Vita Privacy Policy

Last updated: [EFFECTIVE DATE]

This policy explains what data Vita collects, why we collect it, who touches it, and what you can do about it. We have tried to write it the way we would want to read it: plainly, completely, and without hiding anything in the fine print. If anything here is unclear, email us at hello@getvita.health and a human will answer.

The short version

  • You upload blood-test reports you already have. We store the original PDF and the results we extract from it. That is the most sensitive data we hold, and we treat it that way.
  • We never sell your data. Not now, not later, not in "anonymized" form, not to anyone.
  • We never use your health data for advertising or marketing. There are no ad networks, data brokers, or marketing trackers anywhere in Vita.
  • Your health risk scores are computed by a deterministic, versioned rules engine — not by an AI guessing. AI is used to read your PDF and to phrase explanations, and we tell you exactly what it sees.
  • Your uploaded PDFs and your Vita Intelligence chats are processed by OpenAI under API terms under which your data is not used to train their models (see section 5).
  • Apple Health syncing is optional. We store daily and hourly metric summaries plus workout summaries and bounded workout-associated signals. Precise routes, route-derived elevation, and GPS-derived speed are stored only if you separately turn on route sync. The only data Vita writes back to Apple Health is the weight and height you log in Vita.
  • Your data is encrypted in transit and at rest. It is not end-to-end encrypted — the systems and staff that run Vita can technically access it, and we restrict that access to operating the service.
  • You can delete individual lab reports, chat threads, journal entries, synced workout routes, and synced workout history in the app today. Full account deletion and data export are handled by emailing hello@getvita.health while we build self-serve tools.
  • We may create de-identified, aggregated data to improve Vita. We will never try to re-identify it, sell it, or use it for advertising.
  • Vita is for adults 18 and over, is free during the invite-only beta, and is not a healthcare provider or a medical device.

1.Who we are and how to reach us

In short: Vita is operated by [VITA HEALTH, INC.], and one email address reaches us for everything.

Vita is a consumer health app made by [VITA HEALTH, INC.], [REGISTERED ADDRESS]. It runs as a web app at getvita.health and as an iOS app.

Vita helps you understand blood-test results you already have. It is not a hospital, clinic, laboratory, or healthcare provider. It does not diagnose, treat, or screen for any condition, and it is not a medical device. We are not a healthcare provider, and the privacy laws that govern hospitals, clinics, and insurers generally do not apply to consumer apps like Vita — so we wrote this policy to be our binding commitment to you instead.

For anything related to privacy, your data, or this policy: hello@getvita.health. That address also handles support and legal questions. There is no phone tree and no separate "data protection portal" — email us and we will respond.

2.Our promises

In short: we never sell your data, never use your health data for advertising, never try to re-identify de-identified data, and use your health data only to run Vita for you.

  • We never sell your data. No buyer, no broker, no "partner," no exception.
  • We never use your health data for advertising or marketing. This includes anything from your lab reports, Apple Health, lifestyle answers, journal, or AI conversations. Apple's App Store rules for health apps say the same thing, and we treat them as a floor, not a ceiling: health data can never be used for advertising, marketing, or data mining, and can only be shared with others to help manage your health, with your permission.
  • We will never attempt to re-identify de-identified data, and we will require the same of anyone we share such data with.
  • Your health data is used to run Vita for you — parsing your reports, computing your scores, personalizing your actions, answering your questions — and to create the de-identified, aggregated statistics described in section 6. That is the whole list.

3.What we collect

In short: account basics, the lab reports you upload, optional Apple Health summaries and workouts, lifestyle answers, your AI conversations, and web analytics — each shown below with where it comes from.

