Veltro — Privacy Policy
Last updated: 2026-09-11
Veltro is a multi-sport activity tracker for Android. It is built so that your training data stays yours: everything is recorded and kept on your own phone, and nothing is sent anywhere unless you turn a feature on.
This policy explains, in plain terms, what Veltro does with your information.
Who we are
Veltro is developed and operated by Frederik Duvač (publishing as RikoAppDev).
For anything about this policy or about your data, write to hello@veltro.fit.
Frederik Duvač is the controller of the personal data described below.
The short version
- Your activities, routes and workouts are stored on your phone, in Veltro's own database.
- You can use Veltro without an account. Without one, the only thing your phone ever requests from the internet is map imagery — and that comes from Veltro's own server, not from a third party (see "Maps").
- If you create an account and switch on encrypted sync, your activities are encrypted on your phone before they are uploaded. Our server stores sealed data it cannot open — we cannot read your activities, your routes, or your workouts.
- If you choose to publish an activity to the Veltro feed, that published copy is not encrypted — it has to be readable so other people can see it. You decide, for each activity, whether to publish it, who can see it, and whether the route is included.
- There is no advertising in Veltro, no analytics, and no tracking SDKs of any kind. We do not profile you, we do not build heatmaps, and we never sell or rent your data to anyone.
What Veltro stores on your phone
All of this stays on your device unless a section below says otherwise:
- Activities — sport type, title, start time, duration, distance, elevation gain, calories, steps, lap splits, and for strength sessions your exercises, sets, reps and lifted weights.
- Routes — the GPS track of an outdoor activity, stored both as a compact route line and as a detailed per-second track with position, altitude and speed. The detailed per-second track never leaves your phone under any circumstances.
- Gear — the equipment you add and its accumulated distance.
- Your profile — a display name, an optional short bio, an optional location text and a weekly goal. The bio and location are device-only and are never uploaded.
- Settings — theme, units, the blur preference, the sync and Health Connect toggles, and the Bluetooth address of the last heart-rate strap you paired, so it can reconnect automatically. That address is never transmitted.
- If you have an account: your e-mail address and your sign-in tokens. The tokens are sealed with a key held in your device's hardware-backed keystore. Your password is never stored on the device.
Uninstalling Veltro removes all of it from the phone. Veltro also opts out of Android's automatic cloud backup and device-to-device transfer, so your activity database is never copied into a Google backup. To move your data to a new phone, use encrypted sync with your recovery code, or export your activities as GPX files.
Creating an account
An account is optional. You only need one for encrypted sync, the social feed and clubs.
To create one we ask for an e-mail address and a password. That is all — we do not ask for your name, your date of birth, your gender, your weight, your height or your phone number, and Veltro has no field for any of them.
Your password is sent once over an encrypted connection and is stored only as a modern, salted, memory-hard hash (Argon2id). We cannot recover it, and we cannot see it.
We use your e-mail address solely to identify your account. We do not send you e-mail — there are no newsletters, no marketing and no product announcements. A consequence worth knowing: Veltro cannot yet reset a forgotten password, so keep it somewhere safe. A password reset by e-mail is planned, and this policy will be updated when it ships.
Encrypted sync — optional, and off until you turn it on
Sync is switched off by default. It starts only after you turn it on and confirm that you have written down your recovery code.
When it is on, this is what happens:
- Your phone generates a 256-bit encryption key. That key is stored wrapped by a key held in your device's hardware-backed keystore and never leaves your phone in usable form. The only way it can leave is as the recovery code you are shown once, which you write down yourself so you can restore your data on a new device.
- Each activity is encrypted on your phone with AES-256-GCM before upload.
- Only the sealed result is sent to our server, along with the bare minimum needed to keep your devices in step: a random record identifier, a "last changed" timestamp, a deleted flag, a key version, and the encryption nonce. No sport type, no distance, no device identifier and no activity timestamp travel outside the sealed data.
Our server stores the sealed data and hands it back to your other devices. We cannot decrypt it. If you lose your phone and your recovery code, neither we nor anyone else can recover your activities — that is the cost of end-to-end encryption, and it is deliberate.
