Privacy
Your health data stays yours.
We collect only what Vyra needs to work — and we never sell it. We do not use your data to train AI models.
Last updated September 2026
The short version. Your health data is encrypted in transit and at rest, and never sold or shared with advertisers. We do not train AI models on it — not your meal photos, not your corrections, not anything else, and there is no setting that changes that. You can export or delete your data at any time.
Who we are
Vyra is operated by Vyra Health, Inc., a Delaware corporation (“Vyra,” “we,” “us”). We are the controller of the personal data described here. For any privacy question or request, email [email protected].
What we collect
- Account and authentication — your email address and the sign-in details needed to secure your account. We use passwordless sign-in (Google, Apple, or a one-time email code), so we never store a password.
- Health data you add — meals, hydration, weight, and the notes you choose to log or upload. Many people only ever log food.
- Meal photos — a meal photo you take (when you log by photo, or scan a barcode) is sent to our AI processor for food recognition and is stored with your account: in Amazon Web Services (AWS) S3, encrypted with a customer-managed key (SSE-KMS), under a per-user prefix isolated to your account. We keep it while your account is active and use it to run the food-logging feature and to check and improve the accuracy of our food recognition — which can include a member of our team reviewing a photo when you report a wrong result or ask for help. We do not use your photos to train AI models, and there is no setting that changes that. We never run facial recognition or extract biometric identifiers from them, and no setting changes that. Photos are permanently purged when you delete your account. A copy also stays in an encrypted store on your device, and that on-device copy is what your in-app history displays.
- Lab and prescription documents — not currently collected. Uploading and extracting lab or prescription documents is disabled in the public release, and we do not collect or process these unless and until we enable the feature, update this policy, and (where required) obtain your consent. If we do enable it, such documents are stored on our servers: in Amazon Web Services (AWS) S3, encrypted with a customer-managed key (SSE-KMS), under a per-user prefix isolated to your account. Unlike meal photos, raw documents are automatically removed from our servers 90 days after upload, and are permanently purged when you delete your account.
- Device-platform health (Apple Health / Android Health Connect) — only if you connect it, and only for the data types you allow. It works in both directions, and the two halves are treated differently:
- Steps and active energy — the raw readings stay on your device. Vyra reads them to show your step trend, and a “burned” figure next to what you have eaten. The only thing sent to us is one number per day: how much of your own step goal you reached, capped at 100%. Your step counts and calorie-burn readings themselves are never transmitted.
- Body weight — this one does reach us. If you allow it, Vyra imports your most recent weight (for example one recorded by a smart scale) into your own Vyra weight log, at most one per day. Because it becomes an ordinary entry in that log, it is stored with your account just like a weight you type in yourself — which is what lets your weight history survive reinstalling the app or moving to a new device. You can see it and delete it in the app.
- What Vyra writes back. The weight, meals and water you log in Vyra are mirrored into your own Apple Health / Health Connect store, so other apps you trust can read them. That mirroring sends nothing to us, and you can switch any of it off in the health app at any time.
- Purchases and subscription entitlements — whether you have an active subscription, handled through RevenueCat. Your card details never touch our servers.
- Usage and analytics events — privacy-safe, health-free product events that help us understand which features work and keep Vyra reliable.
- Crash diagnostics — error and crash reports, scrubbed of health data, so we can fix problems.
- A notification address for your device — only if you turn reminders on. When you allow notifications, your phone’s operating system issues a push token: an address that lets a reminder reach this one device. We store it with your account so we can send the reminders you asked for, and we delete it when you sign out or delete your account. It is an address for a device, not a name for you, and it carries none of your health data. If you never allow notifications, one is never created.
We do not buy health data about you from third parties.
How we use it
- Provide the core service: splitting your meals into macros, computing nutrition targets, structuring the health data you add, and showing your trends.
- Generate AI insights from your meal logs so you can see what’s working.
- Maintain security, prevent abuse, and improve reliability.
- Send you essential service messages (and, only with your consent, product updates).
Who processes your data (sub-processors)
We use a small set of vetted service providers to run Vyra. None of our analytics or crash tools receives your raw health data — they get only health-free events, hashed identifiers, and scrubbed error contexts. Your health data does live in our AWS data plane (RDS, S3, KMS) — encrypted with our customer-managed key and kept for the periods described above. Separately, the Bedrock models that process it are configured zero-retention and no-training, so the model provider itself keeps nothing. Each provider operates under a data-processing agreement.
The countries involved, and why we are satisfied with them. Your account and health data are handled in the United States (AWS us-east-1, AWS Bedrock, RevenueCat, OneSignal). A limited, health-data-free subset — product-analytics events and scrubbed crash reports — is handled in Germany (PostHog Cloud EU and Sentry Cloud EU, both in Frankfurt). We have assessed the data-protection regime of each of those two countries and chosen our safeguards against what we found there, rather than applying a generic standard: in the United States, which has no single general data-protection statute, we do not rely on the legal regime alone but on contractual data-processing terms with every provider, encryption in transit and at rest under a key we control, per-user isolation enforced in the database itself, and a rule that health data never reaches an analytics or crash tool; in Germany, the GDPR applies to those providers directly and we rely on it in addition to the same contractual terms. Where you ask us for more detail about the measures taken for a particular country or provider, write to [email protected] and we will answer without undue delay.
