This policy explains what personal information VivFit collects, why, who sees it, how long we keep it, and the choices you have. We have tried to write it in plain language. Health information is sensitive, so we say clearly what we do with it and what we never do.
Who we are
VivFit is a fitness, nutrition and wellbeing app and website operated by Vividia Infosys, Kathmandu, Nepal (registered address: [REGISTERED ADDRESS - confirm]). Vividia Infosys is the "controller" of your personal information, which means we decide how and why it is used.
- Privacy questions and requests: privacy@vivfit.app
- General support: support@vivfit.app
- Data protection officer: [DPO or privacy lead - confirm whether one is appointed]
- Representative in the EU and UK: [EU/UK REPRESENTATIVE - confirm]
This policy covers the VivFit mobile apps for iOS and Android, the vivfit.app website, and our support channels.
The short version
- We collect what we need to run VivFit for you: your account, your goals, what you log, and, if you choose, data from Apple Health or Health Connect.
- Your health data, food logs and photos are used only to provide VivFit to you. We do not sell your personal information, we do not share it for advertising, and we do not use it to train AI models.
- Journey progress photos are private. They are protected by an optional lock on your device, stored privately, never sent to AI, and never visible to our staff.
- Meal photos and Body Check photos are sent to an AI vision provider for one analysis. Body Check photos are never stored by us, and only after you give separate, explicit consent.
- Product analytics runs only if you opt in. Crash reports can be switched off.
- You can export your data and delete your account from the app, or ask us to delete it by emailing privacy@vivfit.app.
What we collect
Information you give us
| What | Details |
|---|---|
| Account | Email address, name, and a password (stored only as a salted argon2id hash, never in readable form). If you sign in with Apple or Google we receive an account identifier and a verified email address from them. |
| Profile and goals | Age, sex, height, weight, goal type and pace, activity and experience level, training days, session length and equipment, food preferences and cuisines, allergies and intolerances, whether you are pregnant or breastfeeding, and a screening question about any history of disordered eating. We use some of these only to apply safety limits (see "Health information"). |
| Logs | Meals, water, weight and body measurements, check-ins (for example mood and energy), workouts, sets and personal records, and notes you type. |
| Food photos and descriptions | Photos of meals and nutrition labels you choose to scan, and meal descriptions you type. |
| Journey | Progress photos you add to a Journey, with their date, pose, weight, measurements, mood, energy and notes. |
| Body Check | Tape measurements, optional strength tests, and, if you opt in, up to three body photos (front, side, back). |
| Coach messages | Questions you type to the VivFit coach and its replies. |
| Support and contact | The name, email address, topic and message you send us through the app, the website or email, and replies. |
| Waitlist | Your email address, optional platform, the page you signed up from, and your consent to hear from us. |
| Referrals | A referral code you enter, share or claim. |
Health and fitness data from your phone
If you connect Apple Health (iOS) or Health Connect (Android), VivFit reads only the groups you allow, one group at a time, and you can turn any of them off in the app or in your phone's settings.
On Android we request permission to read: steps, distance, floors climbed, active calories burned, exercise sessions, heart rate, resting heart rate, heart rate variability, VO2 max, oxygen saturation, respiratory rate, sleep, weight and body fat. We also ask to read in the background so your data stays up to date without opening the app (this is optional).
On iOS the same groups apply: activity, heart and recovery, sleep, body measurements and workouts.
VivFit can also write workouts, active calories, nutrition and water you log in VivFit back to Apple Health or Health Connect. Every kind has its own switch and all are off by default.
How we use this data: to show your steps, sleep and readiness, to adjust your targets, and (on Pro) to detect workouts you may want to log. We do not use data from Apple Health or Health Connect for advertising or marketing, we do not sell it, and we do not transfer it to anyone except the service providers that help us run VivFit as described below. We follow the Apple HealthKit rules and the Google Play Health Connect Limited Use requirements. If you disconnect and choose "delete", we remove what VivFit imported; this never changes data inside Apple Health or Health Connect.
