Vigor Privacy Policy

Effective July 29, 2026 · Last updated July 29, 2026

Vigor does not collect your data. The app has no account system, no servers, and makes no network requests. Everything you create — habits, check-ins, notes, photos, tags, and settings — is stored only on your device. We have no way to see it, and no way to recover it if you lose your device.

Who we are

Vigor is developed by Juan Montoya (“we”, “us”). You can reach us at tq7u9sct7@mozmail.com.

What we collect

Nothing. We do not collect, transmit, sell, or share any personal data.

Vigor contains no analytics SDK, no crash-reporting SDK, no advertising SDK, and no attribution or tracking framework. The app does not create a user identifier, does not read your advertising identifier, and does not perform tracking as defined by Apple’s App Tracking Transparency rules.

What stays on your device

The following is created by you and saved locally in the app’s private storage:

This data is written to your device’s local app storage and, on iOS and Android, is included in device backups you have enabled through Apple or Google. Those backups are governed by Apple’s and Google’s own privacy policies, not ours. We have no access to them.

Device permissions we ask for

Vigor requests permissions only when a feature needs them, and each one is optional.

PermissionWhyWhat leaves your device
Photo library To attach an image to a note Nothing. The selected image is copied into the app’s local storage.
Face ID / Touch ID / fingerprint To lock the app behind your device biometrics Nothing. Your biometric data is handled entirely by the operating system’s secure hardware and is never exposed to Vigor. The app only receives a pass/fail result.
Notifications To show habit reminders you schedule Nothing. Reminders are scheduled locally on the device. Vigor uses no push notification service and generates no push token.

Vigor does not request access to your camera, microphone, location, contacts, calendar, or health records.

If you decline or later revoke a permission in your device settings, the rest of the app continues to work; only the related feature is unavailable.

Network use

Vigor is built to work fully offline and makes no requests to any server we operate. The app checks whether a network connection exists, purely to adjust its own behavior on your device; that check does not send any data anywhere. Over-the-air update delivery is disabled in the released app.

If you tap a link that opens a website or another app, you leave Vigor and the privacy policy of that destination applies.

Your control over your data

Because your data never leaves your device, you hold it directly:

We cannot access, export, correct, or restore your data on your behalf, because we never receive it.

Legal rights (GDPR, UK GDPR, CCPA/CPRA and similar laws)

Rights such as access, correction, deletion, portability, and opting out of sale or sharing apply to personal data held by a company. We hold none. We do not sell or share personal information, and we do not process personal data for advertising, profiling, or automated decision-making. Requests of this kind are satisfied by the in-app controls described above; if you want written confirmation that we hold no data about you, email tq7u9sct7@mozmail.com and we will confirm.

Children

Vigor is not directed to children under 13 (or the equivalent minimum age where you live) and we do not knowingly collect personal information from anyone. Because no data is collected at all, no information about a child can reach us.

Security

Your content is stored in the app’s private storage area, protected by your operating system’s app sandbox and by device-level encryption when you have a passcode set. You can add an extra layer by enabling the biometric app lock in Vigor’s settings. No system is perfect, and data on a lost, unlocked, or compromised device may be readable by whoever holds it — a device passcode plus the in-app lock is the strongest protection available here.

Changes to this policy

If a future version of Vigor adds a feature that transmits data — for example optional cloud sync or crash reporting — we will update this policy, change the effective date, and describe the change before or when that feature ships. Continued use after an update means you accept the revised policy.

Contact

Questions about this policy: tq7u9sct7@mozmail.com