Designs by Duhart · Vitals for iPhone and Apple Watch
There are two ways to use Vitals, and they collect different things. This page says exactly what each one collects, why, and how to make it stop. Last updated 18 September 2026.
Without an account, everything you log stays on your phone. We hold one random identifier so we can answer whether the phone is subscribed, and nothing else.
With an account, the training records you create are stored on our server so they appear on your other devices and in the web app. You choose whether to create one; the app is fully usable without one, and you can delete an account and everything in it from inside the app at any time.
Nothing you log is ever sold, and none of it is ever used for advertising.
Designs by Duhart publishes Vitals and is the data controller for the app. Contact: admin@designsbyduhart.org. That address is read by a person and is the fastest way to exercise any right described below.
This is the default. Your workouts, personal records, body measurements, food log, sleep, steps, heart rate and location during a run are stored on your phone and, where you have allowed it, in Apple Health and your calendar. None of it is sent to us.
When Vitals first runs it generates a random identifier and keeps it in your phone’s keychain. It is not your device identifier and it cannot be used to find you anywhere else. The app sends it to our server on launch to ask one question: is this phone subscribed. Legal basis: performing the contract you entered by subscribing.
An account exists so your training appears on more than one device. Creating one is optional and nothing prompts you to.
Registration asks for an email address and a password, and for your date of birth, which sets your training zones and confirms you are old enough to use the app. It also offers, all optional: a display name, sex, height, bodyweight, training load, your main goal, unit preference and country. The optional fields exist because the app’s calorie, macro and body-composition figures are calculated from them; leaving them blank costs you accuracy and nothing else. Your password is stored only as a salted PBKDF2-SHA256 hash, which we cannot reverse.
Once you are signed in, the records you create in the app are stored against an opaque account identifier on our server so they can reach your other devices: timers, protocols and alarms, workout history, personal records, food logs, macro plans, body measurements, goals and settings.
If you switch on health syncing, daily sleep and step summaries read from Apple Health are also uploaded, so the web app can show the same trends as your phone. The web app has no Apple Health to read from, which is the only reason this exists. It is off unless you turn it on, it can be turned off at any time in Settings, and health data is never used for advertising and never shared with an advertiser. Detailed Apple Health records beyond those daily summaries are not uploaded.
We record which devices are linked to your account, with a name you can see and change, so a subscription bought on one device unlocks the others and so you can remove a device you no longer have.
When you subscribe, Stripe handles checkout and stores your payment details; we never see your card number. Stripe tells our server which installation id the purchase belongs to, and we keep a small record: the installation id, the Stripe customer and subscription identifiers, the plan, the subscription status and when the current period ends. Legal basis: contract, and the legal obligations that attach to payments.
The weekly plan shows ads served by Google AdMob. The monthly plan shows none. Before any ad code runs, the app asks for your consent through a consent form that follows the IAB Transparency and Consent Framework, and then asks iOS for tracking permission. If you decline either, ads are non-personalised and no advertising identifier is shared. With consent, Google may receive the advertising identifier and data about the ads shown and tapped. Google acts as an independent controller for that data under its own privacy policy. Legal basis: your consent, which you can withdraw at any time from Settings, then Privacy choices.
Your training records, your profile and your health data are never shared with Google or any other advertiser, whether or not you consent to ads.
Each of these is requested only when you switch on the feature that needs it, with a message that says what it is for. Location recorded during a run is used to draw your route and is stored with that activity; it is not sent to us unless you are signed in and syncing, and privacy zones let you hide chosen places from any route you share.
We do not sell personal data, and there is nothing else it is shared with.
The server runs in the United States. Stripe, Google and Cloudflare each rely on the EU-US Data Privacy Framework or standard contractual clauses for transfers from the EU and UK, as set out in their own terms.
Wherever you live, you can access, export, correct and delete your data. In the EU and UK these are rights under the GDPR, including the right to object and the right to complain to your local data protection authority. In California and other US states you have equivalent rights, including the right to opt out of the sale or sharing of personal information, which the consent form on the weekly plan provides.
Every request by email is answered within 30 days, and you never need an account to make one.
Vitals is not directed at children and is not intended for anyone under 13. Creating an account requires a date of birth and accounts for anyone under 13 are refused. We do not knowingly collect data from children; if you believe a child has registered or subscribed, email us and we will remove the record.
If this policy changes in a way that matters, the date at the top changes and the app shows a notice on its next launch. Older versions are available on request.
Questions: admin@designsbyduhart.org, or the contact form. See also the terms of use.