Information collected automatically
| What | Details |
|---|---|
| Device and session | A random per-install device ID, platform, operating system and app version, time zone, language, push notification token, and the IP address and user agent of your sign-in sessions. |
| Location | Only if you start an outdoor run, walk or ride and allow it. The app uses your location on your phone during the session to work out distance and pace. [CONFIRM: only the finished distance is sent to our servers, not the route.] The in-session map is loaded from OpenStreetMap, which sees your device's IP address and the map area requested. |
| Support diagnostics | App version, platform, device model and OS version, attached to a support request only if you switch that on. Never settings or health data. |
| Crash reports | If the "Crash reports" switch is on (it is on by default), technical error information goes to our crash-reporting provider. We strip personal information, screenshots and message payloads before sending. |
| Product analytics | Only if you opt in under Settings, Privacy. A limited list of events (for example "journey created") with code-like properties. No identifying profile is built, no screen recording is made, and health data is never included. |
| Server logs | Technical logs of requests, kept for 30 days. Request bodies, passwords, tokens and health values are never written to them, and email addresses are masked. |
Purchases
Subscriptions are bought and billed by the Apple App Store or Google Play. We never see your card details. Through our subscription provider, RevenueCat, and the stores' notifications, we receive your subscription status, plan, billing period, trial and renewal dates, store transaction identifier and country, so that we can unlock Pro features.
How we use your information
| Purpose | Examples |
|---|---|
| Provide VivFit | Create your account and sign you in; calculate targets; build meal and training plans; show progress; store your Journey; sync between your devices; apply safety limits. |
| AI features | Meal and label scans, describing a meal in words, the coach, recipe suggestions, weekly report text and Body Check (see "How we use AI"). |
| Health connections | Show and use the Apple Health or Health Connect data you allow. |
| Notifications and email | Sign-in codes, reminders you set, push notifications you allow, and service messages. Optional emails such as the weekly report only if the switch is on. Marketing only with your consent. |
| Purchases and entitlements | Give you Pro features, handle referral rewards, prevent fraud and abuse. |
| Support | Answer your questions and fix problems. Staff cannot read your health data by default (see "Who can see your data"). |
| Security and integrity | Detect abuse, enforce limits, keep audit records of staff actions, and protect against fraud. |
| Improve VivFit | Aggregated and de-identified statistics, crash reports and, only if you opt in, product analytics. |
| Legal | Meet legal obligations and handle legal claims. |
We do not use your personal information for advertising, and we do not make decisions about you that have legal or similarly significant effects. Plans and targets are produced by software using the details you give us. They are general wellness guidance (see our Terms and Conditions) and you can change your details at any time.
How we use AI
Some features use AI models run by outside providers. We call them through our own server, so the AI provider never sees your name or email address. Prompts, photos and replies are not written to our logs. We keep only technical records (which feature, provider, model, token counts, cost and timing) for 365 days to manage cost and quality.
| Feature | What is sent | Notes |
|---|---|---|
| Meal photo scan, nutrition label scan | One photo (JPEG, location and camera metadata removed) | Needs your one-time consent. We do not store the photo. You review every result before it is logged. |
| Describe a meal in words | The text you typed | The result is a draft you confirm. |
| VivFit coach (Pro) | Your message plus a summary of your own data: goal and preferences, today's targets and intake, today's food log, training week and recent workouts | Not sent: your name, email, medical conditions or medications. Questions about diagnosis, medication, pregnancy, self-harm or urgent symptoms are answered by fixed safety text and are not sent to AI. The coach can only propose actions, and you confirm them. |
| Recipe ideas and recipe import | Your request and preferences, or the recipe page you ask us to read | |
| Weekly report | Weekly totals and averages of your own logs (for example calories and weight change), only if you have given health data consent | We do not send raw health samples. |
| Body Check photos | One body photo at a time, with your face already cropped out on your phone | Needs a separate explicit consent that you can withdraw. We run this only on AI providers we have confirmed do not retain the images, never fail over to another provider, and never store, cache or log the photo. Only the returned ranges and body landmarks are kept. Available only to adults and only where the feature is switched on. |
We do not use your data to train AI models, and we do not permit our providers to do so. We choose providers on terms that do not allow training on API data. [CONFIRM per provider - see Open Questions.] Your Journey photos are never sent to any AI provider.
