Skip to content
VITAL
Back to home

Privacy Policy — VITAL Application

In effect since: 10 May 2026 Version: 2026-05-10

This policy is based on EU Regulation 2016/679 (GDPR), Hungarian Act CXII of 2011 (Infotv.), and NAIH Recommendation 1/2018. The VITAL Application processes health data (GDPR Art. 9 — special category), so the primary legal basis for processing is the explicit consent of the data subject [Art. 9(2)(a)].


1. Data controller

FieldValue
ControllerThe operator's company details will be published once the company registration is finalised (see Imprint)
General contactinfo@vitalapp.hu
Data Protection Officer (DPO)info@vitalapp.hu
Websitehttps://vitalapp.hu

Full details: Imprint.


VITAL collects only the minimum data necessary for the listed purposes (Art. 5(1)(c) — data minimization):

Data categoryContentPurposeLegal basisRetention
Account dataEmail, display name, password (bcrypt-hashed), avatar URLAuthentication, account managementArt. 6(1)(b) contractWhile account is active; erased immediately upon account deletion
Basic health data (special category)Weight, height, birth date, genderCalorie + macro target calculationArt. 9(2)(a) explicit consent (at registration)While account active
Health log (special category)Food, water, sleep, vitamin, workout, mood logsWeekly reports, lifestyle score, personalizationArt. 9(2)(a) explicit consentWhile account active
AI Coach context (special category)Health summary, chat historyPersonalized Coach messagesArt. 9(2)(a) separate opt-in (revocable)90 days (auto-purge)
Photo recognitionFood + product photos (camera)Calorie + macro estimation by AIArt. 6(1)(b) contract (only at upload)Photo not stored on server after processing
Avatar + community imagesProfile picture, community post imagesProfile + social feedArt. 6(1)(a) consentWhile account active or until delete
SubscriptionUUID, RevenueCat transaction IDs, tier, expirationPro/Premium feature gatingArt. 6(1)(b) contractAccount + statutory 8 years (accounting)
Push tokenExpo push tokenTransactional notificationsArt. 6(1)(b) contractCleared on logout
Error logging (Sentry)UUID, error code, sanitized stack traceCrash debuggingArt. 6(1)(f) legitimate interest (opt-out available)90 days
Analytics (PostHog)UUID, screen view, feature usage, app versionProduct development, drop-off analysisArt. 6(1)(f) legitimate interest (opt-out available)12 months
Processing audit logsData export events, admin actionsArt. 30 records of processingArt. 6(1)(c) legal obligation5 years

Special-category data (health, mood) processing is recorded at registration (profiles.gdpr_consent_at + gdpr_version columns). Consent is revocable at any time (see Section 6).

Age (Art. 8)

Per Hungarian Infotv. § 6(3), VITAL does not process the data of persons under 16. Age is automatically verified at registration (client + server-side validation). Any data provided by a person under 16 is deleted immediately. Registration with parental (guardian) consent: contact info@vitalapp.hu.


3. Data processors and sharing

We do not sell personal data to third parties. The following processors provide technical services for VITAL:

ProcessorFunctionRegionData categoryDPA / SCC
Supabase, Inc.Database (PostgreSQL) + Auth + StorageEU (Frankfurt)All user tables, avatar, community imagesDPA + SCC
Google LLC (Gemini API)AI Coach + food recognition (opt-in)USACurrent prompt + context, not retainedSCC + Google DPA
RevenueCat, Inc.Subscription managementUSAUUID, transaction eventsDPA + SCC
PostHog Inc.Product analytics (opt-out)EU (eu.i.posthog.com)UUID, events (PII off by default)DPA
Sentry (Functional Software)Error logging (opt-out)USAUUID, sanitized stack trace, breadcrumbsSCC + Sentry DPA
Expo (Exponent, Inc.)OTA updates + push notificationsUSAApp version, push tokenStandard DPA
Apple HealthKit / Google Health ConnectWearable data (opt-in)Local (on-device)Steps, sleep, HR — read/write on-device onlyApple/Google platform agreement
Open Food Facts (FR/EU)Barcode lookupEU (France)Barcode number + User-Agent onlyOpen database (CC0)
Vercel Inc.Website hosting and cookie-less visit measurement (Vercel Web Analytics)USA / Global CDNStatic pages; aggregated page views (page, referrer, country, device type), no cookies and no user profileDPA + SCC

International transfers (Art. 44-49)

Transfers to the USA are protected by the EU Standard Contractual Clauses (SCC) 2021/914. Where a processor holds an EU-US Data Privacy Framework (DPF) certification (e.g. Google, Sentry, RevenueCat), we also rely on it. Special-category data (Art. 9) is transferred to the US only with the data subject's separate explicit consent (e.g. AI Coach) — without consent, fallback templates are generated locally on-device and do not reach the Gemini API.


