Wera

Profile›Feedback›Devices›Settings›Follow us on IG!›

Your saved plan and synced data stay with your account when you log out.

Privacy·Health Data·Terms

Wera

Privacy · Version 2026-08-19

Privacy Policy

Effective August 19, 2026

The short version

Wera uses the information you provide and the health and fitness data you choose to sync to build and adapt your training. Wera does not sell personal information or use health data for advertising.

1. Scope and who controls your data

This Privacy Policy explains how the operator of Wera (“Wera,” “we,” “us,” or “our”) collects, uses, discloses, retains, and deletes personal information through the Wera application, website, and related services. For information Wera receives to operate the Service, Wera is the business or data controller and the providers identified below generally act as service providers or processors.

Wera’s separate Consumer Health Data Privacy Policy provides additional disclosures and rights specifically for health and fitness information.

This policy does not control information that Apple, Garmin, COROS, or another wearable provider keeps independently in its own product. Their policies govern those records.

2. Information Wera collects

  • Account information: email address, account identifier, authentication and session information, and account-setup status. Passwords are handled by Supabase Auth and stored as salted hashes, not readable plaintext.
  • Runner profile and goals: birthdate, sex, preferred units, race distance and date, target time, current fitness and training state, recent and peak weekly distance, training history, available training days, strength preferences, and equipment.
  • Health and fitness information you authorize: workouts, activity type, dates and duration, distance, calories, heart-rate summaries and samples, resting heart rate, heart-rate variability, sleep timing and duration, VO₂ max, training load, and source-device metadata. A synced outdoor workout may include route or GPS information supplied by the wearable provider.
  • Wera-generated information: training plans, workout schedules, Body Scores and component scores, calculated paces and loads, adaptation decisions, plan history, and sync status.
  • Location for weather: when you enable weather guidance, the app requests your device location, reduces coordinates to approximately 100-meter precision, and sends them to Wera and Apple WeatherKit to retrieve nearby conditions. Wera does not intentionally save these coordinates in its user database, though request information may appear temporarily in infrastructure logs.
  • Feedback and support: the message, category, screenshots you attach, your account email, the part of the app you were using, device/browser user-agent information, and submission time.
  • Operational information: limited server, security, and error logs needed to run, diagnose, and protect the Service. Wera’s wearable webhook logging is designed not to include raw health payloads or user identifiers.

3. Where the information comes from

Wera receives information directly from you, from calculations performed by Wera, from your device’s Apple Health store after you grant system permission, and from Garmin, COROS, or Amazfit/Zepp through Terra after you authorize the connection. Wera does not collect a category of Apple Health information when you do not grant access to that category.

4. How Wera uses information

  • create, display, save, and adjust your training plan;
  • calculate Body Score, training load, recovery indicators, fitness estimates, and workout guidance;
  • import and display activities and sync status;
  • provide weather-aware guidance when you enable location access;
  • authenticate you and keep your information associated with the correct account;
  • respond to feedback and support requests;
  • secure, debug, maintain, and improve the Service; and
  • comply with law and respond to valid legal process.

Wera does not use health, fitness, or location information for advertising, targeted marketing, eligibility decisions, or sale to data brokers. Wera does not use HealthKit information for advertising or unrelated data mining.

5. Automated training decisions

Wera automatically uses profile, plan, and wearable information to generate workouts, Body Scores, and plan adaptations. These decisions affect only the training guidance shown in Wera; they do not determine employment, credit, insurance, healthcare access, or another legal or similarly significant right. You can choose not to follow a recommendation and can delete your account at any time.

6. Service providers and disclosures

Wera discloses information only as needed to operate the Service, on your instruction, to protect rights and safety, or as required by law:

  • Supabase: authentication, PostgreSQL database, and private file storage.
  • Vercel: application hosting, server execution, network delivery, and short-lived operational logs.
  • Terra: Garmin, COROS, and Zepp authorization, collection, normalization, transfer, and deletion of connected wearable data. Terra’s End User Privacy Policy describes its role for connected users.
  • Apple Health: the device source you authorize. Apple Health information is sent directly from your device to Wera, rather than through Terra.
  • Apple WeatherKit: rounded location, timezone, and forecast window when weather guidance is enabled.
  • Resend: delivery of operational emails and feedback notifications to Wera support. A feedback notification includes the message, account email, app screen, and screenshots you choose to submit; do not include information you do not want sent by email.

