Privacy Policy
Last Updated: [8 Nov 2024]
1. Introduction
Vitall.ai ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
We are committed to compliance with applicable privacy laws, including:
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- Health Insurance Portability and Accountability Act (HIPAA) principles
2. Information We Collect
2.1 Personal Information
- Account Information: Name, email address, password (securely stored via Firebase)
- Profile Information: Age, gender, height, weight (optional)
- Payment Information: Processed securely through our payment processors
2.2 Health-Related Information
- Blood Test Data: Laboratory results, biomarkers, and related medical information
- Nutritional Data: Dietary preferences, meal logs, ingredient lists
- Health Metrics: Wellness scores, trend analysis, health indicators
2.3 Technical Information
- Device Data: IP address, browser type, device identifiers
- Usage Data: Feature interaction, analysis requests, session duration
- Location Data: Approximate location based on IP address
3. How We Use Your Information
3.1 Core Service Functionality
- Analyzing blood test results and providing insights
- Evaluating ingredient safety and nutritional content
- Generating personalized health recommendations
- Managing your account and preferences
3.2 Service Improvement
- Enhancing analysis algorithms and accuracy
- Improving user experience and interface
- Developing new features and services
3.3 Communication
- Service updates and notifications
- Technical support and assistance
- Marketing communications (with consent)
4. Data Protection and Security
4.1 Security Measures
- End-to-end encryption for sensitive health data
- Regular security audits and penetration testing
- Multi-factor authentication options
- Secure data centers and backup systems
4.2 Data Retention
- Active account data: Retained while account is active
- Deleted account data: Removed within 30 days
- Anonymized data: May be retained for research
5. Your Privacy Rights
5.1 Access and Control
- Right to access your personal information
- Right to correct inaccurate data
- Right to delete your data
- Right to restrict processing
- Right to data portability
- Right to withdraw consent
5.2 Exercise Your Rights
To exercise any of these rights, please contact our Data Protection Officer at privacy@vitall.ai. We will respond to your request within 30 days.
6. Third-Party Services
We use the following third-party services:
- Firebase: User authentication and data storage
- Analytics Providers: Service usage analysis
- Payment Processors: Secure payment handling
Each third-party service has its own privacy policy and data handling practices.
7. International Data Transfers
We may transfer your data internationally. We ensure appropriate safeguards through:
- Standard contractual clauses
- Privacy Shield certification
- Adequate country determinations
8. Children's Privacy
Our service is not intended for users under 13 years of age. We do not knowingly collect or maintain information from children under 13. If we learn that we have collected personal information from a child under 13, we will take steps to delete such information.
9. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of any material changes through:
- Email notification
- Service announcement
- Website notice
10. Contact Information
If you have questions about this Privacy Policy or our practices:
Data Protection Officer
- Email: privacy@vitall.ai
- Support: support@vitall.ai
