1. Controller
The controller responsible for the processing of personal data in connection with Vey is:
Richard Fugger
Arbeiterheimstraße 33
4662 Laakirchen
Austria
Email: support@veydarts.com
Additional legal and contact information is available in the Imprint.
2. Scope of this Privacy Policy
This Privacy Policy applies to:
- The website available at veydarts.com
- The Vey Android application
- Optional Vey user accounts and cloud synchronization
- Transactional and security-related emails
- Support and account-deletion requests
- Vey Premium purchases, subscriptions and entitlement management
Vey does not sell personal data and does not use personal data for third-party advertising.
3. Visiting the Vey website
The Vey website is hosted through GitHub Pages. When the website is accessed, technical request information may be processed by the hosting provider in order to deliver and secure the website.
This information may include:
- IP address
- Date and time of the request
- Requested page or file
- Browser and device information
- Referrer information
- Technical error and security information
The processing is necessary for the secure, stable and efficient provision of the website. The legal basis is our legitimate interest pursuant to Article 6(1)(f) GDPR.
Our legitimate interests include providing the website, preventing misuse, maintaining security and diagnosing technical problems.
Cookies, analytics and security technologies
Vey does not currently use general-purpose website analytics, advertising trackers, marketing pixels or optional marketing cookies.
Vey does not create advertising profiles and does not track visitors across unrelated websites.
Security-related technologies may nevertheless process technical information that is necessary to deliver and protect the website. In particular, the support page uses Cloudflare Turnstile to detect automated abuse. Security metrics generated by Turnstile are used for security and abuse prevention rather than advertising or behavioural profiling. Further details are provided below.
4. Using Vey without an account
Vey can be used without creating or linking a user account.
When Vey is used without an account, training and app data is stored locally on the user's device and is not synchronized with Supabase.
Locally stored information may include:
- Training plans and scheduled sessions
- Completed training sessions
- Scores, results and performance values
- Assessment results
- Progress history and locally calculated statistics
- Training preferences and configuration
- Theme settings
- Onboarding status
- Local profile and synchronization metadata
The progress and performance analytics shown inside Vey are calculated from the user's training data. These calculations are product functionality and are not external user tracking.
When no account is connected, the training and profile information described above remains on the device under the user's control. It may be removed through applicable in-app functions, by clearing the app's storage or by uninstalling the app, subject to the device and operating system's storage and backup behaviour.
On Android, the RevenueCat subscription SDK is initialized when the app starts, including when no Vey account is connected. In that situation RevenueCat may assign an anonymous App User ID and process limited technical information needed to operate the subscription infrastructure. Purchasing and restoring Vey Premium are only available after signing in to a Vey account. Further details are provided in section 10 below.
5. User accounts and cloud synchronization
Users may optionally create or link a Vey account. Account and cloud features are provided through Supabase.
When an account is used, the following categories of data may be processed:
- Email address
- Authentication and account identifiers
- Display name
- Theme setting
- Onboarding status
- Profile and synchronization metadata
- Versions and timestamps relating to the acceptance of the Terms of Use and Privacy Policy
- Training plans and completed sessions
- Scores, results and performance history
- Assessment results
- Training settings and preferences
Training data is first stored locally. When an authenticated account is connected and cloud synchronization is available, the relevant information is additionally synchronized with Supabase.
Cloud synchronization enables users to retain and access their Vey information in connection with their account and supports account-related app functionality.
The legal basis for account creation, authentication and cloud synchronization is Article 6(1)(b) GDPR, as the processing is necessary to provide the account and synchronization features requested by the user.
Password authentication is handled through Supabase Auth. Passwords are not stored by Vey in readable plain text.
When an authenticated user uses the subscription functionality, the Vey account's Supabase user ID is also used as the RevenueCat App User ID. This links Premium entitlement status to the signed-in Vey account. Vey does not send the user's email address, display name, telephone number or other custom customer attributes to RevenueCat.
6. Authentication and security emails
Vey sends transactional emails for account-related purposes, including:
- Email-address confirmation
- Password-reset requests
- Password-change security notifications
- Other necessary account-security messages
Supabase initiates these messages and Resend provides the email delivery infrastructure.
