Back to VitalBrief

Privacy Policy

Last updated: September 21, 2026

The short version.

  • VitalBrief reads the Apple Health data you allow and does its daily work on your iPhone. The readiness reading, the widgets, the weekly score and its commentary, the activity calendar and your records are calculated on the device and send nothing to us or to any AI service.
  • Data leaves your device when you ask for a written report and have agreed to it in the App: a summary of your metrics, your profile and your notes travel encrypted, through our proxy, to the AI provider that writes the report.
  • There are no accounts, no advertising and no analytics or tracking SDKs. We do not sell personal data.

Who is responsible

VitalBrief is provided by its developer, the individual named as the seller on VitalBrief's App Store page ("we," "us"), who is the controller of the personal data described in this policy. The developer is also our data protection contact, including as the person in charge of data protection (encarregado) under Brazil's General Data Protection Law (LGPD). For any privacy question or request, write to [email protected].

What we do not collect

VitalBrief has no accounts, no login and no registration. The App does not ask for your name or email address, and it does not collect advertising identifiers, contacts, precise location, photos or payment details. It contains no analytics, advertising or tracking SDKs.

Apple Health data the App reads

With your permission, the App reads the following types from Apple Health. It works with any device or app that saves data there, such as Apple Watch, Garmin, Oura, Whoop, Fitbit or Withings.

  • Activity: steps, walking and running distance, flights climbed, active and resting energy, exercise time, and Activity ring data (Move, Exercise and Stand)
  • Workouts: workout type, start time, duration, distance (including cycling and swimming), active energy, swimming stroke count, cadence, pace, average and peak heart rate, and heart rate zones when available
  • Heart: heart rate, resting heart rate, walking heart rate average, heart rate variability (HRV), heartbeat series (the beat-to-beat intervals the App uses to calculate HRV on your device), heart rate recovery and VO2 max
  • Mobility: walking speed, walking step length and walking steadiness
  • Respiratory: respiratory rate and blood oxygen saturation
  • Body: body mass, body mass index and body fat percentage
  • Sleep: sleep sessions and stages, and sleeping wrist temperature
  • Other: time in daylight

The App only reads from Apple Health. It never writes to or changes your Apple Health data. You choose which types to share, and you can change your choice at any time in iOS Settings (Privacy & Security, Health) or in the Health app.

We use Apple Health data only to provide the App's features. We never use it for advertising, marketing or data mining, never sell it, and never share it with anyone except the services that write your reports, as described below.

Information you enter

  • Profile: birth month and year (used to calculate your age), height, biological sex, goals, sports, activity level, training days and preferred training time, and the health considerations you select, such as recovering from an injury or a health limitation.
  • About You: optional free text in which you describe yourself.
  • Notes: notes on your workouts, and optional notes you add before creating a report.

This information is stored on your device. It leaves the device only as part of a written report request, as described below.

What the App calculates on your device

The daily readiness reading, the widgets, the weekly score and its commentary, the activity calendar, your personal records and the month-over-month comparison table in monthly reports are calculated by the App on your device, without any AI service. For example, the readiness reading compares last night's heart rate variability and heart rate with your own recent history, and takes your sleep, breathing, blood oxygen and recent training into account. The results are stored on your device and are not sent to us.

Written reports

Written reports are a Premium feature and are created only when you ask for one. Before any data can be sent, the App asks for your explicit consent to send the data described here to an external AI service.

  • What is sent: a summary of the health data needed for the report's period (for example daily and weekly figures for activity, workouts, heart, sleep and recovery, and context derived from the App's own calculations, such as how the week compares with previous weeks); your profile, including your age and any health considerations you selected; your About You text; your workout notes and any note you added for that report; and a short list of themes from your previous report, so that reports can build on each other.
  • What is not added: the App does not add your name, email address, Apple Account, device identifier or any account identifier. Your IP address reaches our proxy, as it does with any internet connection (see Technical logs).
  • How it travels: over an encrypted connection (HTTPS/TLS) to our proxy, which runs on Cloudflare. The proxy adds our service credentials, forwards the request to the AI provider and returns the finished report to your device. It does not store or log the content of requests or reports.
  • Who writes it: the AI provider we currently use is OpenAI, in the United States. It processes the request to write the report. Under its API terms, it does not use this data to train its models, and it may keep it for up to 30 days to monitor for abuse before deleting it, unless the law requires otherwise. If we change or add AI providers, we will update this policy first.
  • Where the report goes: the finished report is stored on your device. We do not keep a copy.

You can withdraw your consent at any time by no longer requesting written reports: nothing is sent unless you ask for a report. Withdrawing does not affect reports already created. To make sure nothing more can be sent, you can also turn off the App's access to Apple Health or delete the App.

Technical logs

When a report request reaches our proxy, we process limited technical information to deliver it, protect the service from abuse and control costs: a request ID, a shortened one-way hash of your IP address (the address itself is not written to the logs), country, user agent, app version and build, platform, request method and path, request and response sizes, response status and duration, rate-limit and error information, which AI model handled the request, and the token counts reported by the provider. These logs do not contain the content of your request or your report, and they are not linked to an account, because there are none.