One thing to be aware of before you switch sync on: it uploads your existing history, not just new activities. Everything already in your Veltro library is encrypted and queued for upload the first time you enable sync.
The detailed per-second track described above is excluded from sync and stays on the device.
Publishing to the feed — always your explicit choice
The social parts of Veltro — the feed, clubs, leaderboards — work on data you deliberately publish. That published data is not end-to-end encrypted, because other people have to be able to read it. There is no automatic sharing anywhere in Veltro: an activity is published only when you open the share sheet and confirm.
When you publish an activity, this is sent and stored on our server in readable form:
- the activity's sport type, title, start time, duration, distance, elevation gain, calories, total volume and set count, and its lap splits;
- your caption, if you write one;
- the route, but only if you leave the route option on;
- your social display name, which you choose and which is visible to anyone who can see the post.
You choose the audience for every post: Followers (only people who follow you) or Public (any signed-in Veltro user). You can also choose not to publish at all.
Route privacy. Veltro removes the parts of your route within 200 metres of where you started and where you finished, before anything is uploaded. This is on by default. Our server never receives the unblurred route from a published post. If a route is too short for that to leave anything meaningful, no route is published at all.
You can delete any post you made at any time; deleting it removes the published copy from our server. Deleting a post does not affect the copy on your own phone.
Other things you publish when you use the social features: comments (visible to anyone who can see the post), reactions, who you follow, the clubs you join, and the name and description of any club you create. Club leaderboards rank published public activities only — an activity you never published counts towards nothing.
Veltro has no photo or image upload anywhere. Profile pictures and club emblems are drawn from initials. Veltro also has no private messaging.
Health Connect
Veltro can read from and write to Android's Health Connect, so that your training is consistent across your health apps. Both directions are entirely under your control.
- Reading happens only when you open Veltro's import screen and choose which sessions to import. Veltro reads exercise sessions and their distance and calorie records. It never reads Health Connect in the background and holds no background-read permission.
- Writing happens only if you switch on "Sync to Health Connect", which is off by default. With it on, an activity you finish and save in Veltro is written back to Health Connect as an exercise session with its distance and calories.
How Health Connect data is used and not used. Data obtained from Health Connect is used only to show you your own training history inside Veltro and to keep your chosen health apps consistent. It is never used for advertising or marketing, never used for any kind of profiling, never sold, never shared with any third party, and never used to determine eligibility for insurance, employment or credit. A session you import becomes an ordinary Veltro activity: it stays on your phone, and it only ever leaves it by the two routes described above — inside encrypted sync if you turned it on, or in a post if you deliberately publish it.
If you withdraw Health Connect permissions, Veltro stops reading and writing immediately. Sessions you already imported remain in your own Veltro history on your phone until you delete them.
Heart-rate sensors
Veltro can connect to a Bluetooth heart-rate strap. Your heart rate is displayed live during an activity and used to compute an average and a maximum for that session.
Heart-rate readings are not saved. They are held in memory for the duration of the activity and discarded. No heart-rate value is written to Veltro's database, included in encrypted sync, published to the feed, or written to Health Connect. The only thing kept is the strap's Bluetooth address, on your phone, so it reconnects next time — and you can clear that from Settings.
Location
Recording a route requires precise location, and Veltro asks for it when you start an outdoor activity. Location is used for exactly two things: drawing and measuring your route, and showing your position on the map.
Veltro does not request background location. It records only while an activity is running, with a visible ongoing notification.
Maps
Veltro draws maps with MapLibre, an open-source mapping library, using OpenStreetMap data that is served from Veltro's own server. Loading a map therefore involves no third party: the request carries no account, no identifier and no activity data, and the server keeps nothing about it beyond the technical request details described under "Where data is stored".
Map data © OpenStreetMap contributors.
Exports and sharing to other apps
You can export an activity as a GPX file, and you can render a share card or a flyover video.
- GPX export writes a file into your device's public Downloads folder. The exported GPX contains your complete, unblurred route — it is your own data export, so the route-blur setting does not apply to it. Once the file is in Downloads, other apps on your phone may be able to read it.
- Share cards and flyover videos are rendered on your device and handed to Android's share sheet. When your route-blur setting is on, they use the same start/finish blur as published posts. Whatever you then send them to — a messaging app, a social network — is governed by that app's own privacy policy, not by this one.
