Privacy Policy — VITAL Application
In effect since: 10 May 2026 Version: 2026-05-10
This policy is based on EU Regulation 2016/679 (GDPR), Hungarian Act CXII of 2011 (Infotv.), and NAIH Recommendation 1/2018. The VITAL Application processes health data (GDPR Art. 9 — special category), so the primary legal basis for processing is the explicit consent of the data subject [Art. 9(2)(a)].
1. Data controller
| Field | Value |
|---|---|
| Controller | The operator's company details will be published once the company registration is finalised (see Imprint) |
| General contact | info@vitalapp.hu |
| Data Protection Officer (DPO) | info@vitalapp.hu |
| Website | https://vitalapp.hu |
Full details: Imprint.
2. What data we collect and on what legal basis
VITAL collects only the minimum data necessary for the listed purposes (Art. 5(1)(c) — data minimization):
| Data category | Content | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Account data | Email, display name, password (bcrypt-hashed), avatar URL | Authentication, account management | Art. 6(1)(b) contract | While account is active; erased immediately upon account deletion |
| Basic health data (special category) | Weight, height, birth date, gender | Calorie + macro target calculation | Art. 9(2)(a) explicit consent (at registration) | While account active |
| Health log (special category) | Food, water, sleep, vitamin, workout, mood logs | Weekly reports, lifestyle score, personalization | Art. 9(2)(a) explicit consent | While account active |
| AI Coach context (special category) | Health summary, chat history | Personalized Coach messages | Art. 9(2)(a) separate opt-in (revocable) | 90 days (auto-purge) |
| Photo recognition | Food + product photos (camera) | Calorie + macro estimation by AI | Art. 6(1)(b) contract (only at upload) | Photo not stored on server after processing |
| Avatar + community images | Profile picture, community post images | Profile + social feed | Art. 6(1)(a) consent | While account active or until delete |
| Subscription | UUID, RevenueCat transaction IDs, tier, expiration | Pro/Premium feature gating | Art. 6(1)(b) contract | Account + statutory 8 years (accounting) |
| Push token | Expo push token | Transactional notifications | Art. 6(1)(b) contract | Cleared on logout |
| Error logging (Sentry) | UUID, error code, sanitized stack trace | Crash debugging | Art. 6(1)(f) legitimate interest (opt-out available) | 90 days |
| Analytics (PostHog) | UUID, screen view, feature usage, app version | Product development, drop-off analysis | Art. 6(1)(f) legitimate interest (opt-out available) | 12 months |
| Processing audit logs | Data export events, admin actions | Art. 30 records of processing | Art. 6(1)(c) legal obligation | 5 years |
Special-category data (health, mood) processing is recorded at registration (profiles.gdpr_consent_at + gdpr_version columns). Consent is revocable at any time (see Section 6).
Age (Art. 8)
Per Hungarian Infotv. § 6(3), VITAL does not process the data of persons under 16. Age is automatically verified at registration (client + server-side validation). Any data provided by a person under 16 is deleted immediately. Registration with parental (guardian) consent: contact info@vitalapp.hu.
3. Data processors and sharing
We do not sell personal data to third parties. The following processors provide technical services for VITAL:
| Processor | Function | Region | Data category | DPA / SCC |
|---|---|---|---|---|
| Supabase, Inc. | Database (PostgreSQL) + Auth + Storage | EU (Frankfurt) | All user tables, avatar, community images | DPA + SCC |
| Google LLC (Gemini API) | AI Coach + food recognition (opt-in) | USA | Current prompt + context, not retained | SCC + Google DPA |
| RevenueCat, Inc. | Subscription management | USA | UUID, transaction events | DPA + SCC |
| PostHog Inc. | Product analytics (opt-out) | EU (eu.i.posthog.com) | UUID, events (PII off by default) | DPA |
| Sentry (Functional Software) | Error logging (opt-out) | USA | UUID, sanitized stack trace, breadcrumbs | SCC + Sentry DPA |
| Expo (Exponent, Inc.) | OTA updates + push notifications | USA | App version, push token | Standard DPA |
| Apple HealthKit / Google Health Connect | Wearable data (opt-in) | Local (on-device) | Steps, sleep, HR — read/write on-device only | Apple/Google platform agreement |
| Open Food Facts (FR/EU) | Barcode lookup | EU (France) | Barcode number + User-Agent only | Open database (CC0) |
| Vercel Inc. | Website hosting and cookie-less visit measurement (Vercel Web Analytics) | USA / Global CDN | Static pages; aggregated page views (page, referrer, country, device type), no cookies and no user profile | DPA + SCC |
International transfers (Art. 44-49)
Transfers to the USA are protected by the EU Standard Contractual Clauses (SCC) 2021/914. Where a processor holds an EU-US Data Privacy Framework (DPF) certification (e.g. Google, Sentry, RevenueCat), we also rely on it. Special-category data (Art. 9) is transferred to the US only with the data subject's separate explicit consent (e.g. AI Coach) — without consent, fallback templates are generated locally on-device and do not reach the Gemini API.
