Veltro — Privacy Policy

Last updated: 2026-09-11

Veltro is a multi-sport activity tracker for Android. It is built so that your training data stays yours: everything is recorded and kept on your own phone, and nothing is sent anywhere unless you turn a feature on.

This policy explains, in plain terms, what Veltro does with your information.

Who we are

Veltro is developed and operated by Frederik Duvač (publishing as RikoAppDev).

For anything about this policy or about your data, write to hello@veltro.fit.

Frederik Duvač is the controller of the personal data described below.

The short version

What Veltro stores on your phone

All of this stays on your device unless a section below says otherwise:

Uninstalling Veltro removes all of it from the phone. Veltro also opts out of Android's automatic cloud backup and device-to-device transfer, so your activity database is never copied into a Google backup. To move your data to a new phone, use encrypted sync with your recovery code, or export your activities as GPX files.

Creating an account

An account is optional. You only need one for encrypted sync, the social feed and clubs.

To create one we ask for an e-mail address and a password. That is all — we do not ask for your name, your date of birth, your gender, your weight, your height or your phone number, and Veltro has no field for any of them.

Your password is sent once over an encrypted connection and is stored only as a modern, salted, memory-hard hash (Argon2id). We cannot recover it, and we cannot see it.

We use your e-mail address solely to identify your account. We do not send you e-mail — there are no newsletters, no marketing and no product announcements. A consequence worth knowing: Veltro cannot yet reset a forgotten password, so keep it somewhere safe. A password reset by e-mail is planned, and this policy will be updated when it ships.

Encrypted sync — optional, and off until you turn it on

Sync is switched off by default. It starts only after you turn it on and confirm that you have written down your recovery code.

When it is on, this is what happens:

  1. Your phone generates a 256-bit encryption key. That key is stored wrapped by a key held in your device's hardware-backed keystore and never leaves your phone in usable form. The only way it can leave is as the recovery code you are shown once, which you write down yourself so you can restore your data on a new device.
  2. Each activity is encrypted on your phone with AES-256-GCM before upload.
  3. Only the sealed result is sent to our server, along with the bare minimum needed to keep your devices in step: a random record identifier, a "last changed" timestamp, a deleted flag, a key version, and the encryption nonce. No sport type, no distance, no device identifier and no activity timestamp travel outside the sealed data.

Our server stores the sealed data and hands it back to your other devices. We cannot decrypt it. If you lose your phone and your recovery code, neither we nor anyone else can recover your activities — that is the cost of end-to-end encryption, and it is deliberate.

One thing to be aware of before you switch sync on: it uploads your existing history, not just new activities. Everything already in your Veltro library is encrypted and queued for upload the first time you enable sync.

The detailed per-second track described above is excluded from sync and stays on the device.

Publishing to the feed — always your explicit choice

The social parts of Veltro — the feed, clubs, leaderboards — work on data you deliberately publish. That published data is not end-to-end encrypted, because other people have to be able to read it. There is no automatic sharing anywhere in Veltro: an activity is published only when you open the share sheet and confirm.

When you publish an activity, this is sent and stored on our server in readable form:

You choose the audience for every post: Followers (only people who follow you) or Public (any signed-in Veltro user). You can also choose not to publish at all.

Route privacy. Veltro removes the parts of your route within 200 metres of where you started and where you finished, before anything is uploaded. This is on by default. Our server never receives the unblurred route from a published post. If a route is too short for that to leave anything meaningful, no route is published at all.

You can delete any post you made at any time; deleting it removes the published copy from our server. Deleting a post does not affect the copy on your own phone.

Other things you publish when you use the social features: comments (visible to anyone who can see the post), reactions, who you follow, the clubs you join, and the name and description of any club you create. Club leaderboards rank published public activities only — an activity you never published counts towards nothing.

Veltro has no photo or image upload anywhere. Profile pictures and club emblems are drawn from initials. Veltro also has no private messaging.

Health Connect

Veltro can read from and write to Android's Health Connect, so that your training is consistent across your health apps. Both directions are entirely under your control.

