Vital

Privacy Policy

Effective August 16, 2026

Private personal health and performance software.

Vital is a private personal health and performance application designed for a very small number of authorized users. Vital is not an advertising platform, social network, public health service, or data brokerage service.

This Privacy Policy explains what information Vital processes, how that information is used, and the services involved in operating the application.

Information Vital Processes

Vital may process information you provide directly, including:

  • Account information such as your email address and application preferences.
  • Bodyweight measurements and daily check-ins.
  • Workout plans, exercises, sets, and training history.
  • Nutrition entries, foods, meals, calorie and macronutrient information.
  • Skincare routines and skin observations.
  • Goals, routines, reminders, and completion history.
  • Progress photos and optional notes or capture metadata.
  • Other health or wellness information you choose to enter into Vital.

WHOOP Data

If you choose to connect your WHOOP account, Vital requests access only to the WHOOP information required for its features.

Vital currently requests permission to access:

  • Basic WHOOP profile information.
  • Recovery data.
  • Physiological cycle data.
  • Sleep data.
  • Workout data.

Vital also requests offline access so that it can refresh your authorization and keep your WHOOP information synchronized.

Vital does not currently request WHOOP body-measurement access.

WHOOP data may include information such as Recovery score, heart-rate variability, resting heart rate, sleep duration and performance, Strain, workout information, and associated timestamps.

Connecting WHOOP is optional. You may disconnect WHOOP from Vital at any time.

How Vital Uses Information

Vital uses your information only to provide personal health and performance features, including:

  • Displaying your health and fitness history.
  • Tracking goals and progress.
  • Calculating deterministic trends and summaries.
  • Managing workouts, routines, nutrition, skincare, and reminders.
  • Displaying WHOOP Recovery, sleep, HRV, resting heart rate, Strain, and related trends.
  • Synchronizing data you have authorized Vital to obtain from WHOOP.
  • Providing features that you explicitly request, such as food search or meal-image analysis.
  • Maintaining application security and reliability.

Vital does not use WHOOP Recovery or other wearable scores as automatic medical clearance and does not automatically change your training plan based solely on WHOOP information.

AI-Assisted Features

Vital includes optional AI-assisted nutrition, health interpretation, Ask Vital, and Voice Log features. AI health coaching and Voice Logging are off until you enable them.

When you explicitly choose features such as meal-photo analysis or nutrition-label scanning, the selected image and information necessary to perform that request may be transmitted to OpenAI for processing.

When you enable and use AI Coach or Ask Vital, selected Vital health and performance data relevant to your request, and your question when applicable, are sent to OpenAI for processing. Vital does not send your email address, WHOOP authorization tokens, or progress photos to the health coach.

Ask Vital does not create a server conversation or long-term AI memory. The running app may keep up to six recent question-and-answer display entries for the current account; you may clear them, and they are cleared on sign-out, account switch, or app-process exit.

When you explicitly tap Voice Log, a short recording is sent to OpenAI for transcription. Vital does not intentionally store the raw recording permanently. The transcript may be sent to OpenAI in a subsequent request to prepare a structured logging proposal that you can review or cancel.

AI output is treated as a proposal and is not automatically accepted as authoritative health or nutrition data. You are given an opportunity to review or correct results before they become confirmed Vital records.

A transcript or natural-language request does not write canonical health data. A supported health action is written only after you explicitly confirm the review card.

Progress photos are separate from meal-analysis images and are not automatically submitted for AI analysis.

Vital AI provides wellness and performance interpretation, not medical diagnosis, treatment, or emergency assessment.

OpenAI processes information under its applicable API data policies. Vital does not claim that these requests have Zero Data Retention.

Food Data Services

Vital may use third-party food databases, including:

Food searches, product identifiers, or barcodes may be sent to these services when necessary to find nutrition information.

Storage and Service Providers

Vital uses Supabase for services including authentication, database storage, private file storage, and server-side application functions.

Information may therefore be processed by Supabase as necessary to operate Vital.

WHOOP information is obtained only after you authorize Vital through WHOOP's OAuth authorization process.

Vital may also use OpenAI, USDA FoodData Central, and Open Food Facts for the specific optional features described above.

Vital does not sell, rent, or license your personal information or WHOOP data.

Vital does not use your health or WHOOP information for advertising.

Progress Photos

Progress photos are treated as private data.

They are stored in private storage protected by authenticated access controls and are not given public URLs.

Vital does not provide public profiles or automatically share progress photos with other users or third parties.

WHOOP Authorization Credentials

WHOOP access and refresh credentials are stored only on Vital's server infrastructure.

They are not stored as ordinary mobile application data and are not exposed to the Vital client.

Vital protects stored WHOOP credentials using encrypted server-side storage.

Data Security

Vital uses reasonable technical safeguards designed to protect personal information, including:

  • Authenticated user accounts.
  • Per-user database access controls.
  • Private file storage.
  • Encryption in transit.
  • Server-side storage of integration credentials.
  • Encrypted WHOOP access and refresh tokens.
  • Account isolation between Vital users.

No system can guarantee absolute security, but Vital is designed to minimize access to sensitive information and limit data exposure.

Data Sharing

Vital does not sell personal information.

Information is shared with service providers only when necessary to operate a feature you have chosen to use.

These may include:

  • Supabase — application hosting, authentication, database, file storage, and backend functions.
  • WHOOP — account authorization and WHOOP data synchronization.
  • OpenAI — optional meal-photo and nutrition-label analysis, selected AI Coach/Ask Vital context, and explicit Voice Log transcription.
  • USDA FoodData Central — food and nutrition lookup.
  • Open Food Facts — barcode and food-product lookup.

Vital does not use third-party advertising networks or behavioral advertising analytics.

Data Retention and Deletion

Vital retains personal information for as long as it is needed to provide the application or until it is deleted.

Individual records and progress photos may be deleted where the application provides that functionality.

When a progress photo is deleted, Vital is designed to remove both the private stored image and its associated application record.

Disconnecting WHOOP stops future synchronization and removes Vital's stored authorization credentials. Previously imported WHOOP history may remain in Vital unless it is separately deleted.

Where account deletion is available, Vital attempts to revoke connected integrations, destroys Vital's stored integration credentials, and removes live account data and associated private files. If provider revocation cannot be confirmed, Vital reports that state instead of claiming completion. Limited copies may temporarily remain in infrastructure backups until those backups expire under the service provider's normal retention process.

Vital provides an authenticated machine-readable export of canonical account data. The ordinary lightweight export excludes progress photos, private photo paths, authentication sessions, integration credentials, provider secrets, and operational logs.

Your Choices

You may:

  • Choose whether to connect WHOOP.
  • Disconnect WHOOP at any time.
  • Choose whether to enable AI Coach and, separately, Voice Logging.
  • Delete supported records and progress photos.
  • Export supported canonical account data in a private machine-readable file.
  • Delete your Vital account after recent password confirmation.
  • Control notification permissions through your device.
  • Choose whether to enable biometric App Lock.

WHOOP authorization may also be revoked through WHOOP where supported.

Health Information Disclaimer

Vital is a personal wellness and performance tool.

It is not a medical device and does not provide medical diagnosis, treatment, or emergency medical services.

Information displayed by Vital, including WHOOP information and AI-assisted output, should not be considered a substitute for professional medical advice.

Children's Privacy

Vital is intended for adult users and is not designed for children.

Changes to This Policy

This Privacy Policy may be updated if Vital's features, integrations, or data practices materially change.

The effective date at the top of this policy will be updated when changes are made.

Contact

Questions about this Privacy Policy or Vital's handling of personal information can be directed to:

aydenlhughes@hotmail.com