Privacy Policy
Last updated: August 3, 2026
Version: 2026-08-03
Effective: August 3, 2026
1. Controller and scope
The controller is Roberto Diaz, a self-employed sole trader established in Spain (Spanish tax ID 71655922C), with a professional address at Calle Vázquez de Mella 75, 33012 Oviedo, Asturias, Spain.
- Privacy and rights requests: [email protected].
- General and legal contact: [email protected].
No Data Protection Officer has been appointed because, given the current scale and organisation, appointment is not considered mandatory under GDPR Article 37. This decision will be revisited if the scale, nature, or regular and systematic monitoring changes.
This Policy covers verxion.ai, the web and mobile apps, API, MCP servers, widgets, coaching, social profiles, waitlist, support, and connected apps operated by Verxion. Third-party products you choose—such as an identity provider, AI model, or MCP client—have their own policies where they act as independent controllers.
2. Data we process
Depending on the features you use, we process:
- Account and authentication: email, name, provider image, Apple/Google identifiers, sessions, tokens, verification state, and acceptance versions and evidence. Email/password access may exceptionally be enabled for authorised app-store reviewers; only a password hash is then stored.
- Profile and onboarding: username, account type, date of birth, sex or gender, height, measurement system, experience, goals, preferences, language, theme, referral source, and answers about working as or with a coach.
- Health, training, and wellbeing: routines, programmes, mesocycles, sessions, sets, loads, repetitions, cardio, steps, pauses, sleep, energy, stress, motivation, feelings, notes, declared injury or illness, availability, and time off.
- Nutrition: plans, meals, recipes, foods, water, supplements, macros, adherence, and analytics.
- Measurements and images: weight, perimeters, body composition and progress, tracking or projection images, avatars, and exercise-instruction images; plus type, size, path, thumbnail, and linked-video metadata.
- Conversations and AI: titles, messages, replies, summaries, message parts, tool results, attachment metadata, selected model/provider, token usage, estimated cost, usage caps, and finish state. BYOK keys transit the request and must not be persisted or logged by Verxion.
- Coaching: coach profile, relationships and invitations, scopes, assignments, library, measurements, monitoring, and coach notes about clients.
- Social: athlete profile, bio, avatar, tags, visibility, showcase metrics, follows, requests, blocks, mutes, feed, and profile views. A hash of an IP address may be used to deduplicate views.
- API, OAuth, and MCP: API-key names and hashes, prefixes, usage, OAuth clients, redirect URIs, scopes, tokens, consents, idempotency, executed tools, and access audits.
- Analytics and diagnostics: pseudonymous internal ID, navigation and product events, page, device/browser, timing, errors, traces, and performance. When enabled, PostHog may receive attributes such as language, measurement system, experience, gender, goal, and onboarding state; Sentry receives filtered errors and performance data. PostHog session replay is disabled.
- Communications and feedback: email, communication preferences, deliveries, bounces, waitlist status, feedback category and free text, and support messages.
- Billing, if enabled: store, purchase or RevenueCat identifiers, product, entitlement, renewal, price, currency, issues, and subscription events.
- Technical and security: request ID, timestamps, rate-limit state, IP address or hash where needed, user agent, security events, deletion/export records, and minimised operational logs.
- Local storage: preferences, interface state, OAuth context, and onboarding drafts described in the Cookie Policy.
Some data reveals or permits inference about health and is special-category data under GDPR Article 9. Selected sensitive fields also use application-level encryption with a per-user key wrapped by AWS KMS in eu-north-1; infrastructure providers also apply transport and storage encryption. Encryption does not make personal data anonymous.
