vamo

Privacy Policy

Last updated: 14 September 2026

Vamo ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the Vamo mobile application and related services (the "App").

This policy applies to everyone who uses the App, wherever you are located. Vamo is operated from the United Kingdom, and we handle personal data in line with UK and EU data protection law (the UK GDPR and EU GDPR). Additional information for users in the United States, including California, is set out in section 14.

1. Who We Are

Vamo is a fitness, nutrition, and coaching application.

The data controller responsible for your personal data is Jack Robinson Contracting Ltd (“Vamo”, “we”, “us”, “our”), a company registered in England & Wales (company number 16969770), registered office 6 Vousden Grove, London, SE28 0PG, United Kingdom. We are registered with the UK Information Commissioner’s Office (ICO), registration reference ZC161358.

Contact email: support@vamo.fit

2. Data We Collect

We collect only the data necessary to provide and improve the App.

a) Information You Provide

  • Account information (such as your email address)
  • Profile information (such as your name and fitness goals)
  • Biometrics you enter during onboarding (age, sex, height, weight, and activity level)
  • Allergies and dietary preferences
  • Your pre-exercise screening answers and health declaration, injury notes and movement restrictions, and any condition you tell us about so we can adapt or withhold a programme
  • Workout, nutrition, hydration, and habit logs you record, and check-in entries you submit
  • Messages you send to a coach through the App

b) Health & Fitness Data

With your explicit permission, the App reads health and fitness data from Apple Health (HealthKit) on iOS and Android Health Connect on Android. Depending on the permissions you grant, this may include:

  • Steps and activity
  • Heart rate
  • Sleep
  • Calories (active and resting energy)
  • Workouts
  • Hydration / water intake
  • Body weight and body-fat percentage

The App also writes data back to Apple Health and Android Health Connect when you use certain features, for example logging water intake, completed workouts, and nutrition macros, so your records stay in sync across your health apps. You can turn this off at any time in your device health settings.

This data is not medical data, and Vamo is not a medical service, but under GDPR it is treated as special-category health data. We process it only with your explicit consent and solely to provide fitness, nutrition, and coaching functionality. Vamo does not access medical records, diagnoses, or clinical health data.

c) User Content

  • Profile pictures
  • Progress and check-in body photos you upload to track and share your progress

These images are stored in private AWS S3 storage and are not publicly accessible. Check-in photos are shared with a coach you have connected with (see section 7).

d) Automatically Collected Information

  • App usage data (features used, screens viewed)
  • Device information (device type, operating system, app version)
  • Log files and error/crash reports for debugging and performance monitoring

e) Identifiers

  • A device push notification token (used to deliver notifications)
  • Your Clerk user id (your account identifier)
  • An analytics identifier used to attribute product-usage events

f) Optional Third-Party Integrations

If you choose to connect Strava, the App can write your workouts back to your Strava account. This integration is optional, and you can disconnect it at any time.

The MyFitnessPal diary import is currently switched off. If you connected it before it was switched off, we still hold the MyFitnessPal username and, where you gave us one, the diary key you entered, on our servers. Neither is used while the feature is off, nothing further is fetched from MyFitnessPal, and both are removed when you delete your account (section 11) or on request to support@vamo.fit. Meals already imported from your diary stay in your nutrition log like any other entry, and are deleted with your account or on the same request.

3. How We Use Your Data

We use your data to:

  • Provide, operate, and maintain the App
  • Create and personalise fitness, nutrition, and coaching experiences
  • Sync health and fitness data with Apple Health and Android Health Connect
  • Enable coaching, messaging, and progress sharing between you and your coach
  • Send you notifications and transactional emails
  • Improve features, performance, and reliability
  • Provide customer support and respond to enquiries
  • Ensure security and prevent misuse of the App

We do not sell your personal or health data.

Automated personalisation and AI-generated guidance

Your training programmes and nutrition targets are generated automatically, by our own algorithms applied to the profile, goals, training history, screening answers and logged activity described above. The plain-English explanations, rationale and weekly review text that accompany them are written by a large language model hosted for us in the European Union by Amazon Web Services (Amazon Bedrock), which acts as our processor under contract.

