1. Who operates VYALS
VYALS is an iPhone app and website that help people organize self-entered health and wellness information. VYALS is operated by MC Social Agency, LLC (legal entity name to be verified before publication). The VYALS website is vyals.com. For privacy questions, contact hello@vyals.com.
Last updated: October 8, 2026. This notice describes the current implementation, not potential future features.
2. Data stored locally on your iPhone
VYALS currently has no sign-up or login. Your ordinary tracking records are stored on your iPhone rather than in a VYALS-hosted cloud account. These records may include:
- Medications, GLP-1s, peptides and custom compounds; protocols, schedules, dose histories, injection-site entries, vial inventory and cycle notes.
- Meals, calorie and nutrient information, hydration, body weight and measurements, check-ins, personal goals and progress history.
- Settings and preferences you enter for tracking and local reminders.
VYALS does not currently use Firebase, Supabase, or automatic iCloud synchronization for these tracking records. Data you separately export, or copies included in device-level backups, may be stored or retained outside VYALS under the relevant device, backup or export destination’s practices.
3. Vy and AI-assisted features
Vy is an optional conversational feature powered through a Cloudflare backend and OpenAI. When you send a request to Vy, the text you submit and relevant context used to answer your question may be sent to Cloudflare and OpenAI for processing. Vy is meant to help you navigate and understand your own recorded information, not diagnose conditions or prescribe medications or dosing.
Cloudflare stores temporary conversation state. Vy conversations expire after 24 hours, at which point VYALS initiates conversation-content cleanup and a request to delete associated provider-held content. Failed deletion requests are retried. Expiration and a deletion request do not guarantee immediate erasure of all provider-maintained logs, backups or recovery copies; those periods remain subject to the provider’s terms and technical configuration.
Do not include information in an AI request that you do not want processed by the services involved. The exact OpenAI API data retention and model-training configuration must be verified before this policy is final.
4. Food photos, barcode scanning and food search
VYALS can use OpenAI to generate estimates from food photos you choose to submit. The VYALS backend does not save copies of submitted food photos. Images and related requests still pass through service providers for processing; their applicable retention and recovery periods need confirmation.
VYALS uses Open Food Facts for barcode and food-name searches. Search terms or product identifiers are sent as needed to retrieve food information. Food database information and AI-generated nutrition estimates can be incomplete or inaccurate, so you should check the result before relying on or saving it.
5. Apple Health, device verification and notifications
If you enable Apple Health access, VYALS requests access to the selected HealthKit information with your permission. You can review or withdraw applicable permissions using Apple’s Health and iPhone settings. Ordinary tracking records remain stored locally on the iPhone; optional AI requests follow the separate processing described above.
VYALS uses Apple App Attest for device verification and supports local notifications for reminders. Reminders do not require a separate push-notification service in the current implementation.
6. Device-verification and abuse-prevention information
Although VYALS does not have a user login, its Cloudflare-backed AI service uses device verification and abuse-prevention mechanisms. Cloudflare holds device-verification records and temporary service state needed to operate those features. Abuse-limit counters are cleaned after approximately 30 days.
Device-verification records currently remain on the backend until the operator removes them. They are not automatically deleted when you delete a local tracking entry or uninstall the app. This is a known limitation we intend to address through a complete data-deletion workflow.
7. Services that receive information
VYALS uses the following services in its current implementation:
- Cloudflare: Hosts and protects the AI backend; processes AI requests; holds temporary conversation state, device-verification records and abuse-prevention information.
- OpenAI: Processes Vy conversations and food-photo estimation requests.
- Open Food Facts: Responds to barcode and food-name lookups.
- Apple: Provides iPhone system services, permission-controlled HealthKit access, App Attest and local notifications.
No separate analytics, crash-reporting, authentication or automatic cloud-sync provider is integrated into the app at this time. This does not establish what cookies, hosting logs or other technologies the website uses; those need a separate check of the published WordPress site. This notice does not claim that providers retain no logs or copies.
8. How long information is kept and how to delete it
- On-device tracking records: Remain on your iPhone until you delete them or remove the app, subject to any separate exports or device backups.
- Vy conversations: Expire after 24 hours and trigger content cleanup and a provider-deletion request. If a deletion request fails, it is retried. Provider-held logs and recovery copies may persist for other periods.
- Abuse-limit counters: Cleaned after approximately 30 days.
- Device-verification records: Currently remain until the operator removes them.
- Food photos: Not stored by the VYALS backend, but external processor retention remains to be confirmed.
You can delete individual tracking records in the app and request deletion of Vy conversations. A single “Delete all VYALS data” control is not implemented yet. We intend for that control to clear applicable on-device data and request deletion of the backend device registration, but we are not describing it as an available feature today.
To request assistance with server-side data or a device registration, email hello@vyals.com. We may need sufficient details to locate the correct records and assess a request securely. Removing the app may remove its local records but does not necessarily remove server-side records or any copies previously exported or backed up.
9. Your choices and privacy rights
You decide what to enter in VYALS and whether to use AI features, submit food photos, grant Apple Health access or enable local notifications. Available individual-entry deletion controls are provided in the app. You can change applicable Apple permissions in iOS settings.
Depending on where you live, you may have rights to request access to, correction of, or deletion of personal information, or to raise other privacy requests. Contact hello@vyals.com. Some records exist only on your device and may not be accessible to us. We will assess requests based on the information actually held and applicable law.
10. Children and website information
VYALS is designed as a personal health and wellness tracker. The minimum age requirements and any age-screening controls must be confirmed before publication of a final policy. Parents and guardians should not assume VYALS is a supervised medical or pediatric service.
The VYALS website may have hosting logs or technologies separate from those used inside the app. The live website’s cookie, form, analytics and hosting configuration must be checked before the website privacy disclosures are considered complete.
11. Updates and contact
We may update this policy as VYALS changes. We will post the current version and its effective date on this page, and provide additional notice where required by law.
For questions about this notice, AI processing, or deletion requests, contact hello@vyals.com or visit Support. For available deletion options, see Account & Data Deletion.