3. Purposes and legal bases
| Purpose | GDPR Article 6 basis | Additional health-data condition |
|---|---|---|
| Account creation, authentication, onboarding, and requested service delivery | Art. 6(1)(b), contract | Art. 9(2)(a), explicit consent where health data is involved |
| Training, nutrition, measurement, wellbeing, time-off, and image tracking | Art. 6(1)(b) | Art. 9(2)(a), explicit consent |
| Conversation storage and assistant, tool, and summary execution | Art. 6(1)(b) | Art. 9(2)(a) where content contains or infers health data |
| User-selected MCP, OAuth, API, and connected-app access | Art. 6(1)(b); Art. 6(1)(f) for security and auditing | Art. 9(2)(a) before exposing health data within an authorised scope |
| Coaching within an active relationship and granted scopes | Art. 6(1)(b) | Client’s Art. 9(2)(a) explicit consent for health data |
| Optional public profile and social features | Art. 6(1)(a), consent; Art. 6(1)(f) for abuse prevention | Art. 9(2)(e) only for data the user manifestly makes public; otherwise Art. 9(2)(a) |
| Optional PostHog product analytics | Art. 6(1)(a), consent | Art. 9(2)(a) if an event or attribute reveals or permits health inference |
| Diagnostics, security, fraud prevention, rate limiting, and auditing | Art. 6(1)(f), legitimate interest in protecting users and systems; Art. 6(1)(c) where legally required | Health content is minimised and excluded; where indispensable, Art. 9(2)(f) for claims or Art. 9(2)(a), as applicable |
| Transactional email and support | Art. 6(1)(b); Art. 6(1)(f) for handling requests | Health data is not requested; if volunteered, processing is limited to the request under explicit Art. 9(2)(a) initiative or Art. 9(2)(f) where needed for a claim |
| Waitlist and promotional messages | Art. 6(1)(a), consent, revocable in each message | Health data is not requested |
| Billing, purchases, and accounting | Art. 6(1)(b) and Art. 6(1)(c) | Health data is not requested |
| Rights, compliance, consent evidence, and legal claims | Art. 6(1)(c) and Art. 6(1)(f) | Art. 9(2)(f) where necessary |
Security interests include preventing unauthorised access, investigating incidents, preserving integrity, limiting abuse, and defending claims. You may ask about the balancing assessment and object; we will consider your circumstances.
Health consent is specific, informed, versioned, and withdrawable. Withdrawal does not affect earlier processing but stops new processing based on it and may disable incompatible features. Merely accepting this Policy is not that consent.
4. AI, MCP, and automated decisions
Verxion does not make solely automated decisions producing legal or similarly significant effects within GDPR Article 22.
There are two main flows:
- Your selected MCP client. The client calls Verxion within OAuth scopes. Its provider processes received data under its own agreement and normally as an independent controller.
- Verxion’s BYOK assistant. The message and context transit the EEA-hosted Verxion harness and are sent to your selected provider—OpenAI, Anthropic, Google, or OpenRouter—using your own key. Verxion stores the encrypted conversation under this Policy but does not persist the BYOK key or train its own models on the content. OpenRouter may route to another provider; Verxion requests no-training and zero-retention routing where supported by the API.
The interface informs you that you are interacting with AI. Outputs are reviewable suggestions, not diagnosis or professional instructions. Where a feature generates or manipulates content subject to labelling under Regulation (EU) 2024/1689, Verxion will apply required machine-readable markings or notices.
If web search is enabled, necessary query text may reach the BYOK provider’s search partner. We will not enable LLM credits using a Verxion-owned key without reviewing roles, executing the applicable DPA, and updating this Policy.
5. Data sources
We obtain data directly from you, your device and use, Apple or Google during sign-in, authorised apps or MCP clients, and public providers queried through a feature. A coach may contribute assignments, notes, or measurements concerning a client; other users may generate follows, views, or interactions. App stores or billing providers may send purchase events.
Where data comes from another source and GDPR Article 14 applies, we provide required information within the statutory period unless a valid exception applies.
6. Recipients and roles
We do not sell personal data or use it for third-party behavioural advertising.
Processors that may act on Verxion instructions include Railway, AWS, Sentry, Upstash, Resend, Vercel, Cloudflare and, when optional analytics is lawfully enabled, PostHog. The current list, purpose, region, transfer mechanism, and contractual links appear on the Sub-processors page.
Telegram currently receives operational sign-up and feedback notifications when enabled; these may include email, category, and submitted text. Telegram acts under its own terms and must not be used to send health or other sensitive information. This flow remains subject to contractual and minimisation review.
The following normally act as independent controllers for their own purposes: Apple and Google for sign-in; BYOK providers and MCP clients selected by you; OpenFoodFacts; YouTube, Vimeo, TikTok, or Instagram when resolving a link; app stores; and coaches for their professional service where they determine their own purposes. Classification can vary by flow; if Verxion acts on documented instructions from a coach or organisation, an Article 28 agreement will be put in place.
