Effective August 31, 2026
Privacy Policy
How VitalSyncLabs handles personal information across the website and app.
Contents
- What this policy covers
- Your account and Insight Profile
- Information we may handle
- Where information comes from
- How we use information
- AI processing, training, and human access
- Website analytics and browser choices
- Service providers and disclosures
- Sharing and organization access
- Uses we prohibit
- Aggregate, synthetic, and de-identified information
- Apple Health and other integrations
- Platform, device, and notification data
- Communications and notification choices
- Retention and deletion
- Your controls and privacy requests
- Age and launch region
- Security and incidents
- Policy changes and contact
What this policy covers
This policy covers the VitalSyncLabs website, beta-access and support forms, a VitalSync account, optional Insight Profile, connected data sources, AI processing, communications, exports, and account lifecycle.
VitalSyncLabs is a consumer product, not a health care provider or a substitute for a provider's medical record. VitalSyncLabs does not claim HIPAA coverage, certification, or compliance. Other privacy, consumer-health, breach-notification, platform, and state laws may apply. The Consumer Health Data Privacy Notice addresses information that reveals or supports an inference about a person's health.
Your account and Insight Profile
A VitalSync account contains the information needed for sign-in, security, eligibility, preferences, legal records, AI conversations, files you choose to provide, notifications, and account operations. A conversation may include health-related or sensitive text even when Insight Profile is not active.
Insight Profile begins only after a separate activation and date-of-birth eligibility check. It may then hold structured profile details, symptoms, signals, observations, medications, follow-up answers, source links, timelines, integrations, imported records, attachments, and derived results. Creating an account does not silently create or populate an Insight Profile.
Information we may handle
We collect a category of information only when you use the feature that requires it.
- Account and eligibility information, such as email, authentication identifiers, age attestation, Insight Profile date of birth, account state, and legal acceptance records.
- Conversations and content you choose to provide, including messages, feedback, files, photos, voice-derived text, and related metadata.
- Insight Profile information, including structured profile fields, symptoms, signals, observations, medications, follow-up answers, timelines, relationships, corrections, and provenance.
- Connected-source information from Apple Health or another separately enabled integration, limited to the approved data types and purpose shown at activation.
- Derived information, such as classifications, summaries, patterns, changes, relationships, suggested follow-ups, safety decisions, and other user-facing outputs.
- Technical and security information, such as session and device details, request metadata, push tokens, reliability events, abuse-prevention signals, and content-minimized audit records.
- Website and communication information submitted through beta access, contact, support, newsletter, enterprise, careers, press, or similar forms that are actually available.
- Privacy choices, notification preferences, integration permissions, export requests, correction requests, and deletion or account-lifecycle state.
Where information comes from
Information may come directly from you, from your use of the website or app, from an authentication or platform service, from a device or integration you separately connect, and from VitalSyncLabs processing needed to provide the requested feature.
VitalSyncLabs does not treat permission for one source as permission for another. Apple Health, files, location, motion, environmental data, wearables, and medical-record imports each require their own enabled feature, stated purpose, and user control before use.
How we use information
VitalSyncLabs uses information to provide, personalize, secure, maintain, and support the features you request; preserve conversation continuity; operate an activated Insight Profile; connect approved sources; generate results; communicate about the account or beta; respond to requests; prevent misuse; and meet legal obligations.
We do not use sensitive information for unrelated product development. We limit its use to the stated purpose and apply appropriate access, retention, and deletion controls.
AI processing, training, and human access
Before health-related AI processing is enabled in the beta, VitalSyncLabs requires it to use controlled infrastructure and authorized providers. Models receive only context relevant to the requested task; they are not given automatic access to the entire account, every conversation, all profile history, or every connected source.
This policy does not permit identifiable or linkable conversations, health records, attachments, wearable values, personalized summaries, or saved memory to be used for general-model training by default. We do not send raw health content to ordinary website analytics or evaluation stores.
VitalSyncLabs does not routinely monitor conversations or Insight Profile results through employees or clinicians. Limited human access may occur for a defined purpose, such as support requested by the user, a security or safety investigation, a legal requirement, or a separately chosen improvement or research workflow. Any such access must be restricted and audited.
Website analytics and browser choices
Optional website analytics are off unless the user makes an affirmative choice. If enabled, the website may use approved performance and product-use measurement tools. VitalSyncLabs does not send conversation text, Insight Profile content, symptom details, or health records through website analytics.
A user can reject optional analytics, change the choice later through Privacy Choices, and stop future optional collection. Withdrawal also clears VitalSyncLabs-owned website analytics identifiers where the implemented browser control supports it. Essential session, security, routing, and preference storage may still operate because it is needed to provide or protect the site.