The following information may be processed for this purpose:
- Recipient email address
- Message content
- Delivery time and status
- Technical delivery and error information
- Security and anti-abuse information
Account and password-recovery emails are processed on the basis of Article 6(1)(b) GDPR. Security notifications and abuse prevention may additionally be based on our legitimate interests under Article 6(1)(f) GDPR.
Vey does not use authentication emails for advertising or newsletter marketing.
7. Local training reminders
Vey may provide optional local training reminders. Where this feature is available, reminders are enabled and configured by the user.
The selected reminder information is stored and processed locally on the device. The operating system may request permission before notifications can be displayed.
Vey does not currently use a server-based push-notification service and does not transfer push tokens to an external notification provider.
Users can disable reminders at any time inside Vey or through their device notification settings.
8. Support and contact requests
Users can contact Vey directly by email or through the contact form on the Support page. The information provided is processed in order to respond to and manage the request.
Depending on the contact method and the information provided by the user, this may include:
- Name, where voluntarily provided
- Email address and sender information
- Subject and message content
- Account information voluntarily provided by the user
- Device, app-version and technical information
- Attachments such as screenshots when sent by email
- Communication history
Contact form and anti-abuse protection
The contact form is protected by Cloudflare Turnstile. Turnstile is loaded on the Support page and evaluates technical and browser-related signals in order to distinguish legitimate users from automated or abusive traffic. According to Cloudflare, these signals may include the IP address, TLS fingerprint, user-agent information, the Turnstile site key and the associated origin, as well as other security-related browser signals.
The legal basis for this security processing is Article 6(1)(f) GDPR. Vey has a legitimate interest in protecting the contact form, email infrastructure and website against spam, automated abuse and malicious submissions.
When the form is submitted, the request is sent to a Cloudflare Worker. The Worker validates the request, verifies the Turnstile token and applies technical rate limits before an email is sent. The request IP address may be used temporarily as a security and rate-limit key and may be provided to Cloudflare for Turnstile verification. Vey does not store the request IP address in its D1 contact-form database.
A Cloudflare D1 database is used only for a global daily send counter that limits contact-form abuse. The D1 database is configured to the European Union jurisdiction. The counter stores only a calendar date and the number of reserved contact-form sends; it does not contain the user's name, email address, IP address, subject or message content.
Contact-form email delivery
After the security checks have succeeded, Brevo provides the transactional email-delivery infrastructure for the contact form. For this purpose, the information entered into the form, including the user's email address, optional name, subject and message, is processed as necessary to create and deliver the support email.
Brevo transactional logs are configured to be automatically deleted after one month. Email previews are configured not to be stored for new transactional emails. Brevo may nevertheless process delivery metadata as required to provide, secure and troubleshoot the email-delivery service.
The support address is forwarded through Porkbun to a Google Gmail inbox. Porkbun and Google may therefore process email metadata and message content for forwarding, delivery, spam prevention, storage and security. Direct emails sent to support@veydarts.com are also delivered through this forwarding setup.
Support processing is based on Article 6(1)(b) GDPR where it is necessary to respond to a request concerning the app, an account or another service requested by the user. General enquiries, security investigations and abuse prevention may be processed on the basis of Article 6(1)(f) GDPR.
The contact form and support email address are not used to subscribe users to advertising or newsletter marketing. Users should never send passwords, authentication codes or other secret credentials through the contact form or by email.
9. Analytics, crash reporting and advertising
Vey currently does not integrate general-purpose behavioural analytics or advertising technologies such as:
- External behavioural user-analytics SDKs
- Advertising SDKs
- Cross-app tracking services
- Firebase Analytics
- Firebase Crashlytics
- Sentry or another external crash-reporting service
Cloudflare Turnstile provides security-related challenge and validation metrics for the contact form. These metrics are used to protect the form against automated abuse and are not used by Vey for advertising or behavioural user profiling.
Performance analytics visible inside the app are generated from the user's own training data and are used to provide the requested training and progress functionality.
RevenueCat is used specifically for subscription processing, entitlement management and subscription-related operational information. It is not used by Vey for advertising, cross-app tracking or general behavioural profiling. The related processing is described in section 10.
