Vially Vially

Privacy Policy

Effective date: September 9, 2026

Introduction

Vially ("we", "our", "the App") is a health tracking application for iOS. This Privacy Policy explains what data we collect, how we use it, and the choices you have. We built Vially with a simple principle: your health data belongs to you.

By downloading or using Vially, you agree to this Privacy Policy. If you do not agree, please do not use the App.

Where This Policy Applies

This policy covers the Vially iOS application available on the Apple App Store and the Vially website at vially.app. Different features may handle data differently — we explain each below.

What We Collect (and Why)

Vially is designed to minimize data collection. Here is a complete breakdown of the data involved when you use the App:

Health & Medication Data

This includes medication logs, injection records, dose schedules, weight entries, body measurements, side effect logs, mood tracking, nutrition entries, and lab results. This data is stored locally in the App's SQLite database, protected by iOS Data Protection. Vially does not operate a server that stores these records. Beginning with Vially 1.2.8, AI Lab Scanner transmits only a report you explicitly accept for that extraction, and AI Meal Scan transmits a reviewed meal photo only after one-time, revocable consent and only when you tap Estimate with AI for that photo; selecting a photo never uploads it automatically. Vially relays these requests to Google Gemini without retaining them. Also beginning with Vially 1.2.8, Vially health records are not uploaded through iCloud Sync. Data otherwise leaves the App only when you explicitly export or share it, through the local Apple Health integration you authorize, through the optional AI transfers and associated security infrastructure described below, through automatic software-update checks, or through the disclosed subscription and default-off analytics services.

Apple Health Integration

If you enable Apple Health sync, the categories available in your App version can include body mass, BMI, body fat percentage, height, dietary energy, protein, water, steps, active energy, heart rate, sleep, and workouts. You choose the categories Apple Health authorizes, and you can change those permissions at any time. This exchange happens between the App and Apple Health on your device; it does not pass through Vially or another external server. Apple Health data is never attached to Aurora Coach.

Automatic Lab Scanning

AI Lab Scanner and AI Meal Scan are Vially 1.2.8 Pro features for adults aged 18 and older. Their remote transfers occur only through the consent and deliberate actions described below.

AI Lab Scanner captures or imports a report into an encrypted, device-only draft. Before extraction, the App clearly states that the complete report may contain personal and health information and requires explicit per-report consent. If you tap Accept & Extract, the complete image or PDF is sent through Vially's authenticated service to paid Google Gemini to organize candidate report fields for your review. You must review every extracted field before saving.

Vially processes the scanner request and response only in transit and does not log or retain the report, extracted content, or model response on its servers. Google states that paid Gemini prompts and responses may be retained for up to 55 days for abuse monitoring and may be processed internationally. Extraction can be incomplete or inaccurate; every candidate must be reviewed before it is saved locally. Unfinished encrypted drafts expire after 24 hours, temporary upload copies expire within five minutes and are deleted immediately after the request when possible, and local source documents are deleted after save or discard.

AI Meal Scan

Before the first AI meal-photo upload, the App names Google Gemini, explains the transfer and retention terms, and asks for explicit one-time consent. The persistent consent record is stored locally by the App and is not sent to Vially or Google. Each upload carries a separate per-request consent assertion to Vially's authenticated service; Vially does not include that assertion in the Gemini prompt. Consent remains active until you revoke it under Settings > Privacy & Security. After consent, every meal photo still appears for review and is transmitted only when you deliberately tap Estimate with AI for that photo. Taking or selecting a photo never uploads it automatically. The complete photo is sent through Vially's authenticated service to paid Google Gemini, which returns an estimated meal name, serving description, calories, protein, and fiber. A pseudonymous subscription identifier is used separately by Vially and RevenueCat to verify Pro access and is not included in the Gemini prompt.

