Privacy Policy
This policy describes how VitalDial ("the App"), published by FatherXLdn ("we", "us"), collects, uses, and shares information when you use it. If anything here is unclear, email us at hello@vitaldial.co.uk.
Who we are
FatherXLdn is a trading name of FATHERXLDN LIMITED, a company registered in England and Wales (company no. 17286358). We're the data controller for personal data processed in connection with the App and our related services, unless a third party (such as Apple, RevenueCat, or the subprocessors listed below) processes data solely under their own terms.
The short version
VitalDial reads health metrics from Apple Health, scores them on your device, and shows you the results. Your raw HealthKit data never leaves your device. Data travels off your device only for subscription verification through RevenueCat and the Apple App Store, the optional AI Coach, the optional Fitbit connection, and the optional Connect to Claude. When you use the AI Coach, your question and derived scores (not raw sensor readings) go through a Cloudflare proxy to an AI provider. Which provider depends on your subscription tier. If you connect Fitbit, your Fitbit data is fetched from Google through that same proxy and delivered to your device, and not kept on our servers. If you're on Elite and connect VitalDial to Claude, your daily scores are shared with Claude as described below.
What we process
Health data · processed on your device
With your permission, the App reads from Apple HealthKit: heart rate, heart rate variability, resting heart rate, sleep analysis, workouts, active energy, steps, respiratory rate, blood oxygen (SpO₂), and wrist or body temperature. All of that is read locally and used only to compute scores on-device. We don't upload raw HealthKit readings anywhere. You control exactly which categories the App can read in iOS Settings → Health → Apps. We never use your health data for advertising, marketing, or data mining, and we never sell it.
If you connect Fitbit, the App also asks permission to write to Apple Health: sleep, heart rate variability, resting heart rate, blood oxygen and breathing rate from your Fitbit, so they sit alongside your other health data. It never writes anything else, and you can turn write access off in the same Settings screen.
Location data · stays on your device
If you start an interval or running workout, the App uses your device's location (GPS), including while the screen is locked or the App is in the background, to measure distance, pace and route for that session. Location is processed on your device to calculate workout metrics and is not uploaded to our servers or shared with third parties. You control location access in iOS Settings → Privacy & Security → Location Services → VitalDial, and the system background-use indicator appears while a workout is tracking.
Daily check-in data · stays on your device
You can optionally log a daily check-in: perceived wellness (1–5), stress (1–5), and perceived exertion (RPE 1–10). These are stored on-device using Core Data. If you ask the AI Coach a question, your check-in for that day is included in the context sent to the coach, as described below.
Subscriptions and purchases
Purchases go through the Apple App Store. We don't receive your payment card details. RevenueCat handles subscription and entitlement data under their own policies and gives our Cloudflare Worker what it needs to verify your subscription before unlocking paid features. That amounts to a pseudonymous customer identifier: a stable UUID stored in your device's Keychain, not your name or email address.
Fitbit · optional
Fitbit data now comes through Google. If you connect Fitbit in the App, you sign in with Google and grant read-only access. Our Cloudflare Worker stores the resulting access tokens, keyed to your pseudonymous user ID, so it can fetch your data when the App syncs. On each sync it requests your sleep, heart rate variability, resting heart rate, blood oxygen, skin temperature variation and workouts (type, time, duration, distance and heart rate, for runs, walks, strength sessions and other exercise) for the days requested, and passes them straight to your device. We don't keep that Fitbit data on our servers; only the tokens and the time of your last sync are stored. Disconnecting in the App deletes the tokens and asks Google to revoke them. You can also remove access from your Google account at any time.
Device key
Each installation of the App creates a random device key, kept in your device's Keychain. The App sends it with requests to our Worker, which stores only a one-way hash of it, so requests about your account can only come from your device. It contains no personal information.
AI Coach · optional, paid tiers
When you ask the AI Coach a question, your device sends a request to our Cloudflare Worker proxy. That request contains three things.
- Your pseudonymous user ID, used to verify your subscription tier and track your monthly question quota.
- Derived scores computed on-device: readiness, recovery, sleep, and strain scores, your 21-day personal baselines, any subjective check-in you logged, and the question you asked. This is processed output, not raw HealthKit sensor readings.
- Timestamps and your IP address, which may appear in Cloudflare's infrastructure logs.