TierWhat it includesSource
Account DataEmail, display name, avatar, nickname, and your sign-in method (password, email one-time code, or Google), plus the IP address and basic device details that come along with signing in. Waitlist emails. No phone numbers.You provide it / automatic during sign-in
Lab & Health DataThe original PDF you upload; details extracted from it, which can include your name, patient ID, date of birth, sex, lab name, and report and collection dates; parsed results with values, units, reference ranges, sample type (blood, urine, and so on), and raw text lines; your corrections with edit history (the original value is kept); technical parsing details (AI model ID, token counts). Also manual logs: blood pressure, weight, and height.You upload it / you enter it
Body ProfileHeight, weight, BMI, date of birth or age, biological sex, unit preferences.You enter it, or Apple Health
Apple Health Data (iOS only, optional)Heart, activity, body, sleep, and vitals metrics stored as daily and hourly summaries; workout summaries and bounded associated signals; and, only with separate permission, simplified outdoor routes plus route-derived elevation and speed.Your device, with your permission
Lifestyle & Self-Reported DataFamily history, conditions, habits, practical constraints, goals, and journal answers — full list below.You tell us
AI Conversation DataFull text of your Vita Intelligence messages and the assistant's replies, AI-generated thread titles, a per-message snapshot of which screen, biomarker, or report you asked from, and tool-call summaries that can contain lab-derived content.You write it / generated as you chat
Device & Usage Data (web only)Product analytics identified with your user ID, email, and name; events such as "report uploaded," "onboarding step completed," and "AI message sent"; error and exception capture; technical logs with personal details stripped out. The iOS app currently contains no analytics or crash-reporting SDK at all.Automatic
Derived DataRisk-score snapshots per report, risk levels, how confident each score is and how complete the underlying data was, per-marker contribution breakdowns, personalized action recommendations with the reasoning behind their ranking.Computed by us from the above

The full Apple Health list. With your permission, Vita reads: date of birth, biological sex, heart rate, heart-rate variability, resting heart rate, heart-rate recovery, VO2 max, steps, walking/running distance, flights climbed, exercise time, stand hours, active and basal energy, weight, height, BMI, body-fat percentage, lean body mass, waist circumference, blood pressure, blood glucose, blood-oxygen saturation, respiratory rate, body temperature, dietary energy, dietary water, sleep analysis including sleep stages, mindful minutes, workouts, and available workout-associated speed, power, cadence, stride, vertical-oscillation, ground-contact, and stroke samples. Metric samples are stored as daily and hourly summaries. Workout records store the activity, start and end times, duration, source, available summary statistics, and bounded display-quality signal series. Full-resolution samples stay in Apple Health. Outdoor routes, route-derived elevation, and GPS-derived speed are stored only after you separately turn on route cloud sync. One thing flows the other way: if you log weight or height manually in Vita, we write those two values back to Apple Health. Nothing else is ever written to Apple Health.

The full lifestyle list. Family history (early heart disease, diabetes, hypertension, kidney disease, gout); conditions you tell us about (hypertension, diabetes or prediabetes, kidney disease or stones, fatty liver, heart disease or stroke); smoking status; alcohol pattern; diet patterns (sugary drinks, fried food, processed meat, salt, late-night eating, high-purine foods, and similar); produce intake; hydration; practical constraints (budget, cooking confidence, food access, gym access, schedule); and your top health goal and top barrier. We do not collect a medication list. The journal adds multiple-choice answers to fixed daily prompts about sleep, diet, alcohol, smoking, exercise, and hydration; action check-ins (yes/no, a barrier reason, and an optional free-text note); and weekly reviews.

One thing worth calling out: a lab PDF is a document your lab produced, and it often contains identifying details we did not ask for. When you upload it, we receive those too. They stay inside your report data and are covered by everything in this policy.

4.How we use your data

In short: to run Vita for you — parse your reports, compute your scores with a deterministic rules engine, personalize your actions, answer your questions, and keep the service working.

