Last updated: July 6, 2026
Vura is a running-coaching app published by Impact Bakers, a company registered in France ("Impact Bakers", "we", "us", "our"). For the purposes of the EU General Data Protection Regulation ("GDPR"), Impact Bakers is the data controller of the personal data described in this policy.
Contact for any privacy question or request: hello@vuraapp.com.
This policy covers the Vura mobile app (iOS and Android, including the Apple Watch companion app) and the vuraapp.com website. It explains what data we process, why, on what legal basis, who we share it with, and the rights and choices you have.
When you set up Vura you provide your first name, your goal (race distance and date, or general fitness), your running experience, how many days per week you train, your recent weekly volume and longest run, optional recent race or personal-best times, an optional threshold-pace override, and your preferred units. This is used to build and calibrate your training plan.
With your explicit permission, Vura reads the following from Apple Health (HealthKit) on iOS or Health Connect on Android: workouts (type, duration, distance, calories), heart rate, heart-rate variability (HRV), resting heart rate, sleep, and workout GPS routes. If you connect a WHOOP account, Vura also receives your daily WHOOP recovery score and the underlying HRV, resting heart rate, and sleep metrics.
Access is read-only — Vura never writes to your health store — and you can revoke it at any time in your device's health settings or by disconnecting WHOOP in the app.
If you use in-app run tracking, Vura records your GPS position while the app is in use to measure distance, pace, splits, and your route. Vura does not track your location in the background. Routes recorded by other devices (e.g. Apple Watch) are imported from your health store as historical records. For optional weather-aware session advice, an approximate location may be used to fetch a local forecast; it is used only for that lookup and is not stored.
Optional morning check-ins (energy, soreness, mood), manually entered readiness scores, run notes, perceived effort (RPE), and manually logged runs.
Your conversations with the coach, and any durable facts you ask the coach to remember (goals, constraints, injuries, preferences). You can review and clear coach memory in the app's settings.
Vura works without an account: on first launch we create an anonymous identifier so the app can function. If you choose to create an account to back up and sync your data, we collect your email address (email sign-up) or an identifier provided by Apple (Sign in with Apple). We do not collect your contacts, calendar, or phone number.
If you choose a photo as the background of a shareable run card, the photo is used on your device to render the card. We do not upload your photo library.
Until you create an account, all of the data above is stored only on your device. Nothing is uploaded to our servers, and the AI coach is unavailable. When you create an account, your profile, plan, runs, readiness history, and coach conversations are backed up to your private cloud space so you can restore and sync them across devices.
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Build, adapt, and personalize your training plan; compute daily readiness; detect and celebrate personal records | Profile, health & recovery data, activity data, check-ins | Performance of our contract with you (Art. 6(1)(b)); your explicit consent for health data (Art. 9(2)(a)) |
| Provide the AI coach (answers, insights, plan suggestions) | First name, training summaries, recent runs, readiness score, coach memory, conversation context | Performance of our contract; explicit consent for health-derived data — the AI coach only runs if you turn it on |
| Back up and sync your data across devices | All app data listed in Section 3 | Performance of our contract; explicit consent for health data |
| Show weather-aware session advice | Approximate location (not stored) | Legitimate interest in providing useful, safe training guidance (Art. 6(1)(f)) |
| Secure the service, prevent abuse, enforce rate limits | Account identifier, request metadata | Legitimate interest in keeping the service secure and available |
| Respond to your requests and communicate service changes | Email address | Performance of our contract; legal obligations |
We do not sell or rent your personal data, do not use it for advertising, and do not use third-party advertising or analytics SDKs in the app.
When you enable the AI coach, your questions are answered by an AI language model. Requests go through Vura's secure backend — API keys never leave our servers — to our AI provider, OpenAI, which processes them on our behalf.
What is sent with a coach request: your first name, your readiness score and level, training-load summaries (such as your acute:chronic workload ratio and average effort), weekly volume, training paces, today's and upcoming sessions, a short summary of recent runs, your coach memory, and the recent turns of the current conversation.
What is never sent: your precise location or GPS routes, your email address, your account credentials, your contacts, or raw health records (such as heart-rate samples or sleep stages).
Under our agreement with OpenAI, data submitted through its API is not used to train its models. The AI coach is off by default and only available once you have an account; you can turn it off at any time in settings, and Vura falls back to its built-in rule-based coaching.
For data obtained from Apple Health (HealthKit), Health Connect, or WHOOP, we additionally commit that this data is: used solely to provide Vura's coaching, readiness, and training features; never used for advertising, marketing, or data mining; never sold; and never shared with third parties except with service providers processing it on our behalf as described in Section 8, or as required by law. Our use of Health Connect data complies with Google's Health Connect Permissions policy, including its Limited Use requirements.
We share personal data only with service providers (processors) that we need to run Vura, under contracts that restrict them to processing on our instructions:
| Provider | Role | Data involved |
|---|---|---|
| Google Firebase (Google LLC) | Authentication, encrypted database, and backend functions | Account identifiers and, once you create an account, your backed-up app data (Section 3). Access is restricted so only your authenticated account can read your data. |
| OpenAI | Generates AI-coach responses | The coaching context described in Section 6, only when the AI coach is enabled |
| WHOOP | Optional recovery-data source you connect yourself | You authorize Vura to read your recovery data via WHOOP's API; governed also by WHOOP's own privacy policy. Connection tokens are stored on your device. |
| Apple Maps / Google Maps | Rendering route maps in the app | Map tiles are requested for the area of your route, subject to Apple's and Google's terms |
| Open-Meteo | Weather forecasts for session advice | Approximate coordinates for the forecast lookup only; no account identifiers are sent |
We may also disclose data if required by law, or as part of a merger, acquisition, or asset sale — in which case this policy will continue to apply to your data and we will notify you of any change of controller.
Our cloud infrastructure and AI provider process data in the United States. Where personal data is transferred outside the European Economic Area, we rely on safeguards recognized by the GDPR, including the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, as applicable to each provider.
Your data is retained for as long as you use Vura, so the coach can learn from your full training history. If you delete your account, your cloud data, your authentication record, and the data stored on your device by Vura are permanently deleted (see Section 11). Residual copies in encrypted backups of our infrastructure provider are purged on that provider's standard backup-rotation schedule. If you never create an account, your data exists only on your device and is removed when you delete the app.
Directly in the app you can:
Under the GDPR you also have the right to access, rectify, erase, and receive a portable copy of your personal data; to restrict or object to certain processing; and to withdraw consent at any time (without affecting past processing). Depending on where you live, you may have similar rights under other laws, such as the California Consumer Privacy Act. To exercise any right, email hello@vuraapp.com; we respond within one month. You also have the right to lodge a complaint with your data-protection authority — in France, the CNIL (cnil.fr).
Your data is encrypted in transit and at rest in the cloud, cloud access is restricted to your authenticated account only, and API keys for our backend services never leave our servers. No method of storage or transmission is completely secure, but we take technical and organizational measures appropriate to the sensitivity of health data, and we will notify you and the competent authority of a breach where the law requires it.
Vura is not directed to children under 13, and we do not knowingly collect data from them. In countries where data-protection law sets a higher age of digital consent (for example, 15 in France), users below that age may use Vura only with the consent of a parent or guardian. If you believe a child has provided us personal data without the required consent, contact us and we will delete it.
We will update this policy as Vura evolves and revise the date at the top. If a change materially affects how we handle your health data, we will notify you in the app before it takes effect.
Impact Bakers — hello@vuraapp.com
© 2026 Vura · Impact Bakers · vuraapp.com · Terms of Service