Vially processes the photo and estimate only in transit and does not log or retain them on its servers. Google states that paid Gemini prompts and responses may be retained for up to 55 days for abuse monitoring and may be processed internationally. Revoking consent prevents future AI meal-photo uploads but cannot erase requests already retained by Google during that period. Meal estimates can be incomplete or inaccurate and are not medical or dietary advice. The values remain editable and are saved locally only after you review and confirm them. The temporary local photo is deleted after save, discard, or replacement when possible.

Aurora Coach & Google Gemini

Aurora Coach is available in Vially 1.2.8 for people aged 18 or older. Before the first question is sent, the App names Google Gemini, explains the transfer, and asks for explicit consent and age confirmation. The first time a disclosure combination is used, the App lists the question and any included summary classes or recent chat history and asks you to confirm the send. You can choose “Don't ask again for sends like this,” which remembers that combination only on this device and allows later sends with the same data categories without another prompt. You can clear remembered send types under Settings > Privacy & Security to require confirmation again. Nothing is sent unless the applicable send type is authorized. The exact question text is then sent through a Vially server to Google Gemini so it can generate a response. A question may itself contain health or personal information, so include only information you are comfortable sharing.

Beyond the question, Aurora Coach attaches only compact on-device summaries of up to four classes of your Vially records — current stack, weight trend, side effects, and labs — and only when you choose them for a question or enable automatic use in Settings; it never attaches photos, notes, or Apple Health data. When conversation memory is enabled, recent messages from THIS chat only — up to 8 turns or 4,000 characters — accompany a question; other chats and deleted messages are never sent. When it is off, prior messages stay on device. The App sends its pseudonymous RevenueCat app user ID and consent proof to Vially's server; the server uses the pseudonymous ID with RevenueCat only to verify Pro access. Those fields are not included in the Gemini prompt. The App stores up to 50 recent Coach chats and the 100 recent messages in each chat in a local database; older local items are removed automatically. You can reopen, rename, or delete retained chats. Vially does not keep a server-side Coach transcript.

Coach is enabled only with a paid Gemini API service. Under Google's paid-service terms, Google does not use prompts or responses to improve its products. Google states that prompts and responses are retained for 55 days for abuse monitoring, may be reviewed by authorized personnel when misuse is flagged, and may be processed in countries where Google or its agents maintain facilities. See Google's abuse-monitoring policy for details.

Vially's security service stores a pseudonymous App Attest installation record, challenges for up to two minutes, daily request counters, an idempotent deletion receipt, and a pseudonymous RevenueCat active-entitlement verdict keyed to a one-way HMAC-derived installation subject and cached for no more than five minutes. None of these records contains Coach questions, answers, or other health content. You can decline Coach and continue using the rest of Vially. You can delete individual local conversations, or revoke consent inside Coach to prevent future questions from being sent, delete all locally saved Coach conversations, and request deletion of Vially's server request counters. If the device is offline, Coach remains blocked while the signed deletion request is retried. The installation security record and deletion receipt remain for replay and abuse prevention. Revocation cannot erase copies already retained by Google for its stated abuse-monitoring period. Each generated Google Gemini response includes a Report response control that can open an editable report addressed to Vially support; the report is never sent automatically.

Subscription & Purchase Data

Vially uses RevenueCat to manage Pro subscriptions. RevenueCat receives:

  • A pseudonymous app user ID (not a Vially login and not your name or email address)
  • Device type, OS/platform version, App and RevenueCat SDK version, and first- and last-seen timestamps
  • Apple receipt and purchase transaction data when you buy or restore a subscription
  • Subscription status and entitlement information
  • A country code derived transiently from the request IP address; RevenueCat states that it drops the raw IP address after determining the country

Vially does not provide RevenueCat with your name, email address, advertising identifier, lab counts, lab content, or any other health-record content. All purchase processing is handled by Apple's App Store.

