Data practices
Effective 2 October 2026 · Preview policy version 2026-10-02
Operator and launch status
Vitalo is in preparation for a public release. Legal business identity and registration details are being finalized before public accounts or purchases open. This website describes the preview and its intended data practices.
Privacy enquiries: privacy@vitalo.online.
Account access
Email, account identifiers and authentication records provide access and security. Google sign-in is optional; existing password accounts can link Google after confirming ownership. Google does not receive your health records through sign-in.
Records you choose to save
Profiles, report PDFs/photos, medical notes, measurements, plans, meals, workouts and diary entries are stored on the Vitalo service. This is off-device collection even though private fields are encrypted. Each user has a separate storage namespace. Profiles and reports are not posted publicly.
Optional connections and movement
Device readings stay on the phone until you select them for upload. Imported records include the source device label or Health Connect app name. GPS and steps are used during a session you start. Saving a route needs a separate choice. External maps send tile requests and network metadata to OpenFreeMap only after you enable them.
Messages, searches and technical support
Friend connections, shared content and moderation reports support the community features. Library searches are sent to return results. Support messages and optional diagnostics help resolve bugs. Automatic diagnostics are off initially and exclude medical content, exception messages and precise location.
AI is a separate choice
When enabled, a selected AI request sends report text or a question with health context through the server gateway to the connected AI service. Processing terms and retention must be finalized before public health use. No health information is sold or used for advertising.
Your controls
Use in-app export, individual-record deletion and account deletion. Google-only accounts confirm deletion with their linked Google account. You can also use the external deletion page. Permission revocation stops future access; delete existing imports separately. See the privacy policy for retention limitations and contact details.
Preview status
This page describes current app data flows. Public registration and purchases remain closed. It is not an independent security assessment or a claim of Google Play approval.