Privacy Policy
Effective Date: 18 August 2026
Infin8 Plus Pty Ltd (ABN 83 652 827 382) ("we", "us", "our") operates the VitaGuardian mobile application (the "App") and the website at vitaguardian.com (the "Website", together the "Services"). This Privacy Policy explains how we collect, use, store, disclose, and protect your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the UK General Data Protection Regulation and Data Protection Act 2018, the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA), and Apple's App Store and HealthKit requirements.
Health information is sensitive information under Australian law and special category data under the GDPR and UK GDPR. We process it only with your explicit consent. The App is built around a clear split: what your phone measures stays on your phone, and the records you type in are backed up to your account so you do not lose them.
Your use of the Services is also governed by our Terms & Conditions.
1. Information we collect
1.1 Your profile
When you create an account, we collect your profile and store it in Firestore (Firebase, Google Cloud):
- First and last name
- Email address
- Height and weight
- Date of birth
- Gender
- Avatar (if you set one)
Height and weight are health data. They are part of your profile so your metrics work after a reinstall or on a new device, and they are protected in the same way as the rest of your profile. Nothing else in your profile document contains health information.
1.2 Health data from Apple Health
With your explicit permission, the App reads the following from Apple Health (HealthKit) on your device:
- Heart rate, resting heart rate, and heart rate variability (HRV), together with the high, low, and irregular rhythm notifications your watch records
- ECG recordings from Apple Watch, including the result Apple itself reported
- Sleep analysis, including sleep stages
- Steps, flights climbed, active and resting energy, exercise, stand and move time, and time in daylight
- Workouts, including running measures such as distance, speed, power, and stride
- Walking and mobility measures such as walking speed, step length, asymmetry, stair speed, and walking steadiness
- Respiratory rate, blood oxygen saturation (SpO2), and VO2 max
- Body temperature and wrist temperature
- Weight, height, body mass index, lean body mass, and body fat percentage
- Date of birth and biological sex
- Menstrual flow
- Mindful sessions
- Nutrition, including energy, water, macronutrients, vitamins, minerals, caffeine, and alcoholic drinks
- Headphone and environmental audio exposure
Apple's permission sheet lets you grant or refuse each category individually, and you can change your mind at any time in the Health app. Anything you refuse simply goes unfilled.
We read from Apple Health, and write back only what you enter yourself. When you log an activity in the App, we add it to Apple Health as a workout, so it sits alongside the workouts your watch recorded. When you enter your weight, we save it as a body mass reading. Those two are the only things we ever write, and both are marked as manually entered. Activities with no matching Apple workout type, such as sauna, cold plunge, and similar recovery entries, are not written at all. We never write your sleep, we never write ECG data, and we never write anything the App calculates: no scores, no trends, no baselines, no insights. If you edit or delete an activity in the App, we update or remove the matching workout in Apple Health, and we can only touch entries the App created itself. Weight works differently: the App cannot remove a weight reading once written, so to delete one, use the Health app.
We do not request or read clinical or medical records. Apple Health can also hold medical records released by a healthcare provider. Some apps ask for those. VitaGuardian does not: it neither requests nor reads them, and they are not part of its permission request.
Your Apple Health data never leaves your device. Every calculation the App performs on it, scores, trends, baselines, insights, happens on your device, and the results stay on your device. We do not transmit this data to our servers, we do not store it in iCloud, we never use it for advertising, and we never sell it.
1.3 Health data you enter
You can add blood test results, journal entries, supplement intake, and medication records to the App. Health data you enter yourself is backed up to your account, so losing or replacing a phone does not lose your records. Here is exactly where each lives:
- Blood work records: stored on your device and backed up to your account. If you photograph a blood report, the text is read on your device using Apple's Vision framework, and the photo itself is never uploaded or kept.
- Journal entries: stored on your device and backed up to your account.
- Supplement and medication list: stored on your device and backed up to your account.
- Score and trend history: stored only on your device, and never uploaded.
- Wearable CSV imports: if you import a history file exported from another wearable, the file is read on your device and is never uploaded or kept. The journal entries it creates are ordinary journal entries, so they are backed up to your account like any other.
The backup runs whenever you are signed in, and holds the same records you can see in the App. You can delete your blood work, journal, or supplement records at any time in the App, which removes the copy on your device and the backup in your account together.
1.4 Usage analytics
We use Firebase Analytics to understand which parts of the App get used, and we ask your permission for it when you first open the App. You can change your answer at any time in Profile, under Preferences.
What we record is a short, fixed list of event names. Which screen you opened (Home, Trends, Supplements, Body and similar), and that certain actions happened: a blood panel saved, a supplement added or logged, a journal entry saved, a trial started, a subscription taken out or declined.
What we never record is any of your health data. The event says a blood panel was saved. It does not say what was in it. No reading, score, result or value is ever attached.
Your account is not identified to the analytics service, and advertising features are switched off whether you consent or not. If you turn analytics off, the App tells the service to delete the data it holds for your device.