The AI providers our system supports are DeepSeek, Google (Gemini), OpenRouter and OpenAI. [CONFIRM which are live at launch; remove the others.] AI can be wrong. Please read "AI-generated content" in our Terms and Conditions.
Health information and your consent
Information about your health, such as weight and body measurements, sleep, heart data, workouts, food logs, pregnancy status and Body Check results, is treated as special category data under the GDPR and UK GDPR and as sensitive personal information elsewhere. We handle it as follows.
- Explicit consent. We ask for your explicit consent before using health information and Apple Health or Health Connect data to tailor your plans. You can withdraw it at any time in Settings, Privacy. Withdrawing turns off health-based adjustments; your other data stays.
- Separate consents. Sending meal photos to AI, Body Check photos to AI, product analytics and marketing each have their own switch. None is required to use the core app.
- Never for advertising. Health data is never sold, used for advertising, or placed in analytics.
- Never used to train AI.
- Safety limits. We use some details (age, pregnancy or breastfeeding, history of disordered eating, low BMI) only to hold back advice that could be unsafe, for example by not offering a calorie deficit or Body Check.
- Limited access. Support staff see your account, subscription and tickets, but not your health data. In rare cases a senior administrator can grant time-limited access to daily summaries for a specific support request. Each access is logged with a reason. Staff can never see Journey photos, not even this way.
- Extra protection. Medical-type fields are encrypted at the database level in addition to storage encryption.
In this version of the app we do not ask about medical conditions or medications. If we add that later, we will update this policy and ask for your explicit consent first.
Journey photos
Journey is your private progress diary.
- Photos are stored in a private bucket under your own account, never on public pages or a public CDN, and are shown to you only through short-lived links.
- On upload we re-encode each photo and strip location and camera data, and we delete the original.
- You can lock Journey with Face ID, Touch ID or a PIN. Photos are fetched only while it is unlocked.
- Face blur runs on your phone. Faces in Journey photos are never sent anywhere by VivFit.
- Photos are never sent to AI, never used for advertising or training, and never visible to our staff.
- Sharing is your choice. When you share a photo or comparison, we create a link or file that carries only your referral code. Once you share something outside VivFit, we cannot recall it.
- Deleting a photo, entry or Journey removes it from storage within 24 hours. Deleted photos leave our backups on the schedule under "How long we keep information".
Legal bases for using your information (UK and EU)
| Purpose | Legal basis |
|---|---|
| Account, profile, logs, plans, Journey, sync, subscriptions | Performing our contract with you (Article 6(1)(b)) |
| Health information and data from Apple Health or Health Connect | Your explicit consent (Article 9(2)(a)), plus Article 6(1)(b) |
| Meal photos and Body Check photos to AI | Your explicit consent |
| Product analytics, marketing emails, optional diagnostics | Your consent (Article 6(1)(a)). You can withdraw it at any time |
| Crash reports | Our legitimate interest in keeping the app stable and secure (Article 6(1)(f)). You can switch it off |
| Security, fraud prevention, audit records, support | Our legitimate interests, and the contract where it is needed to help you |
| Tax, accounting, responding to authorities | Legal obligation (Article 6(1)(c)) |
| Legal claims | Our legitimate interests (Article 6(1)(f)) |
Where we rely on consent, withdrawing it does not affect earlier use that was lawful.
