Consumer health data
Consumer Health Data Privacy Policy.
A standalone notice about the health-related data Vyra collects, why, who processes it, and the rights you have over it — separate from, and in addition to, our general Privacy Policy.
Effective September 5, 2026
This is Vyra’s Consumer Health Data Privacy Policy. It is a standalone notice about the health-related data Vyra collects, why, who processes it, and the rights you have over it. It exists separately from, and in addition to, our general Privacy Policy because Washington’s My Health My Data Act (MHMDA) and several other state laws require a dedicated consumer-health-data notice reachable by its own distinct link.
- Controller: Vyra Health Inc. (“Vyra,” “we,” “us”)
- Effective date: September 5, 2026
- This document’s canonical link: https://getvyra.ai/consumer-health-privacy
- Privacy contact: [email protected]
Not medical advice. Vyra is a nutrition and wellness companion, not a medical device. It does not diagnose, treat, cure, or prevent any medical condition, and it is not a substitute for a licensed professional. This section is a reminder only; it is not the consent this policy describes.
Which laws protect this data. Vyra is a direct-to-consumer wellness app. We are not a HIPAA “covered entity” or “business associate,” and this data is not governed by HIPAA. Instead, your consumer health data is protected under this policy and under consumer-privacy laws — including Washington’s My Health My Data Act (MHMDA), California’s CCPA/CPRA, Connecticut’s Data Privacy Act, and Nevada’s Consumer Health Data Privacy Law (SB370) — plus the FTC Act and the FTC Health Breach Notification Rule.
1. MHMDA compliance at a glance (for reviewers)
| MHMDA / state-law requirement | How Vyra meets it | Section |
|---|---|---|
| Standalone Consumer Health Data Privacy Policy, distinct homepage link | This document, linked separately from the general policy | Header, §13 |
| Categories of consumer health data (CHD) collected + sources | Enumerated, mapped to actual app features | §3, §4 |
| Purposes of collection / how CHD is used | Enumerated; only to provide features you use | §5 |
| Categories of CHD shared + who we share with | Processors only; no advertisers, no data brokers | §6 |
| No sale of CHD (would require separate written authorization) | We do not sell CHD, and have no mechanism to | §6, §7 |
| Opt-in consent to collect/share CHD beyond what’s necessary | Everything we collect is on a necessity basis — only what the feature you are using needs. There is no beyond-necessity use, so there is nothing to consent to | §7 |
| Right to confirm/access CHD | In-app + email request | §8 |
| Right to delete CHD | In-app account deletion + right to erasure | §8, §9 |
| Right to withdraw consent | Nothing is collected on a consent basis, so there is no consent to withdraw. To stop us holding any of it: delete the entry, or delete your account | §7, §8, §9 |
| Right to appeal a denied request | Appeal path + regulator escalation | §8 |
| Data-level security controls for CHD | Encryption at rest/in transit, per-user RLS isolation, least-privilege access | §10 |
| Retention & deletion schedule | Kept while account active; deletion → 30-day grace → hard purge | §9 |
2. What counts as “consumer health data” here
“Consumer health data” (CHD) means personal information linked to you that identifies your past, present, or future physical or mental health status. Under Washington’s MHMDA and comparable laws, this is read broadly — it includes information about your diet, nutrition, body measurements, and health goals, not only clinical records.
For Vyra, your CHD is in scope from your first use, including your food and diet logs. We treat the data described in §3 as CHD and apply this policy to it.
Inferences count too. Values we derive from your inputs — such as BMI, your steps-to-goal activity ratio, and your non-clinical “momentum”/consistency signal — are themselves treated as consumer health data and are covered by this policy, the same as data you enter directly.
3. Consumer health data we collect
We collect only what the features you use require. Depending on which parts of Vyra you use, this includes:
Core (collected for every user, because the core product is a food/nutrition loop):
- Food and diet logs — meals you describe or photograph, the recognized food items, portions, and the resulting nutrition/macro values (calories, protein, carbs, fat, fiber, sugar, sodium).
