, tokens, verification state, and acceptance versions and evidence. Email/password access may exceptionally be enabled for authorised app-store reviewers; only a password hash is then stored.
  • Profile and onboarding: username, account type, date of birth, sex or gender, height, measurement system, experience, goals, preferences, language, theme, referral source, and answers about working as or with a coach.
  • Health, training, and wellbeing: routines, programmes, mesocycles, sessions, sets, loads, repetitions, cardio, steps, pauses, sleep, energy, stress, motivation, feelings, notes, declared injury or illness, availability, and time off.
  • Nutrition: plans, meals, recipes, foods, water, supplements, macros, adherence, and analytics.
  • Measurements and images: weight, perimeters, body composition and progress, tracking or projection images, avatars, and exercise-instruction images; plus type, size, path, thumbnail, and linked-video metadata.
  • Conversations and AI: titles, messages, replies, summaries, message parts, tool results, attachment metadata, selected model/provider, token usage, estimated cost, usage caps, and finish state. BYOK keys transit the request and must not be persisted or logged by Verxion.
  • Coaching: coach profile, relationships and invitations, scopes, assignments, library, measurements, monitoring, and coach notes about clients.
  • Social: athlete profile, bio, avatar, tags, visibility, showcase metrics, follows, requests, blocks, mutes, feed, and profile views. A hash of an IP address may be used to deduplicate views.
  • API, OAuth, and MCP: API-key names and hashes, prefixes, usage, OAuth clients, redirect URIs, scopes, tokens, consents, idempotency, executed tools, and access audits.
  • Analytics and diagnostics: pseudonymous internal ID, navigation and product events, page, device/browser, timing, errors, traces, and performance. When enabled, PostHog may receive attributes such as language, measurement system, experience, gender, goal, and onboarding state; Sentry receives filtered errors and performance data. PostHog session replay is disabled.
  • Communications and feedback: email, communication preferences, deliveries, bounces, waitlist status, feedback category and free text, and support messages.
  • Billing, if enabled: store, purchase or RevenueCat identifiers, product, entitlement, renewal, price, currency, issues, and subscription events.
  • Technical and security: request ID, timestamps, rate-limit state, IP address or hash where needed, user agent, security events, deletion/export records, and minimised operational logs.
  • Local storage: preferences, interface state, OAuth context, and onboarding drafts described in the Cookie Policy.

Some data reveals or permits inference about health and is special-category data under GDPR Article 9. Selected sensitive fields also use application-level encryption with a per-user key wrapped by AWS KMS in eu-north-1; infrastructure providers also apply transport and storage encryption. Encryption does not make personal data anonymous.

PurposeGDPR Article 6 basisAdditional health-data condition
Account creation, authentication, onboarding, and requested service deliveryArt. 6(1)(b), contractArt. 9(2)(a), explicit consent where health data is involved
Training, nutrition, measurement, wellbeing, time-off, and image trackingArt. 6(1)(b)Art. 9(2)(a), explicit consent
Conversation storage and assistant, tool, and summary executionArt. 6(1)(b)Art. 9(2)(a) where content contains or infers health data
User-selected MCP, OAuth, API, and connected-app accessArt. 6(1)(b); Art. 6(1)(f) for security and auditingArt. 9(2)(a) before exposing health data within an authorised scope
Coaching within an active relationship and granted scopesArt. 6(1)(b)Client’s Art. 9(2)(a) explicit consent for health data
Optional public profile and social featuresArt. 6(1)(a), consent; Art. 6(1)(f) for abuse preventionArt. 9(2)(e) only for data the user manifestly makes public; otherwise Art. 9(2)(a)
Optional PostHog product analyticsArt. 6(1)(a), consentArt. 9(2)(a) if an event or attribute reveals or permits health inference
Diagnostics, security, fraud prevention, rate limiting, and auditingArt. 6(1)(f), legitimate interest in protecting users and systems; Art. 6(1)(c) where legally requiredHealth content is minimised and excluded; where indispensable, Art. 9(2)(f) for claims or Art. 9(2)(a), as applicable
Transactional email and supportArt. 6(1)(b); Art. 6(1)(f) for handling requestsHealth data is not requested; if volunteered, processing is limited to the request under explicit Art. 9(2)(a) initiative or Art. 9(2)(f) where needed for a claim
Waitlist and promotional messagesArt. 6(1)(a), consent, revocable in each messageHealth data is not requested
Billing, purchases, and accountingArt. 6(1)(b) and Art. 6(1)(c)Health data is not requested
Rights, compliance, consent evidence, and legal claimsArt. 6(1)(c) and Art. 6(1)(f)Art. 9(2)(f) where necessary

