Back to Vertical

Privacy Policy

Last updated: July 23, 2026

1. Introduction

Seru Works Limited (company number 16861273, registered at 128 City Road, London, United Kingdom, EC1V 2NX) ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Vertical, our AI-powered running coach mobile application (package name ai.getvertical.mobile on Google Play, bundle identifier ai.getvertical.mobile on the App Store) and related website at www.getvertical.ai (collectively, the "Service"). Please read this privacy policy carefully.

2. Information We Collect

Personal Information

We collect information that you provide directly to us, including:

  • Name and email address
  • Account credentials
  • Profile information (age, gender, fitness goals)
  • Payment information (processed securely by third-party providers)

Fitness and Health Data

With your consent, we collect fitness and health-related information, including:

  • Workout data (duration, distance, heart rate, pace)
  • Training metrics and performance analytics
  • Data from connected fitness devices and apps (e.g., Garmin, Strava)
  • Goals and preferences

Automatically Collected Information

When you use our Service, we automatically collect certain information, including:

  • Device information (type, operating system)
  • Usage data (features used, time spent)
  • Log data (IP address, browser type)

Mobile App Permissions

The Vertical mobile app requests the following device permissions. Each permission is requested only when the corresponding feature is used and can be revoked at any time from your device settings.

  • Microphone (Android & iOS): Used to let you dictate messages to your AI running coach by voice instead of typing. Speech-to-text is performed by your device's operating system Apple's Speech framework on iOS, Google's speech recognition service on Android which may process audio on Apple's or Google's servers to produce a transcript. We do not receive or store raw audio; only the resulting text transcript is sent to our servers, where it is handled like any other chat message (see Section 5).
  • Push notifications (Android & iOS): Used to send you training plan reminders, coaching insights, and workout completion notifications. Required only if you opt in.
  • Camera and photo library (iOS only): Used to let you select or capture a profile photo. Camera and photo library access are blocked on Android.

We do not collect precise or coarse location data, contacts, call logs, SMS, or installed-application data. We do not use Android Health Connect or Google Fit.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our Service
  • Generate personalized training plans and recommendations
  • Analyze your fitness progress and performance
  • Send you technical notices, updates, and support messages
  • Respond to your comments and questions
  • Detect, prevent, and address technical issues and security
  • Comply with legal obligations

4. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

  • With your consent: When you authorize us to share information with third parties
  • Service providers: With vendors who perform services on our behalf:
    • AI / coaching processing: Google, OpenAI, and other AI model providers routed via OpenRouter (see Section 5)
    • Fitness data: Terra, for connecting COROS, Suunto, and Polar (see Section 10)
    • Payments: Stripe, RevenueCat
    • Email: Resend
    • Push notifications: Expo (relays to Apple APNs / Google FCM)
    • Product analytics: PostHog
    • Error monitoring: Sentry
    • Hosting and infrastructure: Hetzner (servers), Cloudflare (CDN, DNS, and object storage)
  • Third-party integrations: When you connect your account to fitness tracking services
  • Legal requirements: When required by law or to protect our rights
  • Business transfers: In connection with a merger, acquisition, or sale of assets

5. AI Coaching and Third-Party Language Model Providers

Vertical uses large language models ("LLMs") to generate personalized coaching responses, training plan adjustments, and workout analysis. To do so, we transmit relevant portions of your conversation history, training data, and goals to third-party LLM providers who process the data on our behalf.

Providers we currently use:

  • Google (Gemini API): Primary provider for coaching conversations and workout generation, subject to Google's Privacy Policy.
  • OpenAI: Used to generate vector embeddings of coaching-relevant facts (e.g. goals, preferences, and recurring themes from your conversations) so we can retrieve relevant context in future conversations. Subject to OpenAI's Privacy Policy.
  • OpenRouter: Used to route selected coaching, workout-translation, and analysis tasks to a panel of underlying AI model providers. The specific providers in this panel may change over time as we adopt new models; all routing is subject to OpenRouter's privacy policy. Some underlying providers may be based outside the UK/EEA/US; where this applies, we rely on OpenRouter's contractual safeguards for the international transfer of your data.

How your data is used by these providers:

  • Providers process your data solely to generate the response we request on your behalf.
  • Under the contractual terms we rely on with each provider, your data is not used to train or improve their foundation models.
  • Providers may retain inputs and outputs for a limited period (typically up to 30 days) solely for abuse monitoring and service reliability, after which the data is deleted on their side.
  • We do not authorize these providers to sell your data or share it with any additional third parties.

Voice input: If you dictate a message to your coach, speech-to-text conversion happens on your device via the operating system's built-in speech recognition (see Section 2). We do not operate, and do not send your audio to, any separate voice-call or text-to-speech infrastructure.

Engineering access to development data: Our engineers use AI-assisted coding tools, including Anthropic's Claude and OpenAI's tools, in local development. When troubleshooting, engineers may work against an isolated, temporary copy of production data (see Section 7). In that scenario, portions of that data may be processed by Anthropic or OpenAI as part of an engineering session, subject to Anthropic's and OpenAI's privacy policies. This is separate from, and unrelated to, the AI coaching providers above, which process every user's live conversations as part of the Service.

