Privacy and data

Privacy Policy

What stays on the device, what you may send to an AI provider you choose, and how to ask us about support mail.

Effective 2026-09-16. Previous version 2026-09-14. Page reviewed 2026-09-18. No new processing was added.

Read this first

VitaGauge organizes authorized Apple Health records on the device. The developer does not run an account system and does not receive health chats. Text and selected context leave the device only after you configure your own API and give separate consent. This policy is not consent.

Reviewed on 18 September 2026 against the live 1.1.0 app. No new processing was added. The App Store Privacy URL stays on this English page for English listings.

Controller and scope

This policy covers the iOS app VitaGauge (元气指数, bundle ID com.jiankangzhuli.healthassistant.app, App Store ID 6762522305) and this GitHub Pages site. The controller is 智超 卫 (zhichao wei), email weizhichao1027@gmail.com.

The app has no developer account and no server that relays health chats. Apple is an independent controller for App Store distribution and StoreKit purchases.

Categories of data

Health and fitness: 16 Apple Health types after system permission, for on-device summary, trends, goals and the assistant. The Privacy Manifest marks health and fitness as linked, used for app functionality, and not used for tracking.

Content you enter: chat, goals and notes, optional nickname and gender, optional avatar, and the AI endpoint, model name and API key you type.

Photos: an optional avatar through the system photo picker (PHPicker). It is resized and stored on-device only, never attached to AI requests or sent to the developer. There is no camera permission.

Microphone and speech: used when you start speech-to-text. Recognition is on-device for supported devices and languages, with no cloud fallback. Text lands in the editor for review. Maximum 55 seconds.

Preferences: UserDefaults for language and conversation mode (CA92.1), not advertising.

Support mail: if you email us, we receive your address, message and attachments to respond.

This website: no sign-in, forms, cookies, analytics scripts or external fonts. GitHub may process IPs and logs under the GitHub Privacy Statement.

The app has no third-party analytics, advertising or crash SDK, and does not request tracking permission.

HealthKit

After permission the app may read steps, walking and running distance, active energy, heart rate, resting heart rate, blood oxygen, sleep, weight, workouts, heart rate variability, respiratory rate, cardio fitness, body fat percentage, systolic and diastolic blood pressure, and body temperature. It does not write HealthKit samples. Originals stay in Apple Health. Body temperature is the body-temperature type, not sleep wrist temperature. Systolic and diastolic readings are not joined across time into one measurement. Sleep intervals are merged, then split by calendar day and daylight-saving boundaries.

First launch explains the next step, the main button is Continue, then the system sheet appears. There is no Later control that skips that sheet. You can change access in Apple Health or Settings → Health data & permissions.

Widgets on iOS 17+ read a local App Group snapshot. They do not call AI or send data to the developer. The snapshot uses file protection and is excluded from backups. Open the app to sync. Widgets are not real-time monitors.

When data goes to third-party AI

Before any personal data is sent, the app names the recipient and host, lists what will be sent, and asks permission. Closing or declining cancels the send. This policy alone is not consent.

After you configure an endpoint, choose API or trigger an online request in Local + API, consent, and send, the current question and a bounded recent chat go from the device over HTTPS. Your key authenticates that request.

New health context is usually 7 days, or up to 30 for monthly trends. Minute-level samples, avatars and hidden model reasoning are not attached. Health text already inside recent messages may still be sent until you clear the chat.

Local mode sends no online conversation even if a key is saved. Changing the destination requires new consent. Withdrawal cannot recall data already delivered.

Sharing, transfers and processors

The developer does not sell health information or use it for advertising.

Recipients: Presets include DeepSeek (api.deepseek.com), Alibaba Cloud Model Studio / Qwen (dashscope.aliyuncs.com), Zhipu GLM (open.bigmodel.cn), Kimi / Moonshot (api.moonshot.cn), Volcano Engine Ark / Doubao (ark.cn-beijing.volces.com), Baidu Qianfan / ERNIE (qianfan.baidubce.com), SiliconFlow (api.siliconflow.cn), OpenAI (api.openai.com), Anthropic Claude (api.anthropic.com), Google Gemini (generativelanguage.googleapis.com), xAI (api.x.ai), Mistral AI (api.mistral.ai), Groq (api.groq.com), OpenRouter (openrouter.ai), Together AI (api.together.ai). You may also set a custom HTTPS service. Before the first send, the consent screen shows the recognizable name and the actual host. A host change voids prior consent.

Equal protection: a recipient must not sell health data or use HealthKit data for advertising, marketing or use-based mining. Do not connect if its terms fall short.

Providers process what they receive under their terms. Retention, optional training, location and deletion are theirs, and processing may occur outside your country.

Apple processes purchases. GitHub hosts this site. We add no analytics or advertising processors.

Storage and retention

The app does not bulk-copy raw samples into a second health database. Goals, profile, avatar, AI metadata and chats use file protection and are excluded from backups.

Chat is bounded (about 100 messages, 200,000 UTF-8 bytes, 24,000 characters each). Keys use device-only Keychain and are not synced with iCloud Keychain.

Backgrounding covers the app switcher and cancels in-flight AI, voice and health queries. No storage or transfer is absolutely secure.

Rights and deletion

You can manage Health, Photos, microphone and speech in iOS settings; revoke AI consent, clear configuration, clear chat, delete goals or edit the profile in the app.

There is no in-app export of original health samples. Use Apple Health. For support mail we hold, you may request access, correction or deletion. For data a provider already received, contact that provider.

Uninstalling removes sandbox files. Clear AI configuration before uninstalling. Uninstall is not a guarantee that the Keychain item is gone. Revoke or rotate the key with the provider if it must become invalid immediately.

In-app purchases

VitaGauge Pro (com.vitagauge.pro.lifetime) is a one-time non-consumable product verified with StoreKit. We unlock features from the transaction state and do not receive card numbers. Apple handles refunds. The purchase does not include an API key or model credits.

Children and health notice

The app is not intended for children under 13. The App Store rating is 12+. Contact us if you believe a child sent personal information to the developer.

VitaGauge organizes health records for everyday self-management. It is not a medical device and does not provide diagnoses, prescriptions or emergency monitoring. Correlation does not establish causation. Consult a qualified health professional before making medical decisions. Use local emergency services for urgent situations.

This website and changes

The site is hosted on GitHub Pages, with no forms, cookies, analytics scripts or external fonts. Machine-readable facts: llms.txt and product-facts.json. Material updates will change the date on this page and may appear in the app or App Store notes. New processing that needs consent will ask for it. The in-app offline summary date will follow this review date in the next app build.

Contact

Privacy, support or data requests: weizhichao1027@gmail.com. Write “VitaGauge / 元气指数” and send only what is needed.