- AWS (RDS, S3, Bedrock, KMS) — our primary data plane, where your account and health data live, encrypted. Region
us-east-1. - AWS Bedrock (Claude) (United States,
us-east-1) — runs the AI that recognizes food and reads documents. Configured zero-retention and no-training: your inputs are not retained by the model provider or used to train models. - PostHog Cloud EU (Germany, Frankfurt) — product analytics. Health-free events only, with hashed user IDs. This website also uses PostHog for privacy-friendly, cookieless analytics — aggregate page-visit counts only, with no cookies, no tracking across sites, and no personal data, so no cookie banner is needed.
- Sentry Cloud EU (Germany, Frankfurt) — crash and error monitoring. A
beforeSendstep scrubs health data, and user IDs are hashed. - Expo (US) — delivers the reminder notifications you turn on. It receives your device’s push token and the text of the reminder, and passes both to Apple or Google for delivery. Reminder text is drawn from a fixed set of phrases we wrote in advance — it never contains a medication name, a dose, a condition, a weight, or anything you logged.
- RevenueCat (US) — subscription entitlements. No health data, and card details never touch our servers. Like any internet service it sees the internet address your device connects from, and it records the country it resolves to against your subscription record. We do not ask your device for your location, and Vyra requests no location permission — this is a country, worked out from the connection itself.
- Cloudflare (United States, with a global edge network that may serve this site from a location near you) — serves this site and forwards waitlist email. No health data.
- OneSignal (US) — delivers reminder and re-engagement notifications to your device. It receives a device notification token (an address for your phone, not for you), your device model, operating-system version, app version, time zone, and language, and — where you are signed in — a one-way scrambled version of your account ID, never the real one. It receives no health data: not your food, weight, medications, conditions, or lab results. The app has no way to send it your email address, phone number, or any tag describing your health, and a test fails our build if anyone adds one. Its location-tracking component is removed from the app entirely. Like any internet service, its servers see the internet address your device connects from and derive a country from it; we cannot switch that off, so we name it here rather than leave it unsaid.
Data residency and international transfers
Your data is hosted in the United States, in the AWS us-east-1 region. Wherever you live, if you are outside the United States your data is processed in the US, and we apply the same safeguards to every transfer: contractual protections with each processor, encryption in transit and at rest, and the disclosures set out below. Our storage region is a single configurable value, so we can host in additional regions as we expand.
Where Vyra is available. Vyra is offered in a limited set of countries — the ones where you can find it on the App Store or Google Play. We do not offer or market the service in the European Economic Area or the United Kingdom. If you are in one of those places and have an account anyway, we still apply everything described on this page to you — see Your rights, wherever you live below.
If you are in Canada. Your personal information is stored and processed outside Canada, in the United States, and is therefore subject to the laws of that country, including lawful access by US courts and government authorities. Our analytics and crash-reporting providers process a limited, health-data-free subset in the European Union. If you are in Quebec, this is a communication of personal information outside Quebec: we have completed a privacy impact assessment of that transfer before making it, as Law 25 requires, and concluded the information receives protection adequate in light of applicable law and generally recognized privacy principles.
If you are in Australia or New Zealand. Your personal information is stored and processed outside Australia and New Zealand, in the United States, and is therefore subject to the laws of that country, including lawful access by US courts and government authorities. Our analytics and crash-reporting providers process a limited, health-data-free subset in the European Union. For Australian users this is a cross-border disclosure under Australian Privacy Principle 8: we take reasonable steps to ensure our overseas recipients handle your information consistently with the Australian Privacy Principles, and under section 16C of the Privacy Act 1988 we remain accountable for their handling of it. For New Zealand users, we disclose your information overseas only where the recipient is subject to comparable safeguards, as information privacy principle 12 of the Privacy Act 2020 requires.
If you are in Singapore or Hong Kong. Your personal data is stored and processed outside Singapore and Hong Kong, in the United States, and is therefore subject to the laws of that country, including lawful access by US courts and government authorities. Our analytics and crash-reporting providers process a limited, health-data-free subset in the European Union. For users in Singapore, we transfer your personal data only where the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the Personal Data Protection Act 2012, as section 26 requires, and our Data Protection Officer can be reached at the address at the end of this policy during Singapore business hours.
If you are in Japan or Taiwan. Your personal data is stored and processed outside Japan and Taiwan, in the United States, and is therefore subject to the laws of that country, including lawful access by US courts and government authorities. Our analytics and crash-reporting providers process a limited, health-data-free subset in Germany. If you are in Japan, the measures we have taken to protect your data, and the countries in which it is handled, are described in the section above; you may ask us for further detail at [email protected] and we will answer without undue delay.
