VITAL

YOUR VITAL

Privacy policy

Last updated 13 September 2026

Vital helps you understand your health without using your health information for advertising. This notice explains what stays on your device, what optional features send to our services, and the choices you have.

Who is responsible

LMS Labs Ltd, Scotland (company number SC888839), operates Vital and is the controller of personal information used to provide the service. Contact business@lmslabsltd.com for privacy questions, access requests or deletion help.

Your device and Apple Health

Vital stores your local profile, logs and history on your device. If you allow access to Apple Health, it reads the categories you approve to provide your readings and history. Depending on the features you use, these can include sleep, heart rate, resting heart rate, heart-rate variability, heart-rate recovery, blood oxygen, respiratory rate, fitness estimates, steps, distance, stairs, energy, exercise, standing, mindful minutes, body measurements, nutrition, water, caffeine and workouts. Profile information such as age, sex, height and weight helps personalise the experience.

You can decline Apple Health access, change individual permissions in Apple’s Health settings, and use manual logging where supported. Local app data uses iOS file protection; account tokens use the device’s Keychain. An optional app lock adds a screen-access control.

Optional accounts and cloud sync

You can use Vital without registering. If you create an account, we process your email or the identifiers supplied by Apple or Google, account dates and your chosen profile details to authenticate you. A temporary anonymous account may be used to associate an App Store purchase before registration.

Cloud sync is a separate choice. When enabled, it sends supported profile details, preferences, workouts and sets, food and drink entries, body measurements, daily health summaries, and other supported logs to our Supabase backend in Stockholm, Sweden. These summaries can include health measurements, including heart rate, heart-rate variability and sleep information; they are not limited to scores. Progress photos you choose to sync are stored in private cloud storage. Sensitive features such as mood and cycle tracking have their own controls. If you record them and enable the applicable sync, profile and cycle records can include pregnancy due dates, symptoms and intimate cycle information.

Turning sync off stops new general sync transfers. It does not itself erase information already stored in your account. A minimal record of your withdrawal may still be sent so the service can respect and record your choice. Use account deletion to request erasure.

Food search and external services

When you approve external food lookup, a search term or barcode may be sent through our service to food-data providers such as FatSecret, Open Food Facts or USDA FoodData Central. Do not put private health details in a food search. When a completed catalogue search returns no results, we retain the search text and app version to identify missing foods and improve catalogue coverage. This catalogue-maintenance processing is separate from optional onboarding usage sharing. The current app does not provide the retired AI chat, AI insight or AI photo-analysis features. Records from older versions may remain until deleted under the applicable retention controls.

Purchases

Apple processes payments; we do not receive your card details. Vital and RevenueCat process product identifiers, transaction identifiers, purchase and expiry dates, trial and renewal state, country or storefront information and an app-specific customer identifier to recognise purchases, restore access and understand subscription performance. RevenueCat also receives technical information needed to provide its service, such as app and operating-system version, Apple’s identifier for vendor (a device identifier used within the app vendor’s apps), and connection information. We do not send RevenueCat your HealthKit readings, logs, photos, name or answers to health questions.

Deleting Vital or your Vital account does not cancel an Apple subscription. Manage or cancel it in Apple’s subscription settings.

Optional app-usage information

If you choose to share app usage, we record which onboarding steps were reached and whether key actions, such as continuing, completing onboarding or starting a purchase, succeeded. This helps us identify confusing steps. Events use a random identifier and contain no name, email, health answers, HealthKit readings, photos, free-text input or advertising identifier. We do not record your screen or your keystrokes.

This choice is off by default and can be changed in Privacy & data. Declining it does not block the app. Raw events are retained for up to 30 days; aggregated counts contain no individual event history. Connection metadata may be used separately to prevent abuse of the event service. Counts represent users who chose to share usage, so they do not describe everyone using Vital.

Diagnostics, support and service security

Crash and performance reports are stored locally unless you choose to share them, or separately opt into Apple’s diagnostic-sharing settings. If you contact support, we use your message and contact details to respond. Hosting, authentication and security systems process connection metadata, timestamps and error records to deliver and protect the service. Please avoid sending unnecessary health information in support messages.

Authorised operators can access account and service records for support, security and administration. Sensitive content in the app’s administration tools requires an additional access step with a recorded reason. Backend administrative access remains privileged access, so we do not promise that information stored with us is inaccessible to the service operator.

Why we process information

We process account and purchase information as necessary to provide the service you request (UK GDPR Article 6(1)(b)). Optional usage collection relies on consent (Article 6(1)(a)). Catalogue-quality improvements, security, fraud prevention and appropriate service diagnostics rely on legitimate interests (Article 6(1)(f)); legal recordkeeping may rely on a legal obligation (Article 6(1)(c)). Health information also requires a special-category condition: we rely on your explicit consent under Article 9(2)(a). Reading this notice does not by itself grant those optional permissions.

You may withdraw consent at any time. Withdrawal does not change the lawfulness of earlier processing. Vital’s automated readings support general wellbeing; we do not use them to make decisions about your employment, insurance, credit or eligibility for healthcare.

Service providers and international transfers

Our providers include Apple for platform services and purchases, Supabase for authentication, database and storage, RevenueCat for subscription infrastructure, Cloudflare for website delivery, and the food-data providers described above. They receive the information needed for their respective roles. We do not sell personal information or provide health data to advertisers.

Although the main Vital database is hosted in Sweden, some providers and support operations may process information in other countries. Where UK transfer restrictions apply, we use an applicable adequacy decision or appropriate contractual safeguards. Contact us for information about safeguards relevant to your request.

Retention and deletion

Local information remains until you remove it, reset local app data or remove the app, subject to the device’s own backup settings. Cloud account records remain while your account is active. Account deletion removes the active account and associated records; storage cleanup must complete before the app reports success. If deletion fails, retry or contact us so we can finish it.

Deleted information may remain in restricted backups until the provider’s backup cycle expires. Security and administrative audit records are kept only for as long as needed to investigate incidents, prevent abuse and meet applicable legal duties. Transaction records may be retained where needed for billing, fraud prevention or legal obligations. Any retained information is restricted to that purpose. Older chat content is subject to the app’s 90-day retention controls. We do not use backup copies to reactivate a deleted account.

Your rights

Depending on the circumstances, you may request access, correction, erasure, restriction or a portable copy of your information, and object to processing based on legitimate interests. Use the app’s export and deletion controls or contact us. We normally respond within one month; the law allows extensions for some complex requests, which we will explain. You can complain to the UK Information Commissioner’s Office or your local supervisory authority.

Children and changes

Vital is not intended for children under 13. Users aged 13 to 15 need a parent or guardian’s permission. Please contact us if you believe a child has provided information without the required permission. We update this notice when the service changes and will explain material changes in the app or through another appropriate channel.