4. Data security (Art. 32)

  • All data transit secured with HTTPS / TLS 1.2+
  • Passwords stored as bcrypt hashes
  • Auth tokens stored in the device's secure store (iOS Keychain, Android Keystore)
  • Supabase Row Level Security (RLS) — per-user policies on every table
  • Storage bucket file size + MIME-type server-side enforcement (max 10 MB; JPEG/PNG/WebP only)
  • Sentry breadcrumb / extras automatic PII redaction
  • Inactivity timeout 30 minutes → automatic logout
  • In case of a data breach: NAIH notification within 72 hours (Art. 33), and direct notification to data subjects (Art. 34) if high risk is likely.

5. Retention

We store data only for as long as necessary for the defined purpose (Art. 5(1)(e) — storage limitation):

Data categoryRetention
Active account dataUntil account deletion
Coach conversations + message logs90 days (auto-purge)
Error logs (Sentry)90 days
Analytics (PostHog)12 months
Accounting records (subscriptions)8 years (statutory)
Processing audit logs (Art. 30)5 years
Backups7 days (rotating)

On account deletion, all personal data is immediately deleted from the active database. Backups are overwritten within 7 days; after that the data is irrecoverable. Accounting records (statutory obligation) are kept in anonymized form.


6. Data subject rights (Art. 15-22)

RightHow to exercise
Access (Art. 15)In-app: Profile → Download my data — JSON format
Portability (Art. 20)Same place — structured, machine-readable JSON
Rectification (Art. 16)Profile → Edit (basic data); other fields: info@vitalapp.hu
Erasure (Art. 17 — "right to be forgotten")Profile → Delete account (immediate, irreversible)
Restriction (Art. 18)info@vitalapp.hu — case-by-case
Objection (Art. 21)Profile → Settings → Disable analytics (PostHog opt-out); other: info@vitalapp.hu
Withdrawal of consent (Art. 7(3))Profile → Disable AI Coach; withdrawing consent for basic health data = account deletion

We respond to subject requests within 30 days (Art. 12(3)). The in-app data export works immediately.


7. Automated decision-making (Art. 22)

VITAL uses two automated components:

  1. Lifestyle score — daily score is calculated from your weights (calorie, water, sleep, activity, vitamin). This is not a decision producing legal effects (Art. 22(1)) — it does not replace medical advice.
  2. AI Coach — personalized message generated with Google Gemini for opt-in users. Recommendations are informative; they do not constitute medical advice.

You may request human review at any time at info@vitalapp.hu.


8. Storage / cookies

The mobile app does not use HTTP cookies. User preferences, auth tokens, and offline-cached data are stored on-device (AsyncStorage, SecureStore). SecureStore uses iOS Keychain / Android Keystore equivalent encryption.

The vitalapp.hu website uses only essential cookies (session, language). Analytics cookies are activated only after explicit consent via the cookie banner; you can withdraw consent at any time by reopening the banner. Visits are measured by Vercel Web Analytics without cookies and in aggregate (page, referrer, country, device type); no individual profile is built and you are not tracked across other sites.

VITAL does not use ad-tracking (no Meta Pixel, Google Ads tag, TikTok pixel, etc.).


9. Camera and media library access

The app accesses the camera and photo library for:

  1. Barcode scanning — product identification (image is not uploaded)
  2. Food + product photos — AI recognition (available on all plans — Free: 1/week, Premium: 5/day, Pro: higher quota; image is not retained on the server after processing)
  3. Profile picture upload — image stored in Supabase Storage avatars bucket (publicly accessible URL)
  4. Community post images — stored in post-images bucket (public URL)

All image uploads are limited to max 10 MB; JPEG/PNG/WebP only. SVG is not allowed (XSS-as-image risk).


10. Data breach handling

In case of a data breach (e.g. unauthorized access, data leak):

  1. Within 72 hours we notify NAIH about the nature and risks of the breach (Art. 33).
  2. If the breach is likely to result in high risk to the data subject, we notify them directly (Art. 34) — by email + in-app notification.
  3. The full breach response procedure (docs/BREACH_RESPONSE.md) is our internal document; on user request, we provide an anonymized summary.

11. Versioning and changes

Every change to the Privacy Policy is published with a new version number (in the Version line at the top of this document). Existing users are notified at the next app launch and must re-accept if a material change has occurred (new processor, new legal basis, new data category).


12. Supervisory authority — NAIH

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)

ChannelAddress
Address1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address1363 Budapest, Pf.: 9., Hungary
Phone+36 (1) 391-1400
Emailugyfelszolgalat@naih.hu
Websitehttps://www.naih.hu

You are entitled to file a complaint with NAIH or seek judicial remedy at any time if you believe our processing is unlawful.


13. Contact

Request typeAddress
General question / supportinfo@vitalapp.hu
Data protection request (Art. 15-22)info@vitalapp.hu
Data breach notificationinfo@vitalapp.hu (24h response)

Please use the appropriate address — we'll respond faster and more accurately.


This 2026-05-10 release replaces the 2026-04-03 version following the comprehensive GDPR audit (P0+P1 fix-sprint). Main changes: extended processor list (PostHog, Sentry, Open Food Facts, Apple Health, Health Connect), explicit retention table, legal-basis matrix per data category, 16-year age rule, automated decision-making note, breach response procedure. Details: GDPR_AUDIT.md.