Privacy Policy for Vionut

Effective and last updated: August 25, 2026

Vionut is operated by Maksim Geine, an individual developer resident in Kazakhstan (“Vionut”, “we”, “us”). This policy explains how the Vionut Android application and its supporting services process information.

Nutrition and health notice. Vionut is a wellness and nutrition diary, not a medical device or healthcare provider. Its calculations and AI output are informational estimates and are not diagnosis, treatment, or medical advice.

1. Information Vionut processes

Depending on the features you choose, Vionut may process:

2. Health Connect

With your explicit Android permission, Vionut reads only:

These values are used on-device to show activity and, if you enable the option, to adjust the displayed daily energy allowance. Health Connect values, dates, and data-origin package names are not uploaded to the Vionut Firestore backup and are not included in Firebase Analytics event payloads. You can revoke access in Android or Health Connect settings at any time. Vionut does not use Health Connect data for advertising or sale.

3. How information is used

4. AI processing

Vionut uses OpenAI models through Vionut-controlled Firebase Cloud Functions. Relevant minimized inputs may include a food photo or description, dietary restrictions, remaining nutrition targets, and evidence from your diary/profile. Direct account credentials and payment-card details are not intentionally sent to OpenAI. Server requests are configured not to store model responses for model-provider retention. AI output can be wrong; review food, quantities, and calculated nutrition before saving.

5. Cloud backup and reinstall behavior

Eligible profile, diary, settings, pantry, habits, reminders, and progress metadata are stored under your Firebase user ID. Diary totals are rebuilt from the saved meal entries during restore. Payment entitlement is never restored merely from the ordinary backup; it is checked with Google Play or RuStore.

Android system backup and device-to-device transfer are disabled for Vionut. After reinstall, cloud recovery requires signing in to the same recoverable account. “Continue without registration” creates an anonymous Firebase account; after uninstall or clearing app data, that anonymous identity cannot normally be recovered, so its cloud data cannot be reattached to the new guest session.

6. Service providers and disclosures

Vionut does not sell personal data and does not use advertising. Information may be processed by:

We may also disclose information when legally required or necessary to protect users, the service, or legal rights. Providers process data under their own terms and privacy practices. Data may be processed in Kazakhstan, the United States, the EEA, and other locations where these providers operate.

7. Legal bases

Where applicable, processing is based on performance of the service contract, your consent (including optional health/sensitive data and permissions), legitimate interests in security and reliability, and legal obligations. You may withdraw optional permissions or consent, but affected features may stop working.

8. Retention and deletion

Local data remains until you delete it, clear app data, sign out where a local wipe applies, or uninstall. Cloud account activity is touched when the app is used. Vionut’s automated retention policy targets deletion after 30 days of inactivity for anonymous guest accounts and after 90 days for recoverable registered/custom-provider accounts, subject to operational execution and lawful exceptions. Store transaction and accounting records may be retained as required by the store or law.

You can delete individual diary items and supported progress records in the app. The in-app “Delete account” action requests deletion of the Firebase Authentication account, the user’s Firestore namespace, and files under the user’s Firebase Storage path. Deleting the app does not cancel a subscription; cancel it in Google Play or RuStore.

9. Security

Vionut uses authenticated per-user database/storage rules, encrypted transport, server-side subscription verification, bounded server requests, and Android Play Integrity App Check in release builds where Play Integrity is available. No electronic service is completely secure.

10. Your choices and rights

Depending on your jurisdiction, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. You can edit profile and diary data in the app, revoke camera/notification/Health Connect permissions in Android settings, disable optional progress-photo cloud backup, and use in-app account deletion. To make a privacy request, contact marka@vionut.com. We may need to verify your identity.

11. Children

Vionut is not intended for children under 13, or the higher minimum digital-consent age required in the user’s jurisdiction, without appropriate parent or guardian authorization.

12. Changes and contact

Material changes may be announced in the app or on this page. Continued use after an effective update means you acknowledge the revised policy.

Operator: Maksim Geine, Ust-Kamenogorsk, Kazakhstan
Email: marka@vionut.com