Privacy

Your health data stays yours.

We collect only what Vyra needs to work, and we never sell it. We do not use your data to train AI models.

Last updated September 2026

The short version. Your health data is encrypted in transit and at rest, and never sold or shared with advertisers. We do not train AI models on it: not your meal photos, not your corrections, not anything else, and there is no setting that changes that. You can export or delete your data at any time.

Who we are

Vyra is operated by Vyra Health, Inc., a Delaware corporation (“Vyra,” “we,” “us”). We are the controller of the personal data described here. For any privacy question or request, email privacy@getvyra.ai.


What we collect

  • Account and authentication: your email address and the sign-in details needed to secure your account. We use passwordless sign-in (Google, Apple, or a one-time email code), so we never store a password.
  • Health data you add: meals, hydration, weight, and the notes you choose to log or upload. Many people only ever log food.
  • Meal photos: a meal photo you take (when you log by photo, or scan a barcode) is sent to our AI processor for food recognition and is stored with your account: in Amazon Web Services (AWS) S3, encrypted with a customer-managed key (SSE-KMS), under a per-user prefix isolated to your account. We keep it while your account is active and use it to run the food-logging feature and to check and improve the accuracy of our food recognition, which can include a member of our team reviewing a photo when you report a wrong result or ask for help. We do not use your photos to train AI models, and there is no setting that changes that. We never run facial recognition or extract biometric identifiers from them, and no setting changes that. Photos are permanently purged when you delete your account. A copy also stays in an encrypted store on your device, and that on-device copy is what your in-app history displays.
  • Lab and prescription documents: not currently collected. Uploading and extracting lab or prescription documents is disabled in the public release, and we do not collect or process these unless and until we enable the feature, update this policy, and (where required) obtain your consent. If we do enable it, such documents are stored on our servers: in Amazon Web Services (AWS) S3, encrypted with a customer-managed key (SSE-KMS), under a per-user prefix isolated to your account. Unlike meal photos, raw documents are automatically removed from our servers 90 days after upload, and are permanently purged when you delete your account.
  • Device-platform health (Apple Health / Android Health Connect): only if you connect it, and only for the data types you allow. It works in both directions, and the two halves are treated differently:
    • Steps and active energy: the raw readings stay on your device. Vyra reads them to show your step trend, and a “burned” figure next to what you have eaten. The only thing sent to us is one number per day: how much of your own step goal you reached, capped at 100%. Your step counts and calorie-burn readings themselves are never transmitted.
    • Body weight: this one does reach us. If you allow it, Vyra imports your most recent weight (for example one recorded by a smart scale) into your own Vyra weight log, at most one per day. Because it becomes an ordinary entry in that log, it is stored with your account just like a weight you type in yourself, which is what lets your weight history survive reinstalling the app or moving to a new device. You can see it and delete it in the app.
    • What Vyra writes back. The weight, meals and water you log in Vyra are mirrored into your own Apple Health / Health Connect store, so other apps you trust can read them. That mirroring sends nothing to us, and you can switch any of it off in the health app at any time.
    We never use health-platform data for advertising, never sell it, and never use it to train models.
  • Services you connect (Meta Muse): only if you connect Vyra to Meta’s Muse agent. When you ask Muse for an estimate or to save a meal, Muse sends us your words and, when it has one, the photo, and we send back our answer. That request and answer pass through Meta at your direction, under Meta’s own privacy terms. Muse works for you and receives only what you asked it to carry; it is not a processor working for us. What you save through Muse becomes an ordinary entry in your Vyra account, exactly like one you typed in the app. You can disconnect Muse at any time in its settings. Details: Vyra for Muse.
  • Purchases and subscription entitlements: whether you have an active subscription, handled through RevenueCat. Your card details never touch our servers.
  • Usage and analytics events: privacy-safe, health-free product events that help us understand which features work and keep Vyra reliable.
  • Crash diagnostics: error and crash reports, scrubbed of health data, so we can fix problems.
  • A notification address for your device: only if you turn reminders on. When you allow notifications, your phone’s operating system issues a push token: an address that lets a reminder reach this one device. We store it with your account so we can send the reminders you asked for, and we delete it when you sign out or delete your account. It is an address for a device, not a name for you, and it carries none of your health data. If you never allow notifications, one is never created.

We do not buy health data about you from third parties.


How we use it

  • Provide the core service: splitting your meals into macros, computing nutrition targets, structuring the health data you add, and showing your trends.
  • Generate AI insights from your meal logs so you can see what’s working.
  • Maintain security, prevent abuse, and improve reliability.
  • Send you essential service messages (and, only with your consent, product updates).

