Security

Last updated: 18 June 2026

VitaSync brings your health, fitness, money, and mind into one place. That only works if you trust us with sensitive data, so we treat security as a core feature, not an afterthought. This page explains how we protect your information. It will evolve as we move from waitlist to launch.

1. Encryption

All data is encrypted in transit using TLS, and encrypted at rest by our infrastructure providers. End-to-end encryption for your most sensitive health and financial data is on our roadmap.

2. Where your data lives

We host with established providers operating certified data centres. Data is processed only by the vetted service providers listed on our sub-processors page, each under a data processing agreement.

3. Access controls

Access to systems holding personal data is restricted to people who need it, protected by strong authentication, and logged. We follow the principle of least privilege internally.

4. Data minimisation

Every metric in VitaSync is optional, and we collect only what is needed to provide the service. We do not sell, rent, or share your personal data with third parties for marketing, and we do not show ads. See our Privacy Policy for full detail.

5. Your controls

You can export all your data as CSV at any time, and delete your account and associated personal data whenever you choose.

6. Responsible disclosure

If you believe you have found a security vulnerability, please email us at security@vitasync.io. We welcome reports and will work with you to verify and resolve genuine issues. Please give us a reasonable opportunity to fix an issue before any public disclosure.

7. Contact

For general security or data-protection questions, contact us at hello@vitasync.io.