About this policy
This policy applies to Vitalscope Wellness and related services operated by Michael Clarke, trading as Vitalscope. Vitalscope Wellness is an informational wellness service. It is not a medical service and does not provide diagnosis, treatment, emergency monitoring or professional medical advice.
Privacy questions and requests can be sent to privacy@vitalscope.io. General support is available at support@vitalscope.io.
Information we use
Depending on the features you use and the permissions you grant, Vitalscope Wellness may use:
- Account and sign-in information.
- Account and profile information, including your name, email address, credentials, account status and support requests.
- Health information that you permit the app to read from Apple Health/HealthKit or Google Health Connect. Depending on your platform and permissions, this can include sleep, heart rate, resting heart rate, HRV, steps, distance, energy and activity, exercise, respiratory rate, oxygen saturation, body temperature, weight, body fat, blood pressure, blood glucose, hydration and VO2 max.
- Withings connection information and sleep summaries where you choose to connect Withings.
- Lab report images or PDF files that you choose to upload, together with extracted biomarkers, document metadata, warnings, confidence information and review status.
- Device, platform, operating-system, app-version, diagnostic and bounded error information.
- Subscription and purchase-verification information needed to provide Premium access.
- Consent-gated pseudonymous analytics events, such as feature activity, platform, language, app version and timestamps. Analytics validation prohibits raw health values, lab values, names, emails, tokens, passwords and free text.
We only access connected health information after you grant the relevant permission. You can manage permissions through your device or connected health platform.
How information is used
Information is used to provide and personalise Vitalscope Wellness, show trends and patterns, generate local wellness recommendations and scores, process uploaded lab documents, verify Premium access, maintain security, respond to support requests and meet legal obligations.
Uploaded lab documents may be sent to OpenAI through its Responses API for document and biomarker extraction. The extracted results and related metadata are stored so you can review and use the lab feature. Vitalscope Wellness does not send raw HealthKit or Health Connect samples to its backend as raw health records based on the current implementation.
Sharing and security
We do not sell personal health information. The app uses Apple Health/HealthKit and Google Health Connect as user-authorised health-data sources, Withings where connected, OpenAI for uploaded lab-document extraction, and Apple App Store or Google Play for billing and purchase verification. Vitalscope's own backend provides account, lab, Withings, entitlement and analytics services.
Apple, Google, Withings and OpenAI may retain or process information under their own terms and policies. Manage or revoke connected-service access with the relevant service separately.
We use reasonable technical and organisational measures to protect information. No service can guarantee absolute security, so please protect your account credentials and device.
Retention and your choices
Health information and recommendation history are stored locally on the device for app functionality. The current local recommendation history is retained for up to 31 days. Vitalscope servers retain account, lab, Withings, purchase-verification and other service data as needed to provide the service, comply with legal obligations, resolve disputes and maintain security.
Consent-gated analytics are configured for 90-day operational-event retention and 180-day retention for other analytics. The current deletion flow hard-deletes server analytics associated with the submitted pseudonymous identifier and rotates the local identifier. No verified backup provider, backup retention period or backup deletion schedule is established in the current implementation.
You can withdraw connected-data permissions, request access or correction, and request deletion as described on Account deletion.
Changes to this policy
We may update this policy when the service or applicable requirements change. The updated version will be posted on this page with a new effective date.