1.5 Crash reports
We use Firebase Crashlytics to collect crash reports when the App experiences errors: crash stack traces, device type, and operating system version. Crash reports never include your health data. Diagnostic logs record field names and value ranges only, never your actual readings.
1.6 Account and subscription
Sign-in (email and password, or Sign in with Apple) is handled by Firebase Authentication. Subscription purchases are processed entirely by Apple through the App Store; we never see your payment details. Apple provides us with your subscription state so the App can unlock Hero features. The App also records the times you acknowledge insights, so it does not show you the same thing twice.
1.7 Website data
When you visit the Website, our hosting provider records standard server logs (IP address, browser type, pages visited, timestamps) for security and performance. Cookie practices for the Website are described in Section 9.
1.8 Emails we send you
We use Postmark to send our email. Two kinds go out: service messages about your account, such as a welcome or a confirmation that your account was deleted, and marketing messages, which only go to people who have opted in.
Email tracking. When we send you an email we record whether it was opened and whether you clicked any links in it. Opens are measured using a small invisible image in the message. Links are routed through our email provider, Postmark, before taking you to the destination. We use this to check our emails are arriving and working properly. If you would rather not be tracked, turning off remote images in your email app stops open tracking.
Tracking is switched on for every email we send, including service messages. Postmark receives your first name and email address and nothing else about you. It never receives health data. What it records is that a message was opened or a link was clicked, and when.
2. What leaves your device
The complete list of data that reaches our infrastructure or our providers:
- Your profile: name, email, height, weight, date of birth, gender, avatar (Firestore)
- Your blood test results (Firestore)
- Your journal entries (Firestore)
- Your supplement and medication list (Firestore)
- Your marketing preference, if you opted in (Firestore)
- Insight-acknowledgement timestamps (Firestore)
- Sign-in credentials (Firebase Authentication)
- Crash reports without health data (Firebase Crashlytics)
- Usage analytics event names, if you consented (Firebase Analytics)
- Your first name and email address, so we can email you (Postmark)
- Whether you opened our emails and clicked their links (Postmark)
- Subscription state (Apple StoreKit. Apple never shares your payment details with us)
The line is simple: what your phone measures stays on your phone, and what you type in is backed up so you do not lose it. Everything read from Apple Health, and every score, trend and baseline calculated from it, stays on your device and never reaches us.
3. How we use your information
- To provide the App's health tracking and insight features (processing happens on your device)
- To create and manage your account and restore your supplement list on reinstall
- To verify your subscription status
- To diagnose and fix crashes
- To respond to your support requests
- To comply with legal obligations
- To send you news, tips, and offers about VitaGuardian by email, if you have opted in
We do not use your personal information for third-party advertising, we never use your health data for marketing of any kind, and we will never sell your data.
Marketing communications
If you opt in at sign-up, or later in the App's settings, we will occasionally email you about VitaGuardian, product news, new features, tips, and offers. Marketing is based only on your account details: your email address, name, and subscription status. It is never based on or tailored to your health data, and it only ever comes from us. Every marketing email includes a one-click unsubscribe, and you can also opt out in the App or by emailing info@vitaguardian.com. Opting out does not affect your use of the App. We will still send essential service messages about your account, security, or subscription, as these are not marketing.
4. Automated processing
VitaGuardian calculates your scores, trends and baselines automatically on your device. You should know:
- These are educational observations about your own data. They are not medical advice, diagnoses, or treatment recommendations, and they produce no legal or similarly significant effect on you within the meaning of Article 22 of the GDPR and UK GDPR.
- No decision about your access to the Services, pricing, or eligibility is made by automated means.
- Every score shows what fed into it inside the App, and you can contact us at any time to ask how one was worked out or to contest it.
If we later add features that send data to cloud AI services, we will update this policy first and ask for your explicit consent before any of your data is included.
5. Lawful basis for processing (GDPR and UK GDPR)
If you are in the UK or the European Economic Area, we process your personal data on these lawful bases:
- Explicit consent (Article 6(1)(a) and Article 9(2)(a)): for health data, your Apple Health permissions, the health records you enter, and the height and weight in your profile. You can withdraw consent at any time without penalty.
- Performance of a contract (Article 6(1)(b)): for providing the Services, managing your account, and administering subscriptions.
- Legitimate interests (Article 6(1)(f)): for crash reporting and securing the Services.
- Consent (Article 6(1)(a)): for usage analytics. We ask when you first open the App, and you can withdraw it at any time in Profile without losing any features.
- Consent (Article 6(1)(a)): for marketing emails. You can withdraw consent at any time by unsubscribing, without affecting your use of the App.
- Consent and legitimate interests (Article 6(1)(a) and Article 6(1)(f)): for recording whether our emails are opened and their links clicked. For marketing email this sits under the consent you gave when you opted in. For service email about your own account we rely on our interest in knowing those messages are arriving.