  • The data sent to that model is limited to what is needed to explain your programme, such as your training and nutrition context. It is not used to train or improve any third-party model, and Bedrock does not retain it for its own purposes.
  • This processing supports a fitness service. It does not produce decisions with legal or similarly significant effects on you within the meaning of Article 22 of the UK and EU GDPR, and no automated decision is taken about your health, credit, employment or access to services.
  • You can change or ignore anything the App suggests, and you can ask us to review a generated programme by emailing support@vamo.fit. AI-generated text is general information, not medical advice: see our Terms & Conditions.

4. Analytics

We use PostHog for product analytics and crash/error reporting. PostHog is hosted in the European Union (EU data residency) and acts as our data processor under contract.

When you are signed in, analytics events are associated with your email address and a user id so we can understand how features are used and diagnose problems. We do not send the contents of your Apple Health or Android Health Connect data to PostHog: analytics records app-usage events (for example, that a workout was logged) and identity keys, never your underlying health measurements.

Analytics is consent-based. You choose whether to enable it when you first set up the App (the analytics-consent step during onboarding), and you can change your choice at any time from Profile → Account. Turning it off stops further analytics and crash reporting from your device.

5. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds:

  • Contractual necessity – to provide the App and its core features
  • Explicit consent – for processing health and fitness data, including data from Apple Health and Android Health Connect, and for product analytics
  • Legitimate interests – to secure, operate, and improve the App
  • Legal obligations – where required by law

You may withdraw consent for health integrations and analytics at any time through the App or the relevant platform.

6. Data Storage & Security

Your data is hosted on secure, industry-standard cloud infrastructure provided by Amazon Web Services (AWS). We apply appropriate technical and organisational measures, and access to personal data is restricted to authorised personnel and processors.

How your health data is encrypted

Health data is encrypted in transit and at rest using AES-256 with server-managed keys held in AWS Key Management Service (KMS). Health metrics receive an additional client-side AES-256-GCM encryption layer before they leave your device; however, the encryption key for that layer is generated and managed on our servers and protected by a KMS customer-managed key.

Because the keys are server-managed, this is not end-to-end encryption. Vamo's backend is able to decrypt your health data in order to provide features such as syncing, coaching, and progress tracking. Access to your decrypted health data is limited to:

  • You (the account owner)
  • A coach you explicitly choose to share with
  • Authorised Vamo staff and sub-processors, only as needed to operate and support the service

7. Coaches & Data Sharing

Vamo lets you connect with a coach. When you connect with a coach and choose to share your data, that coach can see:

  • The health and fitness data you opt to share with them
  • Your check-in photos
  • Your workout, nutrition, and hydration logs
  • Your progress and check-in entries
  • Messages you exchange with them in the App

Sharing is under your control and is revocable: you can stop sharing with a coach at any time, which withdraws their access going forward.

8. Service Providers & Sub-processors

Vamo does not sell your data. We share limited data with the trusted service providers below, who help us operate the App. Each acts as a data processor and is bound by contract and applicable data protection law (including GDPR) to protect your data and use it only on our instructions.