Purpose by purpose:

  • Parsing your reports. We use AI to read your uploaded PDF and extract the biomarker results, so you do not have to type them in. You can review and correct anything it got wrong.
  • Computing your scores. Your risk scores across the four domains — heart, metabolic, kidney, and gout — are computed by a deterministic, versioned rules engine. Given the same inputs, it produces the same outputs, every time, and we can show you exactly which marker contributed what. No AI model decides your score. AI reads documents and phrases explanations; the math is rules, and the rules are versioned so a score can always be reproduced.
  • Personalizing your recommendations. Your body profile, lifestyle answers, and lab results feed the engine that ranks lifestyle actions for you, including the trace of why each action ranked where it did.
  • Showing your workout history. We sync workout summaries and bounded associated signals so you can review sessions and charts across Vita. If you separately enable route cloud sync, we also store a simplified route, route-derived elevation, and GPS-derived speed so they can appear on the web.
  • Powering Vita Intelligence. When you ask the assistant a question, it may look up your latest labs, biomarkers, risk scores, recommended actions, lifestyle profile, body profile, and Apple Health metrics to answer usefully. Section 5 covers exactly where that data goes.
  • Running the service. Authentication, storing your data, syncing with Apple Health, sending sign-in emails, and fixing bugs.
  • Understanding usage (web only). Analytics events tell us which features are used and where errors happen, so we can improve the product. The content of your health data and chats is not part of this — see section 8.
  • Improving Vita over time. Through de-identified, aggregated data as described in section 6 — never through your identified health data.

We do not use your data to build advertising profiles, and we have no advertising to profile you for.

5.AI processing

In short: your PDFs and chat conversations go to OpenAI, which does not use them to train its models under the API terms we use; an optional iOS mode keeps AI processing entirely on your phone; analytics never receive chat content.

Here is precisely what AI systems see:

  • Lab PDF extraction. When you upload a report, the full PDF is sent to OpenAI (currently the gpt-5.4-mini model; the specific model changes over time as we adopt newer ones) in two passes — one to extract the results, one to review the extraction. The PDF passes through Vercel's AI Gateway — a relay service — on its way there.
  • Vita Intelligence chat. Your messages, the conversation history, and whatever health context the assistant looks up to answer you — latest labs, biomarkers, risk scores, recommended actions, lifestyle profile, body profile, Apple Health metrics — are sent to OpenAI to generate the response. Thread titles are auto-generated the same way.
  • On-device mode (iOS). On iOS you can choose an optional on-device AI mode. When you do, that processing happens on your phone using Apple's on-device models, and the content is not sent to Vita's servers or to OpenAI.

What happens to this data at OpenAI: under the API terms we use, OpenAI does not use this data to train its models, and deletes it after a limited abuse-monitoring period of roughly 30 days. To be precise about the promise we can make: our AI providers do not use your data to train their models under the terms we use them on. We cannot promise what any AI company will do forever, but we can promise that if those terms ever changed in a way that affected you, we would tell you before continuing (see section 14).

Two more guarantees:

  • The content of your AI conversations — prompts and responses — is never sent to our analytics. Analytics sees only the event that a message was sent.
  • When you delete a lab report, we also scrub the AI chat content that was derived from it.

6.De-identified and aggregated data

In short: we may create data with your identity removed to improve Vita's scoring and product; we will never re-identify it, sell it, or use it for advertising, and it may survive account deletion.

We may create de-identified, aggregated data from usage of Vita — data with names, emails, IDs, and other identifiers removed so it cannot reasonably be linked back to you — to improve Vita's scoring and product. There is no toggle for this today: de-identification happens as part of how Vita improves, and we are telling you here rather than behind a settings switch. If that ever changes, this section will change first.

A concrete example of what this looks like: "among users with elevated LDL cholesterol who chose the 'reduce fried food' action, 40% showed improvement at their next upload." That statistic helps us learn which recommendations actually work — and nothing in it points back to any individual person.

Our commitments for this data:

  • We will never attempt to re-identify it, and we will hold anyone we share it with to the same standard.
  • We will never sell it.
  • We will never use it for advertising.

