Privacy

We keep a clear boundary between personal health and account data.

Summary

Personal health tracking works on the device without an account. Pro verification uses an account identifier and does not send health values. Accounts that previously used sharing may still have member numbers, roles, structured exercise schedules, and status in the service. In-app ads are shown on a limited basis only to adult free users age 18 or older; Pro members and users under 18 see no ads.

Data-processing boundary
On device only Raw HealthKit data, heart rate and BPM, glucose, calories, sleep, disease estimates, and health values entered manually
In the legacy sharing service Keyed-HMAC sign-in identifier, member number and role, expiring invite code, exercise intensity (MPA/VPA), schedule, duration, and status
Previously provided to connected members Member number and role plus the exercise intensity (MPA/VPA), weekday, local time, time zone, duration, and complete or in progress or no-record state you explicitly share
Anonymous ad-performance data Coupang campaign and creative version, impression, click or report, home placement, card position, and app version; no health, account, or device identifier

Information processed by personal features

HealthKit data you permit, along with glucose you confirm and enter, is processed on the device for target BPM, workout records, trends, and wellness estimates. Apple Health remains the source of truth. Vitatally stores only the minimum derived daily summaries needed for its views under iOS Data Protection.

Personal features require no sign-in. During personal use, health data is not sent to a developer server. The Coupang card performance events described below contain no personal health data or account identifier.

Public evidence requests

The app may download a signed, public catalogue of research evidence. This request contains no health value, family information, or user identifier.

In-app advertising

Version 1.0 shows one Vitatally-reviewed Coupang Partners card in one Home slot only for free users age 18 or older. Pro members, users under 18, and users whose age is unknown see no ad.

A Coupang card is always labeled Ad and includes a commission-information button. Opening it displays the exact Coupang Partners commission disclosure. After a product link opens, Coupang's privacy policy applies.

Information excluded from ad requests

Vitatally does not use or send HealthKit data, BPM, METs, workout type, intensity or calories, disease or risk estimates, profile or account data, the IDFA, device location, or ad-targeting keywords for Coupang product selection or performance measurement. It does not request App Tracking Transparency permission.

Anonymous measurement and reporting

An impression is counted after at least 50% of the card remains visible for at least one second, and a click only when the product link actually opens. The payload is limited to schema version, a random exposure UUID that identifies no person, account, or device, campaign ID, creative version, impression, click or report, app surface and home placement, card position, and app version. The server hashes the UUID with SHA-256 and deletes the impression-hash ledger, separate report-hash ledger, and anonymous daily aggregates after 91 days. A report does not add an impression.

The information button lets a user report an inappropriate or age-inappropriate ad. A reported ad is hidden immediately and cannot be reported twice from the same app installation. A report contains no health, account, or device identifier.

Google AdMob support status

The version 1.0 App Store main target and distributed binary do not link or include the Google Mobile Ads SDK or User Messaging Platform. The conditional AdMob adapter can be re-enabled only in a dedicated PhoneOnlyQA target that is not distributed. Version 1.0 therefore makes no Google ad or UMP request and does not request App Tracking Transparency permission. Before any future version enables AdMob, Vitatally will update this notice and its App Store Connect privacy answers for the actual processing and revalidate any required consent flow before adding Google advertising dependencies to the App Store target.

Information processed for existing sharing accounts

This section describes data that may remain for accounts that previously used family sharing. New family-sharing enrollment and invitations are no longer offered.

Account and membership

A Google sign-in token and account information returned by Google are processed temporarily only during authentication. The server stores only a keyed HMAC of the verified Google account identifier. A display name or sign-in-provider profile name is never transmitted to or stored by the service. Apple account identifiers are also stored as keyed HMACs. Within a family, the service uses an automatically assigned member number and the owner or member role instead of a name.

Email sign-in

A plaintext email address is processed temporarily only while requesting delivery of a sign-in code. D1 stores only a keyed HMAC, not the address itself. The plaintext address is not retained as family-account data after the code-delivery request finishes.

Shared exercise schedules

The service processes only the exercise intensity (MPA/VPA), weekday, local time, time zone, duration, and complete or in progress or no-record status you choose to share. A free-form routine title is never transmitted to or stored by the service. Family members receive only this scope plus member number and role.

