Vitalis is a suite of four iOS applications — Vitalis Core, Vitalis Motion, Vitalis Somna, and Vitalis Nourish — designed to help you understand your own health. This Privacy Policy explains what data Vitalis processes, where that data lives, and what we do (and emphatically do not do) with it.
The short version: Vitalis is a local-first, privacy-first product. Health data you log in any Vitalis app stays on your device. We do not transmit it to our servers because we do not have servers that handle your health data.
Vitalis integrates with Apple HealthKit to read and (optionally) write health data. HealthKit is a system-level framework managed by iOS — Vitalis can only access the specific data types you authorize, and you can revoke that access at any time in Settings → Privacy → Health.
Per Apple's developer guidelines, data obtained from HealthKit is never transmitted to Vitalis servers, never used for advertising, and never shared with third parties. This is enforced both by our policy and by Apple's App Review process.
Health entries created in Vitalis are stored locally on your device. We use iOS's built-in protections, including:
If you delete a Vitalis app, the local data is removed from your device per iOS standard behavior. Data backed up to iCloud is governed by Apple's iCloud privacy policies.
The four Vitalis apps communicate through Apple's App Group mechanism — a sandboxed, on-device shared container. This allows, for example, Vitalis Core to read a daily summary from Vitalis Somna so it can correlate sleep and mood. No data leaves your device through this mechanism.
You are always in control. If you only install one Vitalis app, no inter-app sharing occurs. Each app functions fully on its own.
Vitalis does not embed third-party SDKs that collect your health data. We do not use ad networks. We do not sell, rent, or share your data with anyone — including insurers, employers, marketers, data brokers, or research institutions — period.
The only third parties involved in delivering Vitalis to you are:
Vitalis is a consumer wellness application, not a covered entity or business associate under HIPAA (the U.S. Health Insurance Portability and Accountability Act). HIPAA generally applies to healthcare providers, health plans, and clearinghouses — not to consumer-controlled apps.
However, we voluntarily adopt many HIPAA-aligned practices because they are simply good engineering:
If you are a healthcare provider considering using Vitalis with patients, please contact us. We do not currently offer Business Associate Agreements (BAAs).
Because your data lives on your device, you control it directly. You can at any time:
If you reside in a jurisdiction with specific data rights (e.g., EU GDPR, California CCPA/CPRA), those rights apply. However, since we do not collect or store your health data on our infrastructure, most "right to access" or "right to deletion" requests can be satisfied by you, on-device, immediately.
If we materially change this policy, we will update the "Last updated" date at the top and, where reasonable, notify you in-app. Continued use of Vitalis after a change indicates acceptance of the revised policy.
Questions, concerns, or polite corrections about this policy can be directed to:
We read every message and respond within five business days.