Vitly Privacy Policy
Effective date: February 17, 2026
This Privacy Policy explains how Vitly ("Vitly", "we", "us") collects, uses, shares, and protects information when you use the Vitly mobile application and related services (the "App").
If you do not agree with this policy, please do not use the App.
1. Who We Are
Vitly B.V. provides a health and wellness app that helps users track nutrition, activity, and body metrics and receive personalised recommendations. In most cases, Vitly B.V. acts as the data controller for personal data collected through the App. If your employer provides the App to you, your employer may be the controller and Vitly B.V. may act as a processor on its behalf.
2. Scope
This policy applies to the Vitly mobile App and the related backend services that power it. It does not cover third-party services you choose to connect (such as Apple Health/HealthKit, Google Health Connect, or Garmin Connect) except as described in Section 8.
We do not use cookies or tracking pixels in the App.
3. Information We Collect
We collect the following categories of information, depending on how you use the App:
- Account and identity data: email address, name, company domain, and user ID.
- Demographics and intake data: age, sex/gender, height, weight, activity level, goals, injuries, dietary preferences, and lifestyle inputs.
- Health and biometric data: body scan images or PDFs, extracted body composition metrics, and optional device health data such as steps, heart rate, sleep, calories, distance, weight, and water.
- Voice and audio data: if you use the voice input feature, your microphone audio is recorded and transmitted to OpenAI for transcription. Audio is not stored on our servers after transcription is complete.
- Nutrition data: meal logs, macros, restrictions, saved meals, and meal plans.
- Fitness data: workout plans, exercises, completions, and activity summaries.
- Behavioural data: in-app activity points, streaks, achievements, and gamification progress used to personalise your experience.
- Notifications data: push notification token and preferences.
- Usage and diagnostics: app error logs and diagnostics if enabled.
- Device and app data: basic device identifiers and app configuration needed for functionality.
4. How We Use Information
We use your information to:
- Provide core app functionality, including personalised meal plans, workouts, and progress tracking.
- Process body scans and generate health insights using AI.
- Transcribe voice input to support hands-free data entry.
- Sync and display health data from connected device platforms, if you enable them.
- Send optional notifications and reminders.
- Maintain security, prevent abuse, and debug issues.
- Improve app performance and reliability.
5. AI Processing
Vitly uses AI features powered by OpenAI (GPT-4o) to analyse body scans, transcribe voice input, and generate personalised meal plans, workout plans, and health tips.
Body scans: When you upload a body scan, the image is transmitted from our backend servers to OpenAI's API for analysis. We do not include direct identifiers such as your name or email in these requests. Body scan images may be downscaled before transmission, but the image content itself is shared with OpenAI as a third-party processor.
Voice input: When you use the voice input feature, your audio recording is transmitted to OpenAI's API for transcription. The audio is not stored on our servers after the transcription response is returned.
OpenAI data retention: Under our agreement with OpenAI, data submitted via the API is not used to train OpenAI's models and is not retained by OpenAI beyond the period needed to return a response (typically zero data retention for API calls under our API usage tier).
AI-generated recommendations are produced automatically based on your inputs. These outputs are intended as general wellness guidance and do not constitute medical advice. If you have questions about how a specific recommendation was generated, contact us using the details in Section 16.
6. Legal Bases (Where Applicable)
Depending on your location, we process data based on one or more of the following:
- Contractual necessity to provide the App and its features.
- Your explicit consent for special category data (health and biometric data, including body scan images and voice recordings) and optional features such as Garmin integration.
- Legitimate interests for security, fraud prevention, and service reliability.
You may withdraw consent at any time using either of the following methods:
- In the App: go to Settings → Delete Account to remove your account and associated data.
- By email: contact [email protected] to request withdrawal of consent for specific processing.
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
7. Sharing of Information
We do not sell your personal information. We do not share health data collected via Apple HealthKit, Google Health Connect, or Garmin with advertisers, data brokers, or any third party for advertising purposes.
