VitalGraph Privacy Policy
Last updated: 19 July 2026
1. Who we are
VitalGraph ("we") is the controller for the personal data you process through vitalgraph.app. Questions or requests: privacy@vitalgraph.app.
2. What we process
Account data (name, email, password hash, gender, height, date of birth) and the health measurements you enter yourself or import through a linked service (such as Withings): weight, circumferences, body fat, heart rate, blood pressure and similar values, plus values and scores derived from them.
3. Legal basis and purposes
Health data is a special category of personal data (art. 9 GDPR). We process it solely on the basis of your explicit consent, given at registration and revocable at any time by deleting your account. Purposes: showing you your measurements, trends, scores and (AI) summaries, and providing the features you activate yourself.
4. Sharing
We do not share your data with anyone. There is one exception: if you join a club (via a request, invite or join link), that club's admins and coaches gain access to your account and can view and edit your data and measurements. You can leave a club at any time from your profile, which ends that access immediately.
Technically we rely on processors acting solely on our instructions: Amazon Web Services (hosting and email, Frankfurt/EU region), Google (Gemini, only to generate your AI summaries) and Withings (only if you activate that link yourself). We have data processing agreements with our processors. We never sell data.
5. Partner contact (optional)
Only with your separate consent may we contact you on behalf of partners about relevant health-related products. This is off by default, never required to use VitalGraph, and revocable at any time via privacy@vitalgraph.app. We do not hand your data to partners; communication goes through us.
6. Retention
We keep your data for as long as your account exists. If you delete your account, we delete your personal data and measurements. Logs are automatically removed after 90 days.
7. Security
Connections are encrypted (TLS), passwords are stored hashed (scrypt), the database runs in a shielded network and access is limited to what is necessary.
8. Your rights
You have the right to access, rectification, erasure, restriction, data portability (via the CSV export in the app) and objection. You can withdraw consent at any time. Complaints can be filed with the Dutch DPA (Autoriteit Persoonsgegevens).
9. Cookies and local storage
We use no tracking or advertising cookies. The app only stores functional data in your browser (login session, language, preferences).
10. Changes
We will inform you via the app or email about material changes to this policy.