Who we share information with
We do not sell your personal information. We do not "share" it for cross-context behavioural advertising. We share it only with service providers ("processors") who act on our instructions under data protection agreements, and where the law requires it.
| Category | Provider | What they handle |
|---|---|---|
| Cloud hosting and database | [HOSTING PROVIDER - confirm] | Application servers and the database that holds your account data |
| Private file storage | S3-compatible object storage, [Cloudflare R2 or AWS S3 - confirm] | Journey photos |
| AI providers | DeepSeek, Google (Gemini), OpenRouter, OpenAI [confirm which are live] | Only what is listed under "How we use AI" |
| Subscriptions | RevenueCat; Apple App Store; Google Play | Subscription status and store transaction data |
| Push notifications | Google Firebase Cloud Messaging (including Apple Push Notification service for iPhones) | Your device token and a notification message. Lock-screen text is generic unless you turn on details |
| Crash reports | Sentry [confirm enabled and region] | Scrubbed technical error reports |
| Product analytics | PostHog [confirm enabled and region] | Opt-in events only |
| Email delivery | [EMAIL PROVIDER - confirm: SMTP relay, Resend or Amazon SES] | Sign-in codes, service emails, waitlist and support mail |
| Sign-in | Apple, Google | Verifying your identity when you choose "Sign in with" |
| Food data | Open Food Facts | The barcode you scan, to look up a product [confirm] |
| Maps | OpenStreetMap | Map tiles during an outdoor session |
Others who may receive information: professional advisers, and authorities or courts where we are legally required, or to protect rights and safety. If Vividia Infosys is ever sold or restructured, your information may transfer to the new owner, who must honour this policy.
Health data never goes to analytics or advertising providers. Analysts see only aggregated, de-identified figures, and small groups are hidden.
International transfers
We are based in Nepal. Our servers are located in [HOSTING REGION - confirm], and some of our providers process data in other countries, including the United States and [other countries - confirm, including where each AI provider processes data]. When personal information of people in the UK or EEA is transferred to a country without an adequacy decision, we rely on [Standard Contractual Clauses and the UK International Data Transfer Addendum or Agreement - confirm] and additional safeguards. Ask us at privacy@vivfit.app for details. If you are in Nepal, we handle transfers in line with the Individual Privacy Act, 2075 (2018). [lawyer to confirm]
How long we keep information
| Information | How long |
|---|---|
| Account, profile, logs, Journey and Body Check results | Until you delete them or your account (see below) |
| Account deletion | 30-day grace period you can cancel, then permanent erasure (see below) |
| Raw health samples imported from your phone | Pruned after 400 days. Short activity buckets after 30 days. Daily summaries stay until you delete them |
| Journey photos | Until you delete them. Removed from storage within 24 hours of deletion |
| Meal photos and Body Check photos | Not stored by us |
| Support tickets and website contact messages | Until the ticket is closed plus 730 days, or until your account is erased |
| Waitlist sign-ups | Until you unsubscribe [retention period - confirm] |
| Sign-in sessions | Up to 180 days, shorter if idle. Expired sessions are cleaned up |
| Emailed codes | Valid for 10 minutes and deleted soon after |
| Data export files | Download link valid for 24 hours |
| Server logs | 30 days |
| Staff action audit records | 2 years. On account deletion they are stripped of anything that identifies you |
| AI usage records (no prompts or photos) | 365 days, anonymised on account deletion |
| Fraud prevention | If an account is banned, we keep a one-way hash of its identifiers so it cannot simply re-register |
| Legal records | Billing records are held by Apple or Google. We keep only what the law requires, in a separate minimal store |
| Backups | Encrypted backups are kept for a limited period [BACKUP PERIOD - confirm; the Journey terms say 35 days]. Deleted information leaves backups as they are rotated |
Deleting your account and your data
You can start deletion in the app (Settings, Privacy) or, if you cannot open the app, by emailing privacy@vivfit.app; we confirm the request with a 6-digit code sent to the address on your account.
- When you request deletion, all your sessions are signed out and your push tokens are removed.
- A 30-day grace period begins. You can cancel in the app by signing in again during that time.
- After the 30 days, we permanently erase your account, logs, health data, Journey photos and other stored files. After that, you cannot sign in with it, and the same email can register as a new account.
- Subscriptions are not cancelled automatically. Cancel them in the App Store or Google Play so you are not billed.
You can also delete individual items (a photo, a Journey, a Body Check scan) or remove imported health data ("disconnect and delete") at any time.
