Privacy Policy
Last updated: July 31, 2026
This Privacy Policy explains how Vitale accesses, collects, uses, shares, retains, and protects information when you use the Vitale mobile app and related services.
1. Information We Handle
Depending on the features you use, Vitale may handle:
- Account information — an authentication identifier and, if you add one, your email address. Authentication credentials are processed by Supabase Auth.
- Health and wellness entries — mood, energy, sleep duration and quality, food and drink tags, symptoms, and notes you choose to enter.
- Health Connect data — sleep and step data, only when you explicitly connect Health Connect and grant the requested read permissions. Vitale does not write data to Health Connect.
- AI feature content — questions submitted to Ask Vitale and relevant summaries derived from your wellness entries.
- Purchase information — subscription product, entitlement, purchase status, and expiration information. Vitale does not receive your complete payment-card details.
- App, device, and advertising information — app interactions, device or advertising identifiers, diagnostics, and approximate technical information collected by configured analytics or advertising services.
2. How We Use Information
We use information to:
- Provide daily tracking, trends, correlations, reminders, and exports.
- Sync your history across devices and secure your account.
- Generate the AI-powered wellness insights or answers you request.
- Manage subscriptions, premium access, and rewarded-ad access.
- Operate, secure, troubleshoot, and improve Vitale.
- Comply with legal, fraud-prevention, and platform requirements.
3. Local Storage and Cloud Sync
Wellness entries are stored in an on-device SQLite database so core tracking can work offline. When cloud services are configured, entries are also synced to Supabase. Data sent between the app and service providers is encrypted in transit using HTTPS/TLS. No system can be guaranteed completely secure, but we use access controls and user-scoped database policies designed to prevent users from accessing one another's records.
4. Service Providers
Vitale uses service providers for specific app functions:
- Supabase — authentication, cloud storage, sync, and server functions.
- Firebase Cloud Messaging — provides a device registration token and delivers notifications when you enable them.
- Google Gemini — processes relevant wellness-log summaries and questions to generate requested insights and answers. Account credentials are not included in AI prompts.
- Google AdMob — displays and verifies ads for free-tier features.
- RevenueCat and Google Play Billing — process subscription status and entitlements.
- PostHog— receives sanitized product-usage events when analytics is enabled. Vitale's analytics layer excludes health values, symptoms, notes, and Ask Vitale text.
- Health Connect — provides sleep and step data after optional, permission-based access.
Providers process information under their own terms and privacy policies. We do not sell your personal or health information.
5. Ads and Analytics
The free tier may show Google AdMob ads. AdMob may process advertising identifiers and app or device information for ad delivery, measurement, fraud prevention, and—where permitted by your choices and applicable law—personalization. Product analytics are disabled when Vitale is built without a PostHog project token.
6. Retention and Deletion
Cloud account and wellness data are retained while your account is active. When in-app account deletion succeeds, Vitale deletes the Supabase account and its associated cloud records and clears the on-device wellness database and app preferences. Limited records may be retained when required for security, fraud prevention, tax, accounting, dispute resolution, or other legal obligations. Residual encrypted backups may remain until they cycle out under provider backup schedules.
Deleting a Vitale account does not automatically cancel a Google Play subscription. Cancel an active subscription in Google Play to stop future renewal charges.
7. Your Choices and Rights
You can:
- Choose which wellness fields to enter and whether to add notes.
- Decline or revoke Health Connect and notification permissions.
- Export your wellness history from the app.
- Request access, correction, or deletion where applicable.
- Delete your account in Vitale under Profile → Delete Account, or follow the steps on our account deletion page.
8. Children's Privacy
Vitale is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us so we can investigate and delete it.
9. Health and AI Notice
Vitale is a general wellness and self-tracking app, not a medical device. It does not diagnose, treat, cure, or prevent any medical condition. AI-generated content and correlations may be incomplete or inaccurate. Consult a qualified healthcare professional for medical advice, diagnosis, or treatment.
10. Changes to This Policy
We may update this policy as Vitale or legal requirements change. The latest version will be posted here with a revised update date.
11. Contact
For privacy questions or requests, email shahidshamimshah3@gmail.com.