6. Disclosure of your information
We do not sell, rent, or trade your personal information. We share it only with:
- Google (Firebase / Google Cloud): authentication, storage of your profile, blood work, journal entries and supplement list, crash reporting, and usage analytics where you have consented. Google processes this data on our behalf under data processing agreements.
- Postmark: sending our email, and recording whether it was opened or its links clicked. It holds your first name and email address only, and never any health data
- Apple: App Store subscription processing. Apple Health data access happens entirely on your device
- Authorities, if legally required: where law, regulation, or legal process compels disclosure, or to protect the rights or safety of our users or the public
7. Data storage, security, and breaches
Data on our infrastructure (your profile, blood work, journal entries, supplement list, and sign-in credentials) is encrypted in transit (TLS) and at rest. Each record is stored under your own user identifier, and per-user security rules mean only your signed-in account can read it. Your Apple Health readings are protected by your device's own encryption and Apple's HealthKit security framework, because that is where they stay. The workouts and weights the App writes go into Apple Health on your device, and never to us.
We hold the health records you enter, so we keep what we hold to the minimum the App needs and protect it accordingly. You can remove your blood work, journal, or supplement records from both your device and your account at any time in the App. If a breach is likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme, and for UK or EEA users, the relevant supervisory authority within 72 hours, as the UK GDPR and GDPR require.
8. Data retention and deletion
We keep your data while your account is active. Delete your account in the App (Settings > Data & Privacy) and your health data goes with it: your Firestore records are deleted within 30 days, except where the law requires us to keep something, and your on-device data is removed when you delete the App. No email or phone call is needed.
If you unsubscribe from marketing email, we keep your email address on a suppression list held by Postmark, so that we do not email you again by mistake. It is stored as your ordinary email address, it is never used to send you anything, and it is the only reason we would still hold your address after you unsubscribe.
9. Cookies and website analytics
The App does not use cookies. On the Website, essential cookies (security, session management, preferences) are used without consent, as the law permits. If we use analytics that set non-essential cookies, we will ask for your consent through a banner first, and declining costs you nothing. We do not use advertising or cross-site tracking cookies.
The tracking image in our emails works in a similar way to a cookie, because it loads from our email provider when you open the message. Section 1.8 explains what it records and how to stop it.
10. International data transfers
The data we hold (your profile, blood work records, journal entries, supplement and medication list, and sign-in credentials) is processed on Google Cloud infrastructure, which may be located in the United States. Your first name, email address and email engagement records are processed by Postmark, which is also United States based. Where data is transferred outside Australia, the UK, or the EEA, we ensure appropriate safeguards: standard contractual clauses (including the UK International Data Transfer Addendum where UK data is involved) or adequacy decisions, as required by APP 8, the UK GDPR, and Chapter V of the GDPR.
11. Your rights
11.1 Australia (Privacy Act 1988)
- Access the personal information we hold about you (APP 12)
- Request correction of inaccurate or out-of-date information (APP 13)
- Complain about a breach of the APPs to us or to the OAIC (www.oaic.gov.au)
- Opt out of direct marketing at any time (APP 7)
11.2 UK and EEA (UK GDPR / GDPR)
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict or object to processing, including an absolute right to opt out of direct marketing
- Right to data portability: your Apple Health data can be exported from the Health app, and the blood work, journal entries and supplement list held in your account can be provided to you on request
- Right to withdraw consent at any time
- Right to complain to the UK Information Commissioner's Office (ico.org.uk) or your local EEA supervisory authority
We respond to rights requests within 30 days. Complex requests may take up to a further 60 days, and we will tell you if so.
11.3 California (CCPA/CPRA)
- Right to know what personal information we collect, use, and disclose
- Right to request deletion and correction of your personal information
- Right to opt out of sale or sharing. we do not sell or share personal information as the CCPA defines those terms
- Right to limit use of sensitive personal information: we use it only to provide the Services
- Right to non-discrimination for exercising your privacy rights
11.4 Removing your contact details
Deleting your account in the App removes your health data and your account record. Your email address can still sit on the suppression list described in Section 8, which exists only to stop us contacting you. If you want your contact details erased from that list as well, email info@vitaguardian.com and ask. We will remove them within 30 days. Be aware that once the entry is gone we no longer hold anything telling us not to contact you, so if you sign up again later you will be treated as a new subscriber.
12. Children's privacy
The Services are not intended for anyone under 18, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it promptly. If you believe a minor has provided us with personal information, contact us at info@vitaguardian.com.
13. Changes to this policy
We may update this policy from time to time. We will post material changes in the App and on the Website and update the effective date above. If a change materially affects how we handle your health data, we will ask for your consent again before it applies to you.
14. Complaints and contact
If you believe we have breached applicable privacy law, contact us first, and we will respond within 30 days. If you are not satisfied, you can escalate to the OAIC (www.oaic.gov.au), the UK Information Commissioner's Office (ico.org.uk), or your local EEA supervisory authority.
Infin8 Plus Pty Ltd
ABN: 83 652 827 382
Email: info@vitaguardian.com
Website: https://vitaguardian.com
