Last updated: July 20, 2026
This Privacy Policy describes how Vrtl Pirates LLC ("we," "us," or "our") collects, uses, shares, and protects information when you use GURV, an iMessage-native AI fitness, nutrition, and supplement tracker (the "Service"). GURV consists of (a) an iMessage-based interface through which you log workouts, meals, and supplements by texting a designated phone number, and (b) a native iOS application that displays your fitness data, patterns, and insights.
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, do not use the Service.
Account Information
Body and Profile Information
iMessage Content
Payment Information
Workout Data. Exercises, weights, repetitions, sets, split day, and workout date -- parsed by AI from the text messages you send.
Meal and Nutrition Data. Food items, quantities, estimated calories, macronutrients (protein, carbohydrates, fat), and meal timing -- parsed by AI from your messages and cross-referenced with USDA and FatSecret nutrition databases.
Supplement Logs. Supplement name, dose, and timing, parsed from your iMessage texts.
Personal Records. Automatically detected from your workout history (e.g., heaviest bench press, most volume in a session).
Daily Macro Aggregates. Daily totals of calories and macronutrients computed from your individual meal entries.
AI-Generated Insights. The Service generates fitness insights including plateau detection, volume trends, recovery patterns, schedule drift analysis, and nutrition correlations. These are produced by AI models based on your stored data.
AI-Generated Messages. GURV sends service messages through iMessage, including onboarding, logging confirmations, and clarification questions. Optional proactive check-ins are sent only after you turn them on and can be disabled at any time.
Notification Preferences. We store your preferences for which types of messages you wish to receive (e.g., morning prime, nightly recap, weekly digest).
We use the information we collect for the following purposes:
To Provide the Service
To Improve AI Parsing Accuracy
To Understand Product Reliability and Use
To Process Payments
To Communicate with You
To Maintain Security and Prevent Abuse
We share information with the following third-party service providers solely to operate the Service. We do not sell, rent, or lease your personal information to any third party.
| Provider | Data Shared | Purpose | Relevant Policy |
|---|---|---|---|
| Anthropic (Claude API) | Message content, user profile context | AI processing: message classification, parsing, insight generation, response generation | Anthropic does not use API data to train models per their API data policy |
| Supabase | All stored user data | Database hosting (PostgreSQL), authentication, real-time data sync to iOS app | SOC 2 Type II certified |
| Photon Spectrum | Phone numbers, message content | iMessage delivery and routing | Photon processes messages in transit to deliver the service |
| RevenueCat and Apple | Pseudonymous user identifier, product and subscription status | In-app purchases and entitlement management | Apple processes payment credentials; Orph receives purchase lifecycle status |
| FatSecret | Food item names and descriptions (no user identifiers) | Nutrition data lookup (calories, macros) | We send only food names, not user names, phone numbers, or account information |
| PostHog | Pseudonymous user identifier and bounded product events | Onboarding, purchase, activation, and retention analytics | No message bodies, health measurements, or free-form content are included |
| Sentry | Pseudonymous technical diagnostics | Crash, error, and performance monitoring | Request bodies, message content, health data, and sensitive headers are scrubbed |
| Railway | Application runtime data | Backend hosting infrastructure | Application code and runtime environment |
We may disclose your information if required to do so by law, or in the good-faith belief that such disclosure is necessary to: (a) comply with a legal obligation, court order, or legal process; (b) protect and defend our rights or property; (c) prevent fraud or protect the safety of users or the public; or (d) protect against legal liability.
GURV uses artificial intelligence extensively. This section explains precisely how.
Every text message you send to GURV is transmitted to Anthropic's Claude API for processing. This includes:
Your user profile (body stats, training profile, supplement stack, and recent conversation history) may be included as context in AI requests to provide personalized and accurate responses.
Per Anthropic's API data policy as of the date of this Privacy Policy:
We encourage you to review Anthropic's privacy policy and usage policy for the most current information.
If Anthropic materially changes their API data policy in a manner that would affect your data (such as using API data for model training), we will promptly notify you via iMessage, suspend transmission of your data to Anthropic, and either obtain your updated consent or transition to an alternative AI provider before resuming data processing.
AI-generated nutrition estimates (calories, macros) are approximations and should not be treated as medical or dietary advice. AI-generated insights (plateau detection, recovery analysis) are informational and do not constitute professional fitness or medical guidance.
| Data Type | Retention Period |
|---|---|
| Account information (phone and profile) | Retained until you request account deletion |
| iMessage content (all messages sent and received) | Retained indefinitely for conversation context and insight generation, until you request account deletion |
| Workout, nutrition, and supplement data | Retained until you request account deletion |
| Personal records and insights | Retained until dismissed by you or until account deletion |
| Daily macro aggregates | Retained until account deletion |
| Notification preferences | Retained until account deletion |
| Subscription data | Managed by Apple and RevenueCat under their retention policies. We store entitlement status and product information needed to provide access. |
| Product analytics and diagnostics | Retained according to the configured PostHog and Sentry retention periods and deleted or de-identified when no longer needed. |
| AI processing logs | Anthropic retains API data for up to 30 days for safety monitoring, then deletes it |
| Photon Spectrum (iMessage delivery) | Message transit logs are retained according to Photon's service configuration and policies. |
We retain your iMessage conversation history for the lifetime of your account because GURV uses historical context to provide more accurate and personalized responses over time. If this concerns you, you may request deletion of your account and all associated data at any time (see Section 7).
If you are located in the EEA, UK, or Switzerland, you have the following rights under the General Data Protection Regulation:
For processing health-related data (fitness activity, nutrition intake, supplement usage, body measurements), our legal basis is your explicit consent provided when you accept this Privacy Policy and begin using the Service (GDPR Article 9(2)(a)). For non-health data processing (account management, payment processing, communications), our legal basis is the performance of our contract with you.
