Privacy

We keep a clear boundary between personal health and family sharing.

Summary

Personal health tracking works on the device without an account. Only when you deliberately enable family sharing does the minimum information needed for a family account go to the service. Family can see member number and role plus a structured exercise schedule and status, never personal health values.

Data-processing boundary
On device only Raw HealthKit data, heart rate and BPM, blood pressure, glucose, calories, sleep, disease estimates, and health values entered manually
In the family service Keyed-HMAC sign-in identifier, member number and role, expiring invite code, activity type, schedule, duration, and status
Visible to family Member number and role plus the activity type, weekday, local time, time zone, duration, and complete or in progress or no-record state you explicitly share

Information processed by personal features

HealthKit data you permit, along with blood pressure or glucose you confirm and enter, is processed on the device for target BPM, workout records, trends, and wellness estimates. Apple Health remains the source of truth. Vitatally stores only the minimum derived daily summaries needed for its views under iOS Data Protection.

Personal features require no sign-in. During personal use, health data, advertising identifiers, and analytics events are not sent to a developer server. The app uses no advertising or behavioral-analytics SDK.

Public evidence requests

The app may download a signed, public catalogue of research evidence. This request contains no health value, family information, or user identifier.

Information processed by family sharing

Family sharing is an optional paid add-on. Only when you turn it on do you create a family account with Google, Apple, or email sign-in.

Account and membership

The family service converts Google or Apple account identifiers into keyed HMACs before storage. Within a family, it uses an automatically assigned member number and the owner or member role instead of a name. A display name or sign-in-provider profile name is never transmitted to or stored by the service. Invite codes are designed to expire and work once.

Email sign-in

A plaintext email address is processed temporarily only while requesting delivery of a sign-in code. D1 stores only a keyed HMAC, not the address itself. The plaintext address is not retained as family-account data after the code-delivery request finishes.

Shared exercise schedules

The service processes only the activity type, weekday, local time, time zone, duration, and complete or in progress or no-record status you choose to share. A free-form routine title is never transmitted to or stored by the service. Family members receive only this scope plus member number and role.

Never provided to family

Current or target BPM, heart-rate history, blood pressure, glucose, calories, raw HealthKit data, disease estimates, applied study results, and health values entered manually are excluded from family-sharing APIs and views. The family service also never receives a display name or free-form routine title.

Service providers

Google, Apple, and email sign-in

The selected provider authenticates you. Vitatally does not receive or store your Google or Apple password. An email address is processed temporarily only for code delivery, and D1 stores only its keyed HMAC.

Cloudflare

Cloudflare Workers and D1 process keyed-HMAC sign-in identifiers, family links, invite codes, and structured exercise schedules, while Cloudflare Email Sending delivers sign-in codes. D1 stores no personal health value, display name, plaintext email address, or free-form routine title.

Apple App Store and RevenueCat

Apple App Store and RevenueCat are used to purchase and verify access to the family add-on. RevenueCat may receive an account-scoped entitlement identifier and subscription state, but no health value or family exercise schedule. Vitatally does not receive payment-card details.

This website

This introduction site uses no tracking script, advertising, analytics tool, or cookie. Cloudflare may process ordinary request information for site delivery and security under its own terms.

Retention and deletion

Keyed-HMAC sign-in identifiers, family relationships, member number and role, and shared exercise schedules are retained while the account is active. When you delete a family account, family access is revoked immediately. Account identifiers, sign-in HMACs, family relationships, invite codes, activity type, schedule, duration, and status are permanently deleted within 30 days.

Purchase history retained by Apple follows Apple's policies. Deleting the family account does not automatically cancel an App Store subscription; cancel it separately in iOS subscription settings.

Read the family account deletion instructions

Your choices and controls

  • Change permission for each health-data type in Apple Health settings at any time.
  • Leave a family group or disconnect a particular family member.
  • Stop sharing an exercise schedule with family.
  • Deleting the app removes Vitatally's local summaries. Review and delete workouts or entries written to HealthKit separately in Apple Health.

Age and service scope

Vitatally is intended for ages 14 and older. A user who requires separate guardian consent under local law should set up the family account feature with a guardian.

Vitatally provides wellness estimates that apply published group statistics to an exercise pattern. It does not provide diagnosis, treatment, emergency detection, or an individual's absolute probability of disease.