Providers may process information in the United States and other countries where they or their subprocessors operate. Wera requires providers to protect information under their agreements and applicable law. Wera may disclose information in a business transfer, but health information remains subject to this policy and applicable consent requirements.

7. Legal bases where required

Where the GDPR, UK GDPR, or similar law applies, Wera processes account and training information to perform the service you request; processes optional health, wearable, and location information with your consent; processes limited security and operational information for legitimate interests in protecting and maintaining Wera; and processes information when necessary to comply with law. You may withdraw consent, but withdrawal does not make earlier lawful processing unlawful.

8. Storage, security, and access

Wera’s active server data is stored primarily in Supabase. Traffic to Wera and its providers uses encrypted HTTPS/TLS connections, and the hosting providers state that production data is encrypted at rest. Wera uses authentication, database row-level security, private storage, server-only credentials, signed wearable webhooks, and access limitations intended to prevent one runner from reading another runner’s information.

Your current training plan is also stored in app/browser local storage for offline restoration. Temporary onboarding answers may be stored briefly on your device and in protected account metadata while you complete account or wearable authorization. Information stored locally is protected by your device and operating system, so you should use a device passcode and keep your device secure.

No system can guarantee absolute security. If Wera learns of a qualifying breach, it will investigate and provide notices required by applicable law.

9. Retention

  • Account, plan, and health information: kept while your account is active so Wera can provide history, calculations, and adaptations, then deleted from active Wera systems when you delete the account.
  • Temporary onboarding recovery: designed to expire after approximately 30 minutes for wearable returns or two hours for account confirmation.
  • Feedback: kept while reasonably needed to investigate and resolve the submission, or until account deletion where it can be linked and removed.
  • Operational logs: retained for short periods determined by the hosting plan and longer only when reasonably necessary for security investigation.
  • Backups and provider copies: deleted or overwritten on each provider’s protected backup lifecycle. Information may be retained longer only when required by law, necessary for security or fraud prevention, or needed to establish or defend legal claims.

Wera periodically reviews retention and aims to minimize raw health information that is no longer needed for the Service.

10. Your choices and rights

  • Change Apple Health and location permission through your device settings.
  • Revoke a Garmin, COROS, or Zepp connection through its provider app, or delete your Wera account to have Wera request Terra deauthentication and deletion.
  • Access and update profile or plan information through the Service.
  • Delete your Wera account and associated active Wera data in Settings.
  • Request access, correction, portability, restriction, objection, or other rights available where you live by emailing team@wera.run.

California residents may have rights to know, correct, delete, and obtain information about personal information, and to receive equal service when exercising those rights. Wera does not sell personal information or share it for cross-context behavioral advertising. European and UK residents may complain to their local data-protection authority.

11. Account deletion

In Settings, choose “Delete account,” enter the requested confirmation, and verify your password. Wera will remove your account, profile, plans, Body Scores, adaptations, connected wearable records, health and activity records, consent record, and linked feedback from active Wera database and file-storage systems. Wera will also call Terra’s deauthentication endpoint for linked Garmin, COROS, and Zepp identities before completing deletion.

Deletion is permanent. It does not delete records independently controlled by Apple, Garmin, COROS, or your wearable provider. Protected backup copies are isolated from normal use and expire under provider schedules unless retention is legally required.

12. Children

Wera is for adults age 18 and older. Wera does not knowingly collect personal information from children. If you believe a child has provided information, contact Wera at team@wera.run so it can be removed.

13. Changes and contact

Wera may update this policy as the Service or law changes. Material changes will be presented in the Service and renewed consent will be requested when required. The current version and effective date appear above.

Wera’s official support contact is team@wera.run. Use this address to ask a privacy question or exercise a privacy right. Wera may need to verify that the request belongs to you before acting on it.

This policy describes Wera’s current product and data flows. It should be reviewed by qualified privacy counsel before broad commercial release or expansion into additional jurisdictions.