Privacy Policy
Last updated: June 28, 2026
This page is maintained by the VitalVault team to explain what we collect, why, and the controls you have. VitalVault helps you track medications, log doses, and share status with caregivers you choose.
1. Information We Collect
- Account info: email, name, and (optionally) date of birth and emergency contact.
- Health-related entries you add: medications, schedules, doses logged, lab results, adherence history.
- Caregiver links: pairing tokens and the relationship between patient and caregiver accounts.
- Device info: a device identifier and OneSignal player ID used to deliver push notifications.
- Diagnostic logs: error and operational logs used to keep the service running.
2. How We Use It
- To deliver medication reminders, refill alerts, and caregiver notifications.
- To show your linked caregivers your medication adherence and important alerts.
- To send transactional emails such as verification codes and a monthly adherence review.
- To detect abuse and keep VitalVault secure.
3. Sharing
We do not sell your data. We share data only with subprocessors that operate the service on our behalf — for example our cloud database and authentication provider, our push notification provider (OneSignal), and our email delivery provider (Resend). Caregivers you link receive access to the patient information necessary to support care.
When you type a medication name, that search text alone is sent to the public RxNav / RxNorm service operated by the U.S. National Library of Medicine so we can suggest recognised medication names. No account identifier, health record, or other personal information is included in that lookup.
3a. AI Features and Third-Party Processing
VitalVault offers optional AI-powered features. Each feature is off until you tap it, and the first time you use each one the app shows an in-app dialog listing the exact data that will be sent, who receives it, and how it is used. Nothing is sent to any AI service unless you tap Allow & continue in that dialog. You can revoke consent for all AI features at any time from Profile → Reset AI permissions.
Who receives the data
All AI processing is performed by Google's Gemini large-language model, accessed on our behalf through the Lovable AI Gateway operated by Lovable. Both providers are contractually required to protect this data at a level equal to or greater than the protections described in this policy, are not permitted to use your data to train their models, and are not permitted to sell it or use it for advertising.
What is sent, per feature
- Health Companion chat: the message you type, your active medication list (names, dosages, schedule), a summary of your recent dose adherence, and a summary of the lab results you have logged.
- Lab report photo scan: the single photo of the lab report you select.
- Prescription photo scan: the single photo of the prescription label you select.
- Medication interaction check: the names of the medications on your active list.
- Health Hub personalized tips: your active medication list (names, dosages, schedule), only after you tap Generate tips.
Data is sent over HTTPS, processed only to produce the response for that single request, and is not retained by the AI provider beyond what is needed to deliver and secure the service. AI responses are informational only and are not medical advice, diagnosis, or treatment.
4. Security
Data is transmitted over HTTPS and stored in a managed Postgres database protected by row-level security. Optional Face ID / Touch ID app lock and a configurable senior mode are available in the app. No system is perfectly secure; choose a strong password and keep your device passcode private.
5. Retention and Deletion
You can request account deletion at any time from Profile → Delete Account. Your account enters a 30-day grace period during which you can cancel; after 30 days your account and associated personal data are permanently removed.
6. Your Choices
- Update profile information from the Profile screen.
- Disable push notifications from your device's iOS settings.
- Unlink any caregiver from the Caregivers screen.
- Email us to request a copy of your data or to ask a privacy question.
7. Children
VitalVault is not directed to children under 13 and we do not knowingly collect data from children under 13.
8. Contact
Privacy questions or requests: support@vitalvaultlife.com.