Privacy Policy
Last updated: May 25, 2026
1. Summary
We collect what we need to run Vitriv for you and nothing more. We don't sell your data. We don't share your data with advertisers. AI providers process your prompts only to answer them and are contractually barred from training on your data. You can export or delete your data at any time.
2. Who we are
Vitriv ("we", "us", "our") is the controller of the personal data described in this Privacy Policy. If you have a question about this policy or your data, contact us at [email protected].
3. What we collect
3.1 Account data
- Name, email address, password hash.
- Profile attributes you choose to set: date of birth, sex, height, weight, activity level, goals.
3.2 Activity data
- Meals you log, recipes you bookmark or create.
- Macro targets and the history of changes to them (so old scores stay honest as your goals evolve).
- Workouts, progress entries, body measurements.
- Photos you upload (meal pictures, progress shots).
3.3 AI inputs and outputs
- Prompts and photos you submit to AI features, and the responses generated for you.
- We log the model used, token counts, and cost so you can audit your AI spend.
3.4 Device and usage data
- Device model, OS version, app version, language, timezone.
- IP address (for rate limiting and security), session timestamps, crash reports.
- Feature usage metrics (which screens are opened, what actions are taken) — used in aggregate to improve the app.
3.5 What we don't collect
- We don't run third-party ad SDKs.
- We don't read your contacts, calendar, SMS, or files unless you explicitly grant permission for a specific feature.
- We don't track your location in the background.
4. How we use your data
- To run the Service: store your logs, sync across devices, calculate scores, generate plans you requested.
- To process AI requests: forward your prompt to the relevant model and return the response.
- To communicate: send transactional emails (password reset, account confirmations, billing receipts) and, if you opt in, occasional product updates.
- To keep things secure: detect abuse, rate limit, investigate incidents.
- To improve Vitriv: review aggregated and anonymized usage to find what's broken and what's missing.
- To comply with law: respond to lawful requests, enforce our Terms, defend our rights.
We do not use your personal data for advertising and we do not sell it.
5. Legal bases (GDPR/UK GDPR)
- Contract: processing required to deliver the Service you signed up for.
- Legitimate interests: security, fraud prevention, product improvement.
- Consent: optional features (marketing emails, certain AI features, photo uploads). You can withdraw consent any time.
- Legal obligation: tax records, lawful requests.
6. Sharing your data
We share data only with the categories below:
- Infrastructure providers — MongoDB Atlas (database), Cloudflare R2 (file storage), Railway (app hosting). They process data on our instructions and under data processing agreements.
- Email delivery — Resend, for transactional email.
- AI providers — only when you use an AI feature, and only the data needed to answer that prompt. They are contractually barred from training models on your data.
- Payment processors — for AI credit purchases and any other paid features. We don't store your card details.
- Legal requests — where required by valid law, court order, or to protect the rights, safety, or property of Vitriv or others.
- Business transfers — if Vitriv is acquired or merged, your data may be transferred to the successor entity under the same protections.
7. International transfers
Your data may be processed in countries other than your own, including the United States, the European Union, and India. Where transfers occur from a region with restricted transfer rules (such as the EEA or UK), we rely on Standard Contractual Clauses or equivalent safeguards.
8. Data retention
- Active accounts: we keep your data for as long as your account exists.
- Deleted accounts: we erase your personal data within 30 days of deletion, except where retention is required by law (e.g. tax records of paid transactions — up to 7 years).
- Backups: deleted data may persist in encrypted backups for up to 90 days before being overwritten.
- Aggregated analytics: we keep anonymized and aggregated metrics indefinitely.
9. Your rights
Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, India DPDP Act, others), you have some or all of the following rights:
- Access a copy of your data.
- Correct inaccurate data.
- Delete your data.
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time.
- Lodge a complaint with your local data protection authority.
To exercise these rights, email [email protected] from the address on your account, or use the in-app controls. We respond within 30 days.
10. Security
- Data is encrypted in transit (TLS) and at rest.
- Passwords are hashed with a modern algorithm (we never see your plaintext password).
- Access to production data is restricted, logged, and reviewed.
- We run rate limiting, brute-force protection, and routine dependency audits.
No system is perfect. If we discover a breach affecting your personal data, we'll notify you and the relevant authority within 72 hours of becoming aware.
11. Children
Vitriv is not intended for children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Cookies and similar technologies
The Vitriv website uses strictly necessary cookies for session management. The mobile app uses local storage for session tokens and offline data. We don't use third-party analytics or advertising cookies.
13. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified via the app or by email. The "Last updated" date at the top of this page reflects the most recent revision.