Effective date: 31.07.2026
Version: 1.0
Locale: en-EN
Vantage ("Vantage", "we", "us", "our") is a health and longevity application for iOS. This Privacy Policy explains how we collect, use, share, and protect your personal data, and the rights you have under the EU General Data Protection Regulation (GDPR) and Romanian data-protection law.
The data controller responsible for your personal data is:
Vantage Labs SRL
Str. Azurului 5, Sector 6, București, Romania
CUI: 54630331 (D-U-N-S: 303165524)
Email: privacy@vantagehealthapp.com
This policy covers personal data we process when you create an account and use the Vantage app, including health and fitness data you provide or that we receive (with your permission) from Apple Health. It does not cover Apple's own processing of your App Store purchases or device data — see Apple's privacy policy for that.
Minimum age. Vantage is intended for adults and is not directed at children. You must be at least 16 years old to use Vantage.
We process the following categories of personal data. Where a category is special-category data under Article 9 (data concerning health), we say so — this data receives additional protection and is processed only with your explicit consent (see §5).
Identity and account data
Name, email address, username, date of birth, and gender. Account status, subscription tier and status, onboarding status, and account-creation date.
Health and fitness data — special category (Article 9)
Data we derive about you (inferred data — also personal, and where health-related, special category)
Vantage computes insights from your data, including your Longevity Score, Recovery Score, Sleep Score, heart-rate training zones, nutritional status, and personalized sleep/nutrition/workout formulas and recommendations. See §6 (profiling).
Consent and legal-acceptance records
Records of the consents you give or withdraw, and your acceptance of our Terms & Conditions and this Privacy Policy (including the document version, timestamp, and, for proof, the originating IP address and device identifier).
Technical and security data
IP address, device identifier, device type and model, operating system, and app version; and records of sign-in attempts (for security and fraud prevention).
Communications data
Records of transactional and (if you opt in) marketing emails and push notifications we send you.
Subscription data
Your subscription status, billing period, and cancellation state, and subscription lifecycle events. Apple is the merchant of record for in-app purchases; we do not receive or store your card or payment-instrument details (see §7).
If you choose to connect Apple Health, Vantage reads health and fitness data from HealthKit with your permission to provide the app's features (for example, syncing sleep, heart-rate, body-composition, and activity data). You can see and change exactly what Vantage may read or write in iOS Settings → Privacy & Security → Health → Vantage, and you can revoke this access at any time there.
In line with Apple's requirements, data obtained through HealthKit is used only to provide you with health and fitness features inside Vantage. We do not use HealthKit data for advertising or marketing, we do not sell it, and we do not share it with third parties for their own purposes. Our analytics (PostHog) and diagnostics (Sentry) providers receive technical data such as your account identifier and IP address — never your HealthKit health data — and our food-database lookups send only a product barcode (see §7).
Most of your data comes directly from you (what you enter) or from your device with your permission (Apple Health / HealthKit, which may itself aggregate data from your iPhone, Apple Watch, or connected wearables). Some data is generated by Vantage itself (the derived scores and recommendations in §2). We do not buy personal data about you from third parties.
We process your personal data for the purposes below. For each, the table states the legal basis under Article 6 and, for health data, Article 9.
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and operate your account; provide the app and its core (non-health-personalization) functions; manage your subscription | Identity, account, subscription, technical data | Contract — Art. 6(1)(b) |
| Process your health and fitness data to generate personalized plans, scores, and recommendations | Health and fitness data; derived data | Explicit consent — Art. 9(2)(a) (with Art. 6(1)(a)) |
| Provide exercise programming after you confirm you understand the associated health risks | Health-disclaimer acceptance; fitness data | Explicit consent — Art. 9(2)(a) |
| Measure and improve app usage (analytics) | Pseudonymized usage data | Consent — Art. 6(1)(a) |
| Send you tips, updates, and offers (marketing) | Email, push token, account data | Consent — Art. 6(1)(a) |
| Read health data from Apple Health | HealthKit data | Consent — Art. 6(1)(a) / Art. 9(2)(a) |
| Keep the service secure; prevent fraud and abuse; investigate sign-in anomalies | Technical and security data | Legitimate interests — Art. 6(1)(f) |
| Maintain accountability and compliance records (consent proof, audit logs) | Consent records, audit logs | Legal obligation — Art. 6(1)(c) (Art. 5(2)) / legitimate interests — Art. 6(1)(f) |
| Keep financial records relating to subscriptions | Aggregated payout/accounting records (not per-user payment rows) | Legal obligation — Art. 6(1)(c) (Romanian fiscal law) |
The consents marked above are the consents you give at sign-up (Terms & Conditions and Privacy Policy acceptance; health-data processing; and optional analytics and marketing), when you connect Apple Health, and before your first workout. You can withdraw the optional consents (analytics, marketing, Apple Health) at any time without affecting your use of the rest of the app. Withdrawing the consents required to operate the app or process your health data means we can no longer provide the service to you; you withdraw those by deleting your account (see §10). Withdrawal does not affect processing carried out before you withdrew.