4. Data security (Art. 32)
- All data transit secured with HTTPS / TLS 1.2+
- Passwords stored as bcrypt hashes
- Auth tokens stored in the device's secure store (iOS Keychain, Android Keystore)
- Supabase Row Level Security (RLS) — per-user policies on every table
- Storage bucket file size + MIME-type server-side enforcement (max 10 MB; JPEG/PNG/WebP only)
- Sentry breadcrumb / extras automatic PII redaction
- Inactivity timeout 30 minutes → automatic logout
- In case of a data breach: NAIH notification within 72 hours (Art. 33), and direct notification to data subjects (Art. 34) if high risk is likely.
5. Retention
We store data only for as long as necessary for the defined purpose (Art. 5(1)(e) — storage limitation):
| Data category | Retention |
|---|---|
| Active account data | Until account deletion |
| Coach conversations + message logs | 90 days (auto-purge) |
| Error logs (Sentry) | 90 days |
| Analytics (PostHog) | 12 months |
| Accounting records (subscriptions) | 8 years (statutory) |
| Processing audit logs (Art. 30) | 5 years |
| Backups | 7 days (rotating) |
On account deletion, all personal data is immediately deleted from the active database. Backups are overwritten within 7 days; after that the data is irrecoverable. Accounting records (statutory obligation) are kept in anonymized form.
6. Data subject rights (Art. 15-22)
| Right | How to exercise |
|---|---|
| Access (Art. 15) | In-app: Profile → Download my data — JSON format |
| Portability (Art. 20) | Same place — structured, machine-readable JSON |
| Rectification (Art. 16) | Profile → Edit (basic data); other fields: info@vitalapp.hu |
| Erasure (Art. 17 — "right to be forgotten") | Profile → Delete account (immediate, irreversible) |
| Restriction (Art. 18) | info@vitalapp.hu — case-by-case |
| Objection (Art. 21) | Profile → Settings → Disable analytics (PostHog opt-out); other: info@vitalapp.hu |
| Withdrawal of consent (Art. 7(3)) | Profile → Disable AI Coach; withdrawing consent for basic health data = account deletion |
We respond to subject requests within 30 days (Art. 12(3)). The in-app data export works immediately.
7. Automated decision-making (Art. 22)
VITAL uses two automated components:
- Lifestyle score — daily score is calculated from your weights (calorie, water, sleep, activity, vitamin). This is not a decision producing legal effects (Art. 22(1)) — it does not replace medical advice.
- AI Coach — personalized message generated with Google Gemini for opt-in users. Recommendations are informative; they do not constitute medical advice.
You may request human review at any time at info@vitalapp.hu.
8. Storage / cookies
The mobile app does not use HTTP cookies. User preferences, auth tokens, and offline-cached data are stored on-device (AsyncStorage, SecureStore). SecureStore uses iOS Keychain / Android Keystore equivalent encryption.
The vitalapp.hu website uses only essential cookies (session, language). Analytics cookies are activated only after explicit consent via the cookie banner; you can withdraw consent at any time by reopening the banner. Visits are measured by Vercel Web Analytics without cookies and in aggregate (page, referrer, country, device type); no individual profile is built and you are not tracked across other sites.
VITAL does not use ad-tracking (no Meta Pixel, Google Ads tag, TikTok pixel, etc.).
9. Camera and media library access
The app accesses the camera and photo library for:
- Barcode scanning — product identification (image is not uploaded)
- Food + product photos — AI recognition (available on all plans — Free: 1/week, Premium: 5/day, Pro: higher quota; image is not retained on the server after processing)
- Profile picture upload — image stored in Supabase Storage
avatarsbucket (publicly accessible URL) - Community post images — stored in
post-imagesbucket (public URL)
All image uploads are limited to max 10 MB; JPEG/PNG/WebP only. SVG is not allowed (XSS-as-image risk).
10. Data breach handling
In case of a data breach (e.g. unauthorized access, data leak):
- Within 72 hours we notify NAIH about the nature and risks of the breach (Art. 33).
- If the breach is likely to result in high risk to the data subject, we notify them directly (Art. 34) — by email + in-app notification.
- The full breach response procedure (
docs/BREACH_RESPONSE.md) is our internal document; on user request, we provide an anonymized summary.
11. Versioning and changes
Every change to the Privacy Policy is published with a new version number (in the Version line at the top of this document). Existing users are notified at the next app launch and must re-accept if a material change has occurred (new processor, new legal basis, new data category).
12. Supervisory authority — NAIH
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
| Channel | Address |
|---|---|
| Address | 1055 Budapest, Falk Miksa utca 9-11., Hungary |
| Postal address | 1363 Budapest, Pf.: 9., Hungary |
| Phone | +36 (1) 391-1400 |
| ugyfelszolgalat@naih.hu | |
| Website | https://www.naih.hu |
You are entitled to file a complaint with NAIH or seek judicial remedy at any time if you believe our processing is unlawful.
13. Contact
| Request type | Address |
|---|---|
| General question / support | info@vitalapp.hu |
| Data protection request (Art. 15-22) | info@vitalapp.hu |
| Data breach notification | info@vitalapp.hu (24h response) |
Please use the appropriate address — we'll respond faster and more accurately.
This 2026-05-10 release replaces the 2026-04-03 version following the comprehensive GDPR audit (P0+P1 fix-sprint). Main changes: extended processor list (PostHog, Sentry, Open Food Facts, Apple Health, Health Connect), explicit retention table, legal-basis matrix per data category, 16-year age rule, automated decision-making note, breach response procedure. Details: GDPR_AUDIT.md.