Vitality Privacy Policy

Last updated: July 20, 2026 · Status: founding beta

Vitality (the trade name of the operating company currently being formed — the legal entity name will be inserted here upon formation; “Vitality”, “we”, “us”) is a personal data vault: you connect accounts you own (like a WHOOP wearable or your Google Calendar), we keep a fresh copy of that data in a vault only you can open, and we serve it back to you through one read-only key or an AI connector. This policy says exactly what we collect, why, where it lives, and what your rights are — in plain words first, because you should not need a lawyer to know what happens to your health data.

The short version

1. What we collect

2. What we use it for

That is the whole list. We do not use your data for advertising, we do not build profiles for third parties, we do not train AI models on your data, and we never sell personal data — including consumer health data — to anyone.

3. Who your data is shared with

No one, except the infrastructure that runs the service (our “processors”), and any consumer you point your own key at:

We may also disclose data if the law genuinely compels us to, and we will tell you it happened unless we are legally barred from doing so.

4. Google user data and Limited Use

If you connect Google Calendar, we access your calendar event data through Google APIs using the calendar.events.readonly scope, and only after you grant it on Google’s own consent screen. Vitality’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely: we use Google Calendar data only to provide the feature you connected it for — serving your own schedule back to you and to the AI connectors you set up. We do not transfer this data to others except as necessary to provide that feature, to comply with applicable law, or in connection with a merger or acquisition. We do not use Google user data for advertising. We do not allow humans to read it, except with your explicit consent for support you have asked us for, to comply with the law, or for security. We never sell Google user data, and we never use it to develop, improve, or train generalized AI or machine-learning models.

5. Consumer health data (Washington My Health My Data Act and similar laws)

The health data described in Section 1 is “consumer health data.” We collect it only with your explicit consent — the act of connecting a provider on its own consent screen — and use it only for the purposes in Section 2. We do not sell consumer health data, we do not share it for advertising, and we do not use geofencing. You may withdraw consent at any time by disconnecting the provider (which deletes our copies of its access tokens and purges the data we synced from it) and may request deletion of any remaining data as described in Section 8.

6. Where your data lives and how it is protected

No system on earth can honestly promise perfection, and we will never use the words “100% secure.” What we promise is the architecture above, maintained as the core of the product.

7. How long we keep it

8. Your rights

We respond to rights requests within 30 days and do not discriminate against you for exercising them.

9. What Vitality is not

10. Changes to this policy

If we change this policy in any meaningful way, we will post the new version here with a new date and email active members before it takes effect. Quiet edits to substance are not how we operate.

11. Contact

, a founder reads every message.

Terms of Service · Help & FAQ · Home