Privacy Policy
Last updated: 2 September 2026
Your raw Apple Health samples and blood test results stay on your device. To build your plan and sync it across your devices, VitSync computes a few summary signals (your sleep, HRV and activity averages, and cycle phase) and stores those, encrypted and scoped to your account. Your safety screening answers (medications, conditions, allergies) are also stored with your account so your plan stays safe across devices. We don't sell your data. We don't share it with advertisers. VitSync is a wellness tool, not a data business.
Who we are
VitSync is operated by VitSync Ltd, registered in the United Kingdom. When we say "we", "us", or "VitSync" in this policy, we mean VitSync Ltd.
VitSync Ltd is registered as a data controller with the UK Information Commissioner's Office (ICO), registration reference ZC133229.
For questions about this policy or your data, contact us at hello@vitsync.com.
Where you are
VitSync is available on the App Store in the United Kingdom only. This policy is written to satisfy UK GDPR and the Data Protection Act 2018. If we open the app in other countries we will update this policy before we do.
Our processing of your personal data is intentionally minimal:
- Raw Apple Health samples and blood test results are processed on your device and are never persisted on our servers. Computed summary signals (your sleep, HRV and activity averages, and cycle phase) and your generated supplement plan are stored, encrypted and scoped to your authenticated account, so your plan persists and adapts across your devices.
- Account information, plan summaries, and chat messages are stored with Firebase / Google Cloud in the United States (Firestore multi-region
nam5). Chat messages are also sent to Anthropic in the United States to generate a reply. - Because both providers are in the United States, your data is transferred outside the United Kingdom. Where the provider is certified under the EU-US Data Privacy Framework and its UK Extension, the transfer relies on the UK adequacy regulations for that framework (UK GDPR Article 45). Otherwise it relies on the standard contractual clauses and UK International Data Transfer Addendum in Google's and Anthropic's data processing terms (UK GDPR Article 46). Anthropic retains chat data for up to 30 days for safety and abuse-prevention purposes only and does not train models on it.
What data we collect
VitSync collects the following categories of data to build and adapt your supplement plan:
- Apple Health data, sleep duration, sleep quality, heart rate variability (HRV), exercise minutes, step count, and nutrition data (if you log food in apps like MyFitnessPal). This data is read from Apple Health with your permission and processed on your device.
- Profile information, age, height, weight, gender, health goal, dietary habits, and safety screening answers (medications, conditions, allergies). You provide this during onboarding.
- Blood test results, if you choose to enter them. These are optional and stored exclusively on your device. They are never persisted on our servers. When the VitSync engine generates a weekly plan they are transmitted in a single API request, used in memory to build the engine's reasoning, and discarded as soon as the response returns. See "How your data is processed" below for the full data flow.
- Chat conversations, messages you send to the VitSync assistant. These are processed by the VitSync engine, which is powered by an Anthropic API. We send your current plan data and conversation context to generate relevant answers.
- Account information, if you sign in with Apple, we receive your Apple ID and optionally your name and email. We use Firebase Authentication to manage your account.
- Purchase records, when you confirm a supplement purchase through VitSync, we store the ingredient, date, and estimated bottle size locally to track your supply levels.
How your data is processed
Raw Apple Health samples stay on your device and are never transmitted. To build and sync your plan, VitSync computes summary signals on your device (your sleep, HRV and activity averages) and stores those, encrypted and scoped to your account. Your safety screening answers (medications, conditions, allergies) are stored with your account too, so your plan stays safe across devices.
Your supplement plan is built by the VitSync engine using your Apple Health data, profile answers, and any blood results you have entered.
The engine has two parts: an on-device rules layer (which always runs) and a server-side reasoning layer hosted in our Cloud Functions and powered by an Anthropic API. When the server-side layer runs, it receives a single request from your device containing the data needed to build that plan, generates the plan, and returns it. Critically:
- Blood test results are sent in this request only when needed and are never persisted on our servers. They live in memory for the duration of the plan-generation call and are discarded when the response returns.
- Your generated plan (ingredient names, doses, explanations) is stored under your authenticated Firestore account so it persists across devices and so the next week's plan can reference what was recommended last week. Plan storage does not include any blood biomarker numbers.
- Apple Health data is read on-device and used to compute summary signals (sleep average, HRV average, active minutes). Only those summary signals are sent to the server, where they are stored under your encrypted, authenticated account so your plan persists and adapts across devices. Raw HealthKit samples are never transmitted.
When you use the VitSync chat, your message and relevant plan context are processed by the VitSync engine. The Anthropic API processes this data under their privacy policy, retains it for up to 30 days for safety and abuse-prevention purposes only, then deletes it. We do not use your chat data to train AI models, and the Anthropic API does not train on data sent through it.
