Last updated: September 21, 2026
The short version.
VitalBrief is provided by its developer, the individual named as the seller on VitalBrief's App Store page ("we," "us"), who is the controller of the personal data described in this policy. The developer is also our data protection contact, including as the person in charge of data protection (encarregado) under Brazil's General Data Protection Law (LGPD). For any privacy question or request, write to [email protected].
VitalBrief has no accounts, no login and no registration. The App does not ask for your name or email address, and it does not collect advertising identifiers, contacts, precise location, photos or payment details. It contains no analytics, advertising or tracking SDKs.
With your permission, the App reads the following types from Apple Health. It works with any device or app that saves data there, such as Apple Watch, Garmin, Oura, Whoop, Fitbit or Withings.
The App only reads from Apple Health. It never writes to or changes your Apple Health data. You choose which types to share, and you can change your choice at any time in iOS Settings (Privacy & Security, Health) or in the Health app.
We use Apple Health data only to provide the App's features. We never use it for advertising, marketing or data mining, never sell it, and never share it with anyone except the services that write your reports, as described below.
This information is stored on your device. It leaves the device only as part of a written report request, as described below.
The daily readiness reading, the widgets, the weekly score and its commentary, the activity calendar, your personal records and the month-over-month comparison table in monthly reports are calculated by the App on your device, without any AI service. For example, the readiness reading compares last night's heart rate variability and heart rate with your own recent history, and takes your sleep, breathing, blood oxygen and recent training into account. The results are stored on your device and are not sent to us.
Written reports are a Premium feature and are created only when you ask for one. Before any data can be sent, the App asks for your explicit consent to send the data described here to an external AI service.
You can withdraw your consent at any time by no longer requesting written reports: nothing is sent unless you ask for a report. Withdrawing does not affect reports already created. To make sure nothing more can be sent, you can also turn off the App's access to Apple Health or delete the App.
When a report request reaches our proxy, we process limited technical information to deliver it, protect the service from abuse and control costs: a request ID, a shortened one-way hash of your IP address (the address itself is not written to the logs), country, user agent, app version and build, platform, request method and path, request and response sizes, response status and duration, rate-limit and error information, which AI model handled the request, and the token counts reported by the provider. These logs do not contain the content of your request or your report, and they are not linked to an account, because there are none.
The logs are kept in Cloudflare Workers Logs and deleted automatically within a few days. Short-lived counters used for rate limiting and cost control expire automatically within minutes to hours. Cloudflare also processes IP addresses to protect our proxy from attacks, under its own security practices.
The App keeps a short log of its last 20 internal events on your device to help with troubleshooting, such as request IDs, error codes and which data categories were available. It contains no health values or personal details and is never sent automatically. You can view, copy or clear it in the App (More, About, Diagnostics) and choose to include it in an email to us.
If you have chosen in iOS settings to share analytics with app developers, Apple may provide us with crash reports and aggregated usage statistics that do not identify you.
Notifications are scheduled on your device to tell you when a week or a month has closed. VitalBrief does not send remote push notifications. Widgets show a short version of your daily reading, from data the App keeps on your device for them, so anyone who can see your screen can see what they show.
Apple processes all purchases. We do not receive your payment details, name or email address from Apple. The App checks your subscription status with Apple on your device, and Apple provides us with sales reports that do not identify you.
If you email us, we receive your email address, your message and anything you attach, such as a diagnostics log or screenshots. We use it only to answer you and to fix problems in the App. Our email is hosted by Google (Gmail). We keep support emails for as long as needed to resolve your request and any related matter, and you can ask us to delete them at any time, unless the law requires us to keep them.
You can export a report as a PDF, copy a report to explore it with another AI assistant, or take screenshots. When you share that content, the app, service or person you share it with handles it under its own terms. We have no access to it.
| Recipient | Role | What it receives |
|---|---|---|
| Cloudflare | Hosts our proxy and protects it from attacks | Report requests in transit, IP addresses and technical logs |
| OpenAI | Writes the written reports | The report request described above |
| Hosts our support email | Emails you send us |
Apple provides the App Store, purchases, Apple Health and iOS, and handles the data involved under its own privacy policy. We do not sell personal data or share it for targeted advertising. We may disclose information when the law requires it.
Where the law requires a legal basis, for example the GDPR in the European Union and the United Kingdom or the LGPD in Brazil, we rely on:
Cloudflare runs a global network, OpenAI processes data in the United States and Google hosts email in several countries, so your data may be processed outside the country where you live. When that happens, we rely on the safeguards these providers offer, such as standard contractual clauses, or on another transfer mechanism permitted by law.
| Data | Where | How long |
|---|---|---|
| Readings, scores, reports, profile, notes and preferences | Your device | Until you delete them or the App. Workout notes are removed after 90 days, and the readiness history keeps about 400 days. |
| Report requests | Our proxy (Cloudflare) | Not stored |
| Report requests | OpenAI | Up to 30 days, for abuse monitoring |
| Technical logs | Cloudflare Workers Logs | A few days |
| Rate-limit and cost counters | Cloudflare | Minutes to hours |
| Support emails | Google (Gmail) | As long as needed for your request, or until you ask us to delete them |
Data is encrypted in transit. On your device, it is protected by iOS, including the encryption tied to your passcode. Our proxy keeps service credentials on the server side, rejects malformed or excessive requests and does not store report content, and access to the technical logs is limited to us. No method of transmission or storage is completely secure, and we will handle any security incident as the law requires.
VitalBrief is not directed to anyone under 16, and our Terms of Use require users to be at least 16. We do not knowingly collect personal data from anyone under 16. Users under 18 need the permission of a parent or legal guardian, and where the law of their country requires a parent's or guardian's consent for data processing at their age, they may request written reports only with that consent. If you believe someone under 16 has sent data through the report feature, contact us and we will delete what we hold.
Depending on where you live, including in the European Union, the United Kingdom, Brazil and several US states, you may have the right to confirm whether we process your personal data, to access, correct or delete it, to receive a copy, to restrict or object to its processing, to withdraw consent, and not to be treated differently for exercising these rights.
Because there are no accounts and most data lives only on your device, you can exercise most of these rights yourself in the App: edit your profile (More, Customize), change your notes, turn off Apple Health access, or delete the App to erase everything it stored. For information we hold, such as support emails and technical logs, write to us. We may ask for details that help us find the records, such as the approximate date of a request, and we answer within the time limits set by law.
You can also complain to a data protection authority: in Brazil, the ANPD, and in the European Union or the United Kingdom, the authority where you live or work.
If you live in a US state with a consumer health data law, such as Washington or Nevada, these rights also cover your consumer health data, including the right to withdraw consent and to ask for deletion. We do not sell consumer health data.
When we update this policy, we will publish the new version on this page with a new date. If a change is significant, for example a new type of data sent off your device or a new kind of recipient, we will tell you in the App before it applies and ask for your consent again where the law requires it.
Questions or requests about privacy: [email protected].