We share data only with the following categories of service providers and partners who help us operate the App:
| Category | Purpose |
|---|---|
| Database, authentication, and storage providers | Store account data and files (including body scan uploads). |
| Backend hosting providers | Run our API services and infrastructure. |
| AI service providers | Analyze body scans, transcribe voice input, and generate personalised recommendations. |
| Error monitoring providers | Diagnose crashes and improve reliability. |
| Push notification providers | Deliver notifications if you opt in. |
| Wearable platform partners | Sync health data if you connect a wearable account. |
| Content delivery providers | Serve workout and meal illustration images; your IP address may be shared as part of standard HTTP requests. |
Each provider is permitted to process your data only to deliver their services to us and is required to protect it under a data processing agreement or equivalent safeguard.
You can request a current list of subprocessors by contacting [email protected]. If we add or replace subprocessors in a way that materially affects how your data is processed, we will update this policy and notify you in the App or by other appropriate means.
8. Health Platform and Wearable Integrations
Apple Health / HealthKit
If you connect Apple Health/HealthKit, you control what data categories are shared via your device permissions. Data read from HealthKit is used only to display your health metrics and provide personalised recommendations within the App. It is not used for advertising, shared with data brokers, or combined with third-party data for advertising purposes. You can revoke access at any time in your iOS device settings under Privacy & Security → Health.
Google Health Connect
If you connect Google Health Connect, you control what data categories are shared via your device permissions. You can revoke access at any time in your Android device settings.
Garmin Connect
If you choose to connect your Garmin account, Vitly receives daily health summaries (such as steps, heart rate, sleep, calories, and activity duration) pushed directly from Garmin's servers to our backend via the Garmin Health API. You authorise this connection through Garmin's OAuth flow. You can disconnect your Garmin account at any time in the App settings under Wearables, which stops future data transfers and removes your stored Garmin credentials from our systems.
9. Company and Employer Relationship
Vitly is made available to users through their employer or company. Your company's email domain is used to verify eligibility. Vitly does not share individual user health or biometric data with your employer. Company administrators may have access to account-level information (such as whether an account exists) for the purpose of managing access, but they do not have access to your personal health data, body scans, voice recordings, or activity within the App.
10. Data Retention
We retain your information while your account is active. Upon account deletion:
- Profile and health data are deleted from our active database immediately.
- Body scan images stored in our file storage are deleted within 30 days of account deletion.
- Voice recordings are not stored on our servers after transcription is complete.
- Backups and logs may retain data for up to 90 days before being purged as part of routine backup cycles.
We may retain certain data longer where required to comply with legal obligations or resolve disputes.
11. Security
We use administrative, technical, and physical safeguards to protect your data, including:
- Encrypted data transmission (HTTPS/TLS) between the App and our servers.
- Encrypted on-device storage for authentication tokens (using device-level secure storage).
- Access controls limiting who can access your data within our systems.
No system is completely secure. In the event of a personal data breach that is likely to result in high risk to your rights and freedoms, we will notify affected users without undue delay and will report the breach to the relevant supervisory authority within 72 hours as required by applicable law.
12. Your Choices and Rights
Depending on your location, you may have the right to access, correct, export, restrict, or delete your data, and to object to or withdraw consent for certain processing. You can:
- Update your profile information in the App.
- Control notification preferences in the App.
- Disconnect Garmin or other health integrations in the App settings under Wearables.
- Export your data using the self-service Data Export button in App Settings, which downloads a copy of your personal data in a portable format (GDPR Article 20).
- Delete your account in App Settings → Account → Delete Account.
- Contact us at [email protected] to request access, correction, deletion, or a portable copy of your data.
If you are located in the European Union, you also have the right to lodge a complaint with your local data protection supervisory authority if you believe your data has been processed unlawfully.
13. International Transfers
We aim to process your data within the European Economic Area. If any transfer outside the EEA occurs, we will ensure appropriate safeguards are in place, such as standard contractual clauses approved by the relevant authority.
14. Children's Privacy
Vitly is intended for adults and is not directed at children. Given that the App collects health and biometric data, we require users to be at least 18 years old, or the minimum age required by your local laws if higher. We do not knowingly collect data from anyone below this age.
15. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will notify you in the App or by other appropriate means. The effective date at the top will reflect the latest version.
16. Contact Us
If you have questions or requests about this policy or your data, contact us at:
Legal entity: Vitly B.V.
Address: De Boelelaan 1095-A, 1081HV Amsterdam, The Netherlands
Email: [email protected]
Website: https://www.vitly.work/
