Vitalo
VITALO POLICIES

Privacy policy

Effective 1 October 2026 · Preview policy version 2026-10-01

Operator and launch status

Vitalo is in preparation for a public release. Legal business identity and registration details are being finalized before public accounts or purchases open. This website describes the preview and its intended data practices.

Privacy enquiries: privacy@vitalo.online.

What this policy covers

This policy covers vitalo.online and the Vitalo Android preview. The website is public information and administrator access; public health-account registration remains closed. The app is intended for adults aged 18 or older. We do not knowingly invite children to submit health records.

Data and purposes

When account services open, account email, credentials, consent and recovery information support secure access. Profile details, report files, reviewed results, medical notes, meal/workout plans, diary entries and imported health measurements support the features you choose. Optional saved routes can contain precise location.

Support requests include what you submit and limited technical metadata. Do not send blood reports or other medical records by ordinary email. The website does not use advertising trackers or Google Analytics.

AI and your consent

AI processing is a separate action. Selected extracted report text, or a coach question with the relevant profile, saved history and reviewed records, is sent to the configured AI provider through a server gateway. Free text may contain names and sensitive information. Public-user AI processing is not enabled until provider terms and retention are finalized. Do not rely on AI for diagnosis, medication or emergency decisions.

Health Connect, Bluetooth and location

Read-only health permissions are requested for relevant features. Review device imports before choosing what to save. A location session starts on your action and stops with the Stop control; route saving is a separate choice. If you load external map tiles, the map provider can receive your IP address and the map area requested. Permissions can be revoked in Android settings.

Storage and access

Login information is held in a dedicated identity database. Each health account has a separate PostgreSQL namespace and account-specific derived encryption key. This is logical separation, not a separate physical server per person or end-to-end encryption. Authorized service operators can access data where necessary to run or support the service. Access must be limited and audited.

Transport uses HTTPS. Passwords are salted and hashed. Authenticator secrets and private records are encrypted at rest. Public illustrations may be served from a CDN; private reports are not placed in public image storage.

Sharing and processors

A friend connection does not grant access to private records. Each share sends a selected copy to the recipient, who may retain it. Hosting, email, map and any configured AI providers process information needed for their services. Provider processing locations, retention and contractual details will be finalized before public health-account launch. Health data is not sold or used for advertising targeting.

Optional diagnostics

Automatic technical reporting is off by default. If enabled, it includes app version, Android API level, error class and up to 30 application code locations. It excludes exception messages, health records, chats, GPS, screenshots, passwords, tokens and device identifiers. The encrypted phone queue holds at most 20 reports and clears when you disable reporting or sign out.

Manual descriptions are submitted with consent. Active issue records expire after 90 days or earlier when removed by the user or through account deletion. The operator may respond inside the app.

Retention and deletion

Active health records are kept until you remove them or delete your account. Account deletion revokes sessions and removes the account’s active private storage and related shares. Recipients may keep copies they already received. Completed AI processing cannot always be recalled.

This website currently keeps administrator authentication and configuration records. Expired sign-in challenges and sessions are purged. The public health service will not open until backup retention, restore deletion handling and processor retention are documented. Privacy requests sent by email are retained only as needed to resolve the request and meet applicable obligations.

Request deletion or see the in-app steps.

Cookies and choices

The public information pages use no advertising or analytics cookies. Administrator pages use necessary, secure first-party cookies for CSRF protection and sign-in. You can read the public policies without an account. Optional Android permissions, AI requests, diagnostics and sharing can be declined separately.

Your enquiries and changes

Contact privacy@vitalo.online about access, correction, export, deletion or a privacy concern. Verify your identity through a secure channel before sensitive requests are fulfilled. Do not include passwords, authentication codes or medical attachments. Material changes will update this page and relevant in-app notices before new processing begins.