Effective 3 September 2026 · Last updated 3 September 2026
The short version. Vivora is built to keep your data yours. Your health and personal information stays on your device and in your own iCloud account. We don't run ads, and we use no analytics or tracking SDKs. The only time your information leaves your device is when you use an optional AI feature — then only the specific content you're analysing is sent to produce the result. If you subscribe to Vivora Pro and use AI without your own API key, those requests pass through a small server we run, which counts your daily usage but never stores what you sent or what came back.
This policy explains what Vivora ("the app", "we") does with your information. Vivora is provided by Patrick Funk. Questions: pkfk@me.com.
1. Who we are
Data controller: Patrick Funk. Contact: pkfk@me.com. Vivora is an iOS health-and-wellbeing app.
2. Health & fitness data (Apple Health / HealthKit)
With your explicit permission, Vivora reads health and fitness data from Apple Health to show you insights, and writes a limited set of entries back when you ask it to. This data is read live from Apple Health when a screen needs it — Vivora does not copy your Apple Health history into its own database.
Read (only what you grant): steps, active & resting energy, distance, flights climbed, exercise/stand time, workouts and routes, heart rate, heart-rate variability, resting & walking heart rate, cardio fitness (VO₂max), ECG and heart-rhythm notifications, respiratory rate, blood oxygen, body & wrist temperature, sleep, mobility metrics (walking steadiness, gait, stair speed, six-minute walk, falls), weight, body fat, height, nutrition, water, and — only if you opt in — cycle-tracking data.
Write (only when you enter it): weight, body fat, height, blood pressure, dietary energy and water, workouts, mindful minutes, and sleep.
In line with Apple's rules, health data is never used for advertising or marketing and is never shared with anyone without your consent. You can review or revoke Vivora's access any time in Settings → Health → Data Access & Devices.
3. Information you enter
Vivora stores what you log and set up: your profile (date of birth, sex, height, weight, goals), food and drink logs, body measurements, custom drinks, recipes and saved meals, and any photos you take (food, drinks, progress photos). This is stored on your device and in your own iCloud (see §6).
4. Device permissions
Camera — to scan barcodes and photograph food, drinks and menus.
Microphone & Speech Recognition — for optional voice logging.
Photo Library — if you pick an existing photo to log.
Notifications — for reminders and nudges you choose to enable.
Each permission is requested only when its feature is first used, and every one is optional.
5. AI features & third parties
Some features use AI and public food databases. These are the only times your information is sent off your device:
AI Scan, Voice logging, Menu scan, and Recipe import send the specific content you're analysing — a food/menu photo, a voice transcript, or recipe text/URL — to an AI provider to generate the result. Which provider that is depends on whether you have added your own key — see the next point. Photos are stripped of metadata (including location) and downscaled before sending, whichever provider receives them. When you have not added your own key, the request goes to Google or Anthropic — see the next point for which — and is used to generate your result. Google handles it under the Gemini API terms: on the paid tier we use, it is not used to improve Google products, and is retained for a limited period for abuse monitoring. Anthropic handles it under Anthropic's privacy policy: it is not used to train its models, and may be retained briefly for safety monitoring. AI features are entirely optional and can be turned off in Settings.
Where your AI request goes depends on whose key pays for it.
If you have added your own API key, the request goes from your device straight to the provider you selected, and Vivora is not involved — it does not pass through our servers at all. You choose that provider in Settings → AI Keys: Anthropic, OpenAI, Google Gemini, MiniMax, or any other OpenAI-compatible service whose address you enter yourself. Your content is then handled under that provider's privacy policy, not ours and not Anthropic's. If you enter the address of a service yourself, we cannot vet it and have no relationship with it — please read its policy before sending anything to it.
If you subscribe to Vivora Pro and have not added a key, we pay for the request. Most scans go to Google (the Gemini API); some — reading a nutrition label, and the automatic second look at a difficult photo — go to Anthropic. Either way it is routed through a server we operate on Cloudflare so we can confirm the request came from a genuine copy of the app on your device, confirm any subscription is active, and count it against your daily allowance. Cloudflare passes the request to whichever of the two providers is handling it, and the answer back to you. We have turned off request logging and response caching on that route, so neither we nor Cloudflare keeps a copy of what you sent or what came back. What we do keep is described in §6. The free daily allowance does not use that server — it runs on your own key, straight from your device, exactly as the own-key case above.
Food database lookups query Open Food Facts and the USDA FoodData Central database. Only your search term or scanned barcode is sent — never your identity or health data. (European food-composition data is bundled inside the app and needs no network.)
