Privacy Policy
How we handle your personal data, including health data, and what rights you have over it.
Last updated: 17 July 2026
Versione inglese
Questa pagina legale non è ancora disponibile in italiano. Il testo che segue è la versione inglese, che fa fede. Una traduzione professionale è in preparazione; nel frattempo scrivici per qualsiasi dubbio.
This text is a starting draft written from the information provided. It is not legal advice and must be reviewed by a lawyer before publication.
Data controller
- Controller: Neus Digital Technologies LTD
- Address: China Hong Kong Tower, 8-12 Hennessy Road, Wan Chai, Hong Kong
- Data protection contact: privacy@vidacore.io
- Data Protection Officer: TODO_DPO_CONTACT
- EU representative (Art. 27 GDPR): TODO_EU_REPRESENTATIVE
Scope
This policy covers processing arising from use of this website (vidacore.io) and the VidaCore application (app.vidacore.io).
This website is informational: it requires no registration and collects nothing through forms. Most of the processing described here happens when you create an account and use the application.
Data we process
Depending on how you use VidaCore, we may process:
- Identity and contact data: name, email address, language and country.
- Physical profile data: age, sex, height, weight, body measurements and any progress photos you upload.
- Health data (special category): metabolic goals, injuries, insulin resistance, blood panels you upload, supplement protocols, sleep, energy, mood and stress.
- Activity data: logged workouts, loads, plan adherence and logged meals.
- The content of your conversations with the AI coach, including voice notes you send.
- Minimal technical data needed to deliver and secure the service.
Health data is a special category of data (Art. 9 GDPR) and receives heightened protection. We process it only with your explicit consent, which you may withdraw at any time.
Purposes and legal bases
- Delivering the service: generating and adapting your nutrition and training plans and maintaining the coach's memory. Basis: performance of a contract (Art. 6.1.b) and, for health data, explicit consent (Art. 9.2.a).
- Analysing your blood panels and proposing a supplement protocol. Basis: explicit consent (Art. 9.2.a).
- Handling your support requests. Basis: contract and legitimate interest (Art. 6.1.f).
- Keeping the service secure and preventing abuse. Basis: legitimate interest (Art. 6.1.f).
- Complying with applicable legal obligations. Basis: legal obligation (Art. 6.1.c).
- Audience measurement, if you enable it. Basis: consent (Art. 6.1.a).
Automated decisions and artificial intelligence
VidaCore generates meal plans, workouts and blood panel interpretations using AI models. These outputs are wellness suggestions: they are not diagnoses, they produce no legal effects concerning you, and they do not replace a healthcare professional's judgement.
You can modify, reject or ignore any recommendation, and request human intervention by writing to support@vidacore.io.
Recipients
We do not sell your personal data. We may share it with providers acting as processors on our behalf under contract (hosting, email delivery, AI model providers and, where applicable, payment processing), and with authorities where legally required.
The specific list of processors and sub-processors must be published here before launch. This cannot be invented: list the providers actually engaged.
International transfers
Neus Digital Technologies LTD is established in Hong Kong SAR. Hong Kong does not currently benefit from a European Commission adequacy decision, so transfers of personal data from the European Economic Area to the controller, or to providers outside the EEA, require appropriate safeguards under Chapter V GDPR — typically Standard Contractual Clauses together with a transfer impact assessment.
You can request information about the safeguards in place by writing to privacy@vidacore.io.
Outstanding legal requirement: execute Standard Contractual Clauses and a transfer impact assessment before processing EU residents' data, and describe the specific mechanism adopted here.
Retention
- Account and health data: while the account is active. After deletion it is erased or anonymised within a reasonable period, unless legally required to retain it.
- Coach conversations: while the account is active, as they are the basis of the coach's memory.
- Cookie consent record: up to 12 months, or until you withdraw it.
- Data needed to meet legal obligations: for the applicable limitation periods.
Your rights
You may at any time exercise your rights of access, rectification, erasure, restriction, portability and objection, and withdraw any consent given, without affecting the lawfulness of processing before withdrawal.
To exercise them, write to privacy@vidacore.io. We respond within one month, extendable as permitted by the GDPR.
The application also lets you export your data and delete your account directly from your profile.
