Privacy receipt
Last updated 17 September 2026
Every network call Vitals can make, what it sends, and what it does not. This is the full list, counted from the code, not a summary.
The calls
1. Describe a meal
POST to our server, which forwards to Anthropic's Claude API. Sends the description you typed and any photos you attached. Also used when you describe a prepped batch.
2. Read a nutrition label
POST to our server, then Claude. Sends the photo of the label.
3. Read a supplement label
POST to our server, then Claude. Sends the photo of the bottle or label.
4. Estimate micronutrients
POST to our server, then Claude. Runs automatically after a meal is analysed. Sends the names and serving sizes of the foods in that meal, and nothing else about you.
5. Check a claim, or open a research topic
POST to our server, then Claude. Sends the claim you typed and the abstracts fetched in call 7.
6. Barcode lookup
GET https://world.openfoodfacts.org/api/v2/product/<barcode>.json, falling back to the us.openfoodfacts.org andworld.openfoodfacts.net hosts if the first does not know the product. Sends the barcode digits and the user agent stringVitals/1.0 (personal iOS app). It carries no device identifier and no subscription.
7. Research search
GET https://www.ebi.ac.uk/europepmc/webservices/rest/search. Sends the search terms and the same user agent string. No device identifier and no subscription.
8. Subscription check
There is no separate call. The Apple-signed receipt for your subscription travels as a header, x-vitals-entitlement, on calls 1 to 5, so the server can confirm you are entitled and count your monthly AI actions. Apple's own StoreKit talks to the App Store for the purchase itself, which is Apple, not us, and we never see your card or your Apple Account.
9. Offer attribution
POST to /api/attribution on our server. After a purchase, the app sends our server the App Store's signed receipt once, so we can count which offer, if any, was used. We keep the subscription identifier, the offer name, the product and the date. No name, no email. The record is kept while the app is on sale.
What travels on calls 1 to 5, and 9
- A random identifier generated on your device the first time the app runs. It is not your name, your email, your Apple ID, or an identifier issued by Apple.
- A build token that is the same for every copy of the app.
- Your Apple-signed subscription receipt, once you subscribe.
- Your IP address, which any web request reveals to the server and its host.
What is never sent
- Your name, email, or Apple ID. There is no account, so there is nothing to send.
- Your food log, bodyweight, workouts, routines, supplements, water, or check-ins.
- Anything read from or written to Apple Health.
- Your contacts, your photo library, or your location.
- Your advertising identifier. Vitals does not ask for one.
What is not in the app at all
- No analytics, of any kind, first party or otherwise.
- No third-party SDKs. The app has no external dependencies to add one.
- No crash reporter, no attribution SDK, no advertising, no trackers.
- No background calls. Every call above happens because you tapped something, except call 4, which follows a meal you analysed, and call 9, which follows a subscription you started.
The full policy
The Privacy Policy covers storage, retention and deletion. This page covers the wire.
More
Pricing, plainly ·What works in airplane mode ·Terms