How Health Connect data is used and not used. Data obtained from Health Connect is used only to show you your own training history inside Veltro and to keep your chosen health apps consistent. It is never used for advertising or marketing, never used for any kind of profiling, never sold, never shared with any third party, and never used to determine eligibility for insurance, employment or credit. A session you import becomes an ordinary Veltro activity: it stays on your phone, and it only ever leaves it by the two routes described above — inside encrypted sync if you turned it on, or in a post if you deliberately publish it.

If you withdraw Health Connect permissions, Veltro stops reading and writing immediately. Sessions you already imported remain in your own Veltro history on your phone until you delete them.

Heart-rate sensors

Veltro can connect to a Bluetooth heart-rate strap. Your heart rate is displayed live during an activity and used to compute an average and a maximum for that session.

Heart-rate readings are not saved. They are held in memory for the duration of the activity and discarded. No heart-rate value is written to Veltro's database, included in encrypted sync, published to the feed, or written to Health Connect. The only thing kept is the strap's Bluetooth address, on your phone, so it reconnects next time — and you can clear that from Settings.

Location

Recording a route requires precise location, and Veltro asks for it when you start an outdoor activity. Location is used for exactly two things: drawing and measuring your route, and showing your position on the map.

Veltro does not request background location. It records only while an activity is running, with a visible ongoing notification.

Maps

Veltro draws maps with MapLibre, an open-source mapping library, using OpenStreetMap data that is served from Veltro's own server. Loading a map therefore involves no third party: the request carries no account, no identifier and no activity data, and the server keeps nothing about it beyond the technical request details described under "Where data is stored".

Map data © OpenStreetMap contributors.

Exports and sharing to other apps

You can export an activity as a GPX file, and you can render a share card or a flyover video.

None of these files are uploaded to Veltro.

Who we share data with

Nobody. Veltro shares no personal data with any third party. Specifically:

The only parties involved in running Veltro at all are Hetzner Online GmbH, which hosts our server in Germany and sees only what any internet host sees (encrypted traffic to the server, never readable activity data), and Google Play, which distributes the app and, if you use it, checks for updates and delivers optional sport modules under Google's own terms. Neither receives your activity data in readable form.

Other Veltro users see exactly what you publish, and nothing else.

Where data is stored

Veltro's server runs on a rented virtual server operated by Hetzner Online GmbH, located in Germany (European Union), with an encrypted connection between the app and the server at all times.

The server records only the technical details of each request — the method, the path, the response status and how long it took. It does not log request contents, and it does not log your IP address. Your IP address is used momentarily, in memory, to apply rate limits, and is not written down.

How long data is kept

Deleting your data

Deletion is permanent and cannot be undone. Because activity data is end-to-end encrypted, we cannot hand you a readable copy of it from the server — your own device holds the readable copy, and you can export activities as GPX files at any time.

Your rights

Depending on where you live you may have the right to access the personal data we hold about you, to correct it, to have it deleted, to restrict or object to how it is used, and to receive it in a portable form. You may also have the right to complain to your local data-protection authority.

To exercise any of these, write to hello@veltro.fit. We do not charge for this and we respond within 30 days.

In practice most of these rights are already in your hands: the readable copy of your training data lives on your own device, you can export it yourself, and you can delete any part of it or all of it from within the app.

Where a legal basis is required, ours is: performance of a contract for running your account and delivering the features you turn on; your consent for optional features such as encrypted sync, publishing to the feed and Health Connect access, which you can withdraw at any time by switching the feature off; and legitimate interests for keeping the service secure and available, such as rate limiting.

Children

Veltro is not intended for children under 13, and we do not knowingly collect personal data from anyone under 13. If you believe a child under 13 has created an account, write to hello@veltro.fit and we will delete it.

Veltro includes a public social feed with user-written content, so it is not suitable for young children.

Security

No system is perfectly secure, but the design goal is that a breach of our server exposes sealed data that nobody can read.

Reporting content

If you see a post or a comment that breaks the rules you can report it from within the app. Reports come to us for manual review. There is no automated moderation, and we look at reports ourselves.

Changes to this policy

If this policy changes materially we will update the date at the top and note the change in the app's release notes. Continuing to use Veltro after a change means you accept the updated policy. Past versions are available on request.

Contact

hello@veltro.fit