Emergency safety records. If a chat message indicates a possible emergency (for example self-harm or a serious medical symptom), the app replies with local emergency contacts instead of an AI answer, and we store a minimal safety record: your anonymous account identifier, the category of the trigger, and a timestamp. The text of your message is deliberately not stored. These records exist so we can verify the emergency signposting works and are never used for anything else. They are included in your data export and permanently deleted when you delete your account.
Your account profile, plan history, and chat transcripts are also stored in Firebase (Google Cloud) so they persist across devices. This data is encrypted in transit and at rest, and is only accessible to your authenticated account.
What we don't do
- We don't sell your personal data to anyone.
- We don't share your data with advertisers.
- We don't use your health data for targeted advertising.
- We don't store your raw Apple Health samples or your blood test results on our servers.
- We don't access your data without your explicit permission.
Third-party services
VitSync uses the following third-party services:
- Anthropic API, powers the VitSync engine's reasoning for plan generation and chat responses. Receives your message + relevant context, returns a response. Privacy policy.
- Firebase (Google), authentication, Firestore data sync, Cloud Functions, Firebase Analytics, and Crashlytics. Firebase Analytics receives app event names such as screen_view, plan_generated, chat_message_sent, affiliate_link_tapped, purchase_confirmed, subscription_started, and share_credit_redeemed, plus limited non-health parameters for app flow. It does not receive Apple Health values, blood biomarker values, chat message text, or supplement plan text. Crashlytics receives crash and non-fatal error reports, the Firebase user identifier, device model, OS version, and error context so we can fix faults. Privacy policy.
- Apple (HealthKit, StoreKit, WeatherKit), health data access, subscription management, weather data. Privacy policy.
- Amazon Associates, affiliate links for supplement purchases. When you tap a buy link, you leave VitSync and enter Amazon's platform. We receive a commission on qualifying purchases but do not receive your Amazon purchase history or payment details.
Data retention
Your profile, plan history, and chat transcripts are stored locally on your device using Apple's SwiftData framework. If you sign in and sync is enabled, a copy is stored in Firebase Firestore under your authenticated account.
You can delete all your data at any time with the "Delete account" option in Profile, which removes both on-device data and everything stored under your account on our servers. You can also email hello@vitsync.com and we will delete your server-side data for you.
Children
VitSync is designed for adults aged 18 and over. If you are under 18, the app's safety gate will block all supplement recommendations and display a message directing you to consult a healthcare professional. We do not knowingly collect data from children under 18.
Your rights
Under UK GDPR and the Data Protection Act 2018, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data ("right to be forgotten")
- Object to or restrict processing
- Data portability, receive your data in a machine-readable format
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with a supervisory authority (see below)
To exercise any of these rights, email hello@vitsync.com. We will respond within one calendar month, as required by UK GDPR Article 12.
Supervisory authorities
If you believe we have not handled your personal data in line with the law, you have the right to complain to your local data protection authority. You can also contact us first at hello@vitsync.com and we will try to resolve your concern.
- United Kingdom: Information Commissioner's Office (ICO), ico.org.uk
The app is sold in the United Kingdom only. If you are outside the UK and have used vitsync.com, you can also raise a concern with the data protection authority for your own country.
Cookies
vitsync.com uses two non-essential cookies set only after you accept on the consent banner: Google Analytics 4 (with IP anonymisation) for visitor counts, and the LinkedIn Insight Tag for ad-campaign measurement. Both default to denied; we do not set them until you click Accept. You can change your decision at any time using the link below.
EU representative
The VitSync app is not sold in the European Economic Area; only our website is reachable from there. VitSync Ltd also processes a limited and clearly delimited set of personal data. Raw Apple Health samples and blood test results are processed on your device and are not persisted on our servers; the health-derived data we receive and store are summary signals (your sleep, HRV and activity averages, and cycle phase) and your safety screening answers (medications, conditions, allergies), held encrypted and scoped to your authenticated account to build and keep your plan safe across devices. On that basis we rely on the exemption in Article 27(2)(a) of the EU GDPR for processing that is "occasional, does not include, on a large scale, processing of special categories of data... and is unlikely to result in a risk to the rights and freedoms of natural persons".
Anyone in the EEA who wants to raise a data-protection issue can contact us directly at hello@vitsync.com. If we open the app in the EEA, we will appoint a designated EU representative and update this policy before we do.
Changes to this policy
We may update this policy from time to time. If we make material changes, we'll notify you through the app or by email. The "last updated" date at the top of this page reflects the most recent revision.
Contact
If you have questions about this privacy policy or how VitSync handles your data:
Email: hello@vitsync.com
Website: vitsync.com
Back to VitSync