Never provided to family

Current or target BPM, heart-rate history, glucose, calories, raw HealthKit data, disease estimates, applied study results, and health values entered manually are excluded from family-sharing APIs and views. The family service also never receives a display name or free-form routine title.

Service providers

Google, Apple, and email sign-in

Google Sign-In is an optional account sign-in method for new and returning users, not a Google advertising SDK. The Google Sign-In 9.2 privacy manifest declares Name, Email Address, Phone Number, Other Data, Coarse Location, and User ID for app functionality, plus Other Data, User ID, Device ID, and Other Usage Data for analytics. It declares these data types linked to the user and not used for tracking. The Google Privacy Policy applies to processing by the Google SDK. Vitatally processes the Google sign-in token and information returned by Google only during authentication, then stores only a keyed HMAC of the verified account identifier. A display name or sign-in-provider profile name is never transmitted to or stored by the service, and no health data is added to the sign-in request.

A Sign in with Apple authorization code is exchanged immediately on the server and is never stored or logged. Only the refresh token needed to disconnect Apple sign-in during account deletion is retained under server-side encryption and removed when deletion completes. An email address is processed temporarily only for code delivery, and D1 stores only its keyed HMAC.

Google Gmail

Sign-in codes are delivered through the Google Gmail API. The recipient's email address and a message containing the code are sent to Google for delivery. No health data is included.

Cloudflare

Cloudflare Workers and D1 process keyed-HMAC sign-in identifiers, family links, invite codes, and structured exercise schedules. D1 stores no personal health value, display name, plaintext email address, or free-form routine title.

To prevent excessive API requests and sign-in abuse, the service temporarily processes the connection IP supplied by Cloudflare and, where applicable, an email address or account identifier. D1 rate-limit records store a keyed HMAC instead of the original identifier, together with the time window, request count, and expiration time. These records are configured to expire within two hours, with daily cleanup of expired records. These records contain no plaintext IP address or health value.

Apple App Store and RevenueCat

Apple App Store and RevenueCat are used to purchase and verify Pro access. RevenueCat may receive an account-scoped entitlement identifier and subscription state, but no health value or existing shared exercise schedule. Vitatally does not receive payment-card details.

Coupang Partners

The app downloads reviewed Coupang cards from a public product list and sends limited anonymous performance events to Vitatally's ad server. Coupang's terms and privacy policy apply to purchases and service use after a product link opens.

This website

Separate from the in-app advertising above, this introduction website itself uses no tracking script, advertising, analytics tool, pixel, or cookie. Cloudflare may process ordinary request information for site delivery and security under its own terms.

Retention and deletion

Keyed-HMAC sign-in identifiers, family relationships, member number and role, and shared exercise schedules are retained while the account is active. When you delete a family account, family access is revoked immediately. Account identifiers, sign-in HMACs, family relationships, invite codes, exercise intensity (MPA/VPA), schedule, duration, and status are permanently deleted within 30 days.

Unsent Coupang card events remain on the device for no more than 24 hours and 200 items. The server deletes its impression- and report-hash deduplication ledgers and anonymous daily campaign aggregates after 91 days.

Purchase history retained by Apple follows Apple's policies. Deleting the family account does not automatically cancel an App Store subscription; cancel it separately in iOS subscription settings.

Read the existing account deletion instructions

Your choices and controls

  • Change permission for each health-data type in Apple Health settings at any time.
  • Open the upper-left Menu, then Profile > Subscription, and select Delete account in Subscription management to delete the existing account and its server data.
  • Use the ad-information button to report and immediately hide an inappropriate or age-inappropriate Coupang card.
  • Deleting the app removes Vitatally's local summaries. Review and delete workouts or entries written to HealthKit separately in Apple Health.

Age and service scope

Vitatally is intended for ages 14 and older. A user who requires separate guardian consent under local law should set up the app and account with a guardian.

Vitatally provides wellness estimates that apply published group statistics to an exercise pattern. It does not provide diagnosis, treatment, emergency detection, or an individual's absolute probability of disease.