Vivora contains no advertising, no analytics SDKs, and no third-party trackers.
6. Where your data lives & how it's protected
On your device — stored locally, protected by iOS file encryption.
Your own iCloud — your data is included in your encrypted iCloud device backup, and some records may sync through your private iCloud account. This is your iCloud; we have no access to it.
API keys you enter are stored only in your device's Keychain.
Vivora has no server that stores your health data, your logs, your photos, or your AI content. None of it is ever sent to us.
There is one exception, and it applies only if you subscribe to Vivora Pro and use AI without your own API key (§5). To meter that allowance we run a small server on Cloudflare, which keeps:
A pseudonymous subscription reference — not your Apple ID or your name. We take the transaction identifier Apple gives us for your subscription and put it through a one-way keyed hash; the result is what we store. It lets us recognise the same subscription tomorrow without knowing whose it is, and it cannot be reversed back to your Apple account.
A daily count of funded AI actions against that reference, which resets every day.
A device verification record — a public key your iPhone generates specifically for Vivora, plus a counter, used to confirm requests come from a genuine, unmodified copy of the app. It identifies the app installation, not you.
A running total of what your funded AI use has cost this month — a single number against the pseudonymous reference, used to keep one subscription inside its monthly allowance. It resets at the start of each month.
A short-lived note of which one-time codes a device has already used — each request is signed against a code that can only be used once, so the code and the moment it was used are kept briefly to stop the same signed request being replayed.
A short list of which device verification records belong to that subscription reference — kept for exactly one purpose: so that deleting your record (§9) can remove every linked device's entry in one step. A device drops off this list after 90 days without use, and the list itself is erased with everything else.
A record that Apple notified us about a subscription event (renewal, expiry, refund), so the same notice isn't processed twice. This holds the event's identifier and timestamp.
That is the complete list. Prompts, photos, voice transcripts and AI responses are not stored there — they pass through and are gone.
7. Subscriptions (Vivora Pro)
Vivora Pro is sold through Apple's App Store. Apple processes the payment and manages the subscription — we never see or store your card or payment details. Vivora keeps a small on-device record of whether a Pro subscription is active. If you use the Pro AI allowance without your own API key, your device also sends Apple's signed proof of that subscription to our server each time, so it can check the subscription is genuine and still valid before paying for the request; we verify the signature and keep only the pseudonymous reference described in §6. Purchases are subject to Apple's standard terms and Apple's privacy policy.
8. Keeping, exporting & deleting your data
Export your logs as CSV or JSON at any time.
Delete individual entries, or use Delete Everything in Settings to erase all app data. If you subscribe to Vivora Pro, that also deletes the small subscription record described in §6 from our server (see §9).
Uninstalling Vivora removes its on-device data; to remove the iCloud copy, delete it from your iCloud storage.
Apple Health data is owned by Apple Health — manage it there.
9. Your rights
Because your information lives on your own device and in your own iCloud, you already control the vast majority of it directly. Under the GDPR and similar laws you also have the right to access, correct, export, restrict, or delete your personal data, and to withdraw consent.
Deleting the subscription record we hold (§6) is done from inside the app, not by writing to us — and the reason matters. That record is identified only by a one-way hash, so we genuinely cannot look it up from your name, your email, or your Apple ID. Your iPhone can, because it holds the signed proof of your subscription. Open Settings → Privacy Settings → Delete My Subscription Record. (Delete Everything does the same thing alongside erasing your on-device data.) Our server does not require an active subscription to accept a deletion request — only proof, from your device, that the subscription was yours. Because that proof comes from the device, the surest time to delete is while the option is still showing in the app.
That erases the notification record, the device verification record for the device you delete from, and the verification records of every other device linked to your subscription, together with the list that linked them. One request from one device is normally enough. There are two exceptions, and both point the same way: a device that never used the funded AI allowance after 8 August 2026 was never linked, and a device that has not used it for more than 90 days has since dropped off the list. So if you use Vivora Pro on more than one iPhone or iPad, and one of them has been idle a while, delete from each of them once to be sure. One thing is briefly kept: the number of AI actions you have already used today. Deleting your record would otherwise hand back a fresh daily allowance every time, so that number — and the pseudonymous reference it is stored under — remain until they clear automatically at midnight UTC. After that, none of the record described in §6 remains.
Deleting is not the same as switching the feature off. If you keep using the Pro AI allowance afterwards, a new record is created from scratch exactly as before — your device registers again and the daily count starts over. To stop one being created at all, turn AI features off in Settings, or use your own API key, in which case requests go straight to the provider you chose and never reach our server (§5).
