Legal

Privacy Policy

Effective [EFFECTIVE DATE] · Last updated [LAST UPDATED DATE]

About this policy

This policy explains how [COMPANY LEGAL NAME] (“Vantage”, “we”, “us”) handles personal information when you use the Vantage mobile app and the services that support it (the “Service”), and when you visit our website. It is part of our Terms of Service.

Vantage is offered to adults 18 and older in the United States.

Information we collect

Account information

When you create an account, our sign-in provider, Clerk, collects your email address and either your password or your Apple or Google sign-in. Clerk handles your password, so we never see it. If you sign in with Apple or Google, we receive the name, email address and profile photo link that you allow that provider to share. Clerk also records sign-in activity, such as when you sign in and from what kind of device.

Profile information

During setup you give us your name, birthday, gender, height, weight, activity level, goals, the areas you want to track, your preferred units and your notification preferences. If you change any daily targets, we also store those changes. Vantage uses this information to calculate your targets and your Day Score.

Food and nutrition

We store the meals you log and the foods in them, with amounts, meal type, time, how you logged them (search, barcode, describe, voice or scan) and the nutrition values. We also store the custom foods, recipes, saved meals and favorites you create, and any corrections you make to a food’s values, including your reason if you give one.

When you search for a food or scan a barcode, our server sends the search words or barcode to the food databases described in section 6. We don’t store your search history.

Meal photos, notes, text and recordings

  • Meal scan: we store a resized copy of your meal photo, any note you add, and the foods identified in it.
  • Describe a meal: your text is sent for analysis. We don’t store it. Only the meal you confirm is saved.
  • Voice log: your recording is sent for transcription and is deleted from your phone as soon as it’s sent. We don’t store the recording.
  • Daily verdict: we store the AI-written summary of your day, which may mention values from your Day Score.

Apple Health

If you connect Apple Health on iPhone, Vantage reads your sleep (including sleep stages where available), steps, resting heart rate and heart rate variability. These values are read and used on your phone to calculate your Day Score. They aren’t uploaded to or stored on our servers, with one exception: when you open the daily verdict, a summary of your score is sent through our server to our AI provider, and that summary can include values such as your sleep and resting heart rate (see section 5). Vantage never writes to Apple Health.

AI usage records

To apply daily limits, we record which AI feature you used and on what date.

Diagnostic and technical information

The app uses Sentry to find and fix crashes, errors and slow screens. Sentry receives:

  • crash and error reports;
  • performance measurements;
  • your IP address, and device details such as model, operating system and app version;
  • app event logs. These include record IDs, counts, the Day Score number and error messages, but not your name, email or food names.

Sentry also records screen replays: a replay of every session in which an error occurs, and of about 10% of other sessions. Text, images and anything you type are masked in these replays.

Our server and service providers also keep technical logs of requests and background jobs (see section 7).

Permissions on your phone

Vantage asks for camera access to photograph meals and scan barcodes, and microphone access for voice logging. You can pick a meal photo from your library through your phone’s photo picker, which shares only the photo you choose. Apple Health access is described above.

Vantage doesn’t collect your location, your contacts or advertising identifiers.

Our website

Our website doesn’t use analytics or advertising trackers, and our pages don’t set cookies of their own. Its pages load fonts from Google Fonts, which receives your IP address when you visit. The website is hosted by Cloudflare, which processes your IP address and request details to deliver the pages.

Waitlist

If you join the waitlist on our website, we store your email address, whether you use iPhone or Android, and when you joined. We use this only to tell you when Vantage is available on your phone. Joining the waitlist doesn’t create a Vantage account, and we don’t add your email to any other mailing list.

To keep out automated signups, the waitlist form uses Cloudflare Turnstile. It checks information from your browser and device, such as your IP address and browser characteristics, to tell people from bots. Cloudflare handles this under its own privacy policy. We receive only a pass or fail result.

Data kept only on your phone

Vantage currently stores these logs only in the app’s storage on your phone. They are never sent to our servers:

  • drinks, water and caffeine;
  • supplements and when you took them;
  • tasks, notes and priority check-offs;
  • weigh-ins and body measurements;
  • workouts and workout templates;
  • all money data: accounts, transactions and balances;
  • your past Day Scores and day history.

A copy of the meals you log is also kept on your phone so the app works quickly. We don’t back up device-only data, so it isn’t available on another device and can’t be recovered if your phone is lost or reset.

How we use information

We use the information described above only to:

  • run your account and keep your profile, targets and meals in sync across devices;
  • provide Vantage’s features, including food logging, targets, the Day Score and the AI features;
  • apply daily limits on AI features and prevent misuse;
  • find and fix bugs, crashes and performance problems;
  • keep the Service secure;
  • send you messages about your account or changes to our terms, and verification codes (Clerk sends these);
  • meet legal obligations and enforce our Terms.

We don’t use your information for advertising. We don’t sell it, and we don’t share it for targeted advertising.

AI features

Vantage’s AI features use Google’s Gemini API. When you use one, our server sends Google only what that feature needs:

  • Describe a meal: your text.
  • Voice log: your recording.
  • Meal scan: your photo and note.
  • Daily verdict: a summary of today’s score. This includes category points, items short of target with their values (for example sleep or resting heart rate), your calorie, protein and water totals and targets, and your open priorities for the day. It doesn’t include your name, email or account ID.

We currently use Google’s unpaid Gemini API service. Under Google’s terms for that service, Google may use the content it receives, and the responses it returns, to provide, improve and develop Google products and machine-learning technologies, and human reviewers may read it. Don’t include anything in a note, photo or recording that you don’t want shared this way.