Security
We protect your information with measures including:
- encryption in transit (TLS) and encrypted storage, with extra field-level encryption for sensitive health fields;
- password hashing with argon2id, breached-password checks, sign-in rate limiting and revocable sessions;
- database rules that stop one account from reading another's records;
- sign-in tokens kept in your phone's secure storage (Keychain or Keystore);
- private photo storage with short-lived links;
- separate staff access with multi-factor sign-in, least privilege and audit records, and no engineer access to production data by default;
- security testing, including an external penetration test before launch.
No system is perfectly secure. If a breach affects your personal information, we will notify the relevant authority within the time the law requires (72 hours under the GDPR where applicable) and tell you without undue delay when there is a high risk to you.
Your rights
Depending on where you live, you can ask us to:
- access the personal information we hold about you and get a copy;
- correct it (you can edit most of it in the app);
- erase it;
- restrict or object to some uses;
- receive it in a portable format;
- withdraw your consent at any time;
- not be subject to a decision made only by automated means with legal or similarly significant effects (we make none).
How to use them
- Export: in the app, Settings, Privacy, "Export my data". We prepare a file (JSON, including Journey entries and processed photos) and email you a secure download link valid for 24 hours. Free accounts can always export their own data.
- Delete: in the app, or by emailing privacy@vivfit.app, as above.
- Change consents: Settings, Privacy.
- Anything else: email privacy@vivfit.app. We may need to confirm it is you. We reply within one month (45 days for California, extendable where the law allows).
If you are in the UK or EEA you can complain to your local data protection authority (in the UK, the Information Commissioner's Office). We would appreciate the chance to put things right first.
Rights if you live in California
In the last 12 months we have collected these categories: identifiers (email, name, device ID, IP address); sensitive personal information (health and body measurements, photos, account log-in); commercial information (subscription status); internet and device activity; location (an approximate location inferred from your IP address, and precise location that stays on your phone during outdoor sessions); and inferences used for your plans. We collect them from you, your phone and our providers, for the purposes listed above.
We do not sell personal information and do not share it for cross-context behavioural advertising. We use sensitive personal information only to provide the services you ask for and for the other permitted purposes in the CPRA regulations, so there is no "limit the use of my sensitive information" setting to choose. You can ask to know, delete or correct, and you will not be treated differently for exercising these rights. An authorised agent may act for you if we can verify their authority. We have not knowingly sold or shared data of anyone under 16.
Nepal
We handle personal information in line with the Individual Privacy Act, 2075 (2018) and related rules [lawyer to confirm applicable provisions]. You may ask us to access, correct or delete your information using the contacts above.
Children
VivFit is not designed for children. You must be at least 13 years old to create an account, and the app does not accept an age below 13. [CONFIRM: minimum age for EU countries where the age of digital consent is higher than 13, and for health data of minors.] If you live in a country where the age for consenting to online services is higher than 13, you must be at least that age, or have a parent or guardian's permission.
If you are under 18, we apply extra caution: more conservative guidance, no calorie-deficit targets, and no access to Body Check. We encourage under-18s to talk to a doctor or parent first. We do not knowingly collect information from children under 13. If you believe a child has given us information, write to privacy@vivfit.app and we will delete it.
Website, cookies and similar technologies
The website at vivfit.app does not use advertising or analytics cookies, and it does not run analytics or tracking scripts. Fonts are served from our own site. The site does not store anything in your browser. We do not show a cookie banner because we do not use cookies that need consent. If this changes, we will ask first and update this page.
When you use the waitlist, contact or account deletion forms on the website, your submission is sent to our server over an encrypted connection. We use an invisible anti-spam field and rate limits, and we do not log the contents. Waitlist sign-ups use double opt-in, and every email has an unsubscribe link.
Changes to this policy
We will update this policy when our practices change. For important changes we will tell you in the app or by email before they take effect, and where the law requires it we will ask for your consent again. The date at the top shows when it was last updated.
Contact us
Privacy questions, requests and complaints: privacy@vivfit.app
General help: support@vivfit.app
Vividia Infosys, Kathmandu, Nepal. [REGISTERED ADDRESS - confirm]