Who processes your data (sub-processors)

We use a small set of vetted service providers to run Vyra. None of our analytics or crash tools receives your raw health data: they get only health-free events, hashed identifiers, and scrubbed error contexts. Your health data does live in our AWS data plane (RDS, S3, KMS), encrypted with our customer-managed key and kept for the periods described above. Separately, the Bedrock models that process it are configured zero-retention and no-training, so the model provider itself keeps nothing. Each provider operates under a data-processing agreement.

The countries involved, and why we are satisfied with them. Your account and health data are handled in the United States (AWS us-east-1, AWS Bedrock, RevenueCat). A limited, health-data-free subset (product-analytics events and scrubbed crash reports) is handled in Germany (PostHog Cloud EU and Sentry Cloud EU, both in Frankfurt). We have assessed the data-protection regime of each of those two countries and chosen our safeguards against what we found there, rather than applying a generic standard: in the United States, which has no single general data-protection statute, we do not rely on the legal regime alone but on contractual data-processing terms with every provider, encryption in transit and at rest under a key we control, per-user isolation enforced in the database itself, and a rule that health data never reaches an analytics or crash tool; in Germany, the GDPR applies to those providers directly and we rely on it in addition to the same contractual terms. Where you ask us for more detail about the measures taken for a particular country or provider, write to privacy@getvyra.ai and we will answer without undue delay.

  • AWS (RDS, S3, Bedrock, KMS): our primary data plane, where your account and health data live, encrypted. Region us-east-1.
  • AWS Bedrock (Claude) (United States, us-east-1): runs the AI that recognizes food and reads documents. Configured zero-retention and no-training: your inputs are not retained by the model provider or used to train models.
  • PostHog Cloud EU (Germany, Frankfurt): product analytics. Health-free events only, with hashed user IDs. This website also uses PostHog for privacy-friendly, cookieless analytics: aggregate page-visit counts only, with no cookies, no tracking across sites, and no personal data, so no cookie banner is needed.
  • Google (United States): Analytics for Firebase, in the iOS app only, for one job: counting app installs that came from our own ads. It receives the fact that the app was opened for the first time and nothing else: no health data, no screen names, and no advertising identifier, so Vyra shows no tracking prompt. It is switched off entirely on Android.
  • Sentry Cloud EU (Germany, Frankfurt): crash and error monitoring. A beforeSend step scrubs health data, and user IDs are hashed.
  • Expo (US): delivers the reminder notifications you turn on. It receives your device’s push token and the text of the reminder, and passes both to Apple or Google for delivery. Reminder text is drawn from a fixed set of phrases we wrote in advance. It never contains a medication name, a dose, a condition, a weight, or anything you logged.
  • RevenueCat (US): subscription entitlements. No health data, and card details never touch our servers. Like any internet service it sees the internet address your device connects from, and it records the country it resolves to against your subscription record. We do not ask your device for your location, and Vyra requests no location permission. This is a country, worked out from the connection itself.
  • Cloudflare (United States, with a global edge network that may serve this site from a location near you): serves this site. No health data. (Until 2026-08-10 it also forwarded waitlist email through a Cloudflare Function; that Function and its database were deleted and the site now has none.)
  • OneSignal (US): in use in released builds from version 1.3.0. Reserved for re-engagement notifications. Your reminders are still delivered by Expo (above), and we have not yet sent a single notification through OneSignal. But the integration is switched on, so it receives the following from the moment the app starts. It receives a device notification token (an address for your phone, not for you), your device model, operating-system version, app version, time zone, and language, and (where you are signed in) a one-way scrambled version of your account ID, never the real one. It receives no health data: not your food, weight, medications, conditions, or lab results. The app has no way to send it your email address, phone number, or any tag describing your health, and a test fails our build if anyone adds one. Its location-tracking component is removed from the app entirely. Like any internet service, its servers see the internet address your device connects from and derive a country from it; we could not switch that off, so we name it here rather than leave it unsaid.

Meta’s Muse agent is not a sub-processor. If you connect Vyra to Muse, Muse carries your requests to us and our answers back to you at your direction, under Meta’s own terms. It works for you, under your direction: Meta does not process data on our instructions, and we send it nothing you did not ask for. See “Services you connect” above and Vyra for Muse.


Personalization and automated processing

Vyra tailors what it shows you, and you should know exactly how. Four things are computed from your own data rather than chosen by a person:

  • Your daily calorie and macro targets, computed from the height, weight, age, sex, activity level and goal pace you entered, using a standard published formula (Mifflin–St Jeor). It is a starting point you can adjust, not a prescription.
  • Trends: your own logged values plotted over time.
  • A non-clinical momentum reading, derived from how consistently you have been tracking.
  • Insights: short summaries generated from the meals you logged.

None of this is a decision about you. Nothing in Vyra decides anything that affects your rights or your access to anything: there is no scoring that opens or closes a door, no eligibility judgment, no automated decision with a legal or similarly significant effect. It is your own data, arranged so you can see it.

