Vita Privacy Policy
Last updated: [EFFECTIVE DATE]
This policy explains what data Vita collects, why we collect it, who touches it, and what you can do about it. We have tried to write it the way we would want to read it: plainly, completely, and without hiding anything in the fine print. If anything here is unclear, email us at hello@getvita.health and a human will answer.
The short version
- You upload blood-test reports you already have. We store the original PDF and the results we extract from it. That is the most sensitive data we hold, and we treat it that way.
- We never sell your data. Not now, not later, not in "anonymized" form, not to anyone.
- We never use your health data for advertising or marketing. There are no ad networks, data brokers, or marketing trackers anywhere in Vita.
- Your health risk scores are computed by a deterministic, versioned rules engine — not by an AI guessing. AI is used to read your PDF and to phrase explanations, and we tell you exactly what it sees.
- Your uploaded PDFs and your Vita Intelligence chats are processed by OpenAI under API terms under which your data is not used to train their models (see section 5).
- Apple Health syncing is optional. We store daily and hourly metric summaries plus workout summaries and bounded workout-associated signals. Precise routes, route-derived elevation, and GPS-derived speed are stored only if you separately turn on route sync. The only data Vita writes back to Apple Health is the weight and height you log in Vita.
- Your data is encrypted in transit and at rest. It is not end-to-end encrypted — the systems and staff that run Vita can technically access it, and we restrict that access to operating the service.
- You can delete individual lab reports, chat threads, journal entries, synced workout routes, and synced workout history in the app today. Full account deletion and data export are handled by emailing hello@getvita.health while we build self-serve tools.
- We may create de-identified, aggregated data to improve Vita. We will never try to re-identify it, sell it, or use it for advertising.
- Vita is for adults 18 and over, is free during the invite-only beta, and is not a healthcare provider or a medical device.
1.Who we are and how to reach us
In short: Vita is operated by [VITA HEALTH, INC.], and one email address reaches us for everything.
Vita is a consumer health app made by [VITA HEALTH, INC.], [REGISTERED ADDRESS]. It runs as a web app at getvita.health and as an iOS app.
Vita helps you understand blood-test results you already have. It is not a hospital, clinic, laboratory, or healthcare provider. It does not diagnose, treat, or screen for any condition, and it is not a medical device. We are not a healthcare provider, and the privacy laws that govern hospitals, clinics, and insurers generally do not apply to consumer apps like Vita — so we wrote this policy to be our binding commitment to you instead.
For anything related to privacy, your data, or this policy: hello@getvita.health. That address also handles support and legal questions. There is no phone tree and no separate "data protection portal" — email us and we will respond.
2.Our promises
In short: we never sell your data, never use your health data for advertising, never try to re-identify de-identified data, and use your health data only to run Vita for you.
- We never sell your data. No buyer, no broker, no "partner," no exception.
- We never use your health data for advertising or marketing. This includes anything from your lab reports, Apple Health, lifestyle answers, journal, or AI conversations. Apple's App Store rules for health apps say the same thing, and we treat them as a floor, not a ceiling: health data can never be used for advertising, marketing, or data mining, and can only be shared with others to help manage your health, with your permission.
- We will never attempt to re-identify de-identified data, and we will require the same of anyone we share such data with.
- Your health data is used to run Vita for you — parsing your reports, computing your scores, personalizing your actions, answering your questions — and to create the de-identified, aggregated statistics described in section 6. That is the whole list.
3.What we collect
In short: account basics, the lab reports you upload, optional Apple Health summaries and workouts, lifestyle answers, your AI conversations, and web analytics — each shown below with where it comes from.
