Security policy
Small attack surface. Clear boundaries.
VNTY avoids an account and developer workout backend, then relies on Apple's platform protections for app isolation, Health data access, Bluetooth permission, and paired-device transfer.
Last updated / July 13, 2026
Security at a glance
There is no VNTY password, remote account session, analytics pipeline, or developer-operated workout database to protect. The app keeps its compact records locally and requests Apple system access only for the features you choose.
Local-first architecture
Saved equipment, preferences, diagnostics, companion captures, and compact workout summaries are handled inside the VNTY app process or sandbox. VNTY has no custom cloud API or third-party analytics SDK.
Apple app isolation
iPhone and Apple Watch isolate VNTY from other apps through Apple's app sandbox and device security model. Keeping your devices updated and protected with a passcode is an important part of that model.
HealthKit boundary
Apple Health data is available to VNTY only for the types you authorize. VNTY uses HealthKit APIs to read or save supported workout data; it does not bypass Apple Health permissions or gain unrestricted access to the Health database.
Workout integrity
Fitness+ remains authoritative for its workout, heart rate, active calories, effort, and Ring credit. VNTY does not reopen, alter, or merge into a completed Fitness+ workout. Any eligible companion distance and speed samples are saved as separate Health records.
Direct Bluetooth connection
VNTY connects directly to supported equipment after Apple grants Bluetooth access. Saved peripheral identifiers are local to the app. You can forget equipment in VNTY or revoke Bluetooth access in device settings.
Paired-device transfer
Apple's WatchConnectivity framework carries live relay metrics and compact records between your paired Watch and iPhone. Transfers are bounded, acknowledged, and do not pass through a VNTY account server.
Bounded diagnostics
Bluetooth diagnostic data is kept in memory and capped to limit exposure. Reports are not uploaded automatically. Sharing occurs only after you invoke the system Share sheet and choose a destination; review the report and recipient before sending.
User-controlled permissions
Bluetooth, Health, and workout access are mediated by Apple. You can review Health access in Apple Health and system permissions in Settings. Revoking a permission can limit the related VNTY feature without creating a remote account to close.
Security limits
No software can remove every risk. Device compromise, outdated operating systems, untrusted diagnostic recipients, and the security of Apple or equipment-vendor services are outside VNTY's direct control. VNTY does not claim custom end-to-end encryption beyond Apple platform protections.
Report a security issue
If you believe you found a vulnerability affecting VNTY, contact Pantheon support with the app version, device and OS version, a concise description, and safe reproduction steps. Please do not include personal Health data or raw Bluetooth diagnostics unless they are necessary and you intentionally choose to share them.
Contact Support
Responsible reports are reviewed before public disclosure