1. Who are we?
Vytrix is a fitness and wellness application developed by Vincent Molenkamp (sole proprietorship), based in the Netherlands.
- Data controller: Vincent Molenkamp / Vytrix
- Chamber of Commerce number: 42078574
- Privacy contact: privacy@vytrix.app
- Appeals (DSA Art. 20): appeals@vytrix.app
- Data Protection Officer (DPO): to be appointed prior to v1.0 launch (mandatory under GDPR Art. 37(1)(c) for large-scale Article 9 processing)
2. What data do we collect?
2.1 Account data
Name, email address, username, profile picture (avatar), date of birth, gender.
2.2 Training and activity data
Exercises, sets, reps, weights, workout duration, training templates, routines, personal records, custom exercises.
2.3 Health data (special category — GDPR Article 9)
This data is only processed after your explicit consent (GDPR Art. 9(2)(a)) and consent can be withdrawn at any time via Settings → Privacy → Withdraw consent — as easily as it was given.
- Sleep data: bedtime, wake time, sleep duration, sleep quality, sleep stages.
- Nutrition data: food log, calories, macronutrients, micronutrients, water intake, supplements.
- Body measurements: weight, BMI, body fat percentage, body circumferences, lean body mass, body water mass.
- Heart rate data: heart rate (BPM), HR zones, recovery data, HR variability (HRV).
- Progress photos: body photos with metadata.
- Meal photos (optional): processed temporarily by Google Vertex AI through the EU multi-region
eu(not used for model training). Only extracted nutrition data is stored. - Product photos (barcode/label scan): depending on the selected scanner, processed temporarily by Google Vertex AI in the EU multi-region or by OpenAI to read the label. The barcode and an existing product name may also be sent as context.
- Menstrual cycle data (optional): see separate section below.
2.3a Menstrual cycle and reproductive health data
Reproductive health data warrants special attention. Vytrix follows Mozilla / Privacy International best-practices for period-tracking apps in a post-Roe geopolitical context.
What we collect: last menstruation start date, cycle length (21-35 days), period length (3-10 days), derived cycle phase (menstruation / follicular / ovulation / luteal).
How we use this data: automatic luteal-phase calorie adjustment (+150 kcal, toggleable), notifications about expected fluid retention (toggleable), visual indicators in training calendar, phase-specific training tips.
Guarantees:
- Optional — only active when you turn cycle tracking on (default off).
- Primary storage region in Ireland— the Vytrix Supabase project's Database, Auth and Storage are hosted in AWS
eu-west-1. Backups, support and other processing are governed by the current Supabase DPA and sub-processor terms, so we do not make an absolute "EU-only" promise. - Not visible to coaches — regardless of other permissions.
- Not shared with the AI provider — cycle data is not passed to AI features.
- Not used for advertising or profiling — we do not run advertising.
- Independently deletable — you can delete cycle data without deleting the rest of your account.
- Authority requests— we assess requests for validity under applicable law and limit disclosure to what is legally required. Our processors' terms may also apply to such requests.
2.3b Health Connect / HealthKit permissions
On Android devices you can connect Vytrix to Health Connect. Permissions are requested only when you activate the corresponding feature:
| Permission | Purpose |
|---|---|
| READ_ACTIVE_CALORIES_BURNED | Show calorie expenditure |
| READ_STEPS | Show steps + weekly volume |
| READ_WEIGHT / WRITE_WEIGHT | Sync weight between apps |
| READ_BODY_FAT / WRITE_BODY_FAT | Sync body fat percentage |
| READ_LEAN_BODY_MASS / WRITE_LEAN_BODY_MASS | Sync lean body mass |
| READ_BODY_WATER_MASS / WRITE_BODY_WATER_MASS | Sync body water |
| READ_BASAL_METABOLIC_RATE | Read BMR for daily calorie target |
| READ_SLEEP | Import sleep for recovery correlation |
| READ_HEART_RATE | Heart rate during workouts |
On iOS we use the equivalent HealthKit categories. You can withdraw any permission individually via Health Connect settings on your device.
2.3c Limited Use Statement (Health Connect)
The use of information received from Health Connect will adhere to the Health Connect Permissions policy, including the Limited Use requirements.
- We use Health Connect data only for the features listed in §2.3b.
- We never share Health Connect data with advertising networks, marketing data processors, lenders, insurers, or employers.
- We do not use Health Connect data to determine employment, insurability, or for unauthorized social sharing.
- We do not sell Health Connect data to third parties under any circumstance.
2.4 Social data and messages
- Feed content: posts, comments, likes, friendships, challenges.
- Direct messages and group chats: text and shared content. Messages are visible only to sender, recipient(s), and — for reported content — our moderation procedure. Not shared with third parties.
- UGC moderation metadata: reports stored in
social_reports; reports about you are not visible to you.
2.5 Coach-client data
Training programs, progress, messages with your coach. The coach is an independent data controller. Reproductive health data is excluded from coach access.
2.6 Technical data and device IDs
Device type, OS, app version. We do not collect Android Advertising ID (AD_ID) or Apple's Identifier for Advertisers (IDFA). We do collect a Firebase Installation ID and push notification token.
2.6a Background functions (Foreground Service)
During a workout, the app may show a rest timer (60-300 sec) on the lock-screen notification. No location tracking, audio recording, or other background processing occurs outside this user-started timer.
2.7 Location data (optional)
When you use the "detect gym" feature, the app collects your approximate location (city level, not precise) once. Location is not continuously tracked and not stored on our servers, except gym coordinates when you link a gym.
