Features Integrations AI & API Pricing Blog Docs

Privacy Policy

Last updated: September 11, 2026

1. Information We Collect

When you create an account, we collect your name and email address. When you connect third-party services (such as WHOOP, Oura, Withings, Hevy, or Apple Health), we collect health and fitness data from those services, including but not limited to recovery scores, readiness, heart rate variability, sleep data, strain data, activity and steps, workouts, exercise sets, SpO2, stress, weight, and body composition measurements.

2. How We Use Your Information

We use your data solely to provide the VitalTrends service — displaying your health trends and enabling data exports. We do not sell, rent, or share your personal or health data with third parties for marketing or advertising purposes.

3. Data Storage & Security

Your data is stored in encrypted databases. All OAuth tokens used to access third-party services are encrypted at rest. We use HTTPS for all data transmission. Access to your data is strictly scoped to your account — no other user can access your information.

4. Third-Party Services

We integrate with WHOOP, Oura, and Withings via their official OAuth2 APIs, and with Apple Health via our companion iOS app. When you connect these services, you authorize us to read your health data. You can disconnect any service at any time from your account settings, which will stop further data syncing.

5. Data Retention & Deletion

Your data is retained for as long as your account is active. You may delete your account at any time from your profile settings, which will permanently remove all your data, including synced health records and OAuth tokens.

5A. Workout Share Links

When you create a workout share, VitalTrends publishes the selected workout data at a dedicated link. By default, the link has no password and no expiration, so anyone who receives it can view the shared data until you revoke it. You can optionally require a password or set an expiration date. Access checks are performed on every request.

New share secrets and passwords are stored as one-way hashes. We keep security events for shared links, including access, password attempts, privacy changes, expiration, and revocation. Network addresses and user agents used for this security history are stored only as hashes. Public-share pages are excluded from our product analytics and configured not to be indexed or cached.

5B. Lab Report Imports

If you upload a blood test report, the file is processed to extract the lab values in it and is then deleted. We do not keep the original document. What we retain is the extracted values, their units, the reference ranges printed on your report, and enough source text to show you where each value came from, together with the parser's own output so an import can be re-checked without asking you for the file again.

Blood test results are special-category health data under the GDPR. We process them on the basis of your explicit consent, given separately for each purpose before any file is accepted, and recorded with the exact wording you agreed to, a timestamp and a policy version. You can withdraw any of it at any time from the lab data controls page. Withdrawing consent stops future processing; it does not delete results already imported, which you delete separately.

Reading a report accurately requires an external AI processor, so extraction involves a transfer outside the EU. The report text and page images are sent to OpenRouter, which routes them to the provider serving the model we use, and we cannot guarantee the region for that step. This transfer happens only with your explicit consent, is used solely to extract lab values, and is disclosed with its processors named on the upload screen and in your data controls. Without that consent we do not accept the file at all.

You can export every imported value as CSV or JSON, delete a single report along with everything it contributed to your history, or delete all lab data at once. Your consent records are kept after deletion, because they are the record of what you agreed to and when.

6. Cookies

We use essential cookies for authentication and session management. We also store your theme preference (dark/light mode) in your browser's local storage. We do not use tracking or advertising cookies.

7. Changes to This Policy

We may update this privacy policy from time to time. We will notify registered users of any material changes via email.

8. Contact

If you have questions about this privacy policy or your data, please contact us at hello [at] vitaltrends [dot] net.