If you are in the United Arab Emirates. Your personal data is stored and processed outside the UAE, in the United States, and is therefore subject to the laws of that country, including lawful access by US courts and government authorities. Our analytics and crash-reporting providers process a limited, health-data-free subset in the European Union. Under Federal Decree-Law No. 45 of 2021 (the PDPL), we rely on your explicit consent for this transfer, given when you create an account. Vyra has no establishment, staff, or infrastructure in the UAE, and does not receive data from any UAE health facility.
How AI processing works
Vyra uses AI to turn your data into specific, practical insights. Your inputs are processed to produce your results only. The model provider is configured zero-retention and no-training, and we never share your data with model providers for their own training — that limit is unconditional and no setting of yours changes it. Separately: we do not use your health data to train our own models either. That is unconditional too — there is no setting anywhere in Vyra that turns it on.
AI outputs are informational only. They are never a diagnosis, treatment, or prescription. Vyra shows you your own food and weight trends so that you can see patterns and discuss them with your clinician — it never tells you what is wrong or what to do.
What we never do
- Sell your personal or health data.
- Share it with advertisers or data brokers.
- Use your health data to train AI models. This is unconditional: it covers your meal photos and your corrections to them exactly as it covers your lab results, your medications, and anything you type in chat, and there is no setting anywhere in Vyra that turns it on.
Security
Data is encrypted in transit (TLS) and at rest with a customer-managed encryption key (KMS). Each user’s data is isolated at the database level. Access is limited to the people and systems that need it to operate the service, protected by authentication and audit controls. We do not write your health data to our logs, analytics, or crash reports.
Your rights, wherever you live
You can access, correct, export, or permanently delete your data from within the app, or by emailing [email protected].
We grant every one of the rights listed below to every user, regardless of where you live or where your data is processed. Some countries give their residents these rights by law; we do not limit them to those countries. Concretely, wherever you are, you may: access a copy of your data, correct it, export it in a portable form, delete it permanently, withdraw consent you previously gave, and object to or restrict a particular use. And wherever a data-protection authority exists for your country, you may complain to it about how we have handled your data — that is your right whether or not we have named that regulator below, and nothing on this page limits it. The same tools in the app serve everyone; we do not operate a separate, lesser process for users whose local law asks for less. Granting these rights is not an acknowledgement that any particular country's law applies to us.
Where your local law gives you rights in addition to these — or gives you a regulator to complain to — those apply too, and nothing here reduces them:
- Canada (PIPEDA) and Quebec (Law 25). You have the right to access and correct your personal information, to withdraw consent, and to complain to a regulator. Quebec residents also have the right to data portability, to be informed of and object to decisions based solely on automated processing, and to request that we cease disseminating personal information. You may complain to the Office of the Privacy Commissioner of Canada, or, in Quebec, to the Commission d'accès à l'information du Québec.
- Australia (Privacy Act 1988) and New Zealand (Privacy Act 2020). Australian users have the right to access and correct their personal information under Australian Privacy Principles 12 and 13, to ask how we handle it, and to complain to the Office of the Australian Information Commissioner. New Zealand users have the right to access and correct their personal information under information privacy principles 6 and 7, and to complain to the Office of the Privacy Commissioner. Health information is sensitive information under the Australian Privacy Act, and we collect it only with your consent.
- Singapore (PDPA 2012). You have the right to request access to your personal data and information about how it has been used, and to request correction of it, under Parts V and VI. You may withdraw consent at any time, and you may complain to the Personal Data Protection Commission. Our Data Protection Officer, designated under section 11(3), is the Privacy Officer named at the end of this policy.
- Hong Kong. Vyra has no establishment, staff or infrastructure in Hong Kong, so the Personal Data (Privacy) Ordinance does not impose obligations on us. We nonetheless grant Hong Kong users every right listed above, on the same terms as everyone else.
- California (CCPA / CPRA). You have the right to know, delete, and correct your personal information, and to opt out of its sale or sharing. We do not sell or share your personal information.
- Washington (My Health My Data Act). You have the right to access and delete your consumer health data and to withdraw consent. We do not sell your health data.
- UAE residents. You may exercise access, correction, and deletion rights consistent with applicable UAE data-protection law; contact us using the email above.
We honor these requests and will not discriminate against you for exercising them.
Retention
We keep your data while your account is active. When you delete your account, we delete your personal and health data within a reasonable period, except where we must retain limited records to meet legal obligations.
Children
Vyra is built for adults and is not intended for anyone under 18. We do not knowingly collect data from anyone under 18.
Changes
If we make a material change to this policy, we’ll notify you in the app or by email before it takes effect.
Contact
Questions about privacy? Email [email protected]. This policy is governed by the laws of the State of Delaware, United States. That choice of law does not reduce the rights described above — the rights we grant everyone, the additional regional rights, or any right your local law gives you that cannot be waived by agreement.
Person in charge of the protection of personal information. Quebec's Law 25 requires us to publish who is responsible for protecting personal information at Vyra. That person holds the title Privacy Officer at Vyra Health, Inc., and can be reached at [email protected], or by post at Vyra Health Inc., 2810 N Church St, STE 88042, Wilmington, DE 19802, USA.