Privacy Policy
Vitalis Health, Inc. ("Vitalis", "we", "us") builds software that brings health and performance data into a single record. This policy explains what we collect, why we collect it, and the choices you have. It applies to vitalishealth.ai and to the Vitalis mobile and web applications (together, the "Services").
The short version
- We collect health data only with your explicit consent, and you can withdraw it.
- We use your health data to provide the Services to you.
- We do not sell your personal health data.
- We never use health data for advertising or marketing.
- Research is performed on de-identified data.
- You can request a copy of your data or ask us to delete it.
Information we collect
Information you give us. Account details such as your name and email address, and anything you send us in a support request.
Health and performance data you choose to connect. With your explicit consent, this may include data from wearable devices and health platforms — for example activity, heart rate, heart rate variability, and sleep — along with assessments you complete in the app and clinical information you or your care team choose to add.
Technical data. Device type, operating system version, app version, and diagnostic and crash information used to keep the Services working.
We do not knowingly collect information from children under 13.
Apple Health and HealthKit
Where the Vitalis app reads data from or writes data to Apple HealthKit, it does so only after you grant permission, and only for the categories you approve. You may change or revoke those permissions at any time in the Health app or in iOS Settings.
Consistent with Apple's requirements, we do not use HealthKit data for advertising, marketing, or other use-based data mining; we do not sell it; and we do not disclose it to third parties without your consent, except as required by law. HealthKit data is used solely to provide health and performance features to you.
How we use information
- To provide the Services and show you your own record and insights
- To generate the forecasts and analyses you have asked us for
- To respond to your support requests
- To maintain security, prevent abuse, and diagnose technical problems
- To improve the Services, using de-identified or aggregated data
- To comply with legal obligations
We do not use your personal health data for advertising, and we do not sell it.
Research and model development
Research and the development of our models are conducted on de-identified data, maintained separately from the identified record. De-identified data cannot reasonably be used to identify you, and we do not attempt to re-identify it. Where a study requires identified data, it is conducted only under a separate, specific consent.
When we share information
We share personal information only in these circumstances:
- With your direction or consent — for example, when you choose to share your record with a clinician, a coach, or another person or organization.
- With service providers who host and operate the Services on our behalf, under contracts that limit them to that purpose and require them to protect the data.
- For legal reasons — when required by law, legal process, or to protect the rights and safety of people using the Services.
- In a business transfer — if Vitalis is involved in a merger or acquisition, we will give notice before your information becomes subject to a different privacy policy.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
Organizational deployments
Where Vitalis is deployed through an organization, the scope of what that organization can see is defined by the agreement with it and disclosed to you before you enrol. Individual health data is not made visible to an organization except as you have been told and have consented to.
Security
We encrypt data in transit and at rest, restrict access to personnel who need it to operate the Services, and log administrative access. No system is perfectly secure, but protecting this data is a core engineering requirement rather than an afterthought.
Retention
We keep your information for as long as your account is active, and afterwards only as long as needed for the purposes described here or to meet a legal obligation. When you ask us to delete your data, we delete it from our production systems and from backups on our normal backup expiry cycle.
Your choices and rights
- Access and portability — request a copy of your data.
- Correction — ask us to correct information that is wrong.
- Deletion — ask us to delete your account and your data.
- Withdraw consent — disconnect a data source or revoke a permission at any time, without losing access to the rest of the Services.
- Objection and restriction — where applicable law provides these rights, you may exercise them.
To exercise any of these, email privacy@vitalishealth.ai with the subject line Data request. We will not discriminate against you for exercising a privacy right.
International users
The Services are operated in the United States, and information is processed there. If you use the Services from another country, you understand that your information will be transferred to and processed in the United States.
Changes to this policy
If we make a material change, we will update the date at the top of this page and, where the change materially affects how we handle your health data, give you notice in the app or by email before it takes effect.
Contact
Questions about this policy or about your data: privacy@vitalishealth.ai