What you can and cannot switch off, stated plainly. These functions are the product rather than an add-on layered on top of it, so today there is no setting that leaves your account running with them turned off. What you can do: adjust anything Vyra estimated, correct any entry, export everything, and delete your account, which removes the underlying data and with it every computed value. If we later add a switch for any of them, it will be described here.

We do not build advertising or marketing profiles, we do not use your data to infer anything you have not told us for a purpose outside the app, and we do not track you across other apps or websites.


Data residency and international transfers

Your data is hosted in the United States, in the AWS us-east-1 region. Wherever you live, if you are outside the United States your data is processed in the US, and we apply the same safeguards to every transfer: contractual protections with each processor, encryption in transit and at rest, and the disclosures set out below. Our storage region is a single configurable value, so we can host in additional regions as we expand.

Where Vyra is available. Vyra is offered in a limited set of countries: the ones where you can find it on the App Store or Google Play. We do not offer or market the service in the European Economic Area or the United Kingdom. If you are in one of those places and have an account anyway, we still apply everything described on this page to you (see Your rights, wherever you live below).

If you are in Canada. Your personal information is stored and processed outside Canada, in the United States, and is therefore subject to the laws of that country, including lawful access by US courts and government authorities. Our analytics and crash-reporting providers process a limited, health-data-free subset in the European Union. If you are in Quebec, this is a communication of personal information outside Quebec: we have completed a privacy impact assessment of that transfer before making it, as Law 25 requires, and concluded the information receives protection adequate in light of applicable law and generally recognized privacy principles.

If you are in Australia or New Zealand. Your personal information is stored and processed outside Australia and New Zealand, in the United States, and is therefore subject to the laws of that country, including lawful access by US courts and government authorities. Our analytics and crash-reporting providers process a limited, health-data-free subset in the European Union. For Australian users this is a cross-border disclosure under Australian Privacy Principle 8: we take reasonable steps to ensure our overseas recipients handle your information consistently with the Australian Privacy Principles, and under section 16C of the Privacy Act 1988 we remain accountable for their handling of it. For New Zealand users, we disclose your information overseas only where the recipient is subject to comparable safeguards, as information privacy principle 12 of the Privacy Act 2020 requires.

If you are in Singapore or Hong Kong. Your personal data is stored and processed outside Singapore and Hong Kong, in the United States, and is therefore subject to the laws of that country, including lawful access by US courts and government authorities. Our analytics and crash-reporting providers process a limited, health-data-free subset in the European Union. For users in Singapore, we transfer your personal data only where the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to the Personal Data Protection Act 2012, as section 26 requires, and our Data Protection Officer can be reached at the address at the end of this policy during Singapore business hours.

If you are in Japan or Taiwan. Your personal data is stored and processed outside Japan and Taiwan, in the United States, and is therefore subject to the laws of that country, including lawful access by US courts and government authorities. Our analytics and crash-reporting providers process a limited, health-data-free subset in Germany. If you are in Japan, the measures we have taken to protect your data, and the countries in which it is handled, are described in the section above; you may ask us for further detail at privacy@getvyra.ai and we will answer without undue delay.

If you are in the United Arab Emirates. Your personal data is stored and processed outside the UAE, in the United States, and is therefore subject to the laws of that country, including lawful access by US courts and government authorities. Our analytics and crash-reporting providers process a limited, health-data-free subset in the European Union. Under Federal Decree-Law No. 45 of 2021 (the PDPL), we rely on your explicit consent for this transfer, given when you create an account. Vyra has no establishment, staff, or infrastructure in the UAE, and does not receive data from any UAE health facility.


How AI processing works

Vyra uses AI to turn your data into specific, practical insights. Your inputs are processed to produce your results only. The model provider is configured zero-retention and no-training, and we never share your data with model providers for their own training. That limit is unconditional and no setting of yours changes it. Separately: we do not use your health data to train our own models either. That is unconditional too: there is no setting anywhere in Vyra that turns it on.

AI outputs are informational only. They are never a diagnosis, treatment, or prescription. Vyra shows you your own food and weight trends so that you can see patterns and discuss them with your clinician. It never tells you what is wrong or what to do.


What we never do

  • Sell your personal or health data.
  • Share it with advertisers or data brokers.
  • Use your health data to train AI models. This is unconditional: it covers your meal photos and your corrections to them exactly as it covers your lab results, your medications, and anything you type in chat, and there is no setting anywhere in Vyra that turns it on.

Security

Data is encrypted in transit (TLS) and at rest with a customer-managed encryption key (KMS). Each user’s data is isolated at the database level. Access is limited to the people and systems that need it to operate the service, protected by authentication and audit controls. We do not write your health data to our logs, analytics, or crash reports.


