Privacy Policy
How your information is used, shared and kept.
Last updated
About this policy
This policy explains how VitaDrop handles information when you use our website, iPhone app and optional ChatGPT connection. VitaDrop is operated by Matrix Tech Solution, the controller responsible for the personal information described here. Contact: support@vitadrop.app.
Apple Health and manual entries
You choose which Apple Health data VitaDrop may read or write through Apple’s permission controls. Manual entries are saved to Apple Health on your device. Favourite summaries are read from Apple Health on your device; they are not a continuous cloud health-history feed. App preferences, favourites and sync settings are stored locally.
You can use free manual recording without a VitaDrop account. Revoking a permission stops the corresponding access; it does not remove entries already saved in Apple Health.
Accounts and connected entries
If you create an account, Firebase Authentication processes your sign-in information, such as your email address, sign-in provider and account identifier. We use account, connection and device identifiers to secure access and deliver entries to the correct device.
When you use ChatGPT logging, the health information you provide is processed by ChatGPT and the VitaDrop connection to prepare an entry. You review and confirm interpreted entries before they enter the temporary cloud inbox. The inbox contains the confirmed entry’s type, value, unit, time and delivery state. The original statement is not retained in the inbox after confirmation.
Pending cloud entries are accessible to authorized infrastructure administrators. This service does not provide end-to-end encryption of the cloud inbox.
Optional sharing with ChatGPT
Reading symptom history requires separate connection access and your explicit approval in VitaDrop. You can review or decline a request on your iPhone before selected Apple Health symptom data is shared. Enabling automatic sync for confirmed entries does not approve symptom-history sharing.
Information you type or share in ChatGPT is also subject to OpenAI’s policies and your ChatGPT settings. Deleting your VitaDrop account or allowing an inbox entry to expire does not delete your ChatGPT conversation. See OpenAI’s Privacy Policy.
Subscriptions
Where Premium purchases are available, Apple processes App Store payments. RevenueCat helps validate purchases, restore them and determine Premium access. It processes purchase and subscription information, an anonymous app user identifier or your VitaDrop account identifier, and related device and app information. VitaDrop does not receive your full payment-card details. Health entry values are not sent to RevenueCat by the app.
Website and service operations
The website does not include advertising trackers, analytics scripts or non-essential cookies. Our hosting and infrastructure providers process network information, such as IP addresses and request metadata, to deliver and protect the service. Authentication features may use necessary browser storage.
Service diagnostics are designed to record operational outcomes rather than health values. If you contact us, we use the contact information and message you provide to respond. Please avoid sending health details unless needed for your request.
Why information is used
We use information to provide the features you request, authenticate accounts, sync confirmed entries, manage subscriptions, answer support requests and protect the service. We do not sell health data or use Apple Health data for advertising.
Where European data protection law applies, account and subscription processing is necessary to provide the requested service; security and service diagnostics support our legitimate interest in maintaining a reliable service; and required records may be processed to meet legal obligations. Optional health-data access and sharing rely on your permission and, where required, explicit consent. You can withdraw that consent by disabling the relevant connection or permissions, without affecting earlier lawful processing.
How long information stays
- Confirmed entries: health values are removed from the cloud inbox after delivery acknowledgement or cancellation. Undelivered entries expire after 30 days, and scheduled cleanup removes their health values.
- Delivery receipts: value-free delivery status is retained for a further 30 days, then removed through cleanup.
- Symptom requests: unanswered requests expire after 24 hours. Shared results are available for 15 minutes; expired request data is removed through scheduled cleanup.
- Accounts: sign-in and connection information is kept while your account is active. Account deletion removes the cloud inbox, connection grants and device registrations. A hashed deletion marker without health values is retained for 30 days to prevent late requests from recreating deleted data.
- Other information: support messages, security logs and purchase records may be retained as needed to resolve the request, secure the service or meet applicable recordkeeping requirements. Apple, OpenAI and RevenueCat have their own retention policies for information they process.
Expiry stops use of an entry; physical removal depends on cleanup completing. Apple Health entries remain under your control in Apple Health.
Service providers and transfers
We use Google Firebase for authentication, cloud storage and hosting, and RevenueCat for subscription management. Apple provides Apple Health and App Store services. OpenAI processes information when you choose to use ChatGPT. Information may also be disclosed where required by law or necessary to address abuse and protect users.
These providers operate internationally, so processing may take place outside your country, including outside the European Economic Area. Applicable provider agreements and transfer safeguards govern those transfers. Contact us for information about the safeguards relevant to your use. See Firebase’s privacy information.
Your choices and rights
You can change Apple Health permissions in your device’s Health or Settings app and disconnect the ChatGPT connection. To remove your VitaDrop account and cloud inbox, open the account controls in VitaDrop and choose Delete account and cloud inbox. This does not delete Apple Health entries, cancel an Apple subscription or erase information already shared with ChatGPT.
Depending on your location and the applicable law, you may request access, correction, deletion, restriction, portability or object to certain processing. You may also withdraw consent and complain to your local data protection authority. Contact us using the details above to exercise your rights; we may need to verify your identity. VitaDrop does not use your health entries to make solely automated decisions with legal or similarly significant effects.
Changes
We will update this page when our practices change and show the revised date above. Material changes will be brought to your attention where required. New uses that require consent will be presented for your choice.