Security interests include preventing unauthorised access, investigating incidents, preserving integrity, limiting abuse, and defending claims. You may ask about the balancing assessment and object; we will consider your circumstances.

Health consent is specific, informed, versioned, and withdrawable. Withdrawal does not affect earlier processing but stops new processing based on it and may disable incompatible features. Merely accepting this Policy is not that consent.

4. AI, MCP, and automated decisions

Verxion does not make solely automated decisions producing legal or similarly significant effects within GDPR Article 22.

There are two main flows:

  1. Your selected MCP client. The client calls Verxion within OAuth scopes. Its provider processes received data under its own agreement and normally as an independent controller.
  2. Verxion’s BYOK assistant. The message and context transit the EEA-hosted Verxion harness and are sent to your selected provider—OpenAI, Anthropic, Google, or OpenRouter—using your own key. Verxion stores the encrypted conversation under this Policy but does not persist the BYOK key or train its own models on the content. OpenRouter may route to another provider; Verxion requests no-training and zero-retention routing where supported by the API.

The interface informs you that you are interacting with AI. Outputs are reviewable suggestions, not diagnosis or professional instructions. Where a feature generates or manipulates content subject to labelling under Regulation (EU) 2024/1689, Verxion will apply required machine-readable markings or notices.

If web search is enabled, necessary query text may reach the BYOK provider’s search partner. We will not enable LLM credits using a Verxion-owned key without reviewing roles, executing the applicable DPA, and updating this Policy.

5. Data sources

We obtain data directly from you, your device and use, Apple or Google during sign-in, authorised apps or MCP clients, and public providers queried through a feature. A coach may contribute assignments, notes, or measurements concerning a client; other users may generate follows, views, or interactions. App stores or billing providers may send purchase events.

Where data comes from another source and GDPR Article 14 applies, we provide required information within the statutory period unless a valid exception applies.

6. Recipients and roles

We do not sell personal data or use it for third-party behavioural advertising.

Processors that may act on Verxion instructions include Railway, AWS, Sentry, Upstash, Resend, Vercel, Cloudflare and, when optional analytics is lawfully enabled, PostHog. The current list, purpose, region, transfer mechanism, and contractual links appear on the Sub-processors page.

Telegram currently receives operational sign-up and feedback notifications when enabled; these may include email, category, and submitted text. Telegram acts under its own terms and must not be used to send health or other sensitive information. This flow remains subject to contractual and minimisation review.

The following normally act as independent controllers for their own purposes: Apple and Google for sign-in; BYOK providers and MCP clients selected by you; OpenFoodFacts; YouTube, Vimeo, TikTok, or Instagram when resolving a link; app stores; and coaches for their professional service where they determine their own purposes. Classification can vary by flow; if Verxion acts on documented instructions from a coach or organisation, an Article 28 agreement will be put in place.

7. International transfers

We prioritise EEA regions. Railway hosts the application and Postgres in EU West; AWS KMS runs in eu-north-1; Sentry uses its EU region; Resend has been configured in Ireland; and PostHog, when enabled, uses its EU endpoint. Upstash is in London and relies on the UK adequacy decision.