Vantage analyzes your health and fitness data to build a profile of your training, sleep, nutrition, and recovery, and to generate personalized scores and recommendations (for example, your Longevity Score, Recovery Score, Sleep Score, training zones, and daily targets). This is profiling under Article 4(4) and we want to be transparent about it.
These outputs are information and recommendations to help you make your own decisions. They are advisory only — you decide what, if anything, to do with them. We do not make any decision about you that produces a legal or similarly significant effect based solely on automated processing, so the additional Article 22 safeguards do not apply.
You can still object to this profiling and ask us about the logic involved — see §10.
We do not sell your personal data. We share it only with the service providers ("processors") who help us run Vantage, each under a data-processing agreement, and only as needed for the purposes in §5:
We may also disclose personal data where required by law or to establish, exercise, or defend legal claims.
Your data is hosted in the European Union (AWS, Frankfurt), and our analytics (PostHog) and nutrition-lookup (Open Food Facts) providers also process data in the EU. One of our processors — RevenueCat (subscription management) — is based in the United States, so providing it with the subscription and entitlement data it needs involves a transfer outside the EU/EEA. We rely on the European Commission's Standard Contractual Clauses, as incorporated into RevenueCat's data-processing agreement, together with supplementary measures (transmission over TLS, encryption at rest, and data minimisation — RevenueCat receives only a pseudonymous account identifier and subscription data, never your name or health data). Apple acts as an independent controller for App Store purchases under its own terms.
You can request a copy of the safeguards we rely on using the contact details in §0.
You can request more information about these safeguards using the contact details in §0.
We keep your personal data only as long as needed for the purposes above.
| Data | Retention |
|---|---|
| Account, profile, and health/fitness data | For as long as your account is active. On deletion, see below. |
| After you request account deletion | Your account is deactivated immediately and permanently deleted after a 30-day grace period, during which you can cancel the deletion. After that, your personal data is erased. |
| Sign-in attempt records | 90 days; anonymized records retained up to 2 years for security and accountability. |
| Notification (email/push) records | 180 days. |
| Food-search analytics | 90 days. |
| Subscription webhook/integration logs | 90 days. |
| Proof-of-consent records (after account deletion) | Up to 5 years, as hashed records, to evidence the consent you gave. |
| Account-deletion and legal-acceptance records | Up to 5 years, in anonymized form, for accountability. |
| Audit logs | Up to 2 years in anonymized form. |
| Subscription event records | Up to 5 years in anonymized form. |
| Financial records relating to subscriptions | As required by Romanian fiscal law (currently up to 6 years), as aggregated accounting records — not as per-user transaction data. |
Records retained after account deletion are anonymized or hashed so they can no longer identify you, and are kept only for the legal and accountability reasons stated.
Under the GDPR you have the right to:
How to exercise these rights in Vantage:
We respond to rights requests within one month, as required by Article 12. If a request is complex, we may extend this by up to two further months and will tell you if so.
We use technical and organizational measures appropriate to the sensitivity of your data, including:
No system is perfectly secure, but we work to protect your data and to detect and respond to incidents. If a personal-data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, and we will notify the supervisory authority as required by law.
Vantage is not directed at and is not intended for use by anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this policy. When we make material changes, we will update the version and effective date and, where the law requires, ask you to review and re-accept the updated policy within the app before you continue using affected features. The version you accepted is recorded against your account.
If you have concerns about how we handle your data, please contact us first at privacy@vantagehealthapp.com so we can try to resolve them. You also have the right to lodge a complaint with your local data-protection authority. In Romania this is:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, 010336 București, Romania
Web: www.anspdcp.ro
Vantage Labs SRL
Str. Azurului 5, Sector 6, București, Romania
Email: privacy@vantagehealthapp.com