Version 1.3 — Effective: 5 May 2026
Vitadatum is developed by Spookwerk, a sole proprietorship (eenmanszaak) registered in the Netherlands (Chamber of Commerce / KvK number 42035025, registered office: De Nieuwe Erven 3, Unit 14531, 5431 NV Cuijk, Netherlands). The data controller under the GDPR is Spookwerk, reachable at privacy@spookwerk.app. Spookwerk has not appointed a Data Protection Officer; this is not required under Article 37 GDPR for our processing activities.
This policy explains how the app handles your data. The short version: your data stays on your device. Spookwerk does not access, cannot access, and will not access your data. Spookwerk does not share your data with any third party. Apple processes in-app purchases via StoreKit; you alone choose whether to save export files to a cloud storage provider.
Vitadatum does not collect, transmit, or store any personal data on external servers. The app contains no analytics, no tracking, no telemetry, no advertising, no crash reporting, and no network calls. It does not collect device identifiers, usage data, or any other information. It does not require an internet connection or a user account.
The app reads health data from Apple HealthKit with your explicit permission. It can access up to 187 data types across 14 categories: Activity & Fitness, Mobility, Running, Cycling, Heart, Respiratory, Body Measurements, Vitals & Lab, Nutrition, Sleep, Hearing & Environment, Reproductive Health, Symptoms, and Workouts. This includes sensitive data such as electrocardiogram (ECG) recordings with voltage waveforms.
The app is read-only — it never writes, modifies, or deletes any data in Apple Health.
This data is processed entirely on your device to generate export files (JSON and CSV). Specifically:
Your health data is never used for advertising, marketing, data mining, or any purpose other than generating the export files you requested. This complies with Apple's HealthKit guidelines.
Granting HealthKit access is required for the app to perform its core function. If you do not grant permission, the app cannot generate exports. You choose which specific data types to share in the iOS Health authorization dialog; restricting certain categories simply narrows the scope of what the app can export. There is no contractual obligation to use the app, and no consequences beyond reduced functionality.
Health data is classified as a special category of personal data under the EU General Data Protection Regulation (GDPR). The lawful basis for processing your health data is your explicit consent (Article 9(2)(a)), which you provide through the iOS Health authorization dialog. No data is processed until you grant this permission.
All exported data is stored locally on your device by default, in compliance with Apple's guidelines for health data.
If you choose a cloud-based export folder such as iCloud Drive, Dropbox, Google Drive, or another provider accessible through the iOS Files app, your exported files are written to that location at your direction. Spookwerk does not initiate, intermediate, or control this transfer — it happens locally between your device and the provider you chose. When data is transferred to such a provider, that provider becomes the data controller for the data it holds, under its own terms and privacy policy. Some providers store data outside the European Economic Area; Spookwerk has no commercial relationship with these providers and provides no Standard Contractual Clauses or adequacy guarantees for those transfers. If international transfer matters to you, choose a storage location that meets your requirements (for example, a local folder on your device, or iCloud with a region you are comfortable with).
You are in full control of your exported files. You can view, share, or delete them at any time through the iOS Files app. Uninstalling Vitadatum removes all app data from your device, including export history and settings. Exported files in a custom folder you selected are not affected by uninstallation.
Exported files remain on your device (or in your chosen export folder) until you delete them. There is no automatic expiration or scheduled deletion. Spookwerk retains no copy of any data — all data exists solely on your device and under your control.
You have full control over your data:
Under the GDPR, you also have the following rights:
Vitadatum offers a one-time in-app purchase to unlock premium features. Purchases are processed entirely by Apple through StoreKit and require an internet connection. Spookwerk does not receive or store any payment information.
The app uses no third-party SDKs, libraries, or services. All functionality is built using Apple's native frameworks. There is no server-side component — Spookwerk operates no servers and no backend for this app.
Vitadatum does not perform automated decision-making or profiling of any kind as defined in Article 22 of the GDPR. The app does not score, categorize, evaluate, or make decisions about you based on your data. It generates the export files you requested — nothing else.
Vitadatum is a general-audience tool, not directed at children. Under Article 8 of the EU GDPR (and Article 5 of the Dutch UAVG), processing of a child's personal data based on consent requires authorization from a parent or legal guardian where the child is under the age set by Member State law — in the Netherlands, this age is 16. If you are under 16 and based in the EU, please do not use the app without the involvement of a parent or legal guardian.
The app does not provide medical advice, diagnosis, or treatment recommendations. The exported data reflects what is stored in Apple Health and should not be used as a substitute for professional medical judgment. Exported values reflect device sensor measurements, which have inherent accuracy limitations. Young users in particular should consult a parent or healthcare professional before interpreting health data.
If this policy changes, the updated version will be posted here with a new effective date and version number. Material changes will be noted in the app's update notes. If we ever process your data for a purpose other than what is described in this policy, we will provide notice and obtain new consent where required.
Questions about this privacy policy can be directed to privacy@spookwerk.app.
Spookwerk (eenmanszaak) · KvK 42035025 · De Nieuwe Erven 3, Unit 14531, 5431 NV Cuijk, Netherlands.