- Meal photos — the image itself, when you log a meal by photo or scan a barcode. It is retained with your account; storage, retention, purpose, and the human-review and no-biometrics limits are set out in §4.
- Body and profile measurements — weight and weigh-in history, height, sex, activity level, unit preference, and time zone. If you connect Apple Health or Health Connect and allow it, a body-weight reading imported from there becomes an entry in that same weigh-in history and is saved to your account, exactly like a weight you type in yourself (see §4).
- Goals — your calorie, macro, water, and step targets; target weight; goal direction; and pacing preference.
- Hydration — daily water/glass counts.
- Self-declared dietary preferences — diet style, eating pattern, intermittent-fasting window, and any allergies you enter (allergy matching happens on your device; it is not sent on the food-parsing path).
- Derived activity signal — a single computed ratio of your day’s steps to your step goal, capped at 100%. It is the only thing we receive that is derived from your Apple Health / Health Connect step readings; §4 sets out what reaches us for each reading type.
- Behavioral progress signals — a non-clinical “momentum”/consistency score and cached insight summaries derived from your logging behavior.
- Reminders you set, and the device push token used to deliver them.
Optional (collected only if you use the relevant module — see §7):
- Medications — drug name, optional normalized code, dose, unit, frequency, route, schedule, dose logs, and any side-effect notes you add.
- Conditions — a condition label and optional normalized code you choose to store.
Not currently collected in the released app. Some parts of Vyra are built but turned off in the public release and do not collect or process your data unless and until we enable them, update this policy, and (where required) obtain your consent:
- Lab and blood-test document ingestion (uploading and extracting lab results) is disabled in production.
- The food ↔ medications ↔ labs correlation/insights engine is disabled in production.
- Personalized clinical guidance (“caution”-tier) behaviors are disabled in production.
4. Where the data comes from
- You — everything you type, log, photograph, or set in the app.
- Apple HealthKit / Android Health Connect — only if you connect it, and only for the types you allow. Vyra asks to read three things: your steps, your active energy burned, and your body weight. It asks to write at the same time, in the same permission screen — what that means is set out under “What Vyra writes back” below. The three reading types are handled differently, so here is each one:
- Steps and active energy. Your raw step and active-energy readings stay on your device, where Vyra uses them to show your step trend and a “burned” figure beside what you have eaten. What reaches us is one number per day: how much of your own daily step goal you reached, capped at 100%.
- Body weight — this one does reach us. If you allow it, Vyra imports your most recent weight reading (for example one recorded by a smart scale) into your own Vyra weight log, at most one entry per calendar day. Because it becomes an ordinary entry in that log, it is saved to your account just like a weight you type in yourself — which is what lets your weight history survive reinstalling the app or moving to a new phone. You can see it, correct it, and delete it in the app (§8).
- RevenueCat (subscription processor) — commercial subscription metadata (trial/active/lapsed status, plan) tied to an opaque account identifier, so we know your entitlement. This is not health data and carries no health information.
What Vyra writes back to Apple Health / Health Connect. The connection runs in both directions: Vyra also writes entries you logged in Vyra into the Apple Health / Health Connect store on your phone, so they sit alongside everything else there and the other apps you trust can read them. The permission screen that asks to read the three types above asks for this at the same time. You can refuse that half and keep the reading half, and you can allow only part of it — Vyra writes only the types you actually granted, and if you grant none of them it writes nothing at all. What it copies across, and nothing besides:
- Your weigh-ins — the weight and the moment you recorded it, for weigh-ins that started in Vyra: one you typed on the weigh-in screen, one you entered in chat, or the starting weight you gave during onboarding. A weight that Vyra imported from your health app is normally held back rather than written out again, since it is already there and a second copy would show it twice. That is a normal rule and not an absolute one: if you log a weight in chat for a day your health app had already covered, that day’s entry can be written back carrying the imported reading.
