Privacy Policy

Effective and last updated: 20 July 2026

Document version 1.0
1

Who controls your data

Vayra is the controller of personal data processed to provide the app. Supabase and Apple act as service providers or independent controllers for some processing as described below.

2

Data Vayra processes

Account and identity data: the email address or private relay address supplied through Sign in with Apple, Supabase authentication identifier, account creation date, display name, username, avatar and private-account choice. Vayra does not offer password authentication. Signed-in users can search discoverable profile names, usernames and avatars; email addresses are not exposed through profile search.

Social relationship data: follow requests, accepted follower/following relationships, blocks, in-app social notifications, notification read state and the times those records were created or changed. A block is visible only to the accounts involved and is used to prevent search and relationship access between them.

Activity, Health and location data: activity type, timestamps, duration, distance, pace, estimated or recorded active calories, elevation gain, GPS coordinates and recorded routes. If you enable Apple Health workout import and grant access, Vayra reads recent completed workouts—including Apple Watch workouts—and stores their Health identifier, workout type, time and active calories so they can appear as activity posts without a route map. Vayra-authored workouts written to Health are excluded from re-import. A route can reveal home, work, routines and other sensitive locations.

Preferences and goals: weekly goal type and target, units, recording choices, appearance and notification preferences. iOS provides notification and location authorization status.

Device and support information: when you choose to contact the developer, a support request may include app version/build, iOS version and device model. It does not automatically include routes, precise location, tokens or personal activity data. The current app does not include third-party analytics, advertising SDKs or crash-reporting SDKs. Apple may provide aggregated diagnostics according to your Apple settings.

3

Where data is stored

Guest profile, avatar, preferences and activity history are stored locally in the app’s container. Registered-account profile, preferences, activities, routes, avatar, privacy choice and social relationships may be stored in the configured Supabase project when syncing succeeds. Authentication session credentials are maintained by the Supabase client using protected platform storage. Vayra does not include authentication tokens or secrets in exports.

4

Why data is processed

We process account data to create and secure Apple-linked accounts, restore sessions, sync and provide account controls. Profile search and relationship data are processed to let signed-in users find, follow, approve, remove and block accounts and to enforce private-account choices. We process activity, Health, route and location data to import or record activities, calculate and display metrics, draw routes, build progress/achievements, create the activity posts you enable and sync when enabled by account use. Preferences are processed to apply your choices. Notification preferences are processed to schedule optional local reminders. Support information is processed to respond to your request. Security events and minimal server logs may be processed to prevent abuse and operate the service.

Where GDPR or UK GDPR applies, the intended bases are performance of the user agreement for requested account and recording functions; legitimate interests in reliable, secure operation and support; consent where iOS permission or optional communications require it; and legal obligation where applicable. Privacy-policy acknowledgement is not blanket consent. Marketing notifications, if ever enabled, are separate and off by default.

5

Location behavior

Vayra requests location for route recording, not on app launch. Collection starts when you intentionally start an activity and the recorder begins receiving valid locations. With background permission and the iOS background-location mode, collection can continue while the app is not visible. Collection stops when you finish the activity, when the recorder is stopped by the app or system, or when permissions/settings prevent access. Pausing can affect metric updates; confirm the recording state shown in the app. You can change access in iOS Settings.

6

Notifications

Vayra asks for notification permission only after you enable a notification feature. Reminders are scheduled locally on the device. Follow requests and other social notices are stored securely in the account and shown in Vayra’s notification centre; Vayra does not currently send those notices as remote push notifications. You can cancel reminders in Vayra or disable permission in iOS Settings.

7

Service providers and disclosures

Supabase processes authentication, database, Edge Function and Storage data on the operator’s behalf under its terms and infrastructure configuration. Apple provides iOS, Sign in with Apple, notification, location, distribution and device services and may process related data under Apple’s policies. Data may also be disclosed to professional advisers, authorities or successors where lawfully required, necessary to protect rights and safety, or connected with a service transfer subject to appropriate safeguards. Vayra does not sell personal data and does not use it for targeted advertising.

8

International transfers

Vayra’s Supabase project is hosted in the London region. Supabase or Apple infrastructure may also process data outside your country. Where required, transfers rely on adequacy decisions, contractual safeguards or another lawful mechanism.

9

Retention

Local data remains until you delete it, uninstall the app, or the operating system removes it. Synced account data remains while the account is active and until deletion is requested, subject to resolving offline requests and failures. Account deletion removes profile, preferences, activities, legal records, avatar objects and the Auth user after the server confirms the request. Provider backups and security or operational logs may remain for their limited rotation period or longer where law requires. Support correspondence is retained only as long as needed to resolve the request and meet legal obligations.

10

Your choices and rights

Settings lets you correct profile data, make your account public or private, manage followers and blocks, change preferences, disable Health workout importing or revoke Health access, export activities, clear local cache/history and request account deletion. Public profiles allow signed-in users to see activity totals, imported Health workout posts, recent workout summaries and recorded GPS routes. Private profiles make those activities and routes available only to approved followers. Eligible activity cards can include a reduced route preview in the Home feed; opening a card loads the complete route. Route previews and complete routes remain unavailable to blocked or otherwise unauthorized users. A private account requires approval for new followers; existing approved followers remain until removed or blocked.

Depending on your location, you may have rights to access, correct, delete or export data; restrict processing; object to legitimate-interest processing; withdraw consent without affecting prior lawful processing; and complain to a supervisory authority. Identity verification may be required.

11

Children

Vayra is not directed to children under 16, or the higher minimum digital-consent age required locally. Vayra does not knowingly seek children’s data.

12

Security

Vayra uses local app-container protections, authenticated sessions, private Storage, user-owned paths, encrypted transport and database row-level security intended to restrict sensitive account data and enforce social ownership and blocks. Basic searchable profile information is intentionally available to other signed-in users unless a block applies. Service-role credentials are not placed in the app. No system can guarantee absolute security. Keep your device and credentials secure and install updates.

13

Policy changes

The version and effective date appear above. Material changes will be communicated appropriately, and consent will be requested where a new purpose legally requires it. Older versions should remain archived for accountability.

14

Contact and complaints

Privacy requests can be made through the developer contact channel published with Vayra’s App Store listing. You may also contact your local data-protection authority where the law permits.