Summary
- Your data is yours. We never sell it and never use it to train third-party AI models.
- Health data from Apple Health or Health Connect stays on your device unless you explicitly enable a feature that needs it in the cloud (readiness and training-load adjustments).
- Photos you log are processed to recognise food and are not used for advertising.
- You can export everything or delete your account and all of its data from inside the app, instantly.
1. What we collect
Account data: email address, authentication identifiers, subscription status (from Apple/Google via our billing provider, RevenueCat).
Profile & goals: sex, age, height, weight, activity level, goal, dietary preferences and restrictions you choose to enter.
Logs: food entries (including photos, captions and voice transcriptions you submit), workouts, body metrics, and messages you exchange with the AI coach.
Health data (optional): with your permission, steps, active energy, workouts, sleep, heart rate, HRV and weight from Apple Health or Health Connect and connected wearables.
Technical data: device type, OS version, app version, crash reports, anonymised usage analytics and an installation identifier used to apply free-plan limits.
Website: pages visited and referrer, collected with privacy-preserving analytics without cross-site tracking; anything you send through our contact or partner forms.
2. How we use it
- To provide the Service: logging, targets, programmes, readiness, and coach responses tailored to you.
- To improve accuracy: your corrections to food estimates improve your personal results and, in aggregated, de-identified form, our recognition models.
- To operate the business: billing, support, fraud and abuse prevention, security, legal compliance.
- To communicate: service messages and, only if you opt in, product news. You can opt out any time.
Legal bases where GDPR/UK GDPR applies: performance of contract (providing the Service), consent (health data, marketing), legitimate interests (security, product improvement), legal obligation.
3. Health data
Data read from Apple Health or Health Connect is used only for the features you enable and is never used for advertising or sold. Apple Health data is not shared with third parties except as required to provide the feature (e.g. computing readiness on our servers when you enable it). You can revoke access at any time from your device’s health settings; we then stop reading new data and delete server-side copies of health data within 30 days on request.
4. AI processing
Food recognition, voice transcription and the coach are powered by a combination of on-device models and third-party AI providers processing data on our behalf under contracts that prohibit them from using your data to train their models or for any purpose other than responding to your request. Coach messages include relevant context from your logs so responses are personalised. We may review de-identified samples to improve safety and accuracy.
5. Sharing
We share data only with processors that help us run the Service: cloud hosting and database (Supabase), billing (RevenueCat, Apple, Google), AI providers, crash reporting and analytics, and email delivery, each bound by data-processing agreements. We may disclose data when required by law, to protect rights and safety, or in a merger or acquisition (with notice). We do not share data with advertisers or data brokers.
6. Retention and deletion
We keep your data while your account is active. Deleting your account (Profile → Settings → Delete account) removes your profile, logs, photos, workouts, metrics and coach history immediately; backups are purged within 30 days. Free-plan usage counters are deleted after 30 days. Billing records are retained as required by tax law.
7. Security
Data is encrypted in transit (TLS) and at rest. Access to production data is restricted, logged and protected by row-level security so that your records are only ever accessible to you. No system is perfectly secure; we will notify you and regulators of any breach as required by law.
8. Your rights
Depending on where you live you may have the right to access, correct, export, restrict or delete your data, to object to processing, and to withdraw consent. Export and deletion are available in the app; for anything else email privacy@vitalume.ai. We respond within 30 days. You may also complain to your local data-protection authority. California residents: we do not “sell” or “share” personal information as defined by the CCPA/CPRA.
9. International transfers
Our servers are located in the United States and the European Union. Where data moves across borders we rely on standard contractual clauses or equivalent safeguards.
10. Children
The Service is not directed to children under 16 and we do not knowingly collect their data. If you believe a child has provided data, contact us and we will delete it.
11. Website and cookies
https://vitalume.ai uses only strictly necessary cookies and cookieless, privacy-preserving analytics. We do not use advertising cookies or cross-site tracking. If we add tools that require consent we will ask first.
12. Changes
We will notify you of material changes in the app or by email before they take effect. The effective date at the top of this page tells you when it was last updated.
13. Contact
Data controller: Wapp LTD, Lahore, Pakistan. Privacy questions: privacy@vitalume.ai. (TODO: add EU/UK representative details if required.)