None of these files are uploaded to Veltro.
Who we share data with
Nobody. Veltro shares no personal data with any third party. Specifically:
- there is no advertising SDK, no analytics SDK, no crash-reporting SDK and no attribution SDK in the app — not Firebase, not Crashlytics, not anything else;
- we do not sell, rent or trade personal data, to anyone, ever;
- we do not use your data to build advertising or behavioural profiles.
The only parties involved in running Veltro at all are Hetzner Online GmbH, which hosts our server in Germany and sees only what any internet host sees (encrypted traffic to the server, never readable activity data), and Google Play, which distributes the app and, if you use it, checks for updates and delivers optional sport modules under Google's own terms. Neither receives your activity data in readable form.
Other Veltro users see exactly what you publish, and nothing else.
Where data is stored
Veltro's server runs on a rented virtual server operated by Hetzner Online GmbH, located in Germany (European Union), with an encrypted connection between the app and the server at all times.
The server records only the technical details of each request — the method, the path, the response status and how long it took. It does not log request contents, and it does not log your IP address. Your IP address is used momentarily, in memory, to apply rate limits, and is not written down.
How long data is kept
- On your phone: until you delete the activity or uninstall Veltro.
- On our server: encrypted sync data and published posts are kept until you delete them or delete your account.
- Backups: encrypted database backups are kept for 14 days and then destroyed. Data you have deleted disappears from backups as those backups age out.
- Session refresh tokens expire after 30 days of disuse and are removed when you sign out.
Deleting your data
- A single activity: delete it in the app. If sync is on, the deletion is propagated and the server copy is removed.
- A published post: delete the post. The published copy is removed from our server.
- Everything on the device: sign out (which wipes the local library and your keys) or uninstall Veltro.
- Your whole account: in the app, go to Settings → Account → Delete account and confirm with your password. This permanently removes your account record, every piece of encrypted activity data we hold for you, your social profile and display name, your posts, comments and reactions, who you follow and who follows you, your club memberships and your challenge participations. Nothing of yours is kept behind, and every signed-in device is signed out.
- If you cannot use the app, follow the steps at veltro.fit/delete-account or write to hello@veltro.fit from the address on the account, and we will delete it. We respond within 30 days.
Deletion is permanent and cannot be undone. Because activity data is end-to-end encrypted, we cannot hand you a readable copy of it from the server — your own device holds the readable copy, and you can export activities as GPX files at any time.
Your rights
Depending on where you live you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to how it is used, and to receive it in a portable form. You may also have the right to complain to your local data-protection authority.
To exercise any of these, write to hello@veltro.fit. We do not charge for this and we respond within 30 days.
In practice most of these rights are already in your hands: the readable copy of your training data lives on your own device, you can export it yourself, and you can delete any part of it or all of it from within the app.
Where a legal basis is required, ours is: performance of a contract for running your account and delivering the features you turn on; your consent for optional features such as encrypted sync, publishing to the feed and Health Connect access, which you can withdraw at any time by switching the feature off; and legitimate interests for keeping the service secure and available, such as rate limiting.
Children
Veltro is not intended for children under 13, and we do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has created an account, write to hello@veltro.fit and we will delete it.
Veltro includes a public social feed with user-written content, so it is not suitable for young children.
Security
- All communication between the app and our server uses HTTPS; the app does not permit unencrypted connections.
- Passwords are stored only as Argon2id hashes; sign-in refresh tokens are stored only as hashes and rotate on every use, with reuse detection that invalidates the whole session.
- Activity data sent to our server is encrypted end-to-end on your device with AES-256-GCM, using a key that never leaves your phone in usable form.
- On your device, sign-in tokens and the encryption key are sealed by a hardware-backed keystore key.
No system is perfectly secure, but the design goal is that a breach of our server exposes sealed data that nobody can read.
Reporting content
If you see a post or a comment that breaks the rules you can report it from within the app. Reports come to us for manual review. There is no automated moderation, and we look at reports ourselves.
Changes to this policy
If this policy changes materially we will update the date at the top and note the change in the app's release notes. Continuing to use Veltro after a change means you accept the updated policy. Past versions are available on request.