| Tier | What it includes | Source |
|---|---|---|
| Account Data | Email, display name, avatar, nickname, and your sign-in method (password, email one-time code, or Google), plus the IP address and basic device details that come along with signing in. Waitlist emails. No phone numbers. | You provide it / automatic during sign-in |
| Lab & Health Data | The original PDF you upload; details extracted from it, which can include your name, patient ID, date of birth, sex, lab name, and report and collection dates; parsed results with values, units, reference ranges, sample type (blood, urine, and so on), and raw text lines; your corrections with edit history (the original value is kept); technical parsing details (AI model ID, token counts). Also manual logs: blood pressure, weight, and height. | You upload it / you enter it |
| Body Profile | Height, weight, BMI, date of birth or age, biological sex, unit preferences. | You enter it, or Apple Health |
| Apple Health Data (iOS only, optional) | Heart, activity, body, sleep, and vitals metrics stored as daily and hourly summaries; workout summaries and bounded associated signals; and, only with separate permission, simplified outdoor routes plus route-derived elevation and speed. | Your device, with your permission |
| Lifestyle & Self-Reported Data | Family history, conditions, habits, practical constraints, goals, and journal answers — full list below. | You tell us |
| AI Conversation Data | Full text of your Vita Intelligence messages and the assistant's replies, AI-generated thread titles, a per-message snapshot of which screen, biomarker, or report you asked from, and tool-call summaries that can contain lab-derived content. | You write it / generated as you chat |
| Device & Usage Data (web only) | Product analytics identified with your user ID, email, and name; events such as "report uploaded," "onboarding step completed," and "AI message sent"; error and exception capture; technical logs with personal details stripped out. The iOS app currently contains no analytics or crash-reporting SDK at all. | Automatic |
| Derived Data | Risk-score snapshots per report, risk levels, how confident each score is and how complete the underlying data was, per-marker contribution breakdowns, personalized action recommendations with the reasoning behind their ranking. | Computed by us from the above |
The full Apple Health list. With your permission, Vita reads: date of birth, biological sex, heart rate, heart-rate variability, resting heart rate, heart-rate recovery, VO2 max, steps, walking/running distance, flights climbed, exercise time, stand hours, active and basal energy, weight, height, BMI, body-fat percentage, lean body mass, waist circumference, blood pressure, blood glucose, blood-oxygen saturation, respiratory rate, body temperature, dietary energy, dietary water, sleep analysis including sleep stages, mindful minutes, workouts, and available workout-associated speed, power, cadence, stride, vertical-oscillation, ground-contact, and stroke samples. Metric samples are stored as daily and hourly summaries. Workout records store the activity, start and end times, duration, source, available summary statistics, and bounded display-quality signal series. Full-resolution samples stay in Apple Health. Outdoor routes, route-derived elevation, and GPS-derived speed are stored only after you separately turn on route cloud sync. One thing flows the other way: if you log weight or height manually in Vita, we write those two values back to Apple Health. Nothing else is ever written to Apple Health.
The full lifestyle list. Family history (early heart disease, diabetes, hypertension, kidney disease, gout); conditions you tell us about (hypertension, diabetes or prediabetes, kidney disease or stones, fatty liver, heart disease or stroke); smoking status; alcohol pattern; diet patterns (sugary drinks, fried food, processed meat, salt, late-night eating, high-purine foods, and similar); produce intake; hydration; practical constraints (budget, cooking confidence, food access, gym access, schedule); and your top health goal and top barrier. We do not collect a medication list. The journal adds multiple-choice answers to fixed daily prompts about sleep, diet, alcohol, smoking, exercise, and hydration; action check-ins (yes/no, a barrier reason, and an optional free-text note); and weekly reviews.
One thing worth calling out: a lab PDF is a document your lab produced, and it often contains identifying details we did not ask for. When you upload it, we receive those too. They stay inside your report data and are covered by everything in this policy.
4.How we use your data
In short: to run Vita for you — parse your reports, compute your scores with a deterministic rules engine, personalize your actions, answer your questions, and keep the service working.
Purpose by purpose:
- Parsing your reports. We use AI to read your uploaded PDF and extract the biomarker results, so you do not have to type them in. You can review and correct anything it got wrong.
- Computing your scores. Your risk scores across the four domains — heart, metabolic, kidney, and gout — are computed by a deterministic, versioned rules engine. Given the same inputs, it produces the same outputs, every time, and we can show you exactly which marker contributed what. No AI model decides your score. AI reads documents and phrases explanations; the math is rules, and the rules are versioned so a score can always be reproduced.
