This policy explains what Vivora ("the app", "we") does with your information. Vivora is provided by Patrick Funk. Questions: pkfk@me.com.
Data controller: Patrick Funk. Contact: pkfk@me.com. Vivora is an iOS health-and-wellbeing app.
With your explicit permission, Vivora reads health and fitness data from Apple Health to show you insights, and writes a limited set of entries back when you ask it to. This data is read live from Apple Health when a screen needs it — Vivora does not copy your Apple Health history into its own database.
Read (only what you grant): steps, active & resting energy, distance, flights climbed, exercise/stand time, workouts and routes, heart rate, heart-rate variability, resting & walking heart rate, cardio fitness (VO₂max), ECG and heart-rhythm notifications, respiratory rate, blood oxygen, body & wrist temperature, sleep, mobility metrics (walking steadiness, gait, stair speed, six-minute walk, falls), weight, body fat, height, nutrition, water, and — only if you opt in — cycle-tracking data.
Write (only when you enter it): weight, body fat, height, blood pressure, dietary energy and water, workouts, mindful minutes, and sleep.
In line with Apple's rules, health data is never used for advertising or marketing and is never shared with anyone without your consent. You can review or revoke Vivora's access any time in Settings → Health → Data Access & Devices.
Vivora stores what you log and set up: your profile (date of birth, sex, height, weight, goals), food and drink logs, body measurements, custom drinks, recipes and saved meals, and any photos you take (food, drinks, progress photos). This is stored on your device and in your own iCloud (see §6).
Each permission is requested only when its feature is first used, and every one is optional.
Some features use AI and public food databases. These are the only times your information is sent off your device:
Vivora contains no advertising, no analytics SDKs, and no third-party trackers.
Vivora has no server that stores your health data, your logs, your photos, or your AI content. None of it is ever sent to us.
There is one exception, and it applies only if you subscribe to Vivora Pro and use AI without your own API key (§5). To meter that allowance we run a small server on Cloudflare, which keeps:
That is the complete list. Prompts, photos, voice transcripts and AI responses are not stored there — they pass through and are gone.
Vivora Pro is sold through Apple's App Store. Apple processes the payment and manages the subscription — we never see or store your card or payment details. Vivora keeps a small on-device record of whether a Pro subscription is active. If you use the Pro AI allowance without your own API key, your device also sends Apple's signed proof of that subscription to our server each time, so it can check the subscription is genuine and still valid before paying for the request; we verify the signature and keep only the pseudonymous reference described in §6. Purchases are subject to Apple's standard terms and Apple's privacy policy.
Because your information lives on your own device and in your own iCloud, you already control the vast majority of it directly. Under the GDPR and similar laws you also have the right to access, correct, export, restrict, or delete your personal data, and to withdraw consent.
Deleting the subscription record we hold (§6) is done from inside the app, not by writing to us — and the reason matters. That record is identified only by a one-way hash, so we genuinely cannot look it up from your name, your email, or your Apple ID. Your iPhone can, because it holds the signed proof of your subscription. Open Settings → Privacy Settings → Delete My Subscription Record. (Delete Everything does the same thing alongside erasing your on-device data.) Our server does not require an active subscription to accept a deletion request — only proof, from your device, that the subscription was yours. Because that proof comes from the device, the surest time to delete is while the option is still showing in the app.
That erases the notification record, and the device verification record for the device you delete from — if you use Vivora on more than one iPhone or iPad, delete from each of them. One thing is briefly kept: the number of AI actions you have already used today. Deleting your record would otherwise hand back a fresh daily allowance every time, so that number — and the pseudonymous reference it is stored under — remain until they clear automatically at midnight UTC. After that, none of the record described in §6 remains.
Deleting is not the same as switching the feature off. If you keep using the Pro AI allowance afterwards, a new record is created from scratch exactly as before — your device registers again and the daily count starts over. To stop one being created at all, turn AI features off in Settings, or use your own API key, in which case requests go straight to Anthropic and never reach our server (§5).
For your on-device and iCloud data, and for any other question, contact pkfk@me.com. One limit is worth stating plainly, because it follows from the same one-way hash and applies to every right rather than only deletion: we cannot find your subscription record from an email, so we cannot retrieve, correct or export it for you either. §6 lists in full what that record contains — that list is the complete answer to what we hold — and deleting it is done in the app as described above. You may also complain to your local data-protection authority.
Vivora is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has used the app, contact us and we'll assist.
If you use an AI feature (§5), the content is processed by Anthropic, which may operate servers outside your country (including the United States), under the safeguards in Anthropic's privacy policy.
If you use the Vivora Pro AI allowance without your own API key, that request also passes through Cloudflare, whose network is global; the request is handled at whichever location is nearest to you, and the small subscription record described in §6 is stored on that network. Cloudflare acts as our processor under the data-processing terms that form part of its self-serve subscription agreement, which apply to our account automatically. See Cloudflare's privacy policy.
All other data stays on your device and in your own iCloud.
If we change this policy we'll update the date above and note any significant change in the app. Continued use after a change means you accept the updated policy.
Questions or requests: pkfk@me.com.