Your rights, wherever you live

You can access, correct, export, or permanently delete your data from within the app, or by emailing privacy@getvyra.ai.

We grant every one of the rights listed below to every user, regardless of where you live or where your data is processed. Some countries give their residents these rights by law; we do not limit them to those countries. Concretely, wherever you are, you may: access a copy of your data, correct it, export it in a portable form, delete it permanently, withdraw consent you previously gave, and object to or restrict a particular use. And wherever a data-protection authority exists for your country, you may complain to it about how we have handled your data. That is your right whether or not we have named that regulator below, and nothing on this page limits it. The same tools in the app serve everyone; we do not operate a separate, lesser process for users whose local law asks for less. Granting these rights is not an acknowledgement that any particular country's law applies to us.

Where your local law gives you rights in addition to these (or gives you a regulator to complain to), those apply too, and nothing here reduces them:

  • Canada (PIPEDA) and Quebec (Law 25). You have the right to access and correct your personal information, to withdraw consent, and to complain to a regulator. Quebec residents also have the right to data portability, to be informed of and object to decisions based solely on automated processing, and to request that we cease disseminating personal information. You may complain to the Office of the Privacy Commissioner of Canada, or, in Quebec, to the Commission d'accès à l'information du Québec.
  • Australia (Privacy Act 1988) and New Zealand (Privacy Act 2020). Australian users have the right to access and correct their personal information under Australian Privacy Principles 12 and 13, to ask how we handle it, and to complain to the Office of the Australian Information Commissioner. New Zealand users have the right to access and correct their personal information under information privacy principles 6 and 7, and to complain to the Office of the Privacy Commissioner. Health information is sensitive information under the Australian Privacy Act, and we collect it only with your consent.
  • Singapore (PDPA 2012). You have the right to request access to your personal data and information about how it has been used, and to request correction of it, under Parts V and VI. You may withdraw consent at any time, and you may complain to the Personal Data Protection Commission. Our Data Protection Officer, designated under section 11(3), is the Privacy Officer named at the end of this policy.
  • Hong Kong. Vyra has no establishment, staff or infrastructure in Hong Kong, so the Personal Data (Privacy) Ordinance does not impose obligations on us. We nonetheless grant Hong Kong users every right listed above, on the same terms as everyone else.
  • California (CCPA / CPRA). You have the right to know, delete, and correct your personal information, and to opt out of its sale or sharing. We do not sell or share your personal information.
  • Washington (My Health My Data Act). You have the right to access and delete your consumer health data and to withdraw consent. We do not sell your health data.
  • UAE residents. You may exercise access, correction, and deletion rights consistent with applicable UAE data-protection law; contact us using the email above.

We honor these requests and will not discriminate against you for exercising them.


Retention

We keep your data while your account is active. When you delete your account, we delete your personal and health data within a reasonable period, except where we must retain limited records to meet legal obligations.


Children

Vyra is built for adults and is not intended for anyone under 18. We do not knowingly collect data from anyone under 18.


Changes

If we make a material change to this policy, we’ll notify you in the app or by email before it takes effect.


Contact

Questions about privacy? Email privacy@getvyra.ai. This policy is governed by the laws of the State of Delaware, United States. That choice of law does not reduce the rights described above: the rights we grant everyone, the additional regional rights, or any right your local law gives you that cannot be waived by agreement.

Grievance Officer (India). Rule 5(9) of India's Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 requires us to publish a named grievance officer, and rule 6 of the Consumer Protection (E-Commerce) Rules, 2020 asks the same of a seller. That officer is Bulat Galeev, Founder, Vyra Health, Inc., reachable at privacy@getvyra.ai or by post at Vyra Health Inc., 2810 N Church St, STE 88042, Wilmington, DE 19802, USA. We acknowledge a grievance within 48 hours and aim to resolve it within one month of receipt.

For users in Japan. Article 32(1) of the Act on the Protection of Personal Information asks that four things be readily available to you, so they are gathered here. Who we are: Vyra Health, Inc., 2810 N Church St, STE 88042, Wilmington, DE 19802, USA; representative Bulat Galeev, Founder. What we use your personal data for: the purposes set out above under “How we use it”. How to ask us to disclose, correct, add to, stop using, erase or stop providing your personal data: email privacy@getvyra.ai from the address on your account, or use the export and delete controls in the app under Settings; we verify a request against your account and charge no fee. Where to complain: write to the same address, and you may also contact Japan's Personal Information Protection Commission.

Person in charge of the protection of personal information. Quebec's Law 25 requires us to publish who is responsible for protecting personal information at Vyra. That person holds the title Privacy Officer at Vyra Health, Inc., and can be reached at privacy@getvyra.ai, or by post at Vyra Health Inc., 2810 N Church St, STE 88042, Wilmington, DE 19802, USA.