See Section 13 for detailed California privacy rights.
You may exercise any of these rights by:
We will respond to verified requests within 30 days (or sooner where required by law). This response period may be extended by up to two additional months for complex or numerous requests, in which case we will notify you of the extension and the reasons within the initial one-month period. We may need to verify your identity before processing a request, which we will do by confirming your phone number.
You may request complete deletion of your account and all associated data by:
Upon receiving a deletion request:
We delete all user data from our active database systems. Automated database backups maintained by our infrastructure provider (Supabase) may retain encrypted copies of data for a limited period as part of their standard backup rotation schedule, after which they are automatically overwritten. These backups are encrypted at rest and are not used for individual record retrieval or restoration after account deletion. Anonymized, aggregated statistics (e.g., "X users logged workouts this week") that cannot be linked back to you may persist.
You may request a full export of your data at any time. Exports are provided in JSON format and include:
To request an export, use the "Export My Data" feature in the iOS app (Settings > Account > Export Data) or email privacy@gurv.app. Exports are typically delivered within 48 hours.
We implement the following security measures to protect your data:
Encryption
Access Control
Application Security
Infrastructure
Limitations
No system is perfectly secure. While we implement industry-standard protections, we cannot guarantee absolute security.
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
For California residents, we will comply with the notification requirements of the California Civil Code Section 1798.82.
Law enforcement may request a delay in notification if immediate disclosure would impede a criminal investigation. We will comply with such requests to the extent required by law.
GURV is not intended for use by anyone under 17 years of age. We do not knowingly collect personal information from individuals under 17. If we learn that we have collected information from a user under 17, we will promptly delete that information.
If you are a parent or guardian and believe that someone under 17 has provided personal information to GURV, please contact us at privacy@gurv.app and we will take steps to delete that data.
We recognize that fitness, nutrition, and supplement data may be considered sensitive personal information under various legal frameworks, including but not limited to health-related data under the GDPR's "special categories" of personal data.
We treat all fitness, nutrition, and supplement data with heightened security:
You provide explicit consent for the processing of your health and fitness data by:
(a) Accepting this Privacy Policy during account creation in the GURV iOS app, where you will be presented with a consent screen describing our data practices before your account is activated; and
(b) Voluntarily sending messages to GURV's phone number containing your fitness, nutrition, and supplement information.
You may withdraw your consent at any time by deleting your account (see Section 7). Withdrawal of consent does not affect the lawfulness of processing conducted prior to withdrawal. If you withdraw consent, we will cease processing your health data and delete your account in accordance with our deletion procedures.
All conversations with GURV are treated with equal confidentiality regardless of content. Whether you are logging a meal, discussing your training program, asking about supplements, or sharing any other information, your messages receive the same privacy protections. We do not flag, categorize, or treat any message content differently based on its subject matter for privacy purposes.
Your health and fitness data will never be shared with:
In accordance with Apple's App Store requirements, we declare the following data practices:
These declarations are consistent with our data practices described throughout this Privacy Policy.
If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) provides you with specific rights regarding your personal information.
| Category (per CCPA) | Examples from GURV |
|---|---|
| Identifiers | Phone number and pseudonymous account identifier |
| Personal information under Cal. Civ. Code 1798.80(e) | Phone number, name |
| Internet or electronic network activity | iMessage content sent to GURV |
| Professional or employment-related information | Not collected |
| Biometric information | Not collected |
| Geolocation data | Not collected |
| Sensory data | Not collected |
| Inferences drawn from personal information | AI-generated insights (workout trends, nutrition patterns, personal records) |
| Sensitive personal information | Health-related information (body stats, workout data, nutrition data, supplement usage) |
Although we do not sell or share personal information for cross-context behavioral advertising, California residents may submit a verifiable request regarding the sale of their personal information by contacting us at privacy@gurv.app or through the 'Privacy' section of the GURV iOS app settings.
To exercise your rights, contact us at privacy@gurv.app or use the in-app account management features. We will verify your identity using your phone number before processing any request. We will respond within 45 days of receiving a verifiable request.
We do not offer financial incentives tied to the collection, sale, or deletion of personal information.
GURV's backend infrastructure is hosted in the United States via Railway and Supabase. If you are accessing the Service from outside the United States, your data will be transferred to, stored in, and processed in the United States.
For users in the European Economic Area, United Kingdom, or Switzerland:
For transfers of personal data from the European Economic Area, United Kingdom, or Switzerland to the United States, we rely on transfer mechanisms maintained by our sub-processors, including Supabase, our AI providers, Photon, RevenueCat, PostHog, and Sentry, as applicable.
By using the Service, you acknowledge that your data will be processed in the United States, where data protection laws may differ from those in your jurisdiction.
We may update this Privacy Policy from time to time. When we make material changes, we will:
Your continued use of the Service after notification of changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with any changes, you may delete your account as described in Section 7.
We encourage you to review this Privacy Policy periodically.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, you may contact us at:
Email: privacy@gurv.app
General support: support@gurv.app
Mailing address:
Vrtl Pirates LLC
30 North Gould Street
Sheridan, WY 82801
United States
For GDPR-related inquiries, you may also contact our data protection point of contact at privacy@gurv.app. If you are in the EEA and believe our processing of your personal data violates the GDPR, you have the right to lodge a complaint with your local supervisory authority.
This Privacy Policy is governed by the laws of the State of Wyoming, United States, without regard to its conflict of laws principles.
Vrtl Pirates LLC is committed to protecting your privacy. GURV exists to help you track your fitness goals, and your data is used solely for that purpose.