Privacy Policy

Last updated: 1 September 2026

VitaCal ("we", "our", or "us") is committed to protecting your privacy. This policy explains what VitaCal collects, where it goes, and what you can do about it. It covers the app and its three optional features: Health Sync, the Ask VitaCal AI coach, and VitaCal Connect.

Information We Collect

Account and Profile

Nutrition and Tracking Data

Meal Photos

When you log a meal from a photo, that photo is uploaded to our file storage so it can be analysed, and sent to Google Gemini, which identifies the foods and estimates the nutrition. It is deleted as soon as the analysis finishes. If the AI needs to ask you a clarifying question first, the photo is held until that exchange ends and deleted then. A job runs every five minutes and deletes any meal photo older than ten minutes, so nothing is left behind if an analysis fails partway.

The photo is never attached to the meal you save. A saved food entry holds food names and nutrition figures only, with no image, and there is no option to keep a photo in your log because the app does not store one.

We do keep a short record of each analysis: which file was analysed, its image type, which model ran, and the foods and calories that came back. That record never contains the photo itself, the prompt, or the model's raw output.

Health Data (Health Sync)

Health Sync is off until you turn it on and grant permission on your device. Once connected, VitaCal reads from Apple Health on iOS or Health Connect on Android, and stores what it reads in your account. It can read around 150 data types, and it reads only the ones your platform grants and your devices actually record. They include:

Android reads less. Health Connect exposes a narrower set, and VitaCal asks Android only for workouts, sleep, heart rate, resting heart rate, heart rate variability, steps, distance, floors climbed, active, total and basal energy, weight, height, and the nutrition and water it wrote itself. The heart-and-circulation, reproductive, metabolic, hearing and mindfulness items above are read on iOS only.

Date of birth. On iOS, VitaCal asks Apple Health for your date of birth and uses it once, to estimate your maximum heart rate from your age. Only that estimate is stored; your date of birth is not. Android's Health Connect does not expose it, so nothing is read there. VitaCal's permission request also covers gender and blood type because they sit in the same Apple Health category, but it does not read either.

Workout routes. When a workout has a GPS route, VitaCal uploads the raw latitude, longitude and altitude points to your own folder in our file storage, and derives route segments from them. That is precise location data about where you exercised, and it is kept for as long as the workout is in your account.

Writing back. On Pro, VitaCal writes your nutrition back into Apple Health or Health Connect: energy, protein, carbohydrate, fat and water. It never writes workouts.

Ask VitaCal (AI Coach)

When you send the coach a message, the app sends your recent chat history along with your message. We then send Google Gemini the date, your device locale, the names of the health metrics you have synced, the last four turns of the conversation, and your message. The model can then ask for the data it needs to answer: your health metrics, workouts, sleep, heart rate profile, heart rate zones and timezone.

The coach does not receive your food log, your weight log or your meal photos.

Your coach conversations are saved to your account so the chat history is there when you come back.

VitaCal Connect

VitaCal Connect is off until you set it up. It publishes an endpoint at api.vitacal.app/mcp, and anything holding a valid token for your account can read:

It does not expose your nutrition or food log, your meal photos, or your raw GPS coordinates. A token holder can also change settings on your account: maximum heart rate, heart rate zones, threshold heart rate, timezone and training load model.

There are two kinds of token. One you mint in the app lasts 365 days. If you connect claude.ai, Anthropic is issued an access token that lasts one hour and a refresh token that lasts 90 days, which it uses to keep the connection alive.

Purchases

Subscriptions and AI credit packs are bought through the App Store or Google Play and recorded by RevenueCat, which receives your store purchase receipt and an app user identifier. We never see your card details. Your remaining credit balance is stored on your account record.

Collected Automatically

How We Use Your Information

We use the information we collect to:

We do not use your data to advertise to you, and we do not train AI models on it.

Data Storage and Security

Your data is stored in Firebase, a Google Cloud service, under an identifier unique to your account. Google Cloud encrypts it in transit and at rest. Sign-in is handled by Apple and Google rather than by a password we hold.

Data Sharing

We do not sell your personal information. Your data goes to the following processors, each receiving only what it needs:

We may also disclose information if required by law or to protect our rights and safety, and your information may transfer to a new entity in a merger or acquisition.

Your Rights and Choices

Export

Profile > Tracking > Export Data gives you a JSON file containing your food log, water log, weight log, favourites and nutrition goals. It does not include your synced health metrics, workouts, sleep, workout routes or coach conversations. For a copy of those, email [email protected] and we will send them to you.

Deletion

You can delete your account from Profile > Account > Delete Account, or by emailing [email protected]. Deleting your account erases every document and file we hold under it: your food, water and weight logs, favourites, goals and settings, your meal analysis records, your synced health metrics, sleep sessions and workouts, your workout route files and derived segments, your coach conversations, and your notification schedule. Deletion is permanent and cannot be undone.

Two things are not covered. Any VitaCal Connect tokens you minted remain on record until they expire or you revoke them, so revoke them before you delete your account. And deleting your account does not cancel an active subscription: cancel that in your App Store or Google Play subscription settings.

Access and Correction

You can edit your profile, goals and logged entries in the app at any time. For anything you cannot reach yourself, email [email protected].

Turning Health Sync Off

Health Sync can be revoked from Apple Health or Health Connect on your device, which stops VitaCal reading anything new. Data already imported stays in your account until you delete your account or ask us to remove it.

Revoking VitaCal Connect Access

Tokens you minted yourself are listed in the app, and you can revoke any of them there.

A connection you authorised from claude.ai is not shown in that list and cannot be revoked from inside the app. To end it, disconnect the VitaCal connector in the connected application's own settings, which is where you authorised it. If you cannot get to those settings, email [email protected] and we will revoke it for you. Its access token expires an hour after it was issued, and its refresh token 90 days after.

Data Retention

Children's Privacy

VitaCal is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected such information, please contact us immediately.

International Users

VitaCal runs on Google Cloud, and your data is processed on Google Cloud infrastructure. Your data is stored in the United States: the database sits in Google's United States multi-region and uploaded files in its Iowa (us-central1) region. If you are in the United Kingdom, the European Union or Switzerland, using VitaCal therefore transfers your data to the United States. For that transfer we rely on the data transfer commitments in Appendix 3 of Google's Cloud Data Processing Addendum, which covers the EU GDPR, the UK GDPR and the Swiss FADP.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any significant changes by posting the new policy in the app or via email.

Contact Us

If you have questions about this Privacy Policy or our practices, please contact us at:

Email: [email protected]
Website: https://vitacal.app