Effective date: March 6, 2026 · Last updated: September 19, 2026
Verve ("the App") is a cardiorespiratory fitness tracker designed with privacy as a core principle. Your health and fitness data is stored locally on your device by default. Cloud features (sync, AI Coach) are optional and require your explicit consent.
Verve is also a website, verve-app.health ("the Website"), where you sign in with the same account, read the science, and keep your lab and imaging reports on the My health page. This policy covers both.
When you use Verve, you may provide:
When you grant HealthKit access, Verve reads:
If HealthKit is enabled, Verve may estimate background physical activity from heart rate data using published physiological models. These estimates are processed entirely on your device.
By default, all data is stored and processed locally on your device. No data leaves your device unless you opt in to cloud features.
If you create an account (via email or Apple Sign-In), we use Supabase for secure authentication. Supabase stores your email address and encrypted credentials.
If you enable Cloud Sync in Settings, your profile, activities, and fitness data are synced to secure servers to enable cross-device access. You can disable Cloud Sync at any time.
If you use the AI Coach feature, anonymised fitness context is sent to our secure server to generate personalised activity suggestions. The data sent includes age, sex, weight, resting heart rate, weekly MET-hours, activity breakdown, and CRF level.
We use RevenueCat to manage subscriptions. RevenueCat receives an anonymous user identifier and subscription status. No health or fitness data is shared with RevenueCat.
The Website uses the same account as the App. You sign in with a password or with a code we email you. The name you give at the greeting is stored in your profile and used in the App.
If you tick the newsletter box when you sign up, we record that choice and its time with your account. The weekly letter is sent through Substack, which holds your email address under its own privacy policy. Every letter carries an unsubscribe link.
PDFs and photos of your reports are stored in a private folder that only your account can open, on Supabase servers in Mumbai, India. Photos are reduced in size in your browser before upload. Deleting a report removes the file at once.
When a report is read, the file is sent through Verve's server to Anthropic's Claude model, which returns the values, units, reference ranges, dates and the report's wording. Nothing else about you is sent with it. Under Anthropic's commercial terms the file and the reply are not used to train models and are deleted from Anthropic's systems within 30 days, unless retained to enforce its usage policy or as required by law. Verve counts how many reports each account reads per day, to enforce a limit.
Every value read, with its unit, the lab's printed reference range, its section and date; an imaging report's impression and findings as printed; and, for the markers the App tracks, a copy in your App's lab history, marked unchecked until you confirm it there. These stay on your Labs page and in the App after the file is deleted. Email us to have particular values removed, or delete your account in the App's Settings to remove everything.
My health is for your own reports. If you upload a report about someone else, you need their permission, and you should remove it rather than keep its values in your history.
The Website sets no cookies and loads no analytics, fonts or scripts from anyone else. Your browser keeps your sign-in session and two small preferences (whether you kept two copies of a report, and whether you postponed the name question) until you sign out or clear site data.
| Data | Location | Protection |
|---|---|---|
| Profile, activities, CRF entries | On-device | iOS file-level encryption |
| Auth tokens | iOS Keychain | Hardware-backed encryption |
| HealthKit data | Apple HealthKit | iOS HealthKit encryption |
| Cloud Sync data (if enabled) | Supabase (cloud) | TLS in transit, encrypted at rest |
| Reports and their values | Supabase (Mumbai, India) | Private storage, row-level security, TLS in transit, encrypted at rest |
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Authentication, cloud sync & reports | Email, profile, activities (if sync enabled), reports and their values |
| RevenueCat | Subscription management | Anonymous user ID, subscription status |
| Anthropic | AI activity suggestions; reading uploaded reports | Anonymised fitness context (if AI Coach used); the report file (when you upload one) |
| Apple | HealthKit, Sign-In, App Store | Per Apple's privacy policies |
| GitHub | Hosts the Website | Visitor IP addresses in GitHub's logs, for security, under GitHub's privacy statement; Verve does not receive them |
| Substack | Sends the newsletter | Your email address, if you subscribe |
We do not use analytics, advertising, or tracking SDKs.
You have full control over your data:
Verve is not intended for use by children under 17. We do not knowingly collect personal information from children.
We may update this Privacy Policy from time to time. Changes will be reflected in the "Last updated" date above. For material changes, we will notify you through the App or the Website.
For questions about this Privacy Policy or to exercise your data rights:
Email: roplekarsudeep@gmail.com
Developer: Sudeep Roplekar