VAC is positioned as a fitness and wellness service, not as a medical service. Even so, heart, sleep, body-composition, injury and longitudinal fitness metrics or inferences can reveal physical or mental health and are treated as health and special-category data where applicable.
HealthKit authorization lets the app read selected types and does not authorize transmission to our systems. Under consent “health-local-receipt-v1-2026-07-20”, the app reads only and never writes to Apple Health. Raw or detailed Health signals and related body, dietary and up-to-six-month trend series are processed and retained on the device. The minimized receipts described below are separate projections and do not contain the raw Health fields.
The app keeps only on the device: primary and focus goals; sex, height and current weight used for local training; target weight and body-fat and muscle targets; training days, intensity and experience; manual body measurements and locally entered series; raw Apple Health samples and identifiers; manual workout rows with stable identifier, day and date, type, duration, optional load and calorie values, and explicit manual provenance; macro, hydration, micronutrient and pinned nutrition targets; meal rows with stable identifier, day, name and logging time, calorie, macro, water and per-nutrient values, source, optional recipe link and per-nutrient provenance, confidence and coverage; and day corrections with day, calorie, macro and water values and correction time; custom recipes and meal and recipe favourites and order; long-term goals; private notes, facts and user-authored coaching context; protected progress photos and minimal local metadata; and user-authored local state consumed by the deterministic coach.
For competitions, only a minimized workout receipt may leave the device: a one-way pseudonymous identifier, sport, Europe/Rome civil day, duration rounded down into 5-minute buckets and, when available, distance in 250-metre and energy in 25-kcal buckets. It contains no Health UUID, exact time, heart rate, power, cadence, zones or source. App Attest authenticates the app, device and request and limits replay, but does not certify HealthKit provenance or real-world performance. Manual workout entries stay on the device, are not posted to the workout API and award no IC or GAIN points. Opponents see only necessary competition values or an aggregate result. HealthKit data are not used for advertising or tracking.
For sleep-duration IC, the device may send only a submission of at most five receipts, one for each Europe/Rome wake day in the latest five days. Each receipt contains only the wake day and the sleep duration rounded down into 15-minute buckets, from 4 to 14 hours. The server awards 0 to 53 IC from duration alone. The receipt contains no Health identifier, source, exact time, stages, efficiency, midpoint, quality, consistency or other Health data. VAC does not keep it as a measurement, snapshot or dossier; it retains only the ledger entry needed for IC, with amount, reason, a sleep and day reference, account, team and week attribution and creation time. App Attest is mandatory, body-bound through dedicated headers, and limits unauthenticated requests and replay, but does not certify HealthKit provenance, real sleep or sleep quality.
The device keeps the local archive described above under complete file protection and marked for exclusion from system backups on iOS. Progress photos follow the same local protection. Local-only data do not transfer automatically to a new device and may be lost on uninstall, reinstall or device replacement. The only current Health projections reaching the backend are the minimized workout and sleep receipts described above. Backups created before this protection at the iOS system level may contain historical copies; withdrawal or deletion does not retroactively remove them.
The “.vacbackup” file is VAC's encrypted backup for restoring data to the device, not a generic data export. Once the archive has been verified and a complete trial restore has run, only the part that was held on the device is restored, and only for the same pseudonymous subject the backup is bound to; the part held on our servers is included as read-only and no restore can change it.
On the first authenticated sign-in, the app automatically brings back to this device only the data meant to live there: profile, primary and focus goals, body inputs and targets, training preferences, nutrition targets, meals and corrections, recipes and favourites, long-term goals, and the private context not derived from Health, namely the profile note, private notes and pinned facts. The app verifies the complete copy and saves it on the device before confirming the transfer; only a confirmation bound to the fingerprint of that copy authorizes deletion of the matching remote copy, and a copy that is incomplete or over the size limit is rejected rather than silently truncated. Once that confirmation exists, no other device can download the copy from the server again: receiving those data requires an encrypted, verified “.vacbackup” backup bound to the same subject. Earlier copies kept on our servers — data derived from Health, and manually entered workouts or body measurements outside the transfer — do not become the local reference and follow a separate retention or erasure path.