VITAIL privacy notice
Who we are
VITAIL is a daily coaching app for adults using GLP-1 medication. The service is operated by its founders from the European Union. Questions about your data: v.olexienko@gmail.com.
What we collect
- Account. A Sign in with Apple identifier. We do not store your name or email from Apple.
- Profile. What you tell us: goals, constraints, medication stage and dates, timezone, notification preferences.
- Health summaries. Daily summaries only, never raw samples: sleep and its stages, resting heart rate, heart-rate variability, respiratory rate, blood oxygen, steps, active energy and weight. From Apple Health, aggregated on your phone; and, if you connect one, from a wearable's own service such as WHOOP, read by our server under the permission you grant there.
- Check-ins and coaching. Your daily check-ins, the plan items you complete or skip, your messages to the coach and its replies.
- Consents and audit. A ledger of what you agreed to and when, and of actions taken on your account.
We never store WHOOP's recovery score or any other composite score, and we never read a connected wearable's profile, name or email.
Why, and on what basis
To read your day and write a daily brief, a small plan and a coaching conversation. Health data is special-category data; we process it only on your explicit consent, which you can withdraw in the app at any time. Withdrawing a consent stops the processing it names.
Who processes it
- Cloudflare runs our servers in the EU region.
- Neon hosts our database in Frankfurt, Germany.
- Google (Gemini) receives a bounded snapshot of your recent summaries to write your brief and coach replies, only after you consent to AI processing, under a data-processing agreement. No conversation state is kept by the provider.
- WHOOP, only if you connect it, releases your recovery, sleep and cycle records to us under your own WHOOP permission. You can revoke that in the app or at WHOOP.
We never sell your data, and we never share it with anyone else.
Retention and your rights
Your data stays while your account exists. Deleting your account in the app starts a seven-day grace period during which you can change your mind, after which everything is permanently erased within thirty days, including any copy held by the AI provider under its retention window. You can export everything as one file at any time from the app. Disconnecting a wearable stops new data and voids the permission; summaries already imported stay with your other health data until you delete your account.
Security
Every row of your data is isolated by the database itself. Wearable access tokens are stored encrypted with a key that never enters the database. Raw health samples never leave your phone.
Changes
We will update this page and the in-app privacy consent together, and ask you to accept a new version when the substance changes.