One thing to be clear about: because de-identified data is no longer connected to you, it may be retained after you delete your account. Deleting your account removes your identified data; the anonymous statistics it once contributed to may remain.

7.Who we share data with

In short: only the service providers below, each under contract, each for a stated purpose — no advertisers, no data brokers, no resellers, ever.

Vita runs on a small set of vendors. Each processes data only to provide its service to us, under contract:

VendorWhat they doWhat they receive
Clerk (US)Authentication, account management, sign-in emails, waitlistEmail, name, avatar, credentials, sign-in IP/device details, waitlist emails
Convex Cloud (US, on AWS; SOC 2)Primary database and file storageEffectively everything described in section 3
Vercel (SOC 2, ISO 27001)Web hosting, API routes, analytics proxy, AI GatewayWeb traffic; uploaded PDFs pass through its AI Gateway en route to OpenAI
OpenAI (US)Lab PDF extraction, Vita Intelligence responses, thread titlingUploaded PDFs; chat messages plus looked-up health context (see section 5)
PostHog (US cloud)Web analytics and error trackingUsage events tied to user ID, email, and name; errors; technical logs with personal details stripped out — never chat or health content
OpenFreeMap / Cloudflare CDNWeb map tiles and cartography for workout routesMap requests include your browser IP address, browser details, and the geographic map area requested. OpenFreeMap says it does not routinely store IP addresses, but may temporarily log them during security incidents. Vita renders the route line in your browser and does not upload it to OpenFreeMap.
AppleApple Health integration; optional on-device AIHealth data flows from your device with your permission; weight and height you log in Vita flow back to Apple Health; on-device AI content stays on your phone
Expo / EASiOS app builds and updatesDevice and app metadata only — no health data
GoogleSign-in, only if you choose itThe name and email Google shares when you choose "Sign in with Google"
unpkg.com (CDN)Serves the in-browser PDF-viewer scriptYour IP address and browser user-agent — never PDF content

(SOC 2 and ISO 27001 are independent security audits.)

That is the complete list. There is no payments processor (Vita is free), no push-notification service, no email-marketing platform, no ad network, and no data broker.

Legal compulsion. If a court order, subpoena, or law requires us to disclose data, we will comply only to the extent legally required, we will push back on requests that are overbroad, and we will tell you about the request unless the law bars us from doing so.

If Vita is ever acquired or merges, your data would transfer with the company only under commitments at least as protective as this policy, and you would be notified before anything changed.

8.Cookies and analytics

In short: the web app uses PostHog for identified product analytics with no ad trackers; the iOS app currently has no analytics at all.

On the web app, we use PostHog for product analytics and error tracking. It is identified — events are tied to your user ID, email, and name — because we need to understand real user journeys to fix real problems. Events include things like "report uploaded," "onboarding step completed," and "AI message sent." The content of your health data and AI conversations is never included. Workout screens are excluded from session-replay capture, workout IDs are removed from recorded URLs, and OpenFreeMap requests are excluded from network capture.

PostHog sets cookies and local-storage entries in your browser to make this work. There is currently no cookie banner on the site, because there are no advertising or cross-site trackers to consent to — the only cookies are the operational analytics ones described here. You can block or clear them with your browser's standard controls, and Vita will keep working. If we ever add anything that genuinely requires consent, a banner will arrive before it does.

The iOS app currently contains no analytics or crash-reporting SDK of any kind. If that changes, we will update this policy first.

9.Security

In short: encrypted in transit and at rest, access-controlled — but not end-to-end encrypted, and we will not pretend otherwise.

Your data is encrypted in transit (TLS) and at rest on our infrastructure. Access is restricted to you and to the systems and staff needed to operate the service, and our core infrastructure vendors maintain independent security certifications where noted in the table in section 7.