7. International transfers
We prioritise EEA regions. Railway hosts the application and Postgres in EU West; AWS KMS runs in eu-north-1; Sentry uses its EU region; Resend has been configured in Ireland; and PostHog, when enabled, uses its EU endpoint. Upstash is in London and relies on the UK adequacy decision.
US entities such as Vercel, Resend, Cloudflare, PostHog, or particular providers may access data outside the EEA or use global subprocessors. Where no adequacy decision applies, we use European Commission Standard Contractual Clauses incorporated into the DPA and proportionate supplementary measures. Request a redacted copy of safeguards at [email protected].
Providers or clients you select under your own agreement may make their own international transfers; review their policies before authorising them.
8. Retention
| Category | Criterion or period |
|---|---|
| Account, profile, conversations, training, nutrition, measurements, coaching, and social content | While the account or content remains active; earlier if you delete it, consent withdrawal requires erasure, or the purpose ends |
| Expired OAuth tokens and sessions | Up to 30 days after expiry or revocation; session cookies have their own technical duration |
| Idempotency and rate-limit keys | Normally up to 24 hours |
| Access audits | 30 days, unless limited preservation is required for an incident or claim |
| Usage/cost events | While needed to show consumption, enforce caps, and resolve disputes; no longer than the account plus the applicable legal-claim period |
| Conversations | Until you delete the conversation or account; summaries change as context is compacted |
| Local onboarding draft | Up to 90 days, until completion/sign-out, or until the consent version changes, whichever occurs first |
| Feedback and support | Until the request is closed and documented; normally 24 months, longer if a claim exists |
| Sentry | Up to 90 days under operational settings |
| Optional PostHog | According to consent and project settings; Verxion will limit identifiable retention to what is necessary for product analytics |
| Export download URLs | 15 minutes |
| Export job records | 30 days |
| Acceptance, consent, and deletion evidence | During the account and up to six years afterwards, pseudonymised where possible, for compliance and defence |
| Waitlist/promotions | Until withdrawal, unsubscribe, campaign end, or two years without interaction |
| Invoices and accounting | Applicable tax, accounting, and claim periods |
| Dormant accounts | Target purge after 24 months’ inactivity and 30 days’ prior notice; if automation is unavailable, manual review applies the same criterion |
Account deletion performs a transactional database erasure and retains only limited evidence that must survive. External objects are deleted through retryable tasks. Backups, if any, remain isolated, are not returned to production except for recovery, and rotate under the provider schedule; destroying the per-user key makes encrypted fields in earlier copies unreadable.
9. Rights
You may exercise rights to:
- access and obtain a copy;
- rectification;
- erasure;
- restriction;
- object to legitimate-interest processing;
- portability of provided data where applicable;
- withdraw any consent; and
- not be subject to solely automated decisions with legal or similar significant effects.
The app lets you download a JSON export, delete the account, withdraw health consent, and revoke sessions/apps. For any right, email [email protected]. We may request proportionate information to verify identity. We normally respond within one month, extendable in statutory cases, and will explain an extension.
You may complain to the Spanish Data Protection Agency or the authority for your residence or the place of the alleged infringement.
10. Required data and consequences
Email, authentication, contractual acceptance, and fields marked as minimum onboarding data are needed to create and operate an account. Health consent is voluntary, but features processing those categories cannot work without it. Public profile, coaching, images, AI, optional analytics, and most logs are voluntary. Each screen should distinguish required and optional data.
11. Children
The service is not directed to children under 14. For ages 14 to 17, consent-based processing is valid only under Article 7 of Spain’s LOPDGDD and where the act does not legally require assistance from a representative. If an account lacks sufficient capacity or authority, we will restrict it and erase data where appropriate.
12. Security
Controls include scope separation, coach-client relationship checks, encryption in transit, sensitive-field encryption, per-user keys, PII filtering in observability, audit logs, rate limiting, revocation, and deletion checks. No measure eliminates all risk; report suspected incidents to [email protected].
13. Cookies and local storage
See the Cookie Policy for cookies, localStorage, sessionStorage, analytics, and controls. Storage or access that is not strictly necessary requires prior consent under Spanish LSSI rules.
14. Changes
We publish the date and version of changes. Material changes receive proportionate notice. We may request renewed Terms acceptance or a new specific consent where required; we do not treat mere receipt of this Policy as general consent to processing.