VITA
Privacy
Last updated: August 2026
In brief
Vita is an iPhone app with no account and no server of its own for your data. Everything Vita knows about your body and your nutrition — Apple Health values, your food diary, products, weight, analyses — lives on your device and is computed there. Apple Health data never leaves your iPhone. A few optional features send specific, minimal data to services — each only with your explicit consent and each can be switched off at any time. There is no advertising, no tracking and no analytics SDKs.
The app
- On-device processing: your food diary (products, meals, entries, creatine log, daily notes) and all analyses are stored locally on your iPhone. There is no account and no Vita server storing this data. If VeloStats is installed on the same iPhone, Vita can read time windows and energy (kJ) of power-measured rides from a shared, device-local keychain area — that stays on the device too.
- Apple Health: only after you grant access in iOS, Vita reads sleep, heart rate variability, resting heart rate, respiratory rate, sleeping wrist temperature, VO₂max, heart rate recovery, steps, active energy, exercise minutes, workouts, body weight, height, date of birth and biological sex, plus — only where your Health profile provides it — cycle data. In iOS you decide for each value individually whether Vita may read it. Vita writes nothing to Apple Health. Health data is evaluated exclusively on the device — it is never part of the iCloud backup or of any AI request.
- iCloud backup (optional, off by default): if you enable "Back up to iCloud" in Settings, Vita mirrors your food diary into the private iCloud database of your own Apple account (Apple CloudKit, encrypted by Apple). There is no Vita server in between, and we have no access to this data. Apple Health data is never part of it. If you switch the toggle off, mirroring stops; data already backed up can be deleted in the iCloud settings of iOS.
- Barcode lookup (optional): when you scan a barcode, the app — after your one-time consent — queries the open product database Open Food Facts. Only the barcode is transmitted (for technical reasons Open Food Facts sees your IP address in the process) — no name, no diary or health data. The answer is cached locally.
- Nutrition photo scan (optional): if you photograph a nutrition table, a label or a plate, the app sends the photo (and any short hint text you add) to our server — a Cloudflare Worker operated by us — which passes it on to the AI service Anthropic (Claude) for analysis. The photo is stored neither by us nor in the app. To limit abuse (daily quota), an anonymous, resettable device identifier (Apple's "identifierForVendor") travels along — no Apple ID, no name; our server keeps it only together with a daily counter for 24 hours. You can revoke this consent in Settings at any time.
- "Ask Vita" (optional): the assistant sends your question as text to the same server and from there to Anthropic (Claude). So that known items are recognised, the names of your catalogue products travel along (names only — no quantities, no entries), as does the anonymous device identifier for the daily quota. Only if you give an explicit second consent, a small curated set of derived key figures is added (for example store fill levels in percent or today's modelled expenditure — the app shows you verbatim beforehand which lines these are); never raw history, never individual entries, never your weight history, never health data. The assistant only makes suggestions — nothing is saved until you confirm in the app. Questions and answers are not stored permanently by us. Both consents can be revoked in Settings at any time.
- Feedback from the app (voluntary): if you send feedback, the app transmits your text, the chosen category, app version, build number and iOS version — no name and no device identifier. Screenshots are included only if you deliberately select them. The feedback is stored as an entry in a private GitHub repository of the developers so we can reply; to show you replies, the app asks our server for the status of your own feedback items (their numbers only).
- Update hint: at launch the app asks our server whether a newer version exists. Only the app name is transmitted — no identifier, no content.
- No advertising, no tracking: Vita contains no advertising, tracking or analytics SDKs and shares no data with third parties beyond the services named here.
- Beta via TestFlight: during the beta, Apple distributes the app via TestFlight. We receive crash reports and TestFlight feedback from Apple only to the extent you allow this in TestFlight; Apple's TestFlight terms apply.
Services that receive data
- Apple — iCloud/CloudKit (only with backup enabled) and TestFlight (during the beta).
- Cloudflare, Inc. — runs the infrastructure of our server (photo scan, assistant, feedback, update hint) and processes technically necessary connection data such as the IP address in doing so.
- Anthropic — AI analysis for photo scan and assistant, only with your consent.
- Open Food Facts — barcode lookup, only with your consent.
- GitHub — storage of your feedback, only if you send feedback.
This website (velostats.app)
The pages under velostats.app/vita follow the same rules as the rest of the website: no cookies apart from the strictly necessary language-choice cookie (DE/EN), no trackers, no analytics services; your browser loads the fonts from Google Fonts (Google sees your IP address in the process, but no cookies). The website runs on Cloudflare Workers. Whatever you send via the contact form or by email to support@velostats.app is used solely to answer your enquiry, is not shared with third parties, and is deleted automatically after 90 days at the latest.
Deleting your data
Local data: delete the app — this removes the diary and analyses from the device; you can withdraw Health access at any time in the iOS settings. iCloud backup: switch the toggle off in Vita and delete the backed-up data in the iCloud settings of iOS. For questions, access requests or deletion of feedback you sent: support@velostats.app.
Controller
David Gertis
support@velostats.app