Privacy policy
Last revised: 2026-09-06
Draft text: the controller details in brackets are still to be filled in.
This policy explains what data vita (https://vita.macarryon.com) collects, what it uses it for, where it is stored and what rights you have over it. It is written to be read, not to tick a box: if anything is unclear, write to hola@macarryon.com.
1. Who is responsible
[Nombre o razón social del responsable], [NIF], [Dirección postal]. Contact for anything about your data: hola@macarryon.com.
2. What data we process
Account data
- Email address and password (the password is stored as an irreversible hash).
- If you sign in with Google: the name, email and profile picture Google sends us. We never receive your Google password and we do not access your Google account beyond identifying you.
- Language, time zone and app preferences.
Health and habit data you log
vita is a training, nutrition and recovery app, so almost everything you log is information about your body and habits: weight, measurements, progress photos, workouts and sets, meals and macros, water, fasting, sleep, energy, mood, injuries, allergies and intolerances, goals. This is special-category data (Article 9 GDPR) and we only process it because you enter it to use the service and give us your explicit consent when you create the account.
Content you share with a professional
If a trainer or nutritionist links to you through vita, that person sees the data they need to coach you (workouts, nutrition, progress, chat messages). You accept the link and you can end it at any time from the app.
Technical data
Server logs (IP address, date, path, browser) for a limited time, for security and troubleshooting. We use no third-party analytics and no advertising cookies: the only cookies are session cookies, which the app needs to work.
3. What we use it for
- Providing the service: storing your log, computing your targets and progress, proposing plans.
- AI features you trigger: analysing a meal photo, chatting with the coach, generating a plan. For that we send the AI provider only what that request needs (the photo, the message, a summary of your context). See section 5.
- Service emails: verification, password recovery and, if you enable it, the weekly digest.
- Security, abuse prevention and legal compliance.
We do not sell data, we do not build advertising profiles and we do not hand your information to anyone for their own purposes.
4. Legal basis
- Performance of a contract (Article 6(1)(b) GDPR) for the account and the service.
- Explicit consent (Article 9(2)(a) GDPR) for health data. You give it when you sign up and withdraw it by deleting the account or the specific data.
- Legitimate interest (Article 6(1)(f) GDPR) for security and technical logs.
5. Who can access your data and where it lives
Your data lives on our own server hosted in the European Union, not on a third-party platform. We work with these processors, each only for its part:
- Hosting provider (virtual server in Spain): the infrastructure where vita and its database run.
- Off-server backups (Cloudflare R2): to recover the service if the server fails. Retained for up to 12 months.
- Resend: transactional email delivery. Receives your address and the email content.
- Google: only if you choose to sign in with Google, and only to identify you.
- AI model provider (Anthropic, or an equivalent intermediary): receives the content of the request when you use an AI feature. Contractually it does not use what we send to train its models.
Some of these providers are in the United States. Where that is the case, the transfer relies on the EU-US Data Privacy Framework or on standard contractual clauses approved by the European Commission.
6. How long we keep it
- For as long as you have the account.
- When you delete it, your data is removed from the database immediately. It remains in backups until they rotate (14 daily, 8 weekly, 12 monthly copies: at most 12 months) and is never restored except to recover the whole service.
- Technical server logs are kept for at most 90 days.
7. Your rights
You can access your data, rectify it, erase it, request its portability, restrict or object to its processing and withdraw consent at any time. You can do most of it yourself from the app: edit your profile, delete entries, export your workouts and delete the account from Settings. For anything else, write to hola@macarryon.com and we will answer within one month.
If you believe we have not honoured your rights, you can lodge a complaint with the Spanish Data Protection Agency (aepd.es).
8. Minors
vita is not aimed at anyone under 16. If we detect an account held by a minor without parental authorisation, we will delete it.
9. Security
Encrypted connection (HTTPS) always, hashed passwords, database access restricted per user, daily backups verified weekly, and row-level access control so each account can only read its own data. No system is infallible: if a breach affected you, we would notify you without undue delay, as the law requires.
10. Changes to this policy
If we change anything relevant we will tell you in the app or by email before it takes effect. The date of the last revision is at the top of this page.