Here is the honest limit: Vita is not end-to-end encrypted. Claims like "only you can ever see your data" are simply not true of a service like ours — our staff and the service providers listed above can technically access data when operating the service, and we limit that access to what running Vita requires. We would rather tell you the real security model than a comforting fiction.

If a breach affects your personal data, we will notify you promptly, consistent with applicable law, and tell you what happened, what data was involved, and what we are doing about it.

10.Retention and deletion

In short: we keep your data while your account is active; reports, chats, journal entries, synced workout routes, and synced workout history can be deleted in-app today; account deletion and export work by email while we build self-serve tools.

We retain your data for as long as your account is active, because Vita's core value — tracking how your health markers change over time — depends on history.

What you can delete in the app today:

  • Individual lab reports — this deletes the stored PDF, the parsed results, and scrubs AI chat content derived from that report.
  • AI chat threads.
  • Journal entries.
  • Synced workout routes — this removes precise route data, route-derived elevation, and GPS-derived speed while retaining workout summaries and other associated signals.
  • Synced workout history — this removes workout summaries, signals, and routes from Vita and turns off workout sync. It does not delete anything from Apple Health.

What requires an email today: full account deletion and a complete export of your data. Self-serve tools for both are being built; until they ship, email hello@getvita.health and we will fulfill your request. (In-app, you can already download the original document of any report you uploaded.)

When your account is deleted, your identified data is removed from our systems, with two exceptions: de-identified data as described in section 6, and short-lived copies in backups and vendor retention windows that clear automatically — OpenAI's abuse-monitoring copies, for example, within roughly 30 days.

If you joined the waitlist and never created an account, one email to hello@getvita.health takes you off it.

11.Your rights

In short: everyone gets the same strong rights, regardless of where they live — one email, thirty days, always free.

Privacy laws differ by country, but we do not tier your rights by geography. Wherever you live, you have the right to:

  • Access the personal data we hold about you.
  • Correct anything that is inaccurate (much of this you can do directly in the app).
  • Delete your data.
  • Export a copy of your data in a usable format.
  • Object to, or withdraw consent for, a particular use of your data.
  • Complain to the data-protection authority where you live. We would appreciate the chance to fix things first, but the right is yours either way.

To exercise any of these, email hello@getvita.health. We will respond within 30 days, and exercising your rights is always free. We may need to verify that a request really comes from you before acting on it — that protection exists for your benefit.

12.Where your data lives

In short: US cloud infrastructure, under contract, and we remain responsible for it wherever it is processed.

Vita's infrastructure and the vendors listed in section 7 are US-based cloud services. If you use Vita from outside the United States, your data will be transferred to and processed in the US. Every vendor processes it under a contract that binds them to protections consistent with this policy, and we remain responsible for your data wherever it is processed — a vendor's involvement never dilutes the promises made here.

13.Children

In short: Vita is for adults 18 and over.

Vita is not intended for anyone under 18, and we do not knowingly collect data from minors. Blood-test interpretation for children and teenagers involves different reference ranges and different stakes, and Vita is not built for it. If you believe a minor has created an account, email hello@getvita.health and we will delete it.

14.Beta status and changes to this policy

In short: Vita is a free, invite-only beta; material changes to this policy are announced by email before they take effect.

Vita is currently in an invite-only beta and is free. There are no payments, no subscriptions, and no auto-charges anywhere in the product. If we introduce paid features, you will get advance notice by email — nothing will ever start charging you silently.

Beta also means the product changes quickly. When those changes affect your privacy, this policy changes with them. For material changes — new data types, new vendors, new uses — we will email you before the change takes effect, not after. Every version of this policy is dated, and prior versions are available on request.

15.Contact

In short: one address, read by a human.

Questions, requests, concerns, corrections — for anything in this policy:

hello@getvita.health

[VITA HEALTH, INC.]

[REGISTERED ADDRESS]

A real person reads that inbox. If you think we have fallen short of anything written here, tell us — we take that more seriously than anything else in this document.