Privacy Policy

Your health data security is our highest priority

Last Updated: December 16, 2024

VitalSync Privacy Policy

At VitalSync, we understand that your health information is deeply personal and sensitive. This Privacy Policy explains how we collect, use, protect, and handle your health data when you use our mobile application ("VitalSync," "the App," "our Service"). By using VitalSync, you agree to the practices described in this policy.

HIPAA Compliance Promise: VitalSync is designed with healthcare-grade security standards. We implement HIPAA-compliant practices to protect your Protected Health Information (PHI). Your vital signs, medication data, and health records are encrypted with bank-level security and NEVER sold to third parties. All health data processing happens securely on your device and our HIPAA-compliant servers.

1. Health Information We Collect

1.1 Health Data You Provide

When using VitalSync to manage your health, you may provide:

1.2 Automatically Collected Data

1.3 Health Data We Do NOT Collect

VitalSync does NOT collect:

2. How We Use Your Health Information

2.1 Core Health Tracking

2.2 AI-Powered Insights

2.3 App Improvement

2.4 Communication

3. HIPAA-Compliant Data Security

3.1 Industry-Leading Encryption

VitalSync employs multiple layers of security to protect your health data:

3.2 HIPAA-Compliant Infrastructure

3.3 Data Retention

3.4 Data Backup and Recovery

4. Data Sharing and Disclosure

4.1 We NEVER Sell Your Health Data

VitalSync will NEVER sell, rent, or trade your health information to third parties for marketing purposes. Your health data is not a commodity.

4.2 Sharing with Your Consent

We may share your health data ONLY with your explicit consent:

4.3 Service Providers (Business Associates)

We work with trusted service providers who help us operate VitalSync. All providers sign HIPAA Business Associate Agreements (BAAs):

4.4 Legal Requirements

We may disclose health information if required by law:

4.5 Business Transfers

In the event of a merger, acquisition, or sale of assets, your health information may be transferred. We will notify you via email at least 30 days before any transfer and provide options to delete your data if you do not consent.

5. Your Privacy Rights

5.1 Access and Control

You have comprehensive rights over your health data:

To exercise these rights, email support@vitalsync.health with "Privacy Request" in the subject line.

5.2 Notification Settings

You control all communications:

5.3 Data Portability

Export your health data anytime:

5.4 Account Deletion

Delete your account and health data:

6. Children's Privacy

VitalSync is not intended for children under 13 years of age. We do not knowingly collect health information from children under 13. If you are a parent or guardian and believe your child has provided us with health information, contact us immediately at support@vitalsync.health, and we will delete the information promptly.

Parental Consent for Minors (13-17): For users aged 13-17, we require verified parental consent before collecting any health information. Parents have full access to manage their child's health data.

7. State-Specific Privacy Rights

7.1 California Privacy Rights (CCPA/CPRA)

California residents have additional rights:

To exercise CCPA rights, email support@vitalsync.health with "CCPA Request" in the subject.

7.2 European Privacy Rights (GDPR)

Users in the European Economic Area (EEA), UK, and Switzerland have rights under GDPR:

7.3 Other State Laws

We comply with additional state privacy laws including Virginia CDPA, Colorado CPA, Connecticut CTDPA, and Utah UCPA. Contact us to exercise state-specific rights.

8. International Data Transfers

VitalSync operates globally. If you use the app outside the United States, your health information may be transferred to and processed in the US. We implement appropriate safeguards:

9. Third-Party Services and Links

VitalSync may integrate with third-party health platforms (Apple Health, Google Fit) or contain links to external websites. These services have their own privacy policies. We are not responsible for their practices. Review their policies before sharing health data.

Apple Health Integration: If you enable Apple Health sync, data sharing is governed by Apple's Health app privacy policy. You control what data is shared.

10. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we make changes:

Your continued use after changes constitutes acceptance. If you disagree, you may delete your account.

11. Data Breach Notification

In the unlikely event of a data breach affecting your health information, we will:

12. Contact Us

For privacy questions, concerns, or to exercise your rights:

Email: support@vitalsync.health

Subject Line: Privacy Request - VitalSync

Data Protection Officer: dpo@vitalsync.health

Response Time: Within 48 hours for privacy requests

For data subject requests, include:

13. Your Health, Your Privacy

Our Promise to You: At VitalSync, your health data privacy is sacred. We implement HIPAA-compliant security measures, never sell your information, and give you complete control over your health records. We believe in transparency, security, and putting your health first.

Security Commitments:

  • Bank-level AES-256 encryption for all health data
  • HIPAA-compliant infrastructure and business practices
  • Regular third-party security audits and penetration testing
  • Zero-tolerance policy for unauthorized data access
  • 24/7 security monitoring and threat detection

Thank you for trusting VitalSync with your most personal health information.