Privacy Policy
Effective Date: 8 August 2026
Infin8 Plus Pty Ltd (ABN 83 652 827 382) ("we", "us", "our") operates the VitaGuardian mobile application (the "App") and the website at vitaguardian.com (the "Website", together the "Services"). This Privacy Policy explains how we collect, use, store, disclose, and protect your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the UK General Data Protection Regulation and Data Protection Act 2018, the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA), and Apple's App Store and HealthKit requirements.
Health information is sensitive information under Australian law and special category data under the GDPR and UK GDPR. We process it only with your explicit consent, and we designed the App so that almost none of it ever reaches us.
Your use of the Services is also governed by our Terms & Conditions.
1. Information we collect
1.1 Your profile
When you create an account, we collect your profile and store it in Firestore (Firebase, Google Cloud):
- First and last name
- Email address
- Height and weight
- Date of birth
- Gender
- Avatar (if you set one)
Height and weight are health data. They are part of your profile so your metrics work after a reinstall or on a new device, and they are protected in the same way as the rest of your profile. Nothing else in your profile document contains health information.
1.2 Health data from Apple Health
With your explicit permission, the App reads the following from Apple Health (HealthKit) on your device:
- Heart rate, resting heart rate, and heart rate variability (HRV)
- Sleep analysis, including sleep stages
- Step count and active energy burned
- Respiratory rate
- Blood oxygen saturation (SpO2)
- VO2 max
- Wrist temperature
- Weight, height, and biological sex
We read from Apple Health and never write to it. The App requests read-only access, does not save anything back to Apple Health, and does not read clinical health records.
Your Apple Health data never leaves your device. Every calculation the App performs on it, scores, trends, baselines, insights, happens on your device, and the results stay on your device. We do not transmit this data to our servers, we do not store it in iCloud, we never use it for advertising, and we never sell it.
1.3 Health data you enter
You can add blood test results, journal entries, supplement intake, and medication records to the App. Here is exactly where each lives:
- Blood work records — stored only on your device. If you photograph a blood report, the text is read on your device using Apple's Vision framework; the photo is never uploaded or kept.
- Journal entries — stored only on your device.
- Score and trend history — stored only on your device.
- Supplement and medication list — backed up to Firestore so it survives a reinstall or a new phone. This is the only health record you enter that is stored on our infrastructure.
- Wearable CSV imports (for example Whoop) — processed in memory on your device; the file is not copied or retained.
1.4 Usage analytics
Analytics collection is switched off. The App ships with the Firebase Analytics component, but collection is disabled and we do not gather usage analytics from the App. If we ever switch analytics on, we will update this policy first and give you a choice.
1.5 Crash reports
We use Firebase Crashlytics to collect crash reports when the App experiences errors: crash stack traces, device type, and operating system version. Crash reports never include your health data — diagnostic logs record field names and value ranges only, never your actual readings.
1.6 Account and subscription
Sign-in (email and password, or Sign in with Apple) is handled by Firebase Authentication. Subscription purchases are processed entirely by Apple through the App Store; we never see your payment details. Apple provides us with your subscription state so the App can unlock Pro features. The App also records the times you acknowledge insights, so it does not show you the same thing twice.
1.7 Website data
When you visit the Website, our hosting provider records standard server logs (IP address, browser type, pages visited, timestamps) for security and performance. Cookie practices for the Website are described in Section 9.
2. What leaves your device
The complete list of data that reaches our infrastructure or our providers:
- Your profile — name, email, height, weight, date of birth, gender, avatar (Firestore)
- Your supplement and medication list backup (Firestore)
- Insight-acknowledgement timestamps (Firestore)
- Sign-in credentials (Firebase Authentication)
- Crash reports without health data (Firebase Crashlytics)
- Subscription state (Apple StoreKit — Apple never shares your payment details with us)
That is everything. Blood work, journal entries, scores, and all Apple Health readings stay on your device.
3. How we use your information
- To provide the App's health tracking and insight features (processing happens on your device)
- To create and manage your account and restore your supplement list on reinstall
- To verify your subscription status
- To diagnose and fix crashes
- To respond to your support requests
- To comply with legal obligations
- To send you news, tips, and offers about VitaGuardian by email, if you have opted in
We do not use your personal information for third-party advertising, we never use your health data for marketing of any kind, and we will never sell your data.
Marketing communications
If you opt in at sign-up, or later in the App's settings, we will occasionally email you about VitaGuardian, product news, new features, tips, and offers. Marketing is based only on your account details: your email address, name, and subscription status. It is never based on or tailored to your health data, and it only ever comes from us. Every marketing email includes a one-click unsubscribe, and you can also opt out in the App or by emailing info@vitaguardian.com. Opting out does not affect your use of the App. We will still send essential service messages about your account, security, or subscription, as these are not marketing.