- Your meals — for each food item you logged: the name it carries in your Vyra log, the time you logged it, which meal it belonged to (breakfast, lunch, dinner or snack), its calories, and its protein, carbohydrates, fat, fiber, sugar and sodium.
- Your water — the total volume you logged for a day.
Three limits apply to this write-back. It is forward-only: Vyra copies what you log or edit after you turn writing on, and does not go back and copy across the history you logged before that. Deletions follow for meals and weigh-ins — remove a meal or a weigh-in in Vyra and the copy Vyra wrote is removed too, although Vyra can only remove records it wrote itself and never one that another app created. Water is the exception, and it is the one place this limit does not hold: Vyra updates the day’s water entry in your health app when you change the amount, but it has no way to take that entry back once it is written, so a day you set back to zero leaves the last volume Vyra wrote for it standing in your health app. And it is a hand-off on your own phone rather than a transmission: Vyra passes the entry to the Apple Health / Health Connect store on the device, and nothing about that step reaches our servers, any processor in §6, or our analytics. Once an entry is in your health app it is governed by Apple’s or Google’s terms and by your own settings there, including any backup or sharing you have turned on in that app.
Meal photos: a meal photo you take is sent to our AI processor for food recognition (see §6) and is stored with your account — in AWS S3, encrypted with a customer-managed key (SSE-KMS), under a per-user prefix isolated to your account. We keep it while your account is active and use it to run the food-logging feature and to check and improve the accuracy of our food recognition, which can include a member of our team reviewing a photo when you report a wrong result or ask for help. We do not use your photos to train AI models, and there is no setting that changes that (§7). We never run facial recognition or extract biometric identifiers from them, and no setting changes that. Photos are permanently purged when you delete your account (§9). A copy also stays in an encrypted store on your device, and that on-device copy is what your in-app history displays.
5. Why we collect it (purposes)
We use your CHD solely to provide and improve the features you use:
- Recognize and log your meals and compute their nutrition values.
- Check and improve the accuracy of that food recognition — including reviewing a stored meal photo, by a member of our team, when you report a result as wrong or ask us for help (§4).
- Track your intake against your goals and show your progress and trends.
- Store your optional medications/conditions so you can see them alongside your food and habits.
- Deliver the reminders you set.
- Maintain your account, sync your data across your own devices, and restore it if you reinstall.
- Keep the service secure, debug crashes (without health content — see §6), and understand feature usage in aggregate (without health content).
We do not use your CHD for advertising, and we do not use it to train AI models. That is unconditional — not a default you can change, and there is no setting anywhere in Vyra that turns it on. The accuracy work above is us reading a result you told us was wrong and fixing how the feature handles it; it never means learning from your data (§6, §7).
6. Who processes your data (service providers)
We share data only with vetted processors who act on our instructions under contract. We do not share CHD with advertisers, data brokers, or any third party for their own purposes. Vyra ships with no advertising or attribution SDKs.