US entities such as Vercel, Resend, Cloudflare, PostHog, or particular providers may access data outside the EEA or use global subprocessors. Where no adequacy decision applies, we use European Commission Standard Contractual Clauses incorporated into the DPA and proportionate supplementary measures. Request a redacted copy of safeguards at [email protected].

Providers or clients you select under your own agreement may make their own international transfers; review their policies before authorising them.

8. Retention

CategoryCriterion or period
Account, profile, conversations, training, nutrition, measurements, coaching, and social contentWhile the account or content remains active; earlier if you delete it, consent withdrawal requires erasure, or the purpose ends
Expired OAuth tokens and sessionsUp to 30 days after expiry or revocation; session cookies have their own technical duration
Idempotency and rate-limit keysNormally up to 24 hours
Access audits30 days, unless limited preservation is required for an incident or claim
Usage/cost eventsWhile needed to show consumption, enforce caps, and resolve disputes; no longer than the account plus the applicable legal-claim period
ConversationsUntil you delete the conversation or account; summaries change as context is compacted
Local onboarding draftUp to 90 days, until completion/sign-out, or until the consent version changes, whichever occurs first
Feedback and supportUntil the request is closed and documented; normally 24 months, longer if a claim exists
SentryUp to 90 days under operational settings
Optional PostHogAccording to consent and project settings; Verxion will limit identifiable retention to what is necessary for product analytics
Export download URLs15 minutes
Export job records30 days
Acceptance, consent, and deletion evidenceDuring the account and up to six years afterwards, pseudonymised where possible, for compliance and defence
Waitlist/promotionsUntil withdrawal, unsubscribe, campaign end, or two years without interaction
Invoices and accountingApplicable tax, accounting, and claim periods
Dormant accountsTarget purge after 24 months’ inactivity and 30 days’ prior notice; if automation is unavailable, manual review applies the same criterion

Account deletion performs a transactional database erasure and retains only limited evidence that must survive. External objects are deleted through retryable tasks. Backups, if any, remain isolated, are not returned to production except for recovery, and rotate under the provider schedule; destroying the per-user key makes encrypted fields in earlier copies unreadable.

9. Rights

You may exercise rights to:

  • access and obtain a copy;
  • rectification;
  • erasure;
  • restriction;
  • object to legitimate-interest processing;
  • portability of provided data where applicable;
  • withdraw any consent; and
  • not be subject to solely automated decisions with legal or similar significant effects.

The app lets you download a JSON export, delete the account, withdraw health consent, and revoke sessions/apps. For any right, email [email protected]. We may request proportionate information to verify identity. We normally respond within one month, extendable in statutory cases, and will explain an extension.

You may complain to the Spanish Data Protection Agency or the authority for your residence or the place of the alleged infringement.

10. Required data and consequences

Email, authentication, contractual acceptance, and fields marked as minimum onboarding data are needed to create and operate an account. Health consent is voluntary, but features processing those categories cannot work without it. Public profile, coaching, images, AI, optional analytics, and most logs are voluntary. Each screen should distinguish required and optional data.

11. Children

The service is not directed to children under 14. For ages 14 to 17, consent-based processing is valid only under Article 7 of Spain’s LOPDGDD and where the act does not legally require assistance from a representative. If an account lacks sufficient capacity or authority, we will restrict it and erase data where appropriate.

12. Security

Controls include scope separation, coach-client relationship checks, encryption in transit, sensitive-field encryption, per-user keys, PII filtering in observability, audit logs, rate limiting, revocation, and deletion checks. No measure eliminates all risk; report suspected incidents to [email protected].

13. Cookies and local storage

See the Cookie Policy for cookies, localStorage, sessionStorage, analytics, and controls. Storage or access that is not strictly necessary requires prior consent under Spanish LSSI rules.

14. Changes

We publish the date and version of changes. Material changes receive proportionate notice. We may request renewed Terms acceptance or a new specific consent where required; we do not treat mere receipt of this Policy as general consent to processing.