Apple Ads Measurement

App versions with Apple Ads measurement enabled send Apple's temporary AdServices attribution token to RevenueCat after subscription services initialize. RevenueCat asks Apple whether the installation is attributed to an Apple Ads campaign and associates the returned campaign, ad group, keyword, country or region, and attribution information with the existing pseudonymous subscription record. We use this information to measure subscription conversion and revenue from our App Store ads. This standard attribution does not use Apple's advertising identifier (IDFA), request App Tracking Transparency permission, or include your health records, Apple Health data, or contact details. It is separate from the optional PostHog usage analytics setting. Attribution records are held by RevenueCat with subscription records; contact us about access or deletion requests as described below.

Device & Usage Information

Optional PostHog usage analytics is disabled by default and requires a new, explicit opt-in during onboarding or under Settings > Privacy & Security. Consent previously given to Aptabase does not enable PostHog. Continuing without opting in sends no analytics, and locally recorded events from before consent are not uploaded later. This setting covers both onboarding and app feature use.

After opt-in, Vially sends an approved set of events to PostHog Cloud US through its US collection endpoint (us.i.posthog.com), with storage in the United States. Events include generic onboarding step progress and completion, paywall readiness, purchase attempts and outcomes, and feature interactions such as opening the catalogue, saving a lab result, or using the companion. Permitted properties describe the screen, feature, plan, navigation source, or coarse outcome. Event metadata includes the event time, App version, platform, development or production environment, a session ID, and a randomly generated installation ID stored on this device. The installation ID links visits from the same installation, so this is pseudonymous analytics rather than fully anonymous counts. The request also exposes an IP address and ordinary network metadata to the receiving service in transit. Vially disables IP-based geolocation enrichment and removes IP-address and default device-detail properties from event payloads.

Vially does not include your name, email, onboarding answers, medication choices, dose amounts, lab counts, lab template or panel identifiers, health values, result dates, notes, photos, Apple Health records, or text you enter in PostHog events. Generic events can still reveal use of health-related features. Vially does not join the analytics ID to RevenueCat customers, advertising identifiers, or an account identity. Session recordings, automatic screen or interaction capture, and automatic app-lifecycle capture are disabled; only the approved events described above are collected. Turning analytics off blocks future collection and removes the local analytics queue and identifiers. Deleting all Vially data also clears this local analytics state. If you opt in again, a new random installation ID is used; these actions do not delete events already received by PostHog.

Earlier Aptabase analytics: Older App versions may have sent opted-in events to Aptabase in Germany. Those events could include coarse health-feature categories such as lab marker-count ranges or selected educational panels, in addition to event, session, timestamp, locale, OS/version, App version/build, SDK version, User-Agent, and request IP. They excluded health-record contents and text entered. Aptabase used a per-App salt that rotated every 24 hours rather than a persistent installation ID. Its earlier retention and deletion terms remain relevant to events already sent; they do not describe the current PostHog integration.

The replacement Vially 1.3.1 build does not include the Meta SDK, request App Tracking Transparency permission, access the advertising identifier, or send onboarding, subscription, purchase, app-usage, or health events to Meta. Earlier prerelease builds may have sent limited campaign and SDK operational data to Meta only after a tester granted Apple's tracking permission. Any records already transmitted remain subject to Meta's retention and request processes.

Software Updates & API Security Infrastructure

The production App uses Expo EAS Update to check for and download compatible software updates. It contacts Expo whenever the App launches and sends the device OS/platform, App runtime and update-channel information, a randomized installation/update token used to determine whether an update was downloaded, and the IP address and ordinary network-request metadata inherent in the connection. EAS Update requests do not include Vially health records, Coach questions, lab reports, meal photos, or Apple Health data.

Vially's authenticated Coach API, and the AI Lab Scanner and AI Meal Scan APIs used only when those features are enabled, run on Cloudflare Workers. When you use one of those remote features, Cloudflare handles the applicable request and response content over TLS, together with IP addresses and ordinary routing and security metadata, to host, route, and protect the API. Vially's own Cloudflare application storage is limited to the pseudonymous App Attest installation record, short-lived challenges, request counters, deletion receipt, and pseudonymous RevenueCat active-entitlement verdict cached under a one-way HMAC-derived installation subject for no more than five minutes, as disclosed in this policy; Vially does not use Cloudflare to retain health or chat content, Coach transcripts, lab-report or meal-photo payloads, or Gemini responses.