| Processor | What it handles | Health data? | Safeguards |
|---|---|---|---|
| Amazon Web Services (RDS Postgres, S3, Lambda; US region) | Primary data storage and compute | Yes — your data lives here | AWS Data Processing Addendum (incorporated in the AWS Customer Agreement); HIPAA-eligible services with a BAA executed via AWS Artifact; encryption with our customer-managed key; per-user access isolation |
AWS Bedrock (Claude models) (US region, us-east-1) | Food recognition + text parsing (and meal-photo vision, transiently) | Processes food inputs in-request | Zero-retention, no-training configuration; BAA-eligible; outputs validated before use; inputs are not retained |
| RevenueCat (United States) | Subscription/billing status | No — opaque ID + commercial metadata only | Card numbers never reach our servers (Apple/Google are the merchants of record); identified only by an opaque account ID |
| PostHog (EU Cloud — Germany, Frankfurt) | Product analytics | No — PHI-free events only, enforced by an allow-list and a server-side scrub | EU-hosted; standard DPA |
| Sentry (EU Cloud — Germany, Frankfurt) | Crash/error reporting | No — known health field names scrubbed before send | EU-hosted; standard DPA |
| Expo (United States) | Delivering the reminder notifications you turn on | No — the device push token and the reminder text, which it passes to Apple or Google for delivery; never food, weight, medications, conditions or lab results | Delivery identifier only. Reminder text is drawn solely from a fixed set of phrases written in advance — there is no interpolation of anything you logged, and a test fails our build on a medication name, a dose or a health value |
| OneSignal (United States) | Delivering reminder and re-engagement notifications | No — device notification token, device model, OS and app version, time zone and language, plus a one-way scrambled account ID; never food, weight, medications, conditions or lab results | Delivery identifier only; no health tags — a test fails our build if anyone adds one; its location-tracking component is removed from the app entirely |
| Cloudflare (United States, global edge network) | Serving our website and forwarding waitlist email | No | No health data reaches it; it serves static pages and email forwarding only |
Our internal analytics and error tooling receive PHI-free data by construction — your food, meds, conditions, weights, and other health values never reach them.
We may also disclose data if required by law (e.g., a valid legal request), or in connection with a merger or acquisition — in which case this policy, including its no-sale commitment, continues to govern.
7. Why we may collect this, and our commitments
Everything here is collected on a necessity basis. There is no consent wall, and no consent to give. When you use Vyra’s core food and nutrition loop, we collect the consumer health data that loop needs (your meals, macros, weight, goals, hydration, and the other Core categories in §3) because it is necessary to provide the service you asked for. MHMDA and comparable laws do not require separate consent for collection that is necessary to deliver a feature you are actively using, so we do not put a consent gate in front of core logging. This mirrors how other consumer nutrition and wellness apps (e.g., MacroFactor, Function Health, SiPhox) treat the data you enter to make the product work. You are always in control: you can edit or delete any entry, or delete your whole account (§8–§9).
The optional modules work the same way. The medications, conditions, and lab/blood-test modules are not part of the core loop, so nothing in them is collected unless you open them and enter something. What you enter there is collected on the same necessity basis: it is what those features need in order to show you what you asked them to show you. Not using a module means we hold nothing from it.
Meal photos are Core, not an extra. Keeping the photo of a meal you logged is how the food-logging feature you asked for works — it is what your entry is based on, what lets you check it, and what lets us correct it when you tell us a result is wrong. So it sits in the Core categories in §3 and is collected on the same necessity basis as the rest of core logging, described in full in §4.
There is no use of your data beyond that, so there is no consent to give. Everything we do with your consumer health data is listed in §5, and every item there is part of running a feature you are using. We do not have a secondary use, an optional programme, or a setting that widens what we may do with your data — and we do not train AI models on it (§5). If that ever changed, it would need its own affirmative, unbundled opt-in, asked for before the new use began, not after.
No third-party sharing or sale — so no separate share/sale consent is needed. We do not share your CHD with any third party for that third party’s own purposes, and we do not sell it. The only parties that touch your CHD are the vetted processors in §6, acting on our instructions under contract — which is not “sharing” under MHMDA. Because there is no sharing-for-others and no sale, there is no separate share-consent or sale-authorization to collect.
No sale of consumer health data (monetary-value floor). We do not sell your consumer health data. Under no circumstances do we disclose your CHD in exchange for monetary or other valuable consideration. MHMDA permits a sale of consumer health data only under a signed, valid written authorization — we have no such mechanism and no business arrangement to sell. If this ever changed, we would obtain that separate authorization before any such activity.
No sharing with advertisers. We do not share your CHD for advertising or with data brokers. Vyra ships with no advertising or attribution SDKs (§6).
No training on your data. We do not train AI models on your data — not your meal photos, not your corrections, not anything else. This is unconditional and there is no setting that turns it on. Separately, our AI processor is contractually configured for zero retention and no training: that is a limit on the processor, and it is in addition to this commitment, not a restatement of it.