2.8 App performance and analytics
- Crash reports via Firebase Crashlytics. No personal training, health, or cycle data.
- App interactions via our own Supabase analytics on EU servers. Pseudonymized.
- Diagnostic data: app version, OS version, device model.
- Website performance through Vercel Analytics and Speed Insights. URL query parameters and fragments are removed before an event is sent.
- Optional website analytics through PostHog on its European endpoint, only after your explicit choice. DNT and Global Privacy Control are treated as a refusal; legal pages do not use PostHog.
2.8a No advertising ID
Vytrix does not request access to AD_ID or IDFA. We do not show advertisements and do not share data with ad networks.
2.9 Product interest and early-access email
If you express interest in the Vytrix Food Scale or Body Scale viaConnect Devices in the app or the shop/waitlist on this website, we process the email address you provide, the separate product, your choice (buy, test or updates only), the source (app or website), language, optional country/region, consent version, sending/provider-acceptance metadata and the time you complete the confirmation. An alternative email entered in the app remains unlinked; only an exact, already verified account address may technically be linked to your account.
The checkbox is off by default. Resend sends one confirmation message. Its link first opens a confirmation page; double opt-in is complete only after you actively press the confirmation button on that page. Food and Body interest remain separate segments, and we do not use health, training or nutrition data for these emails. Every product update includes a personal unsubscribe link. Unsubscribing immediately withdraws consent for that record; joining again requires a new double opt-in.
3. Why and on what basis do we process your data?
See the Dutch source at /privacybeleid §3 for the full processing-purpose table. Vytrix relies on:
- Art. 6(1)(a) Consent — for health data
- Art. 6(1)(b) Performance of contract — for account, training, social platform
- Art. 6(1)(f) Legitimate interest — for crashlytics + analytics
- Art. 9(2)(a) Explicit consent — for all special-category data
- Product interest — Art. 6(1)(f) for the requested confirmation message, Art. 6(1)(a) after confirmation for updates, and Art. 6(1)(c) for limited consent evidence
5. International transfers
Your data is primarily processed on EU servers (the primary Supabase region for Database, Auth and Storage is Ireland). Additional processors, including Firebase, RevenueCat, Resend, OpenAI, Vercel, PostHog and Stripe, may process data outside the EEA. Where applicable, they rely on the EU-US Data Privacy Framework (DPF) and/or contractual safeguards such as Standard Contractual Clauses (SCCs) under GDPR Art. 46. The exact combination varies by processor and is set out in the relevant processing agreement or linked privacy terms.
Resend states that its primary processing and storage take place in the US. Selecting a European sending region only controls the mail route; it does not move stored account, message or delivery data to the EU.
Vytrix does not send reproductive health data to AI, marketing or payment providers. Primary storage is in Supabase's Ireland region; any supporting processing or international transfer by the infrastructure provider is governed by the Supabase DPA, sub-processor list and applicable transfer safeguards.
6. Retention periods
| Data | Retention |
|---|---|
| Account / training / health | Until account deletion or consent withdrawal |
| Soft-deleted items (trash) | 90 days, then permanently deleted |
| Data after account deletion | Fully deleted within 90 days |
| Tax-required transactional records (pseudonymized) | 7 years (Dutch Tax Act Art. 52) |
| Crashlytics technical logs | 90 days |
| Audit logs for fraud prevention | 12 months |
| Website account-deletion requests | Unconfirmed: up to 7 days. Confirmed: until handled; deleted within 90 days afterwards |
| Unconfirmed product interest | Up to 30 days after sign-up; never used for product updates |
| Confirmed product interest | Until unsubscribe or the product programme ends; then deleted or anonymised within 12 months |
| Consent records | 5 years after withdrawal |
7. Your rights
You have the following rights under GDPR:
- Access (Art. 15) — view via Settings → Privacy
- Rectification (Art. 16) — edit in the app
- Erasure (Art. 17) — delete via Settings → Account or via vytrix.app/en/delete-account
- Restriction (Art. 18) — withdraw consent per category
- Portability (Art. 20) — JSON export via Settings
- Object (Art. 21) — withdraw consent
- Withdraw consent (Art. 7(3)) — use the unsubscribe link in every product update or email privacy@vytrix.app. Manage other categories in the app.
- Automated decision-making (Art. 22) — Vytrix does not make decisions with legal or similarly significant effects
You can file complaints with:
- Autoriteit Persoonsgegevens (NL)
- Gegevensbeschermingsautoriteit (BE)
- BfDI (DE)
- CNIL (FR)
8. Audience and age
Vytrix is intended for adults aged 18 and over. We do not knowingly process personal data of minors. At registration, your date of birth is verified via a neutral age picker. Users under 18 cannot create accounts.
9. Security
- AES-256 encryption at-rest
- TLS 1.3 in-transit; no cleartext traffic
- Primary Supabase region for Database, Auth and Storage: Ireland (
eu-west-1) - Row Level Security on all personal-data tables
- JWT authentication via Supabase Auth
- Private storage buckets; signed URLs (24h)
- Coach-client data isolation via RLS + consent checks
- Automated retention cleanup (pg_cron)
- BDSG §22(2) "suitable and specific safeguards" for German users
10. Changes
For material changes we proactively inform you via in-app banner, blocking modal requesting renewed consent, and email.
11. Contact
- Privacy questions: privacy@vytrix.app
- Moderation appeals (DSA Art. 20): appeals@vytrix.app