What we collect, why we collect it, how your health data is processed, and the control you have over it.
Version 2026-10-07
VitalSync is a wellness and fitness application operated by NIHAR JENA, DOEBLERGASSE 3, 1070 VIENNA, AUSTRIA.
This policy explains what we collect when you use VitalSync, why we collect it, how it is processed, and the rights you have over it.
We calculate estimated targets (such as a daily calorie and macronutrient target) from your profile. These are estimates only and are never presented as medical measurements.
We record product analytics events, such as when a scan, workout or log entry is created, to understand which features are used. These events contain no health values and are not tied to advertising.
Your AI features run through a third-party AI model provider acting as our processor. When you ask a question or request a briefing, plan or review, the app builds a summary of your relevant data — your profile, today's logged food names and totals, hydration, training, recent sessions, activity, last sleep, weight trend and work schedule — and sends that summary to the model.
When you submit a food photo, the image is uploaded to private storage and shared with the model provider as a short-lived private link so it can be analysed. The photo is not published and not used as a public asset.
AI output is generated automatically and can be wrong. It can contain inaccuracies in food identification, portion estimation and macro estimates. You can edit any value before saving it, and estimates are labelled as estimates throughout the app.
We do not use your data to train AI models ourselves, and we do not sell your personal data.
Where the GDPR or comparable law applies, we process this data because it is necessary to perform our contract with you (providing VitalSync), because you consented to the processing of health and fitness information when you completed onboarding, and because we have a legitimate interest in keeping the service secure and functional. You can withdraw consent at any time by deleting your data (see below), which ends your use of the personalised features.
Subscriptions are sold and processed by our payment provider through their hosted checkout. They receive your payment details, billing information and email in order to complete the transaction, and they act under their own terms and privacy policy. We receive only the confirmation needed to activate your plan.
Your records are stored in your app account and are isolated to your user account by database access rules: records are readable and writable by you, and by administrators only where strictly necessary to operate the service.
Progress photos are stored privately. Access is granted through short-lived private links, so they are not publicly reachable.
We do not sell, rent or trade your personal information. We share it only with the processors needed to run the service — the AI model provider that generates your coaching, our payment provider (Base44 Payments, operated on Wix) for card payments, and the Base44 platform for hosting, private file storage and sign-in — and where the law requires it.
Deleting your account erases the records that reference your uploaded photos. If you also need the stored file objects themselves removed, ask support and we will action it for you.
Your logs, profile, photos, coach messages and derived reports are retained while your account exists so your history and trends keep working.
Daily usage counters used to apply free-plan limits are kept for a short period and can be cleaned up without affecting your history.
When you delete your account, your personal records are deleted as described below. Records we must keep for legal, tax or accounting reasons (for example payment confirmations) are retained for the period the law requires.
Access to your records requires signing in, and database access rules restrict each record set to its owner. Payment credentials and AI provider keys are held server-side and are never sent to the browser.
No system is perfectly secure. If you believe your account has been compromised, change your password and contact us.
VitalSync is not intended for children. Onboarding requires an age above 12, and we ask that the app is used only by people old enough to consent to the processing of their own health data in their jurisdiction.
Our providers may process data in countries other than yours. Where required, transfers rely on the safeguards those providers put in place, such as standard contractual clauses.
We may update this policy as the product changes. The version date is shown at the top. Material changes will be surfaced in the app before they take effect.
Controller: NIHAR JENA, DOEBLERGASSE 3, 1070 VIENNA, AUSTRIA. Contact: support.vitalsync@gmail.com.
Where applicable, you can also complain to the data protection authority in AUSTRIA.