Privacy notice
Last reviewed
Veyrova plans training and meals, which means it holds detail about your body, what you eat and how you train. This page says exactly what is collected, why, who else sees it, and how to get it back or have it deleted.
It describes the Veyrova app and this website. It is written to be read, not to be impressive.
1.Who is responsible for your data
Veyrova is operated by Ajdin Šabanović, registered at Slatinski Put, Sarajevo, Bosna i Hercegovina. For data protection purposes that entity is the controller: it decides what is collected and why.
Questions about this notice, or a request about your data, go to ajdina750@gmail.com. We aim to answer within 30 days.
Veyrova is operated from Bosnia and Herzegovina and is offered to people in the European Economic Area, so two regimes are relevant: the Bosnian Law on Protection of Personal Data, supervised by the Personal Data Protection Agency of Bosnia and Herzegovina, and the EU General Data Protection Regulation, which applies to offering a service to people in the EEA regardless of where the operator sits. Where they differ, the stricter rule is applied.
2.What Veyrova collects
Only what a daily plan needs. Grouped by why it exists:
- Account. Email address and an authentication record held by Supabase Auth. Passwords are never seen by Veyrova: they are hashed and stored by Supabase, and the app only ever hands over what you type at sign-in.
- Profile and goal. Year of birth, height, the parameter used by the energy formula, activity level, goal, body focus areas, time zone, language and units. These drive the calorie and macro calculation.
- Body measurements. Weight entries you record, and the trend derived from them.
- Nutrition. Meals you log, with the food, the portion in grams and the time. Dietary rules you set: halal preference, allergies, excluded ingredients, eating pattern, meals per day, cooking time, budget and disliked foods.
- Food photographs. When you use the scanner, the image you take. It is uploaded to private storage, analysed, and used to propose foods and portions.
- Training. Sessions, exercises, sets, repetitions, load, reps in reserve, rest, plans generated for you, and the morning check-in about sleep, energy and soreness. Physical limitations and problematic movements you record so plans avoid them.
- Coach messages. What you ask the coach and what it answers.
- Technical. App version, platform, and error reports when something crashes. Error reports are sent to Sentry and can include the screen name and a stack trace.
Health information. Some of the above, in particular injuries, physical limitations and detailed nutrition records, can be treated as health data, which has extra protection under the GDPR. Veyrova collects it because you enter it so the plan can avoid hurting you. The legal basis for that specific category needs confirmation by a qualified adviser before launch, and is listed as an open item in the site audit.
3.Why, and on what legal basis
- To provide the service you asked for (performance of a contract): account, profile, goal, training and nutrition records, plan generation, the coach.
- To keep the service working and safe (legitimate interests): crash reports, abuse and rate limiting, and the daily token cap on AI usage.
- To meet legal obligations: records tied to purchases, where those exist.
- With your consent: optional product emails, and any processing of health information that requires explicit consent once confirmed.
Veyrova does not profile you for advertising, does not sell data, and does not share your records with data brokers.
4.How AI is used, and what it is sent
Plans and coach answers are produced by a large language model reached from Veyrova's own server. The app never talks to a model directly, and no API key ever ships inside the app.
What the model receives:
- Your training and nutrition context as figures and short codes: targets, day type, the fatigue estimate, the exercises and foods available to you, your dietary rules, and the last few weeks of sessions in summary form.
- A hashed identifier instead of your user id, used only for the provider's own abuse monitoring.
What it does not receive: your name, email address, or any account identifier.
Nothing the model says about a number is trusted. Calories, macronutrients, portions and fatigue are calculated by Veyrova from its own database, and a plan that breaks the rules is rejected and rebuilt. Token counts and approximate cost are logged; prompt text is not.
5.Who else processes your data
Veyrova runs on services that process data on its instructions. Each one is used for a specific job and receives only what that job needs.
- Supabase. Database, authentication and private file storage, including food photographs.
- Railway. Hosting for the Veyrova server.
- Google. The model that reads a photograph of a meal. The photograph itself is sent to Google for that reading, along with nothing about who you are: no name, no email, no account identifier. Google returns the foods it recognises and an estimate of how much of each is on the plate. The calories and macros are then looked up in the food database rather than taken from the model.
- OpenAI. The language model behind the meal plan, the daily training plan and the coach, receiving the context described above. It does not receive your photographs.
- Sentry. Crash and error reporting.
- PostHog. Product analytics inside the app, where enabled.
- Apple. App distribution and, for purchases made through the App Store, payment. Veyrova never sees your card details.
- RevenueCat. Subscription state, where subscriptions are switched on.
The exact list, regions and contractual terms for each processor still need confirming against the live configuration, and the transfer safeguards below depend on that answer. This is recorded as an open item rather than presented as settled.
This website is separate from the app. It sets no analytics or advertising cookies, embeds nothing from third parties, and loads no external scripts. See the cookie notice.
6.Where your data goes
Several of the processors above are established outside Bosnia and Herzegovina and outside the EEA, principally in the United States. Transfers of that kind need a lawful mechanism, usually the European Commission's standard contractual clauses together with an assessment of the destination country, or an adequacy decision where one exists.
The mechanism relied on for each processor must be confirmed and recorded before launch. Until that is done, this notice does not claim a particular safeguard is in place.
7.How long it is kept
- Account, profile, training and nutrition history: while your account exists, because the plan is built from your history.
- Food photographs: kept only as long as needed to produce and let you correct the result, then deleted. The exact period is being set and will be stated here.
- Coach messages: kept so the conversation makes sense and so quotas can be enforced.
- Crash reports: kept for the provider's standard retention period.
- After you delete your account: personal data is deleted or anonymised, except anything a law requires to be kept, such as records tied to a purchase.
8.Your rights
Under the GDPR and the Bosnian data protection law you can ask for access to your data, a copy in a portable form, correction of anything wrong, deletion, restriction of processing, and you can object to processing based on legitimate interests. Where processing rests on consent you can withdraw it at any time, and withdrawing it does not make what happened before unlawful.
Write to ajdina750@gmail.com. Some of this is already in the app: you can edit your profile, goal, limitations and dietary rules yourself, and change your password from the account screen.
If you think your data has been handled badly you can complain to a supervisory authority: in Bosnia and Herzegovina the Personal Data Protection Agency, and in the EEA the authority where you live or work.
9.Security
- Traffic between the app and the server is encrypted in transit.
- Keys with elevated privileges, including the AI provider key and the database service key, exist only on the server. They are never bundled into the app.
- Food photographs are held in private storage, reached with short-lived signed links.
- Database access rules restrict rows to the account that owns them.
- Passwords, tokens and prompt contents are never written into logs, and signing out clears the local copy of your data from the device.
No system is perfectly secure. If you find a vulnerability, please report it to ajdina750@gmail.com before disclosing it publicly.
10.Age
Veyrova is not built for children. It is intended for people aged 16 and over, and where local law sets a higher age for consenting to this kind of service, that higher age applies. If you believe a child has created an account, write to ajdina750@gmail.com and it will be removed.
11.Changes to this notice
When this notice changes, the review date at the top changes with it. For a change that materially affects how your data is used, you will be told in the app before it takes effect.
This notice was written by the team that built the product and has not yet been reviewed by a qualified data protection lawyer. Items marked as needing confirmation are listed in the project audit and must be settled before launch.