You can review and delete any AI coaching conversation from within the app. All conversation history stored on our servers is permanently deleted within 30 days of account deletion (see Section 8).

6. Data Security

We implement appropriate technical and organizational measures to protect your personal information. However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.

7. Data Retention

We retain different categories of your data for specific periods:

  • Account information (name, email, profile): Retained for the lifetime of your account and deleted within 30 days of account deletion.
  • Workout and fitness data (activities, training metrics, performance history): Retained for the lifetime of your account. Deleted within 30 days of account deletion or integration disconnection.
  • Third-party integration data (data synced from Strava, Garmin, etc.): Cached for no longer than 7 days. Activity data incorporated into your coaching history is retained while your account is active and deleted within 48 hours of disconnecting the integration, or within 30 days of account deletion.
  • Automatically collected data (device info, usage data, log data): Retained for up to 12 months for analytics and security purposes, then automatically deleted.
  • AI coaching conversations: Retained for the lifetime of your account. Deleted within 30 days of account deletion.
  • Payment records: Retained as required by applicable tax and financial regulations (typically 7 years), even after account deletion.

After the applicable retention period, data is permanently deleted from our active systems and backups within 30 days.

8. How to Delete Your Data

You can request deletion of your data in the following ways:

  • From the app: Go to Settings and tap "Delete account". This opens a pre-filled email to our support team. We will permanently delete your account and all associated data within 30 days.
  • Email us directly: Send a deletion request to support@getvertical.ai from the email address associated with your account. We will process your request within 30 days and confirm deletion via email.
  • Disconnect integrations: Go to Settings > Integrations to disconnect any third-party fitness service. Data from that service will be deleted within 48 hours.

Upon account deletion, we permanently remove all your personal information, workout data, coaching conversations, and fitness analytics. The only exceptions are payment records required by law and anonymized, aggregated data that cannot be linked back to you.

9. Your Rights

Depending on your location, you may have certain rights regarding your personal information:

  • Access and receive a copy of your personal information
  • Correct inaccurate or incomplete information
  • Delete your personal information
  • Object to or restrict certain processing of your information
  • Data portability
  • Withdraw consent at any time

To exercise any of these rights, contact us at legal@getvertical.ai. We will respond to your request within 30 days.

10. Third-Party Fitness Services

Our Service integrates with third-party fitness platforms including Strava, Garmin Connect, COROS, Suunto, and Polar. When you connect one of these services, we access your data with your explicit authorization directly through Strava's and Garmin's official APIs, and via Terra for COROS, Suunto, and Polar (see below).

Strava Integration

When you connect your Strava account via OAuth 2.0, we request the following scopes:

  • read, activity:read_all: To import your activity data (distance, duration, pace, heart rate, elevation) for personalized coaching feedback
  • profile:read_all: To identify your account and display your athlete profile
  • activity:write: To post a brief coaching insight to your Strava activity description after each synced workout (e.g., pacing analysis, aerobic efficiency trends)

Data we write to Strava: With your authorization, we may attach a post-workout summary card image to your Strava activities (via Media Enrichment) and append a short coaching insight to the activity description. This content is generated from your own training data and is visible to you and your Strava followers according to your Strava privacy settings. You can disable this at any time from Settings > Integrations.

How we use Strava data: Your activity data is used exclusively to provide you with personalized coaching insights, training plan adjustments, and performance analysis. We display your Strava activity data only to you within your own account.

What we do not do with Strava data:

  • We do not use Strava data for model training related to artificial intelligence, machine learning, or similar applications
  • We do not sell, license, or share Strava data with third parties
  • We do not use Strava data for targeted advertising
  • We do not aggregate or anonymize Strava data for analytics purposes

Disconnecting and data deletion: You can disconnect your Strava account at any time from Settings > Integrations. When you disconnect, or if you revoke access from Strava's side, we delete all Strava-sourced data from our systems within 48 hours. You may also request immediate deletion by contacting us at support@getvertical.ai.

Data retention: Strava activity data is cached for no longer than seven days. Activity data that has been incorporated into your coaching history is retained only for as long as necessary to provide the Service, and is deleted upon account disconnection or deletion.

Third-party data collection: Strava may collect usage data about your interactions with our application. Please refer to Strava's Privacy Policy for details on their data practices.

Garmin Connect

We connect directly to Garmin's official API with your explicit authorization. Similar principles to the Strava section above apply: we access only the data you authorize, use it solely for your personalized coaching, and delete it when you disconnect.

Other Fitness Services (via Terra)

For COROS, Suunto, and Polar, we do not connect to those providers directly. Instead, we use Terra, a fitness-data aggregator, as an intermediary: Terra connects to these services on your behalf and relays your activity data to us. The same data-handling principles as above apply we access only the data you authorize, use it solely for your personalized coaching, and delete it when you disconnect. Our Service may also contain links to third-party websites. We are not responsible for the privacy practices of these third parties and encourage you to read their privacy policies.

11. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.

13. Contact Us

If you have any questions about this Privacy Policy, please contact us at:

Seru Works Limited
Company Number: 16861273
128 City Road, London, United Kingdom, EC1V 2NX
Email: legal@getvertical.ai