Last updated 17 September 2026
Every network call Vitals can make, what it sends, and what it does not. This is the full list, counted from the code, not a summary.
POST to our server, which forwards to Anthropic's Claude API.
Sends the description you typed and any photos you attached. Also used when you
describe a prepped batch.
POST to our server, then Claude. Sends the photo of the label.
POST to our server, then Claude. Sends the photo of the bottle or
label.
POST to our server, then Claude. Runs automatically after a meal
is analysed. Sends the names and serving sizes of the foods in that meal, and
nothing else about you.
POST to our server, then Claude. Sends the claim you typed and
the abstracts fetched in call 7.
GET https://world.openfoodfacts.org/api/v2/product/<barcode>.json,
falling back to the us.openfoodfacts.org and
world.openfoodfacts.net hosts if the first does not know the
product. Sends the barcode digits and the user agent string
Vitals/1.0 (personal iOS app). It carries no device identifier and
no subscription.
GET https://www.ebi.ac.uk/europepmc/webservices/rest/search.
Sends the search terms and the same user agent string. No device identifier and
no subscription.
There is no separate call. The Apple-signed receipt for your subscription
travels as a header, x-vitals-entitlement, on calls 1 to 5, so the
server can confirm you are entitled and count your monthly AI actions. Apple's
own StoreKit talks to the App Store for the purchase itself, which is Apple, not
us, and we never see your card or your Apple Account.
POST to /api/attribution on our server. After a
purchase, the app sends our server the App Store's signed receipt once, so we
can count which offer, if any, was used. We keep the subscription identifier,
the offer name, the product and the date. No name, no email. The record is kept
while the app is on sale.
The Privacy Policy covers storage, retention and deletion. This page covers the wire.
Pricing, plainly · What works in airplane mode · Terms