03 Privacy boundary
The boundary is the product.
VECTAC does not operate a centralised private health or workout-history repository. Private fitness data stays on the device, or moves directly into Apple Health or Health Connect after explicit permission.
01
On the participant's device
Default. No account required.
- Goals, active plan, workout history
- Body-composition inputs and perceived effort
- Recovery check-ins and readiness answers
- Camera and depth frames — held in memory, never written
02
Apple Health or Health Connect
Only after explicit, per-type OS permission.
- The workout the participant chose to export
- Its measurement and verification metadata
- Read scopes requested separately from write scopes
- Revocable at any time from the platform, not from VECTAC
03
Authorised organisation dashboard
Only what the participant published or a proctor attested.
- Roster identity and event state
- Proctor attestations and correction reasons
- Aggregate estimator events during a live session
- Organisation-scoped audit records
04
Never crosses the boundary
No permission, tier or organisation policy unlocks this.
- Raw camera frames, depth maps and face geometry
- Private workout history and health profiles
- Precise routes and location traces
- Anything sent to a general-purpose AI endpoint
Web application boundary This website and the organisation workspace never request Apple Health or Health Connect permissions — those are device permissions, granted on a phone, to the phone. The web product is deliberately not a viewer for private participant fitness histories.
Coaching stays on device Plan adaptation and coaching run on the participant's device. No goals, health details, workout history, readiness answers or identifiers are sent to a general-purpose model endpoint.