Who we share information with

We share personal information only with service providers that help us run Vantage, and only as needed for their role:

  • Clerk (accounts and sign-in): your account details, profile answers, target changes and sign-in activity.
  • Neon (database hosting): the information we store with your account.
  • Cloudflare (website hosting and bot protection): website requests, the waitlist signups stored in a Cloudflare database, and the browser information Turnstile checks on the waitlist form.
  • Google (Gemini API): the AI inputs described in section 5.
  • ImageKit (photo storage): your meal-scan photos.
  • Trigger.dev (background jobs): the account details and profile answers copied from Clerk to our database, and meal-scan processing details, including the foods identified.
  • Sentry (diagnostics): the technical information described in section 2.
  • Apple and Google: if you use Sign in with Apple or Sign in with Google.
  • fatsecret, USDA FoodData Central and Open Food Facts (food data): the search words and barcodes you look up. Our server sends these without your name, email or account ID.
  • [HOSTING PROVIDER FOR THE VANTAGE SERVER] (server hosting): requests between the app and our server.

We may also disclose information:

  • if the law requires it, or to protect the rights, safety or property of our users, the public or Vantage;
  • as part of a merger, acquisition or sale of assets, in which case this policy will continue to apply to your information;
  • with your permission.

No other users can see your information. Vantage has no social or sharing features.

How long we keep information

  • Account, profile, meals, food library and daily verdicts: until you delete them or delete your account. A refreshed verdict replaces that day’s earlier one.
  • Meal-scan photos: until you discard the scan or delete your account. Photos from scans you saved are kept even if you later delete the meal.
  • AI usage records: until you delete your account.
  • Device-only data: on your phone until you delete the app or delete your account on that phone.
  • Diagnostic data (Sentry): [SENTRY RETENTION, e.g. 90 days].
  • Background job logs (Trigger.dev): [TRIGGER.DEV LOG RETENTION].
  • Server request logs: [HOSTING LOG RETENTION].
  • Waitlist signups: until we’ve told you that Vantage is available on your phone, or until you ask us to remove you, whichever comes first. We delete them within [WAITLIST RETENTION, e.g. 30 days] after that.
  • Record of account deletion: a record that an account was deleted is kept, containing the sign-in account ID and the time. It contains no other information about you.

Content sent to Google through AI features is kept under Google’s own terms.

How we protect information

  • Your sign-in session is stored encrypted in your phone’s secure storage.
  • Every request to our server must carry a valid sign-in session, and the server only ever returns the signed-in user’s own data.
  • Keys for our service providers stay on our server and are never included in the app.
  • Meal photos are stored privately and can be opened only through links that expire after 10 minutes.
  • Connections between the app and our server are encrypted in transit [CONFIRM once production hosting is set up].

Device-only data is protected by your phone’s own security, such as your passcode. No method of storing or sending data is completely secure, and we can’t guarantee absolute security.

Your choices and rights

In the app

  • View and edit: change your profile, goals, targets, units and notification preferences in Profile. Edit or delete meals and the foods you created.
  • Apple Health, camera and microphone: turn access on or off at any time in your phone’s Settings.
  • Delete your account: in Profile, tap Delete your account. This permanently deletes your meal photos, all the information stored with your account on our servers, and your sign-in account. It also clears device-only data from that phone. To clear it from other phones, delete the app on each one.

By request

You can ask us to:

  • confirm whether we process your personal information;
  • give you a copy of it;
  • correct it;
  • delete it.

Email [PRIVACY CONTACT EMAIL] from the email address on your account. We may ask for more information to confirm it’s you. We will respond within 45 days, and we’ll tell you if we need more time where the law allows it. We can’t give you copies of device-only data, because we never receive it. To leave the waitlist, email us from the address you signed up with.

Depending on the state where you live, you may have further rights under state privacy law, and you may use an authorized agent to make a request. If we decline your request, you can appeal by replying to our decision. We will respond to your appeal within the time your state’s law requires. We won’t treat you differently for using your privacy rights.

We don’t sell personal information or share it for targeted advertising, so there’s nothing to opt out of.

Consumer health data

Some state laws, such as Washington’s My Health My Data Act, give extra protection to “consumer health data”. In Vantage, this includes:

  • your body measurements in your profile (height and weight);
  • food and nutrition logs, and meal photos;
  • sleep, steps, resting heart rate and heart rate variability read from Apple Health;
  • daily verdicts and AI usage records;
  • device-only health logs.
  • Where it comes from: you, and Apple Health when you connect it.
  • Why we use it: only to provide the features you use, as described in section 4.
  • Who receives it: the service providers in section 6. Google receives the AI inputs described in section 5.

We collect it only when you choose to log it or connect a source, and we don’t sell it. To access or delete it, or to withdraw your consent, use the options in section 9.

Children

Vantage is only for people 18 and older and isn’t directed to children. We don’t knowingly collect information from anyone under 18. If we learn that we have, we will delete the account and its information. If you believe a minor is using Vantage, contact us.

Where data is processed

Vantage is offered in the United States. Our service providers may process information in the United States and in other countries where they operate [CONFIRM provider regions].

Changes to this policy

We will update this policy whenever our practices change. We will post the new version here and update the “Last updated” date. If a change is material, we will tell you in the app or by email before it takes effect. Where the law requires it, we will ask for your consent first.

Contact us

Questions or requests about your privacy:

[COMPANY LEGAL NAME]
[MAILING ADDRESS]
[PRIVACY CONTACT EMAIL]