Service providers and disclosures
VitalSyncLabs may use service providers for hosting, authentication, security, email, notifications, support, storage, and optional analytics. Each provider may receive only the information needed for its approved purpose and must be reviewed for access, use, security, retention, and deletion.
Information may also be disclosed when you direct it, when reasonably necessary to protect users or the Service, as part of a properly governed business transaction, or when required by law.
Uses we prohibit
VitalSyncLabs does not permit selling personal or health information, disclosing it to data brokers, sharing it for cross-context behavioral advertising, or targeting advertising based on symptoms, medications, inferred conditions, Insight Profile details, or connected health data.
VitalSyncLabs also does not permit using health information to make insurance, employment, credit, housing, education, care-denial, or similar significant decisions. Using an account does not authorize human-subject research, and information that remains linkable to a person is not described as anonymous.
Aggregate, synthetic, and de-identified information
VitalSyncLabs may use content-free operational measurements, synthetic data, authored tests, licensed data, and documented aggregate statistics to operate, test, and improve the Service without treating raw health content as ordinary analytics data.
Removing a direct identifier does not necessarily make information anonymous. Pseudonymized or linkable information remains personal information. VitalSyncLabs will describe information as de-identified only after a documented assessment shows that it is not reasonably linkable to a person and controls prevent re-identification.
Apple Health and other integrations
When Apple Health is enabled, the app requests access to specific supported data types for a disclosed health or fitness purpose. Permission is controlled through Apple settings, and a user may grant or deny individual types. Apple Health information is not used for advertising, marketing, sale to data brokers, or unrelated data mining.
Revoking an operating-system permission stops future access but does not automatically delete information already imported. Before an integration is enabled, VitalSyncLabs will explain how to disconnect it and manage previously imported information.
Platform, device, and notification data
Depending on the features you use, VitalSyncLabs may receive account identifiers, notification tokens, app-distribution information, device-stored data, permissions, and limited diagnostic events. Granting access to one feature does not authorize access to unrelated information or services.
Communications and notification choices
Required account, security, legal, privacy, deletion, export, billing, and incident communications are separate from optional reminders and marketing. Required notices may be sent to a verified email address and, when available, through in-app messaging. Push notifications are supplemental and use generic previews without sensitive details.
Users may withdraw from optional marketing by channel without suppressing necessary service communications. The initial beta does not use promotional SMS or calls and does not use health information to select marketing audiences.
Retention and deletion
User-facing conversation and longitudinal Insight Profile history is retained while the related account or profile remains active, unless the user deletes the item, deletes Insight Profile, or requests full-account deletion. Temporary, duplicate, diagnostic, and operational copies require separate, bounded retention rules.
When source deletion is available, its confirmation will explain what information and derived results are removed, recomputed, or marked unavailable. Deleted information must not reappear through search, summaries, model context, exports, or restored copies.
Deactivation, deleting Insight Profile, and deleting an account are separate actions. Disconnecting an integration stops future synchronization; the available controls will explain how previously imported information and derived results are handled.
Full account deletion is not currently available in the beta. Before it is offered, VitalSyncLabs will disclose the applicable cancellation period, deletion scope, provider handling, notices, and backup retention.
Your controls and privacy requests
Depending on the feature and applicable law, users may review and correct profile information, delete conversations or eligible records, manage saved memory, change notification and analytics choices, disconnect integrations, delete imported information, export information, delete Insight Profile, or request full-account deletion.
Where applicable, privacy requests may cover access, correction, deletion, portability, consent withdrawal, appeals, and requests from an authorized agent. VitalSyncLabs may verify identity and an agent's authority before acting. VitalSyncLabs may keep a limited record of a privacy request and the action taken without copying health content into the case.
If a request is denied or only partly completed, VitalSyncLabs will explain the affected information, the reason, any available appeal route, and any information that must be retained for security or legal purposes.
Age and launch region
The initial U.S. beta is limited to users who are at least 18 years old. This applies to both the normal account and Insight Profile. Date of birth is used for Insight Profile eligibility and approved personalization; age or date-of-birth information is not consent to analytics, marketing, research, AI training, HealthKit, or every other processing purpose.
VitalSyncLabs does not currently offer a minor, guardian, caregiver, delegated, clinician-managed patient, researcher-managed participant, or international account model.
Security and incidents
VitalSyncLabs is designing safeguards around account isolation, least-privilege access, protected credentials, privacy-safe logging, and controlled support access. No system is perfectly secure, and VitalSyncLabs does not claim a certification or an unverified encryption, backup, incident-notice, or deletion result.
Policy changes and contact
We will post revisions and update the date shown at the top of this page. If a change requires notice, consent, or acknowledgement, we will provide it before the change takes effect.
Questions about this document
Submit a privacy request. The form explains what information to leave out and how the request will be handled.