4. Automated processing and AI insights
VitaGuardian generates wellness insights from your data using automated processing on your device. You should know:
- Insights are educational observations about your own data. They are not medical advice, diagnoses, or treatment recommendations, and they produce no legal or similarly significant effect on you within the meaning of Article 22 of the GDPR and UK GDPR.
- No decision about your access to the Services, pricing, or eligibility is made by automated means.
- You can contact us at any time to ask how an insight was generated or to contest one.
If we later add features that send data to cloud AI services, we will update this policy first and ask for your explicit consent before any of your data is included.
5. Lawful basis for processing (GDPR and UK GDPR)
If you are in the UK or the European Economic Area, we process your personal data on these lawful bases:
- Explicit consent (Article 6(1)(a) and Article 9(2)(a)) — for health data: your Apple Health permissions, the health records you enter, and the height and weight in your profile. You can withdraw consent at any time without penalty.
- Performance of a contract (Article 6(1)(b)) — for providing the Services, managing your account, and administering subscriptions.
- Legitimate interests (Article 6(1)(f)) — for crash reporting and securing the Services.
- Consent (Article 6(1)(a)) — for marketing emails. You can withdraw consent at any time by unsubscribing, without affecting your use of the App.
6. Disclosure of your information
We do not sell, rent, or trade your personal information. We share it only with:
- Google (Firebase / Google Cloud) — authentication, profile and supplement-list storage, crash reporting, processing data on our behalf under data processing agreements
- Apple — App Store subscription processing; Apple Health data access happens entirely on your device
- Authorities, if legally required — where law, regulation, or legal process compels disclosure, or to protect the rights or safety of our users or the public
7. Data storage, security, and breaches
Data on our infrastructure (your profile, supplement list, and sign-in credentials) is encrypted in transit (TLS) and at rest, and per-user security rules mean only your signed-in account can read your records. Your health data is protected by your device's own encryption and Apple's HealthKit security framework, because that is where it stays.
Because we do not hold your health readings, journal, or blood work on our servers, they cannot be exposed by a breach of our systems. If a breach of the data we do hold is likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme, and for UK or EEA users, the relevant supervisory authority within 72 hours, as the UK GDPR and GDPR require.
8. Data retention and deletion
We keep your data while your account is active. Delete your account in the App (Settings > Data & Privacy) and your health data goes with it: your Firestore records are deleted within 30 days, except where the law requires us to keep something, and your on-device data is removed when you delete the App. No email or phone call is needed.
9. Cookies and website analytics
The App does not use cookies. On the Website, essential cookies (security, session management, preferences) are used without consent, as the law permits. If we use analytics that set non-essential cookies, we will ask for your consent through a banner first, and declining costs you nothing. We do not use advertising or cross-site tracking cookies.
10. International data transfers
The data we hold (profile, supplement list, credentials) is processed on Google Cloud infrastructure, which may be located in the United States. Where data is transferred outside Australia, the UK, or the EEA, we ensure appropriate safeguards — standard contractual clauses (including the UK International Data Transfer Addendum where UK data is involved) or adequacy decisions — as required by APP 8, the UK GDPR, and Chapter V of the GDPR.
11. Your rights
11.1 Australia (Privacy Act 1988)
- Access the personal information we hold about you (APP 12)
- Request correction of inaccurate or out-of-date information (APP 13)
- Complain about a breach of the APPs to us or to the OAIC (www.oaic.gov.au)
- Opt out of direct marketing at any time (APP 7)
11.2 UK and EEA (UK GDPR / GDPR)
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict or object to processing, including an absolute right to opt out of direct marketing
- Right to data portability — most of your data is already on your device, and Apple Health data can be exported via the Health app
- Right to withdraw consent at any time
- Right to complain to the UK Information Commissioner's Office (ico.org.uk) or your local EEA supervisory authority
We respond to rights requests within 30 days. Complex requests may take up to a further 60 days, and we will tell you if so.
11.3 California (CCPA/CPRA)
- Right to know what personal information we collect, use, and disclose
- Right to request deletion and correction of your personal information
- Right to opt out of sale or sharing — we do not sell or share personal information as the CCPA defines those terms
- Right to limit use of sensitive personal information — we use it only to provide the Services
- Right to non-discrimination for exercising your privacy rights
12. Children's privacy
The Services are not intended for anyone under 18, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it promptly. If you believe a minor has provided us with personal information, contact us at info@vitaguardian.com.
13. Changes to this policy
We may update this policy from time to time. We will post material changes in the App and on the Website and update the effective date above. If a change materially affects how we handle your health data, we will ask for your consent again before it applies to you.
14. Complaints and contact
If you believe we have breached applicable privacy law, contact us first — we will respond within 30 days. If you are not satisfied, you can escalate to the OAIC (www.oaic.gov.au), the UK Information Commissioner's Office (ico.org.uk), or your local EEA supervisory authority.
Infin8 Plus Pty Ltd
ABN: 83 652 827 382
Email: info@vitaguardian.com
Website: https://vitaguardian.com