No location tracking, no health-facility geofencing. We do not collect precise geolocation. Vyra requests no location permission and never asks your device where it is, so we do not track your movements. We do not use a geofence around any health-care facility, pharmacy, or other location to infer or collect health data about you.
One thing we do record, and it is a country. Like any internet service, the processors we use see the internet address your device connects from, and two of them — our subscription processor, and our notification processor if enabled — keep the country that address resolves to. That is an approximate location, and we declare it as one on the app stores rather than rely on the fact that we never asked your device for it. It is never joined to your health data, never used to infer anything about your health, and it is a country — not a place.
The onboarding “not medical advice” disclaimer is not a data-collection consent. That disclaimer covers the nature of the product; it does not authorize data collection or sharing, and it never did. This policy is the description of what we collect and why.
8. Your rights and how to exercise them
Regardless of where you live, you can exercise the following with respect to your CHD. Residents of Washington (MHMDA), California (CCPA/CPRA, including sensitive personal information), Connecticut, Nevada (SB370), and other states with comparable laws have these rights by statute; we extend them to all users.
- Confirm / access — confirm whether we collect, share, or sell your consumer health data, and get a copy plus a list of all third parties and affiliates it has been shared with or sold to. We have no affiliates with whom we share CHD, and we do not sell CHD, so that list is limited to the processors in §6 acting on our instructions.
- Data portability — receive a copy of your CHD in a portable, structured, commonly used, machine-readable format so you can move it elsewhere. We fulfill this on request today (we assemble and send the export manually within the statutory window).
- Delete — have your CHD deleted (see §9 for how deletion propagates).
- Stop collection — stop using a feature and we collect nothing further from it; delete the entries it holds, or delete your account (§9), and we hold nothing from it at all. There is no consent to withdraw, because nothing here is collected on a consent basis (§7) — the control is the feature itself and the delete, not a toggle.
- Correct — correct inaccurate information (most profile and log data is directly editable in the app).
- Non-discrimination — we will not deny you service or charge you differently for exercising these rights.
- Appeal — if we deny a request, you may appeal by replying to our decision or writing [email protected]. We will respond with our decision and reasoning within the timeframe the applicable law requires.
Authorized agents. You may use an authorized agent to submit a request on your behalf. We will ask the agent for proof of your written authorization and will separately verify your identity (and, where the law allows, may contact you directly to confirm) before acting.
How to exercise:
- In app: edit or delete individual entries directly; delete your entire account under Settings (this triggers the erasure in §9).
- By email: contact [email protected]. We will verify your request against your account and respond within the timeframe the applicable law requires — generally within 45 days (extendable once where permitted). For Connecticut residents, we will inform you of any action on an appeal within 60 days of receipt.
California — your right to limit use of sensitive personal information. California treats health data as sensitive personal information (SPI). Vyra uses your SPI solely to provide the features you requested and for the purposes in §5 — we never use it to infer characteristics about you, for advertising or cross-context behavioral advertising, or for any purpose that would trigger California’s right to limit. Because we do not sell or share your personal information and do not use SPI beyond those permitted purposes, there is nothing to opt out of, and no “Your Privacy Choices” / “Do Not Sell or Share” control is required or presented. If that ever changed, we would add one.
Global Privacy Control (GPC). On our website we honor browser-based opt-out preference signals, including Global Privacy Control (GPC). Because we do not sell or share consumer health data, a GPC signal has nothing to opt out of — but we still treat any GPC signal we receive as a valid opt-out request.
If you’re unsatisfied after appealing:
- Washington residents may contact the Washington State Attorney General at https://www.atg.wa.gov/file-complaint.
- California residents may contact the California Privacy Protection Agency or the California Attorney General.
- Nevada residents may contact the Nevada Attorney General at https://ag.nv.gov/ under Nevada’s Consumer Health Data Privacy Law (SB370).
- Residents of other states may contact their state Attorney General.
