Effective Date: 2025-08-17
Last Updated: 2025-08-17
Version: 1.1 (Geoblocked launch)
Contact (Privacy): [email protected]
Security (Incidents/Vulns): [email protected]
Data Protection Officer (if required): [email protected]
This Privacy Policy explains how VITALITY ("VITALITY," "we," "us") collects, uses, discloses, and protects personal data when you use our web (PWA), iOS, and Android applications and related services (the "Service"). By using the Service, you agree to this Policy. If you do not agree, please do not use the Service.
For privacy matters, contact [email protected].
Controller: [Insert full legal company name and registered address].
(We will update this section with full corporate details prior to public release.)
The Service is offered only to individuals outside the EEA and the United Kingdom. If we detect access from the EEA/UK, we may block access and/or delete any inadvertently collected data after addressing security and fraud-prevention needs.
We use personal data to:
We treat health/wellness entries and measurements as sensitive. We process such data only as necessary to provide the Service and with your consent where required by applicable law. You may withdraw consent in settings; withdrawal may limit functionality and does not affect prior lawful processing.
The Service is intended for users 18 and older. We do not knowingly collect personal data from children under 18. If you believe a child has provided data, contact us to delete the account and associated data.
The Service uses AI to analyze nutrition data, summarize meals, and assist discovery. AI outputs are estimates and may be inaccurate.
We minimize data sent to AI providers and transmit it with encryption. Under our current enterprise terms, OpenAI does not use submitted data to train its foundation models for our account. We do not permit third‑party providers to use your data for their own advertising.
Where automated processing could have significant effects, you may request human review (see Section 11). You can disable optional AI features in settings where offered.
Some AI features are powered by OpenAI. By using these features, you acknowledge OpenAI’s Usage Policies, Service Terms, and Privacy Policy may apply to the processing of your inputs for those features. You consent to such processing consistent with those policies and this Privacy Policy.
We do not sell personal information. We share data with:
We may disclose information to comply with law, respond to lawful requests, protect safety, and enforce our rights. In a merger, acquisition, or asset sale, data may be transferred subject to this Policy.
Subprocessors List. We maintain a current list of key subprocessors (including locations and purposes) and will make it available upon request.
We may transfer personal data internationally, including to the United States. We implement appropriate safeguards (e.g., contractual and technical measures) and comply with applicable transfer rules in the regions where the Service is offered. Regional transfer frameworks for the EEA/UK are not applicable at launch (see Annex D – Reserved).
The Service may include links to third‑party websites, apps, or services, and may integrate third‑party modules or SDKs. We are not responsible for the content, security, or privacy practices of third parties. Your use of third‑party resources is governed by their terms and privacy policies.
We use administrative, technical, and organizational measures to protect data, including encryption in transit and at rest, access controls, and monitoring. No system is 100% secure; we maintain incident response procedures.
We retain personal data only as long as necessary for the purposes described or as required by law. Indicative periods:
Actual retention may vary based on legal, security, and operational needs.
Depending on your jurisdiction, you may have rights to access, correct, delete, or port your data; to restrict or object to certain processing; and to withdraw consent where processing relies on consent. Submit requests to [email protected]. We will verify requests and respond as required by law.
You may request access to and correction of personal information and raise complaints with local authorities. We will explain our process and timelines when you contact us.
At launch, the Service is not offered in the EEA/UK. If/when we expand, we will publish region‑specific notices, designate representatives, and describe GDPR/UK GDPR rights (access, rectification, erasure, restriction, objection, portability, withdrawal of consent, complaint to authorities).
We may use cookies and similar technologies to operate the Service, remember preferences, and measure performance. Where required, we will request consent. You can manage cookies in your browser or device settings. A detailed Cookie/Tracking Policy may be provided separately.
We may send administrative messages (e.g., security, service updates). Marketing communications are sent with consent where required; you may opt out via unsubscribe links or settings.
We may update this Policy. When we make material changes, we will notify you via the App or email and update the "Last Updated" date. Your continued use after the effective date constitutes acceptance.
We are an independent company and are not affiliated with, endorsed by, or sponsored by OpenAI or its ChatGPT service. References to OpenAI or ChatGPT are for identification only. All trademarks are the property of their respective owners.
Privacy inquiries and rights requests: [email protected]
Security and incident reports: [email protected]
Data Protection Officer (if required): [email protected]
Categories Collected: identifiers (email, device IDs), personal information categories (health entries you submit), internet activity (usage), commercial information (subscription status), inferences (AI recommendations), and approximate geolocation (IP‑based).
Purposes: service provisioning, billing, security, analytics, support, improvements.
Sharing/Sale: service providers only; no sale/share as defined by CPRA.
Rights: know/access, delete, correct, opt‑out of sale/share (not applicable), non‑discrimination.
Consent: meaningful consent for collection, use, and disclosure.
Access/Correction: available upon request; identity verification required.
Transfers: contractual and technical safeguards for cross‑border processing.
Compliance with the Australian Privacy Principles (APPs).
Notifiable Data Breaches scheme: we will notify affected users and the OAIC where required.
Reserved for region‑specific notices applicable when the Service becomes available in the EEA or the UK (including designation of EU/UK data protection representatives and local transfer frameworks).