- Personalizing your recommendations. Your body profile, lifestyle answers, and lab results feed the engine that ranks lifestyle actions for you, including the trace of why each action ranked where it did.
- Showing your workout history. We sync workout summaries and bounded associated signals so you can review sessions and charts across Vita. If you separately enable route cloud sync, we also store a simplified route, route-derived elevation, and GPS-derived speed so they can appear on the web.
- Powering Vita Intelligence. When you ask the assistant a question, it may look up your latest labs, biomarkers, risk scores, recommended actions, lifestyle profile, body profile, and Apple Health metrics to answer usefully. Section 5 covers exactly where that data goes.
- Running the service. Authentication, storing your data, syncing with Apple Health, sending sign-in emails, and fixing bugs.
- Understanding usage (web only). Analytics events tell us which features are used and where errors happen, so we can improve the product. The content of your health data and chats is not part of this — see section 8.
- Improving Vita over time. Through de-identified, aggregated data as described in section 6 — never through your identified health data.
We do not use your data to build advertising profiles, and we have no advertising to profile you for.
5.AI processing
In short: your PDFs and chat conversations go to OpenAI, which does not use them to train its models under the API terms we use; an optional iOS mode keeps AI processing entirely on your phone; analytics never receive chat content.
Here is precisely what AI systems see:
- Lab PDF extraction. When you upload a report, the full PDF is sent to OpenAI (currently the gpt-5.4-mini model; the specific model changes over time as we adopt newer ones) in two passes — one to extract the results, one to review the extraction. The PDF passes through Vercel's AI Gateway — a relay service — on its way there.
- Vita Intelligence chat. Your messages, the conversation history, and whatever health context the assistant looks up to answer you — latest labs, biomarkers, risk scores, recommended actions, lifestyle profile, body profile, Apple Health metrics — are sent to OpenAI to generate the response. Thread titles are auto-generated the same way.
- On-device mode (iOS). On iOS you can choose an optional on-device AI mode. When you do, that processing happens on your phone using Apple's on-device models, and the content is not sent to Vita's servers or to OpenAI.
What happens to this data at OpenAI: under the API terms we use, OpenAI does not use this data to train its models, and deletes it after a limited abuse-monitoring period of roughly 30 days. To be precise about the promise we can make: our AI providers do not use your data to train their models under the terms we use them on. We cannot promise what any AI company will do forever, but we can promise that if those terms ever changed in a way that affected you, we would tell you before continuing (see section 14).
Two more guarantees:
- The content of your AI conversations — prompts and responses — is never sent to our analytics. Analytics sees only the event that a message was sent.
- When you delete a lab report, we also scrub the AI chat content that was derived from it.
6.De-identified and aggregated data
In short: we may create data with your identity removed to improve Vita's scoring and product; we will never re-identify it, sell it, or use it for advertising, and it may survive account deletion.
We may create de-identified, aggregated data from usage of Vita — data with names, emails, IDs, and other identifiers removed so it cannot reasonably be linked back to you — to improve Vita's scoring and product. There is no toggle for this today: de-identification happens as part of how Vita improves, and we are telling you here rather than behind a settings switch. If that ever changes, this section will change first.
A concrete example of what this looks like: "among users with elevated LDL cholesterol who chose the 'reduce fried food' action, 40% showed improvement at their next upload." That statistic helps us learn which recommendations actually work — and nothing in it points back to any individual person.
Our commitments for this data:
- We will never attempt to re-identify it, and we will hold anyone we share it with to the same standard.
- We will never sell it.
- We will never use it for advertising.
One thing to be clear about: because de-identified data is no longer connected to you, it may be retained after you delete your account. Deleting your account removes your identified data; the anonymous statistics it once contributed to may remain.
9.Security
In short: encrypted in transit and at rest, access-controlled — but not end-to-end encrypted, and we will not pretend otherwise.
Your data is encrypted in transit (TLS) and at rest on our infrastructure. Access is restricted to you and to the systems and staff needed to operate the service, and our core infrastructure vendors maintain independent security certifications where noted in the table in section 7.
