Vita DEEN

Vita

Privacy

Last updated: October 2026

In brief

Vita is an iPhone app without an account. Everything Vita knows about your body and your nutrition — Apple Health values, your food diary, products, weight, analyses — lives on your device and is computed there. Raw data and histories from Apple Health never leave your iPhone. Individual values – such as your weight (rounded), workouts with type, duration and calories, or your daily state – go to the Vita service (Cloudflare, processed by Anthropic) only if you explicitly turn on Ask Vita or meal review. The photo scan sends your picture there, but no Health values. These features and the barcode lookup only run with your explicit consent and can be switched off in Settings at any time. Once a day Vita also puts a backup of your diary into your own iCloud Drive — on by default, can be switched off (see below). Apart from that, the only things that go online are feedback you send yourself, the check for a newer app version (with no data from you) and an anonymous error report without any content if the app crashes or something fails internally (see below). There is no advertising, no tracking and no analytics SDKs.

The app

  • On-device processing: your food diary (products, meals, entries, creatine log, daily notes) and all analyses are stored locally on your iPhone. There is no account and no Vita server storing this data. If VeloStats is installed on the same iPhone, Vita reads the rides of the last 35 days from a shared, device-local keychain area: time windows, energy and the food eaten on the ride. This bridge runs on the device only; the rides feed into the diary and the expenditure estimate like other values — what of that goes to the Vita service with your consent is listed under “Ask Vita” and “Meal review”.
  • Apple Health: only after you grant access in iOS, Vita reads sleep, heart rate variability, resting heart rate, respiratory rate, sleeping wrist temperature, steps, active energy, exercise minutes, workouts, body weight, height, date of birth and biological sex, for the analysis of influences mindful minutes, time in daylight, state of mind and heart rate (only within the time window of sauna workouts), plus — only where your Health profile provides it — cycle data. In iOS you decide for each value individually whether Vita may read it. Vita writes nothing to Apple Health. Health data is analysed on the device. Raw data and histories are never part of the backup in iCloud Drive or of an AI request; individual values derived from them only go to the Vita service with your explicit consent — which ones is listed under “Ask Vita” and “Meal review”.
  • Backup in iCloud Drive (on by default, from version 1.59): once a day Vita puts a copy of your data as a file into your own iCloud Drive (folder “Vita › Sicherungen”; the last 14 are kept): food diary, products, meals, creatine log, daily check-ins, experiments, meal reviews and the learned calibration — no values from Apple Health. The file lives at Apple in your iCloud account; there is no Vita server in between, and we have no access to it. It is not additionally encrypted: anyone with access to your iCloud Drive can read it. If iCloud is off for Vita or the last backup is older than 7 days, Vita tells you. You can switch the backup off in Settings under “Back up data”. Up to version 1.56.0 there was instead an optional mirroring into the private iCloud database of your Apple account (Apple CloudKit); since 1.56.1 it is off for everyone.
  • Inbox in iCloud Drive (from version 1.58): Vita files you put into the “Vita › Import” folder of your iCloud Drive are picked up by Vita by itself when you open it — it only adds what’s missing — and then moved to “Übernommen”. Nothing goes out; Vita only reads what you put there yourself.
  • iPhone search (Spotlight): so that you can also find your products through the iPhone’s search, Vita adds the name, brand and kcal per 100 g of your inventory products to Apple’s search index on the device — no quantities, no entries, no health data. You can switch this off in Settings (“In iPhone search (Spotlight)”); Vita then empties the index.
  • Barcode lookup (optional): when you scan a barcode, the app — after your one-time consent — queries the open product database Open Food Facts. Only the barcode is transmitted (for technical reasons Open Food Facts sees your IP address in the process) — no name, no diary or health data. The answer is cached locally.
  • Nutrition photo scan (optional): if you photograph a nutrition table, a label or a plate, the app — after your consent — sends the photo, any short hint text you add and the app language to the Vita service, a Cloudflare Worker operated by us, which passes the photo on to the AI service Anthropic (Claude) for analysis. No Apple Health values travel along. If you then correct the result (“Something not right?” — for example “It’s beef, not pork”), the app sends the same photo again, together with your sentence and the previous result. Neither the app nor the Vita service stores the photo or the sentence; for retention at Anthropic see below. Every request carries the anonymous device identifier for the daily quota (see “Daily quota and cost”). You can revoke this consent in Settings at any time.
  • “Ask Vita” (optional): the assistant sends your question as text to the Vita service and from there to Anthropic (Claude). So that known items are recognised, the names of your catalogue products travel along (names only — no quantities, no entries), as does the anonymous device identifier for the daily quota. Only if you give an explicit second consent, a small curated set of derived key figures is added — partly calculated from your Apple Health data, for example the change in your weight over the period, store fill levels in percent or today’s modelled expenditure. The app shows you verbatim beforehand which lines these are; never raw history, never individual entries, never your weight history, never measurement series from Health. The assistant only makes suggestions — nothing is saved until you confirm in the app. Questions and answers are not stored permanently by the Vita service; for retention at Anthropic see below. With “AI on device” turned on in Settings, no question goes to the Vita service: Apple’s model answers on the iPhone, and Vita only finds products from your inventory. Both consents can be revoked in Settings at any time.
  • “Meal review” — meal or day (optional): if you ask for a review of a meal or of the whole day, Vita calculates the assessment (fits · partly · missing) itself on the device. Only the sentences are written — after your own consent — by Claude (Anthropic) via the Vita service. For this the app sends the items of exactly that meal or day (names, amounts, nutrients) together with the meal’s name and time, only totals for the rest of the day, the day’s key figures (modelled expenditure, targets, store fill level, the balance of the previous days as a single number), the app’s assessment, your body weight (rounded), your 14-day weight trend as a single number (kg per week), workouts with type, duration, calories and their distance to the meal, your daily state (recovered, within range or challenged — derived on the device from your body signals, including heart rate variability and resting heart rate), the app language and the anonymous device identifier for the daily quota — never other individual entries, never a weight history, no measurement series from Health, no name. The Vita service does not store the request; for retention at Anthropic see below. With “AI on device” turned on, Apple’s model writes the sentences on the iPhone (or Vita uses templates), and no request goes to the Vita service. You can revoke this consent in Settings at any time.
  • Daily quota and cost: photo scan, “Ask Vita” and “Meal review” send an anonymous, resettable device identifier (Apple’s “identifierForVendor” — no Apple ID, no name); it never goes to Anthropic. Under this identifier the Vita service counts the AI requests per day (at most 50 per device and day across all three together) and the estimated cost of these requests — numbers only, no content. It deletes the daily counters no later than two days after the last request, and the monthly cost total no later than 40 days after it. So that you can see these numbers of your own in Settings under “AI usage”, the app retrieves them from the Vita service under the same device identifier when you open Settings: your requests today, per feature (photo scan, “Ask Vita”, “Meal review”), and the estimated cost today and in the current month. This only happens if at least one of these three AI features is turned on and “AI on device” is off. The app sends no data of yours apart from the identifier, and only numbers come back; the lookup does not count as an AI request, and the Vita service stores nothing in the process.
  • Retention at Anthropic: under Anthropic’s rules for the API, Anthropic automatically deletes inputs and outputs (for Vita: photo, question, meal review lines and the answers to them) within 30 days of receipt or generation. Exceptions: if Anthropic’s automated trust and safety systems flag a request as violating Anthropic’s Usage Policy, Anthropic keeps inputs and outputs for up to 2 years and the classification scores for up to 7 years; Anthropic may also retain data as required by law. By default, Anthropic does not use API inputs or outputs to train its models. Anthropic may process the requests in the US, Europe, Asia or Australia; the data is stored in the US. Sources in Anthropic’s Privacy Center (retrieved on 1 October 2026): retention, training, server locations.
  • Feedback from the app (voluntary): if you send feedback, the app transmits your text, the chosen category, app version, build number and iOS version as well as a random identifier created per installation, so that replies find their way back to you — no name and no Apple device identifier. The same applies to wishes you send via “Ask Vita” and to language requests. Screenshots are included only if you deliberately select them; a screenshot can only be retrieved through our server and only under its unpublished file name. The feedback is stored as an entry in a private GitHub repository of the developers so we can reply; the developer is notified by a Telegram message, and that message contains your text. To show you replies, the app asks our server for the status of your own feedback items (their numbers only). To prevent abuse, our server counts the feedback requests of a day per identifier or per IP address; it deletes these counters no later than two days after the last request.
  • Update notice: at launch the app asks our server whether a newer version exists that you can install the way you installed the app. Only the app name, the installed version number and whether the app came from the App Store or TestFlight are transmitted — no identifier, no content.
  • Error and crash reports: if Vita crashes or something fails internally (such as a save, a Health query, reading a backup or a response of the Vita service), the app sends an anonymous report to our server so we can fix the problem: error kind and error code, app and iOS version, device model, and for a crash the technical location in the program (iOS delivers crash reports at the next launch) — never entries, values or names, and no device identifier. Vita deliberately omits the wording of an error because it could contain content. The report is stored as an entry in a private GitHub repository of the developers; the developer receives a Telegram notice about it.
  • No advertising, no tracking: Vita contains no advertising, tracking or analytics SDKs and shares no data with third parties beyond the services named here.
  • Beta via TestFlight: during the beta, Apple distributes the app via TestFlight. We receive crash reports and TestFlight feedback from Apple only to the extent you allow this in TestFlight; Apple's TestFlight terms apply.