The logs are kept in Cloudflare Workers Logs and deleted automatically within a few days. Short-lived counters used for rate limiting and cost control expire automatically within minutes to hours. Cloudflare also processes IP addresses to protect our proxy from attacks, under its own security practices.

Diagnostics

The App keeps a short log of its last 20 internal events on your device to help with troubleshooting, such as request IDs, error codes and which data categories were available. It contains no health values or personal details and is never sent automatically. You can view, copy or clear it in the App (More, About, Diagnostics) and choose to include it in an email to us.

If you have chosen in iOS settings to share analytics with app developers, Apple may provide us with crash reports and aggregated usage statistics that do not identify you.

Notifications and widgets

Notifications are scheduled on your device to tell you when a week or a month has closed. VitalBrief does not send remote push notifications. Widgets show a short version of your daily reading, from data the App keeps on your device for them, so anyone who can see your screen can see what they show.

Purchases

Apple processes all purchases. We do not receive your payment details, name or email address from Apple. The App checks your subscription status with Apple on your device, and Apple provides us with sales reports that do not identify you.

Support emails

If you email us, we receive your email address, your message and anything you attach, such as a diagnostics log or screenshots. We use it only to answer you and to fix problems in the App. Our email is hosted by Google (Gmail). We keep support emails for as long as needed to resolve your request and any related matter, and you can ask us to delete them at any time, unless the law requires us to keep them.

What you choose to share

You can export a report as a PDF, copy a report to explore it with another AI assistant, or take screenshots. When you share that content, the app, service or person you share it with handles it under its own terms. We have no access to it.

Who receives personal data

RecipientRoleWhat it receives
CloudflareHosts our proxy and protects it from attacksReport requests in transit, IP addresses and technical logs
OpenAIWrites the written reportsThe report request described above
GoogleHosts our support emailEmails you send us

Apple provides the App Store, purchases, Apple Health and iOS, and handles the data involved under its own privacy policy. We do not sell personal data or share it for targeted advertising. We may disclose information when the law requires it.

Legal bases

Where the law requires a legal basis, for example the GDPR in the European Union and the United Kingdom or the LGPD in Brazil, we rely on:

  • Written reports: your explicit consent, which covers the health data involved.
  • Technical logs and security: our legitimate interest in keeping the service secure, reliable and affordable. These logs contain no health data.
  • Support emails: answering your request, and our legitimate interest in improving the App.
  • Legal obligations: where the law requires us to keep or disclose information.

International transfers

Cloudflare runs a global network, OpenAI processes data in the United States and Google hosts email in several countries, so your data may be processed outside the country where you live. When that happens, we rely on the safeguards these providers offer, such as standard contractual clauses, or on another transfer mechanism permitted by law.

How long data is kept

DataWhereHow long
Readings, scores, reports, profile, notes and preferencesYour deviceUntil you delete them or the App. Workout notes are removed after 90 days, and the readiness history keeps about 400 days.
Report requestsOur proxy (Cloudflare)Not stored
Report requestsOpenAIUp to 30 days, for abuse monitoring
Technical logsCloudflare Workers LogsA few days
Rate-limit and cost countersCloudflareMinutes to hours
Support emailsGoogle (Gmail)As long as needed for your request, or until you ask us to delete them

Security

Data is encrypted in transit. On your device, it is protected by iOS, including the encryption tied to your passcode. Our proxy keeps service credentials on the server side, rejects malformed or excessive requests and does not store report content, and access to the technical logs is limited to us. No method of transmission or storage is completely secure, and we will handle any security incident as the law requires.

Children and teenagers

VitalBrief is not directed to anyone under 16, and our Terms of Use require users to be at least 16. We do not knowingly collect personal data from anyone under 16. Users under 18 need the permission of a parent or legal guardian, and where the law of their country requires a parent's or guardian's consent for data processing at their age, they may request written reports only with that consent. If you believe someone under 16 has sent data through the report feature, contact us and we will delete what we hold.

Your rights

Depending on where you live, including in the European Union, the United Kingdom, Brazil and several US states, you may have the right to confirm whether we process your personal data, to access, correct or delete it, to receive a copy, to restrict or object to its processing, to withdraw consent, and not to be treated differently for exercising these rights.

Because there are no accounts and most data lives only on your device, you can exercise most of these rights yourself in the App: edit your profile (More, Customize), change your notes, turn off Apple Health access, or delete the App to erase everything it stored. For information we hold, such as support emails and technical logs, write to us. We may ask for details that help us find the records, such as the approximate date of a request, and we answer within the time limits set by law.

You can also complain to a data protection authority: in Brazil, the ANPD, and in the European Union or the United Kingdom, the authority where you live or work.

If you live in a US state with a consumer health data law, such as Washington or Nevada, these rights also cover your consumer health data, including the right to withdraw consent and to ask for deletion. We do not sell consumer health data.

Changes to this policy

When we update this policy, we will publish the new version on this page with a new date. If a change is significant, for example a new type of data sent off your device or a new kind of recipient, we will tell you in the App before it applies and ask for your consent again where the law requires it.

Contact

Questions or requests about privacy: [email protected].