Here is the honest limit: Vita is not end-to-end encrypted. Claims like "only you can ever see your data" are simply not true of a service like ours — our staff and the service providers listed above can technically access data when operating the service, and we limit that access to what running Vita requires. We would rather tell you the real security model than a comforting fiction.
If a breach affects your personal data, we will notify you promptly, consistent with applicable law, and tell you what happened, what data was involved, and what we are doing about it.
10.Retention and deletion
In short: we keep your data while your account is active; reports, chats, journal entries, synced workout routes, and synced workout history can be deleted in-app today; account deletion and export work by email while we build self-serve tools.
We retain your data for as long as your account is active, because Vita's core value — tracking how your health markers change over time — depends on history.
What you can delete in the app today:
- Individual lab reports — this deletes the stored PDF, the parsed results, and scrubs AI chat content derived from that report.
- AI chat threads.
- Journal entries.
- Synced workout routes — this removes precise route data, route-derived elevation, and GPS-derived speed while retaining workout summaries and other associated signals.
- Synced workout history — this removes workout summaries, signals, and routes from Vita and turns off workout sync. It does not delete anything from Apple Health.
What requires an email today: full account deletion and a complete export of your data. Self-serve tools for both are being built; until they ship, email hello@getvita.health and we will fulfill your request. (In-app, you can already download the original document of any report you uploaded.)
When your account is deleted, your identified data is removed from our systems, with two exceptions: de-identified data as described in section 6, and short-lived copies in backups and vendor retention windows that clear automatically — OpenAI's abuse-monitoring copies, for example, within roughly 30 days.
If you joined the waitlist and never created an account, one email to hello@getvita.health takes you off it.
11.Your rights
In short: everyone gets the same strong rights, regardless of where they live — one email, thirty days, always free.
Privacy laws differ by country, but we do not tier your rights by geography. Wherever you live, you have the right to:
- Access the personal data we hold about you.
- Correct anything that is inaccurate (much of this you can do directly in the app).
- Delete your data.
- Export a copy of your data in a usable format.
- Object to, or withdraw consent for, a particular use of your data.
- Complain to the data-protection authority where you live. We would appreciate the chance to fix things first, but the right is yours either way.
To exercise any of these, email hello@getvita.health. We will respond within 30 days, and exercising your rights is always free. We may need to verify that a request really comes from you before acting on it — that protection exists for your benefit.
12.Where your data lives
In short: US cloud infrastructure, under contract, and we remain responsible for it wherever it is processed.
Vita's infrastructure and the vendors listed in section 7 are US-based cloud services. If you use Vita from outside the United States, your data will be transferred to and processed in the US. Every vendor processes it under a contract that binds them to protections consistent with this policy, and we remain responsible for your data wherever it is processed — a vendor's involvement never dilutes the promises made here.
13.Children
In short: Vita is for adults 18 and over.
Vita is not intended for anyone under 18, and we do not knowingly collect data from minors. Blood-test interpretation for children and teenagers involves different reference ranges and different stakes, and Vita is not built for it. If you believe a minor has created an account, email hello@getvita.health and we will delete it.
14.Beta status and changes to this policy
In short: Vita is a free, invite-only beta; material changes to this policy are announced by email before they take effect.
Vita is currently in an invite-only beta and is free. There are no payments, no subscriptions, and no auto-charges anywhere in the product. If we introduce paid features, you will get advance notice by email — nothing will ever start charging you silently.
Beta also means the product changes quickly. When those changes affect your privacy, this policy changes with them. For material changes — new data types, new vendors, new uses — we will email you before the change takes effect, not after. Every version of this policy is dated, and prior versions are available on request.
15.Contact
In short: one address, read by a human.
Questions, requests, concerns, corrections — for anything in this policy:
hello@getvita.health
[VITA HEALTH, INC.]
[REGISTERED ADDRESS]
A real person reads that inbox. If you think we have fallen short of anything written here, tell us — we take that more seriously than anything else in this document.