- Canadian residents may complain to the Office of the Privacy Commissioner of Canada. Quebec residents may complain to the Commission d’accès à l’information du Québec.
9. Retention and deletion
Active-account retention. We keep your CHD only while your account is active and for as long as needed to provide the service. We do not retain your CHD after your account is deleted except for the minimal, health-data-free records described below.
When you delete your account:
- Your account is soft-deleted immediately and a 30-day grace period begins (signing back in during that window cancels the deletion).
- After the grace period, a hard purge permanently removes your data across every user-scoped data store — including your food logs, meal photos (every stored version of each image), weights, goals, optional medications and conditions, reminders, and any stored documents — plus your authentication records.
- We retain only a health-data-free deletion record confirming that the deletion occurred (no health content), and any minimal records we are legally required to keep.
Deletion propagates to our processors. On deletion we also direct our processors (§6) to delete your data, except where a processor is legally required to retain it. In practice this is largely already true by design: our AI processor runs under a zero-retention configuration (it keeps nothing to delete), and our analytics and error tools receive PHI-free data only, so they hold no CHD to begin with.
How to request deletion. You can delete your account in-app under Settings, or email [email protected]. You can also request deletion from the web, without installing or opening the app, at getvyra.ai/delete-account.
We delete or de-identify CHD when it is no longer needed for the purpose it was collected.
10. How we protect your data
- Encryption in transit (TLS) and at rest (storage encrypted with our customer-managed key; stored documents use server-side KMS encryption).
- Per-user isolation enforced at the database layer (row-level security), so one account cannot read another’s data.
- Least-privilege access for our systems and staff; production access is scoped and monitored.
- Health data is kept out of logs and analytics by design, with a server-side scrub as a backstop.
- Health-platform minimization — your raw step and active-energy readings stay on your device, and the one thing we receive from them is a single capped daily activity ratio. Body weight is the exception: an imported reading is saved to your account as a weigh-in, and only if you allow it (§4).
- No precise location, no geofencing — we do not collect precise geolocation, request no location permission, and do not geofence health-care facilities or pharmacies. Our processors do record the country your connection resolves to, which we declare as approximate location and never join to your health data (§7).
No system is perfectly secure, but we work to protect your data in line with its sensitivity.
Breach notification. As a non-HIPAA health-app vendor, if a breach affects your identifiable health information, we will notify you and the appropriate authorities as required by the FTC Health Breach Notification Rule and applicable state law.
11. Cookies and tracking technologies
This section covers our website (getvyra.ai), not the app. The app contains no advertising or attribution SDKs and no cross-site trackers (§6).
Our website uses privacy-preserving, cookieless, EU-hosted product analytics (PostHog) to understand aggregate site usage — page-visit counts only, with no cookies, no cross-site tracking, and no personal data, so there is nothing to consent to and no cookie banner is needed. We do not use advertising or cross-site behavioral-tracking cookies, we do not sell or share data collected on the website, and we honor Global Privacy Control signals (§8).
12. Children
Vyra is intended for adults 18 and older. We do not knowingly collect data from anyone under 18. If we learn we have, we will delete it.
13. How this connects to our general Privacy Policy
This Consumer Health Data Privacy Policy governs your health-related data specifically and is reachable by its own distinct link (https://getvyra.ai/consumer-health-privacy), separate from our general Privacy Policy. Where the two overlap, this policy controls for consumer health data. The general policy covers non-health information (e.g., account and device basics) in more detail.
14. Changes to this policy
If we materially change how we handle your CHD — including enabling any of the currently-disabled features in §3, or using your data for anything beyond running a feature you are using — we will update this policy and revise the effective date. A new use that goes beyond necessity would need your affirmative, unbundled opt-in first, asked for before that processing began. There is no such use today (§5, §7).
15. Contact
Questions or requests: [email protected]
Vyra Health Inc., 2810 N Church St, STE 88042, Wilmington, DE 19802