If you believe processing does not comply with the law, you may lodge a complaint with the supervisory authority of your country of residence. In Spain, the Agencia Española de Protección de Datos (www.aepd.es).
United States state privacy rights
This section applies to residents of US states with a comprehensive privacy law — including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and others as those laws take effect. Depending on your state, you have some or all of these rights:
- Know and access: the categories and specific pieces of personal information we hold about you.
- Delete: request deletion of your personal information.
- Correct: request correction of inaccurate personal information.
- Portability: receive a copy of your personal information in a portable format.
- Opt out of the sale or sharing of your personal information, and of targeted advertising and certain profiling.
- Limit the use of sensitive personal information — including your health data — to what is necessary to provide the service.
- Non-discrimination: we will not deny you service, charge a different price, or lower quality because you exercised a right.
- Appeal: where your state provides it, you may appeal a refused request by writing to privacy@vidacore.io.
To exercise any of these rights, email privacy@vidacore.io. We verify your request against your account information and respond within the time your state requires (45 days in California, extendable once). You may use an authorized agent; we may ask them to prove authority and ask you to confirm the request directly.
Categories of personal information we collect (California)
Under the CCPA, VidaCore may collect the following statutory categories of personal information. We disclose them only to the service providers described under "Recipients", for the business purpose of operating the service — never for money and never for cross-context advertising.
| CCPA category | Examples | Sold or shared? |
|---|---|---|
| Identifiers | Name, email, account ID | No |
| Customer records | Age, sex, body measurements | No |
| Health information | Blood panels, insulin data, sleep, mood | No |
| Internet activity | App usage needed to run the service | No |
| Geolocation | Country and language only | No |
| Audio | Voice notes you send the coach | No |
| Inferences | Plan and supplement recommendations | No |
Sensitive personal information
Your health data — blood panels, insulin sensitivity, weight and related metrics — is "sensitive personal information" under the CPRA and analogous state laws. We use it only to provide the service you asked for: generating and adapting your plans. We do not use or disclose it to infer characteristics for advertising, and we do not sell or share it.
You may direct us to limit the use of your sensitive personal information at any time by writing to privacy@vidacore.io — though doing so may stop us from generating your plan, since the plan depends on that data.
Consumer health data (Washington, Nevada and similar)
For residents of Washington (My Health My Data Act) and Nevada (SB 370), this Privacy Policy also serves as our consumer health data privacy notice.
The consumer health data we collect — your metabolic, nutrition, fitness and lab-derived information — and the purposes for which we collect it are described above. We collect it to provide the service, with your consent.
We do not sell consumer health data, and will not sell it without your separate valid authorization. We will not collect or share it beyond what you have consented to. You may withdraw consent and request deletion of your consumer health data by writing to privacy@vidacore.io.
Washington's My Health My Data Act carries a private right of action and very broad definitions. For a metabolic-health product this is one of the highest-risk US statutes — counsel must confirm the in-app consent flow and this notice before serving Washington residents.
HIPAA does not apply here
VidaCore is a consumer wellness product. It is not a healthcare provider, a health plan or a clearinghouse, and it is not a "business associate" of one. That means the health information you give VidaCore is generally NOT protected by HIPAA.
It is still protected — by this Privacy Policy, by your consent, and by the state consumer-health and privacy laws above. But do not assume HIPAA rights apply here; for direct-to-consumer wellness apps, they usually do not.
Breach notification (United States)
If a breach affects your personal information, we will notify you and the relevant authorities as required by the applicable state breach-notification laws.
Because VidaCore handles health information and is not covered by HIPAA, the FTC's Health Breach Notification Rule may also require us to notify you, the FTC, and in some cases the media, of a breach of identifiable health information. We will comply with those obligations.
Minors
VidaCore is intended for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18, and in particular not from children under 13 (US COPPA). If we learn we have, we delete it.
For states that restrict the sale or targeted-advertising use of minors' data: we do not sell any user's data or use it for targeted advertising, minor or not.
Security
We apply technical and organisational measures appropriate to the risk, recognising that we process health data. No system is infallible; if a breach occurs that poses a high risk to your rights, we will notify you under Art. 34 GDPR.
Changes to this policy
If we change this policy materially we will update the date on this page and, where appropriate, notify you by suitable means.