Services that receive data

  • Apple — iCloud Drive (daily backup and inbox, in your own iCloud account; up to version 1.56.0 iCloud/CloudKit if you had turned on the backup of that time) and TestFlight (during the beta).
  • Cloudflare, Inc. — runs the infrastructure of our server and of the Vita service (photo scan, “Ask Vita”, “Meal review”, AI usage lookup, feedback, update hint, error reports) and processes technically necessary connection data such as the IP address in doing so.
  • Anthropic — AI analysis for photo scan, “Ask Vita” and “Meal review”, only with your consent; retention see above.
  • Open Food Facts — barcode lookup, only with your consent.
  • GitHub, Inc. (USA) — storage of your feedback (only if you send feedback) and of the anonymous error reports in a private repository.
  • Telegram — notification of the developer about new feedback (with your text) and new error reports.

This website (velostats.app)

The pages under velostats.app/vita follow the same rules as the rest of the website: no cookies apart from the strictly necessary language-choice cookie (DE/EN), no trackers, no analytics services; your browser loads the fonts from Google Fonts (Google sees your IP address in the process, but no cookies). The website runs on Cloudflare Workers. Whatever you send via the contact form or by email to support@velostats.app is used solely to answer your enquiry, is not shared with third parties, and is deleted automatically after 90 days at the latest.

Deleting your data

Local data: delete the app — this removes the diary and analyses from the device; you can withdraw Health access at any time in the iOS settings. Backup in iCloud Drive: switch it off in Vita under “Back up data” and delete the “Vita” folder in the Files app (iCloud Drive). Data of the former mirroring (up to 1.56.0) can be deleted in the iCloud settings of iOS. For questions, access requests or deletion of feedback you sent: support@velostats.app.

Controller

David Gertis
support@velostats.app