If additional analytics, crash reporting, advertising or other external tracking technologies are introduced in the future, this Privacy Policy and, where required, the user's consent choices will be updated before those technologies are used.
10. Purchases and subscriptions
Vey offers optional Vey Premium subscriptions on Android. Monthly and annual subscription options may be offered through Google Play. Eligible users may also be shown a seven-day free trial for the annual subscription. The price, trial eligibility, billing period and other purchase terms shown by Google Play before confirmation are authoritative for the individual transaction.
Google Play handles the payment transaction. Vey uses RevenueCat, Inc. to validate purchases, determine subscription and entitlement status, support purchase restoration and provide the Premium access associated with the signed-in Vey account.
For these purposes, RevenueCat may process information including:
- An anonymous RevenueCat App User ID when no Vey account is signed in
- The signed-in Vey account's Supabase user ID as the RevenueCat App User ID
- Device type, operating system and similar technical information
- Product and offering identifiers
- Purchase, renewal, cancellation, expiration and entitlement status
- Transaction timing and subscription-period information
- Price and currency information made available through the store
- Google Play purchase tokens and related transaction information
Vey does not send the user's email address, display name or telephone number to RevenueCat and does not manually collect an advertising ID or other hardware identifier for RevenueCat. Vey does not receive complete payment-card details from Google Play or RevenueCat.
Vey does not persist Google Play purchase tokens, transaction IDs or receipts in its own Supabase database. Subscription state and product information used by the app are held as necessary to provide the current app experience, while the underlying purchase and entitlement records are handled by Google Play and RevenueCat.
Premium access is linked to the signed-in Vey account. RevenueCat is configured to keep purchases with the original identified App User ID. A purchase associated with one Vey account is therefore not transferred to another existing Vey account merely because both accounts are used on the same device or because Restore Purchases is selected from the second account.
Where subscription processing is requested or an active Premium entitlement is provided, the primary legal basis is Article 6(1)(b) GDPR. Limited technical processing associated with SDK initialization, security, fraud prevention, troubleshooting and the reliable operation of the subscription infrastructure may be based on our legitimate interests under Article 6(1)(f) GDPR.
11. Google Play distribution and billing
When Vey is downloaded, updated or subscribed to through Google Play, Google independently processes information relating to the user's Google account, device, app installation, purchase, payment method, subscription and billing activity.
This processing is governed by Google's own terms and privacy information. Google Play determines purchase eligibility, local prices, applicable taxes, trial eligibility, billing and refund handling. Vey does not receive the user's Google-account password or complete payment-card details.
12. Service providers and recipients
Vey uses the following principal service providers:
GitHub Pages
GitHub, Inc. provides the hosting and delivery infrastructure for the Vey website and may process technical visitor and security information.
Supabase
Supabase provides authentication, account management, database and cloud-synchronization infrastructure.
Resend
Resend, operated by Plus Five Five, Inc., provides delivery infrastructure for transactional authentication and security emails.
Cloudflare
Cloudflare provides Turnstile bot protection, the contact-form Worker, rate-limiting infrastructure and the D1 database used for the non-personal daily send counter. Turnstile processes technical browser and network signals for bot detection. Cloudflare also states that it may process Turnstile signals as an independent controller to improve its bot-detection capabilities.
Cloudflare Privacy Policy
Cloudflare Turnstile Privacy Addendum
Brevo
Brevo provides transactional email-delivery infrastructure for messages submitted through the Vey contact form. Brevo states that the hosting servers on which it processes and stores its databases are located within the European Union.
Brevo privacy and data-protection information
Porkbun
Porkbun LLC provides domain infrastructure and email forwarding for the support address.
RevenueCat
RevenueCat, Inc. provides subscription validation, entitlement management, purchase restoration and subscription-related operational infrastructure for Vey Premium. RevenueCat may process the App User ID, technical device information and Google Play transaction information described in section 10.
Google provides the Gmail inbox used to receive and manage forwarded support messages. Google also operates Google Play, through which the Android app is distributed and Vey Premium subscriptions are purchased and managed.
Personal data may also be disclosed where required by law, court order or a valid request from a competent public authority.
13. International data transfers
Some service providers or their subprocessors are located outside Austria or the European Economic Area. Personal data may therefore be processed in countries including the United States and Singapore.