The Worker then forwards the question and its context to an AI provider. Which one depends on your tier:
| Free | Google (Gemini) |
| Pro | Anthropic (Claude Haiku) |
| Elite | Anthropic (Claude Sonnet) |
Each provider processes the content under their own API policies as a subprocessor. We don't use your questions or scores to train public AI models; retention on the provider side is governed by their API documentation.
Monthly quotas are tracked server-side in Cloudflare KV storage, keyed to your pseudonymous user ID, and expire automatically after 35 days. No API keys are stored on your device.
Connect to Claude · optional, Elite
If you turn on Connect to Claude, you link VitalDial to your own Claude account (Anthropic) so you can ask Claude about your training. Nothing is shared until you enter the pairing code Claude shows you.
While connected, the App uploads derived daily scores to our Cloudflare Worker: recovery, readiness, performance, capacity, strain, fatigue and training load; daily summaries of heart rate variability, resting heart rate, sleep, blood oxygen and breathing rate; steps and estimated VO₂ max; the day's training verdict; and your training plan sessions. Raw HealthKit samples are never uploaded. Each day is stored for up to 90 days, keyed to your pseudonymous user ID.
Claude reads those scores through a read-only connection when you ask it something. What Claude does with them in your conversations is governed by Anthropic's terms and your Claude account settings. Disconnecting in the App revokes Claude's access immediately and deletes every score we stored.
Legal bases (UK GDPR)
Where UK GDPR applies, we rely on:
- Contract, to provide subscriptions and AI Coach features you've chosen to activate.
- Legitimate interests, to keep the service secure and reliable: quota enforcement, error logging, rate limiting. Balanced against your rights.
- Consent, for HealthKit access and for connecting Fitbit. iOS asks you to grant each health category explicitly, and Google asks before sharing Fitbit data. You can withdraw access at any time in iOS Settings → Health → Apps, or by disconnecting Fitbit in the App. The same applies to Connect to Claude, which you turn on and off in the App.
Retention
All HealthKit data and on-device scores stay on your device until you delete the App or reset your device. Cloudflare KV quota records expire after 35 days. Fitbit access tokens are kept until you disconnect Fitbit. Device key hashes are kept while your pseudonymous user ID is in use. Scores shared through Connect to Claude are kept for up to 90 days per day and deleted immediately when you disconnect. Infrastructure logs, if any, are kept only as long as needed for security and operations. To delete server-side data tied to your pseudonymous user ID, email hello@vitaldial.co.uk.
Sharing and subprocessors
We don't sell your data. We share it with service providers only as needed to run the App:
- Apple · app distribution and in-app purchases.
- RevenueCat · subscription status and pseudonymous customer identifiers.
- Cloudflare · Worker proxy for AI Coach requests and the Fitbit connection; KV storage for quotas, Fitbit tokens, device key hashes and Connect to Claude score storage.
- Google (Fitbit) · source of your Fitbit data, only if you connect Fitbit.
- Google (Gemini) · AI inference for Free-tier AI Coach questions.
- Anthropic (Claude Haiku) · AI inference for Pro-tier AI Coach questions.
- Anthropic (Claude Sonnet) · AI inference for Elite-tier AI Coach questions.
- Anthropic (Claude) · reads your shared scores, only if you connect VitalDial to your Claude account.
International transfers
Some providers operate in the United States or other countries outside the UK. Where required, we rely on Standard Contractual Clauses or adequacy decisions. Get in touch if you need more detail.
Children
The App isn't directed at children under 13 (or the digital consent age in your region). We don't knowingly collect personal information from children. If you believe we have, contact us and we'll delete it.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to certain processing, and to port data or lodge a complaint with a supervisory authority. In the UK that's the ICO at ico.org.uk. To exercise rights against us, email hello@vitaldial.co.uk. Rights against Apple or RevenueCat are exercised through their own account tools.
Security
All off-device communication uses HTTPS. No API keys are stored on your device. Raw HealthKit data never leaves it. No method of transmission is completely secure; use the App only on devices you trust.
Changes
We'll update this policy when we add features or subprocessors, revising the "Last updated" date each time. Where required, we'll notify you in the App or by email. Continued use after changes means you accept the updated policy unless applicable law requires otherwise.
Questions? Email us at hello@vitaldial.co.uk