  • Amazon Web Services (AWS) – AppSync, DynamoDB, S3, and KMS, providing hosting, database, file storage, and encryption, and Amazon Bedrock (EU-hosted) for the AI-generated explanations described in section 3. AWS privacy notice
  • Clerk – account creation, sign-in, and session management. Clerk privacy policy
  • PostHog (EU-hosted) – product analytics and crash/error reporting, as described in section 4. PostHog privacy policy
  • Stripe – coach subscription payments. Vamo does not store your card details. Stripe privacy policy
  • Strava (only if you connect it) – writing your workouts back to Strava. Strava privacy policy
  • Expo – push notifications and over-the-air app updates. Expo privacy policy
  • Open Food Facts – the open food database behind barcode scanning and food search. When you scan a barcode, our servers send Open Food Facts the barcode number. When you search for a food by name, our servers send the text you typed and your device's country, so results match products sold near you. Nothing that identifies you is sent, and because the request comes from our servers, Open Food Facts does not see your device or IP address. Product photos, where shown, load onto your device from Open Food Facts directly. Open Food Facts privacy policy
  • Edamam – the recipe search service our built-in recipe library was built from. We used the Edamam Recipe Search API once, offline, to assemble the library. The App does not query Edamam while you use it, so your searches, logs and account details are never sent there. Recipe photos are served from Edamam's image hosting, so when you open a library recipe your device fetches that photo from Edamam in the same way it would any web image (your IP address and which photo was requested). Edamam privacy policy
  • Resend – sending transactional emails. Resend privacy policy
  • Apple and Google – sign-in identity providers when you use Sign in with Apple or Google. Apple also handles subscription billing for in-app purchases and sends us the transaction and renewal status we need to unlock your subscription. We never receive your card details. Apple privacy policy, Google privacy policy
  • MyFitnessPal (switched off) – the diary import described in section 2(f). While it is off, nothing is sent to or fetched from MyFitnessPal. MyFitnessPal privacy policy

9. Data Retention

We keep your personal and health data only for as long as it is needed:

  • Your account data and health data are retained while your account is active
  • When you delete your account, your account and associated data are deleted immediately (see section 11)
  • Data may be retained for longer only where required to meet a legal obligation
  • Routine encrypted backups are purged within 30 days

10. Your Rights

Subject to your location, you have the right to:

  • Access your personal data
  • Correct inaccurate or incomplete data
  • Request deletion of your data
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent at any time

You can also manage or revoke health data-sharing permissions directly through Apple Health or Android Health Connect on your device.

To exercise your rights, contact: support@vamo.fit

11. Account & Data Deletion

You can delete your account yourself, at any time, from within the App at Profile → Delete Account. Deletion is immediate and irreversible: there is no soft-delete or grace period.

Deleting your account permanently removes your account and its associated data, including:

  • Your account and profile
  • Your health data and health encryption keys
  • Workout, nutrition, hydration, and habit logs
  • Check-ins, photos, conversations, and messages
  • Coach connections and device push tokens
  • Connected-service credentials, including Strava tokens and any MyFitnessPal username and diary key

Coach accounts, which own clients, programmes, and billing, cannot be self-deleted in the App. Please contact support@vamo.fit and we will assist.

12. Apple Health & Android Health Connect Notice

Vamo reads from and writes to Apple Health (HealthKit) and Android Health Connect only with your explicit permission, and solely to provide fitness, nutrition, and coaching features.

  • We do not use this data for advertising
  • We do not sell this data
  • We do not share your health measurements with third parties for their own purposes
  • You can revoke access at any time via your device health settings

To be clear about the limited exceptions: health data you choose to share is visible to a coach you explicitly connect with (section 7), and our EU-hosted analytics provider may record that you used a health-related feature as app-usage metadata, but never the underlying Apple Health or Android Health Connect measurements. Vamo complies with all applicable platform policies relating to health and fitness data.

13. Age Requirement

Vamo is intended for adults. You must be at least 18 years old to create an account and use the App. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected such data, we will delete it.

14. International Users (including the United States & California)

The App is available worldwide, and this policy applies to all users. Vamo is based in the United Kingdom, so your data may be processed in the UK, the EU, and other locations where our sub-processors operate, with appropriate safeguards in place for international transfers.

If you are in the United States, including California, we do not sell your personal information, and you may request access to or deletion of your personal information as described in this policy. To make a request, contact support@vamo.fit.

15. Changes to This Policy

We may update this Privacy Policy from time to time. If changes are significant, we will notify you through the App.

16. Contact Us

If you have questions about this Privacy Policy or your data, contact:

📧 support@vamo.fit

Privacy PolicyTerms & Conditions

© 2026 Vamo. All rights reserved.