For your on-device and iCloud data, and for any other question, contact pkfk@me.com. One limit is worth stating plainly, because it follows from the same one-way hash and applies to every right rather than only deletion: we cannot find your subscription record from an email, so we cannot retrieve, correct or export it for you either. §6 lists in full what that record contains — that list is the complete answer to what we hold — and deleting it is done in the app as described above. You may also complain to your local data-protection authority.
10. Children
Vivora is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has used the app, contact us and we'll assist.
11. International processing
If you use an AI feature (§5) without your own key, the content is processed by Google or Anthropic, either of which may operate servers outside your country (including the United States), under the safeguards in that provider's own policy. If you have added your own key, the content is processed by the provider you selected, which may likewise operate outside your country, under that provider's own safeguards.
If you use the Vivora Pro AI allowance without your own API key, that request also passes through Cloudflare, whose network is global; the request is handled at whichever location is nearest to you, and the small subscription record described in §6 is stored on that network. Cloudflare acts as our processor under the data-processing terms that form part of its self-serve subscription agreement, which apply to our account automatically. See Cloudflare's privacy policy.
All other data stays on your device and in your own iCloud.
12. Changes to this policy
If we change this policy we'll update the date above and note any significant change in the app. Continued use after a change means you accept the updated policy.
What changed on 3 September 2026
§5, §9 and §11 — a second company now handles Vivora Pro AI requests. If you subscribe to Vivora Pro and have not added your own API key, your scans previously all went to Anthropic. Most of them now go to Google (the Gemini API) instead; some — reading a nutrition label, and the automatic second look at a difficult photo — still go to Anthropic. Both are reached through the same Cloudflare server as before, with request logging and response caching still turned off, and we still keep no copy of what you sent or what came back.
What each provider does with it. Google, on the paid tier we use, does not use what you send to improve Google products, and retains it for a limited period for abuse monitoring under its own terms. Anthropic does not use it to train its models, and may retain it briefly for safety monitoring under its own policy. Both are now stated in §5.
This does not affect you if you use your own API key. Your requests still go straight from your device to the provider you chose and never pass through our servers. Nothing about that changed.
Why we changed it. Honestly: cost and speed. The change makes a scan roughly four times cheaper for us and several times faster for you, and on our own testing it identifies food in a photograph more accurately than the previous setup. It also let us raise nothing and cut nothing you had — see the daily allowance in §5.
What changed on 27 August 2026
§5, §9 and §11 — where your AI request goes. These sections named Anthropic unconditionally. That stopped being accurate on 26 August 2026, when your own key could point at providers other than Anthropic: with your own key the request goes straight from your device to the provider you selected — Anthropic, OpenAI, Google Gemini, MiniMax, or an OpenAI-compatible service whose address you enter yourself — and never passes through our servers. The three sections now say so, and §5 adds that we cannot vet a service you name yourself. Nothing changed about how your requests are handled — only how this page describes them. Vivora Pro requests without your own key still go to Anthropic through our Cloudflare server, and we still keep no copy of what you sent or what came back; the free daily allowance still runs on your own key, straight from your device. This is the website catching up to what the app already told you — the in-app AI disclosure has described these providers since 26 August 2026.
What changed on 11 August 2026
§5 — AI features. This section previously said content sent to Anthropic "is used solely to provide the feature". It now says the content is used to generate your result, and that Anthropic may retain it briefly for safety monitoring under its own policy. Nothing about how Vivora handles your data has changed — we and Cloudflare still keep no copy of what you send or what comes back (§6). The wording was too absolute about what happens at Anthropic, and this states it accurately.
What changed on 9 August 2026
§6 — what we store. The server now keeps a monthly cost total, a brief record of used one-time codes, and a short list of which device verification records belong to a subscription, added for one reason: so deletion can remove every device's record in one step. It expires per device after 90 days without use.
§9 — deleting it. Deleting from one device now also removes the verification records of every other linked device. Devices that never used the funded allowance since this change are not linked; the old per-device instruction still works for them.
What changed on 28 July 2026
§6 — what we store. Vivora Pro's AI allowance now runs through a small server we operate, so this section describes the subscription record that server keeps and where it lives.
§9 — deleting it. Deletion is now something you do from inside the app, and this section describes what is erased, what is briefly retained, and for how long.
§11 — processors. Cloudflare is named alongside Anthropic, with the basis on which each handles your requests.