VitalThread legal
VitalThread Privacy Policy
VitalThread is a product operated by Vital Intelligence Labs LLC. This policy explains how we handle information when you use the product.
Last updated: July 31, 2026
1. Data We Process
We process account and profile information; workouts, meals, body measurements, sleep, activity, heart and recovery data; connected provider records; and information you choose to upload such as progress photos, meal photos, lab results, and genome files. We also process beta access requests and questionnaire answers, communication preferences, chat messages, AI guidance, device/sync metadata, and limited technical logs needed to operate and secure the service.
2. Sources
Data comes from you, your VitalThread devices, and services you choose to connect, such as Google, Polar, Fitbit, WHOOP, Apple Health through HealthKit, or another authorized integration. Disconnecting a provider stops future provider access but does not automatically delete information already imported into VitalThread.
3. How We Use Data
We use data to provide tracking, synchronization, history and trends, provider imports, exports, AI-assisted features, support, security, reliability, beta administration, requested email communications, and product improvement. We do not sell personal data or use health data for third-party advertising.
4. AI and Authorized External Clients
When you use an AI feature, relevant information and attachments may be sent to the AI provider selected for that request. When you authorize an external client such as ChatGPT, it may read the user-scoped VitalThread information and submit changes allowed by the OAuth permissions you grant. The external client supplies the confirmation experience for consequential actions; VitalThread does not currently keep a separate approval record for every connector action. External clients do not receive raw sync tables, server logs, administrator data, genome artifacts, or private object-store credentials through the product connector API. The external provider's own terms and privacy policy also apply to data it receives.
5. Storage and Service Providers
Hosted data is stored in systems operated for VitalThread, including private Google Cloud compute, database, object-storage, backup, and secret-management resources. Google processes recipient addresses and message content through Gmail when we send account or beta email; replies go to our designated Gmail support mailbox. We disclose data to infrastructure, authentication, communication, connected-provider, and AI services only as needed to provide a feature, follow your authorization, secure the service, or comply with law.
6. Retention
User-authored health, nutrition, training, chat, and uploaded content is generally retained until you delete it or request account deletion. Short-lived authorization codes, expired sessions, operational jobs, AI telemetry, and sync delivery logs have bounded retention. Communication preferences, delivery status, suppression records, and provider event identifiers may be retained as needed to honor your choices, prevent unwanted delivery, and audit sends. Structured client diagnostics are retained in active storage for up to 14 days. Verified backups are currently retained for up to 90 days, so deleted information may remain in a restricted backup until that backup expires or is overwritten.
7. Security
We use HTTPS, user-scoped authorization, restricted cloud access, infrastructure encryption at rest, private object storage, verified backups, request limits, secret redaction, and audit records for sensitive mutations and support access. No system is completely risk-free, and the service is not currently offered as a HIPAA compliant service for covered entities or business associates.
While you are signed in, VitalThread automatically sends limited, structured operational diagnostics such as timestamps, event categories, error summaries, app version, platform, and a device identifier. Credentials and email addresses are redacted before queuing. Raw local app logs and support bundles are not automatically uploaded, and structured diagnostics are not intended to contain raw health records, meal or chat content, photos, lab/genome payloads, or provider responses. Authorized support administrators can review diagnostics for troubleshooting; each such access is recorded in the security audit log.
8. Your Controls
You can review and update information in the app, export available data and disconnect providers. Signed-in users can manage their identity, beta registration, platform and wearable answers, email choices, access status, and deletion controls at the account portal. They can delete only the beta registration while retaining the OAuth identity, or delete the entire account and associated hosted product data. Full account deletion is also available from Settings > Services & Settings > Server in the product. A deletion initiated in the app also clears VitalThread data on that device. Some security, legal, fraud-prevention, and backup records may be retained for a limited period. Because the mobile app is local-first, deleting hosted data does not erase copies already stored on your other devices; remove local app data separately on each device. You can also manually send pending structured diagnostics from the Logs view by choosing Send diagnostics now. Signed-in users can update optional email choices and leave the beta in Settings or the account portal. Preregistered users can withdraw or delete preregistration data through signed links included in beta email. Contact hello@vitallab.app if you cannot access your account or need help with an access or deletion request.
9. Children
VitalThread is not directed to children under 13. Do not create an account or upload a child's health information without the authority and consent required by applicable law.
10. Changes and Contact
We may update this policy as the product, providers, or legal requirements change. Material changes will be reflected by the date above. Questions can be sent to hello@vitallab.app.