To protect those APIs from unauthorized use, Vially uses Apple App Attest. When an App installation is first attested, the App contacts Apple so Apple can certify a per-install, hardware-backed key and process the associated device and app-integrity metrics and network metadata. The attestation request does not include Vially health records, Coach questions, lab reports, meal photos, or Apple Health data.

Support Communications & Coach Reports

If you choose Contact Us or Report response, Vially opens an email draft that you review before sending. If you send it, Cloudflare Email Routing forwards the complete message to Vially's destination support mailbox, and Vially support receives your sender email address and the text you include. A Coach report draft also includes the generated response, its response type, and a local response ID. It does not separately attach your question or saved health records, but a generated response may repeat information from the chat. Cloudflare's routing analytics can include the sender, recipient, subject, message ID, and processing decisions and may remain available for up to 31 days; this routing record is separate from the complete message forwarded in transit. We use support messages to respond, investigate safety or quality issues, prevent abuse, and meet legal obligations. Review the complete draft and remove any health or other sensitive information you do not want to share. Vially does not send support correspondence to Meta or Google Gemini.

Website

The Vially website (vially.app) is a static site delivered through Cloudflare. When you visit it, Cloudflare processes the IP address and ordinary request, routing, and security metadata needed to deliver and protect the site. Where Cloudflare Network Error Logging is enabled, your browser may also send Cloudflare limited network-error diagnostic metadata. Vially does not use cookies, analytics trackers, or any form of user tracking on the website.

Where & How We Store Your Data

Data Type Storage Location Protection
Health & medication data On-device (SQLite) iOS Data Protection; excluded from standard iOS backups beginning with Vially 1.2.8
App settings & preferences On-device (MMKV) iOS Data Protection
Sensitive credentials On-device (Keychain) iOS Keychain access controls and iOS Data Protection
Subscription, purchase, Apple Ads attribution, and SDK technical data RevenueCat servers Encrypted in transit & at rest; raw request IP dropped after country derivation
Software-update request metadata Expo EAS Update servers TLS in transit; no Vially health records
Pseudonymous App Attest installation record, short-lived challenges, request counters, deletion receipt, and RevenueCat active-entitlement verdict cached under a one-way HMAC-derived installation subject for no more than five minutes Vially API on Cloudflare Workers and Durable Objects TLS in transit; entitlement cache contains no health/chat content; no Coach transcript or lab/meal payload storage
Coach question and generated response; when conversation memory is enabled, up to 8 recent turns or 4,000 characters from this chat only (after initial consent and either confirmation for that send or a matching send type previously authorized on this device) Local App database; Vially server in transit; Google Gemini abuse-monitoring logs for 55 days iOS Data Protection locally; TLS in transit through Cloudflare Workers; no Vially server-side chat history
AI Lab Scanner report image or PDF and extracted candidate fields (only after per-report consent) Vially server in transit only; Google Gemini abuse-monitoring logs for up to 55 days TLS in transit through Cloudflare Workers; no Vially server retention
AI Meal Scan photo and nutrition estimate (after one-time revocable consent and a per-photo Estimate with AI action) Vially server in transit only; Google Gemini abuse-monitoring logs for up to 55 days TLS in transit through Cloudflare Workers; no Vially server retention; confirmed values saved locally
Optional usage events and random installation/session identifiers PostHog Cloud US, United States (only after fresh opt-in); local queued events and IDs on this device TLS in transit; disabled by default; random installation ID links visits until opt-out or data reset; remote retention and deletion are separate from local reset
Support email address and correspondence, including a Coach response only when you send a report draft; sender, recipient, subject, message ID, and routing decisions Cloudflare Email Routing in transit; Vially destination support mailbox User-reviewed email submission; Cloudflare routing analytics available for up to 31 days; support correspondence retained only as needed for support, safety review, abuse prevention, or legal obligations

Data Aurora Coach May Attach to Questions

After you explicitly consent to Aurora Coach, the App presents the first use of each disclosure combination before sending it through Vially's server to Google Gemini. The disclosure lists the question and any additional classes included. If you choose “Don't ask again for sends like this,” the App remembers that combination on this device, and later sends with the same data categories may proceed without another prompt. Aurora Coach can also send compact on-device summaries—not raw records—of your current stack, weight trend, side effects, and labs. Automatic use must be enabled in Settings; otherwise summaries attach only when you choose them. Aurora Coach selects relevant automatic summaries on device and does not attach photos or Apple Health data. Message chips show exactly which summary classes a send attempt included. Google Gemini may retain prompts and responses for up to 55 days for abuse prevention.

You can remove a manually selected class before sending, clear remembered send types under Settings > Privacy & Security, turn automatic data use or conversation memory off, or revoke Aurora Coach consent at any time. When no summary is authorized or remains available, Aurora Coach sends no Vially record summary. When conversation memory is off, prior chat messages stay on device. Revoking consent prevents future Coach sends and deletes locally saved Coach conversations.

How Long We Keep Your Data

Local health data persists while the App remains installed unless you delete it. Locally saved Coach conversations are retained within the disclosed cap of 50 recent chats and 100 recent messages per chat; older local items are removed automatically, and you can delete retained chats in the App or revoke Coach consent. Vially does not store a server-side Coach transcript, lab scan, or meal scan. Google states that paid Gemini requests and responses, including Coach, lab, and meal requests, may be retained for up to 55 days for abuse monitoring. Deleting the App does not automatically delete App Store purchase history, Apple App Attest records, RevenueCat subscription and technical records, Expo update-request metadata, Cloudflare security or network records, Cloudflare email-routing analytics available for up to 31 days, support correspondence in Vially's destination mailbox, opted-in PostHog events and historical Aptabase analytics events, Meta campaign and SDK operational records transmitted by an earlier prerelease build after tracking permission, a Vially iCloud or device-backup copy created by an earlier App version, or AI-provider records still within their stated retention period. Cloudflare's pseudonymous RevenueCat active-entitlement verdict cache contains no health or chat content and expires within five minutes. PostHog event retention is governed by the Vially project retention and deletion settings; opting out or removing the local analytics ID does not erase prior remote events. Contact us about retention, access, or deletion requests. Historical Aptabase events may be retained for up to five years under its earlier terms; Aptabase states that its daily-rotating, unlinked records cannot be mapped to an individual for deletion. Version 1.2.8 cannot inspect or delete an older Vially backup copy; use Apple Settings or Files as described below. RevenueCat records follow its data retention policy; RevenueCat's customer-profile documentation states that the raw request IP is dropped after a country is derived.

What Vially Does Not Do

Vially does not:

  • Operate an account system or a Vially server that stores your health records
  • Sell, rent, or trade health or medication data
  • Include the Meta SDK, access the advertising identifier, or send app, purchase, or health data to Meta
  • Send raw Vially health records, photos, or Apple Health data to Coach
  • Request location data

Who We Share Data With

We do not sell, rent, or trade any user data. The third-party services involved in the data handling described in this policy are:

Vially shares user data only with third-party services whose applicable terms, documented practices, and technical controls provide the same or equivalent protection for the shared data as this policy, including purpose limitation, data minimization, security safeguards, and the retention or deletion controls described here.

Service Purpose Data Shared
Apple (App Store and App Attest) App distribution and payment processing; app/device integrity verification for authenticated Vially API access Purchase transactions; for App Attest, per-install key-attestation and device/app-integrity metrics plus IP and network metadata; no Vially health records
Expo EAS Update Automatic software-update checks and delivery on App launch Device OS/platform, App runtime and update-channel information, randomized installation/update token, IP address, and ordinary network-request metadata; no Vially health records
Cloudflare Deliver and protect the static Vially website; host, route, and secure the authenticated Aurora Coach, lab-scan, and meal-scan APIs; route email sent to [email protected] to Vially's destination support mailbox For website visits: IP address, ordinary request/routing/security metadata, and limited browser network-error diagnostics where Cloudflare Network Error Logging is enabled. For App APIs: applicable request/response content over TLS, IP address, and network/security metadata; Vially's Cloudflare storage holds the disclosed pseudonymous security records and counters plus a pseudonymous RevenueCat active-entitlement verdict for no more than five minutes; the cache contains no health/chat content, and Cloudflare storage does not retain Coach transcripts or lab/meal payloads. For support email: the complete message in transit, plus routing analytics that can include sender, recipient, subject, message ID, and processing decisions and remain available for up to 31 days
RevenueCat Subscription management Pseudonymous app user ID (not a Vially login, name, or email address), device type and OS/platform version, App and SDK version, first/last-seen timestamps, Apple receipt and purchase data, subscription status and entitlement, and country derived from a transient request IP; no advertising identifier, lab counts, or health-record content
PostHog Optional onboarding and product usage measurement; PostHog Cloud US, United States; requires new explicit opt-in Approved step, feature, plan, navigation-source and outcome events; event time, App version, platform, development or production environment, random installation ID and session ID; request IP and ordinary network metadata in transit. No names, answers, health records or values, lab counts or panel IDs, text entered, RevenueCat IDs, advertising IDs, session recording, or autocapture. The random installation ID can link repeated visits
Aptabase (earlier App versions) Historical optional analytics in Germany; current versions no longer send Aptabase events Previously consented event and technical metadata, including the coarse health-feature categories described above; earlier daily-rotating identifier and retention terms apply only to those historical records
Google Gemini Generate an optional Coach response, extract a lab report, or estimate a meal after the applicable consent For Coach: after initial consent and either confirmation for that send or authorization of a matching send type on this device, the question text you explicitly send; when conversation memory is enabled, up to 8 recent turns or 4,000 characters from this chat only; plus compact on-device summaries of up to four classes (current stack, weight trend, side effects, labs) when you choose them for a question or enable automatic use in Settings. Automatic summaries are selected on device; message chips show attempted summary classes; consent and remembered send types are revocable in Settings. For AI Lab Scanner: the complete report image or PDF you explicitly accept for extraction and the resulting candidate fields. For AI Meal Scan: after revocable consent, the complete meal photo you deliberately submit by tapping Estimate with AI and the resulting nutrition estimate. These requests use encryption in transit and paid Gemini processing; Vially does not retain them, while Google may temporarily retain request data for up to 55 days for abuse monitoring under its paid-service terms.

Your Privacy Rights

You can manage your local Vially records from the App:

  • Access: Your local Vially records are visible in the App at any time.
  • Export: You can export your data from within the App.
  • Delete: Delete individual records in the App, or use Delete My Data to remove Vially health, tracking, lifestyle, reminder, and locally saved Coach data, AI Meal Scan consent, Vially-generated export files, and pending encrypted lab drafts and source copies from this device. Unrelated files are not removed. Deleting the App also removes its local data. Manage older iCloud or device-backup copies separately in Apple settings.
  • Apple Health: Manage Apple Health permissions and any data previously written to Apple Health in your device's Settings > Privacy & Security > Health and the Health app.
  • Aurora Coach: Reopen, rename, or delete individual local conversations. Clear remembered send types to require disclosure confirmation again. Declining or revoking Google Gemini consent blocks future sends; revocation also deletes all locally saved Coach conversations. Use Report response on a generated answer to open an editable report to Vially support; nothing is submitted automatically.
  • Support correspondence: Contact us to request access to or deletion of support emails and Coach reports, subject to legal, security, and abuse-prevention retention requirements.

If you are located in the EU, California, or another jurisdiction with data-protection rights, you may contact us about your request. Data held by Apple (including App Attest), RevenueCat, Expo, Cloudflare, PostHog, Aptabase, Meta, Google, or a provider used by an earlier App version may also be subject to those providers' request processes.

Usage analytics: Turn PostHog analytics off in Settings > Privacy & Security to stop future collection and erase local queued analytics and identifiers. Deleting all Vially data clears the same local state. Previously uploaded events are not automatically deleted by either action. Contact us to request access or deletion; because these records are not linked to your name or email, locating them may require the random analytics identifier from your installation. Resetting that identifier or deleting the App can prevent us from linking a request to earlier events. PostHog provides tools to delete people and their associated events; remote event deletion can take time. Historical Aptabase records remain subject to its earlier terms: Aptabase states that it cannot map or individually delete those records because its identifier rotated every 24 hours and was not linked back to a person.

iCloud Sync & Device Backup

Beginning with Vially 1.2.8, the former iCloud Sync feature is unavailable. Version 1.2.8 does not upload or restore Vially health records through that feature and marks its Vially health-storage directories as excluded from standard iOS backups. Because version 1.2.8 no longer has the iCloud container capability, it cannot inspect or programmatically delete an iCloud or device-backup copy created by an earlier version.

To remove an older Vially copy, open Apple Settings > your name > iCloud > Storage (or Manage Account Storage), find Vially, and choose Delete Data. Also check Files > iCloud Drive for a Vially folder and manage any older device backups through your Apple ID and iCloud storage controls. Apple may use slightly different labels depending on your iOS version.

Notifications

Dose reminders and notifications are scheduled locally on your device using iOS notification APIs. No notification data is sent to external servers.

Children's Privacy

Vially is intended only for adults aged 18 and older and is not directed to children. This age requirement applies to the App and its optional remote AI features, including Aurora Coach, AI Lab Scanner, and AI Meal Scan. We do not knowingly collect information from children. If you believe a child has used the App, please contact us.

International Data Transfers

Apple may process App Store, Apple Health, App Attest device/app-integrity, or older device-backup data. RevenueCat may process subscription, purchase, and SDK technical records in the United States or other countries. Expo may process software-update request metadata in the United States or other countries. Cloudflare is a global, U.S.-based infrastructure provider and may process the disclosed website-request and diagnostic metadata, App API request content, network/security metadata, support-email content in transit, and email-routing analytics in the United States, the EEA, or other locations through its network. PostHog Cloud US stores opted-in usage events in the United States. Its privacy policy and data-processing terms describe the provider and its subprocessors. Aptabase may retain events from earlier opted-in App versions in Germany. Meta may retain limited campaign and SDK operational records previously received from an earlier prerelease build, subject to Meta's privacy practices and applicable safeguards. When you explicitly use Coach, consent to AI Lab Scanner extraction, or consent to AI Meal Scan estimation, Google may process the disclosed question, complete lab report, or complete meal photo in countries where Google or its agents maintain facilities under its paid Gemini terms and applicable safeguards.

Changes to This Policy

We may update this policy to reflect changes in the App or legal requirements. Updates will be posted on this page with a revised effective date. Vially does not maintain a marketing mailing list, so we encourage you to review this page periodically.

Contact Us

If you have questions about this privacy policy, contact us at [email protected].

Vially Vially

Privacy-first medication and wellness tracking. Built for people who care about their health and their data.

Product

Features Screenshots FAQ Download

Legal

Privacy Policy Terms of Service

Connect

Instagram TikTok [email protected]

Vially is not a medical device and does not provide medical advice. Always consult your healthcare provider before making changes to your medication. © 2026 Vially. All rights reserved.

Privacy Terms