Where required, such transfers are based on appropriate safeguards under Chapter V GDPR, such as:
- European Commission adequacy decisions
- The EU-US Data Privacy Framework where the recipient is appropriately certified
- European Commission Standard Contractual Clauses
- Supplementary contractual, organisational or technical safeguards
The safeguards applicable to a particular provider may depend on the provider, processing activity and location involved.
14. Data retention
Local app data
Locally stored app data remains on the device until it is deleted through the app, the app storage is cleared, the app is uninstalled or the operating system removes the information.
Account and synchronized data
Account and synchronized data is generally retained while the Vey account remains active and while it is necessary to provide the requested cloud and synchronization features.
When an account is deleted, associated personal data will be deleted or anonymized unless limited retention is required by law, necessary for security, fraud prevention, dispute resolution or the establishment, exercise or defence of legal claims.
Subscription and purchase information
RevenueCat subscription information is retained for as long as it is necessary to provide and administer the account-linked Premium entitlement. As part of a successful Vey account deletion, Vey requests deletion of the RevenueCat customer associated with that Vey account.
Deleting the RevenueCat customer does not cancel an active Google Play subscription. Google may retain purchase, payment, tax, fraud prevention and transaction records independently in accordance with its own policies and legal obligations.
Email delivery information
Transactional authentication and security email data processed through Resend is generally retained by Resend for 30 days. Resend may retain certain information for longer where required for legal obligations, dispute resolution, security or enforcement of its agreements.
Support correspondence and contact-form delivery
Support messages received in the support inbox are retained for as long as necessary to process the request and, where required, to document the communication, protect account security or establish, exercise or defend legal claims.
For contact-form emails, Brevo transactional logs are configured for automatic deletion after one month and new email previews are configured not to be stored. The Cloudflare D1 abuse-prevention counter contains only the date and a send count and does not store the submitted contact details or message content.
Technical website logs
Technical website logs are retained by the hosting provider in accordance with its applicable security and retention practices.
15. Account and data deletion
Users can request deletion of their Vey account and associated cloud data through the app or through the Account Deletion page .
Deleting the app from a device does not by itself delete a connected cloud account or synchronized cloud data. It also does not cancel a Google Play subscription.
A successful Vey account deletion also deletes the corresponding RevenueCat customer record used by Vey. It does not cancel the underlying Google Play subscription. Users with an active subscription should manage or cancel it in Google Play before deleting their Vey account. Premium access in Vey ends when the account deletion is completed because Premium access requires an authenticated Vey account.
Vey may request reasonable verification before processing an account-deletion or data-rights request in order to protect the account from unauthorized deletion.
16. Data-protection rights
Subject to the requirements and limitations of applicable law, data subjects may have the following rights:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time where processing is based on consent
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Requests can be sent to support@veydarts.com .
We may request information necessary to verify the identity of the person making the request.
Right to lodge a complaint
Data subjects also have the right to lodge a complaint with a competent data-protection supervisory authority.
The Austrian supervisory authority is:
Austrian Data Protection Authority
Barichgasse 40–42
1030 Vienna
Austria
Email:
dsb@dsb.gv.at
Austrian Data Protection Authority website
17. Automated decision-making
Vey does not currently make decisions based solely on automated processing that produce legal effects or similarly significantly affect users.
Training statistics, assessments and progress indicators are calculated to provide training feedback. They are not used for credit decisions, employment decisions, insurance decisions or comparable legally significant purposes.
18. Data security
Reasonable technical and organisational measures are used to protect personal data against accidental or unlawful loss, alteration, disclosure or unauthorized access.
These measures may include encrypted network connections, authentication controls, access restrictions, database-security rules and security features provided by the relevant service providers.
No internet-based service can guarantee absolute security. Users should protect their account credentials, use a strong password and never share password-reset links or verification codes.
19. Changes to this Privacy Policy
This Privacy Policy may be updated when Vey's functionality, service providers, legal requirements or data-processing activities change.
The current version will be published on this page. Material changes may additionally be communicated inside the app or through another appropriate channel.
20. Contact
Questions about this Privacy Policy or the processing of personal data can be sent to: