Information we collect
Account information. When you create a Vivy account, we collect your email address, display name, and authentication credentials managed by Firebase Authentication.
Health and protocol data. You voluntarily enter protocol details, dosage logs, biomarker measurements, and check-in data. This data is stored in Firestore under your authenticated user ID and is never sold.
Usage data. We collect anonymized, aggregated analytics about feature usage (screen views, session duration, tap events) using Firebase Analytics. No individual health events are included in analytics payloads.
Device information. Device model, operating system version, app version, and crash logs are collected through Firebase Crashlytics to improve stability.
Communications. If you contact us by email, we retain that correspondence to resolve your inquiry.
How we use your information
Service delivery. Your health and protocol data is used exclusively to provide the Vivy app experience — logging, tracking, AI-powered recommendations, and biomarker insights.
AI personalization. Hey Vivy's AI features use your stack, logs, biomarkers, and uploaded documents to surface contextual recommendations, parse documents, and generate insights. AI processing happens server-side in our Firebase Cloud Functions environment and is performed by a third-party AI processor — see "Third-party AI processor" below for full details and your controls.
We do not train third-party AI models on your health data. Our AI processor does not use the data we send through its API to train its foundation models. Separately, when Vivy's own AI needs to improve — for example, to get better at suggesting relevant content — we train only on aggregated or de-identified data that has been stripped of direct identifiers (like your name, email, and user ID) and combined with data from many other users so that no single person can be picked back out. If any of this ever changes, we will update this policy, notify you in the app, and give you a chance to opt out before the new use takes effect.
Safety and compliance. We may use your data to detect safety-relevant interactions or flag patterns that could represent a risk, as part of our health safety commitment.
Communication. With your consent, we may send product updates, protocol reminders, and educational content. You can opt out at any time.
Third-party AI processor
Provider and region. Hey Vivy's AI features — Chat, protocol parsing, DEXA/bloodwork parsing, the in-app copilot, and AI Insights — are powered by Google Cloud Vertex AI / Gemini in the us-central1 region. When you use an AI feature, relevant data is sent to Google Cloud Vertex AI / Gemini for processing and returned to the app.
What data is sent. Only data needed for the AI feature you are actively using is sent. This may include: your messages or conversation history; health profile safety fields (age, biological sex, conditions, medications, allergies); the protocols, logs, measurements, biomarkers, goals, check-ins, and inventory items relevant to your request; health metrics you have synced from Apple Health (for example resting heart rate, heart-rate variability, sleep, VO2 max, and body composition) where they form part of your measurements; and DEXA or blood-work files you have asked Hey Vivy to parse. Apple Health data is sent to the AI processor only with your explicit consent and only to provide the AI feature you requested — it is never used for advertising, sold, or shared for any other purpose. A full per-feature data-category breakdown is available in the app at Settings → Privacy Settings → AI Data Use, and matches the disclosure shown when you grant consent.
Your explicit in-app consent is required. Before any personal data is sent to Google Cloud Vertex AI / Gemini, Hey Vivy displays a clear in-app disclosure that names Google Cloud Vertex AI / Gemini, the us-central1 region, the data categories the feature will send, and the protections that apply. AI features will not call the third-party AI processor until you tap Allow & continue on that disclosure. You can revoke this consent at any time at Settings → Privacy Settings → AI Data Use; once revoked, AI features stop calling the processor immediately and stay paused until you allow again.
Protections at the third-party processor. Hey Vivy and Google Cloud are bound by a HIPAA Business Associate Agreement effective April 20, 2026 that governs how Google handles HIPAA-covered health data Hey Vivy sends through Vertex AI. Google's Vertex AI Generative AI data-processing terms confirm that data Hey Vivy submits through the Vertex AI API is not used to train Google's foundation models, is not used to develop or improve unrelated Google products, and is processed under privacy protections that are substantially equivalent to those described in this policy. Hey Vivy does not sell your personal data.
No third-party AI processing without consent. If you decline or revoke the in-app consent, Hey Vivy does not send your personal data to Google Cloud Vertex AI / Gemini for any AI-feature processing. Non-AI features of the app remain fully functional.
Training data (opt-in)
Default: off. We do not use your identifiable health data to train models. A separate, opt-in program lets you contribute a de-identified, aggregated version of your measurements to help Vivy's own AI get better over time. You turn it on from Settings → Privacy → "Help improve Vivy AI." You can turn it off at any time.
What we export (only if you opt in). HealthKit / Health Connect metrics (heart rate, steps, sleep, VO2Max, blood pressure, body composition, etc.) along with a small set of aggregate demographic attributes: biological sex, age bucketed into 5-year bins (with 90+ collapsed), weight bucketed into 5 kg bins, and body fat bucketed into 5-point bins. Your primary focus area is included as a category.
What we strip before anything leaves your account. Your name, email, phone number, profile photo, exact date of birth, device identifiers, timezone, and any free-text notes are removed. Exact dates are reduced to year only; we keep only day-of-week and hour-of-day as statistical features, which is consistent with HIPAA Safe Harbor § 164.514(b)(2)(i)(C).
How we identify the rows for your deletion requests. We replace your user ID with a SHA-256 hash salted with a secret only the backend knows. The hash is stable enough that if you later opt out, we can find and delete every row you contributed — but not stable enough to link you to anything else. Salts are rotated annually.
Your control and deletion rights. Opting out revokes consent, triggers an immediate delete of every row keyed to your participant hash, and clears your export cursor so a future re-opt-in starts clean. The deletion SLA is 30 days from revocation; in practice it completes within minutes. Deleting your account also deletes your training-corpus rows as part of the same flow.
How we use the training data. Only to train statistical models that power Vivy's AI suggestions, insights, and forecasts. Trained models never include raw user data — only parameters learned from aggregate patterns. We do not sell this data and we do not share it with advertisers.
AI companions and AI-assisted content
Disclosure. Vivy operates a set of branded accounts — collectively referred to as the "Vivy Team" — that post educational content, commentary, and replies inside the Vivy community and on external platforms (including X, LinkedIn, Instagram, Threads, and TikTok). Some or all content from these accounts is generated or assisted by artificial intelligence under human editorial review.
Where this is surfaced. Each Vivy Team profile carries a clear notice on its profile page, and a full directory of AI-assisted accounts is maintained at heyvivy.com/community/ai-companions. This disclosure is provided in accordance with California SB 1001 (bot disclosure), FTC Section 5 (deceptive practices guidance), and equivalent transparency obligations in other jurisdictions.
What these accounts may collect. If you reply to, DM, or otherwise interact with a Vivy Team account, your message content, username, and timestamp are processed so we can generate a response and improve safety filtering. This data is treated under the same protections as the rest of your account data.
Your choice. You are never required to interact with a Vivy Team account to use Vivy. You may block, mute, or ignore any such account at any time.
No impersonation of real people. Vivy Team personas do not represent real individuals, do not claim medical credentials they do not hold, and do not make individualized medical claims.
Data sharing and disclosure
We do not sell your data. Full stop.
Service providers. We work with Firebase (Google Cloud) as our infrastructure provider. Data processed by Firebase is governed by Google's applicable data processing terms and the safeguards configured for the services we use. Contractual coverage for regulated workflows depends on the applicable service configuration and completed agreements.
Legal requirements. We may disclose information if required by law, court order, or to protect the rights, property, or safety of Vivy, our users, or the public.
Business transfers. In the event of a merger or acquisition, user data may be transferred as part of that transaction. You will be notified in advance.
Data retention
We retain your account and health data for as long as your account is active. You may request deletion of your account and all associated data at any time through the app (Settings → Account → Delete Account) or by emailing support@heyvivy.com.
Deleted data is purged from our primary databases within 30 days and from backups within 90 days.
AI companion conversation logs. Messages exchanged with Vivy Team (AI-assisted) accounts — including replies, DMs, and community interactions — are retained for up to 90 days for safety review, abuse detection, and quality improvement, then automatically purged. Before any internal review, these logs are passed through an automated PII scrubber that redacts email addresses, phone numbers, physical addresses, and other direct identifiers.
Active-account, post-deletion, and moderation retention. While your account is active, we keep the personal health data you've entered so the app can show it back to you and generate your insights. If you delete your account, we remove your personal health data from our primary databases within thirty (30) days. De-identified, aggregated data — data that can no longer be linked back to you — may be kept indefinitely for product analytics and to improve Vivy's own models. Separately, posts or comments that have been flagged for moderation review are retained for up to ninety (90) days after the flag is resolved, so our moderation team can audit decisions, handle appeals, and detect patterns of abuse. After 90 days, flagged content is purged unless it is subject to a legal hold.
Audit and compliance logs. HIPAA-relevant audit entries are retained in a hot tier for 180 days and archived to a cold tier for six (6) years as required by 45 CFR §164.316(b)(2).
Security
All data is encrypted in transit (TLS 1.3) and at rest (AES-256 via Google Cloud). Firestore security rules enforce user-level read/write isolation — no user can access another user's data.
We maintain a security program informed by recognized control frameworks and conduct regular reviews. Contractual coverage for regulated workflows is evaluated alongside the services and configurations in use.
Your rights
Access. You can export all your data from Settings → Account → Export Data.
Correction. You can edit any data you've entered through the app.
Deletion. You can delete your account and all associated data at any time.
Portability. Exported data is provided in JSON format.
California residents (CCPA). You have the right to know what personal information we collect, to opt out of the sale of personal information (we don't sell it), and to non-discrimination for exercising your rights.
EEA/UK residents (GDPR). You have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing. To exercise any right, contact support@heyvivy.com.
Children's privacy
Vivy is not intended for users under the age of 18. We do not knowingly collect personal information from minors. If we become aware that a minor has provided personal information, we will delete it promptly.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top and notify you via in-app notification for material changes. Continued use of the app after changes constitutes acceptance of the updated policy.
Contact
For privacy inquiries, data requests, or to exercise your rights, contact our Privacy Team at support@heyvivy.com.