♥
VitalHowHealth

Privacy

VitalHow Health privacy notice

Draft product notice for the private/test deployment. Review with appropriate legal/compliance advice before offering VitalHow as a public health-data service.

What VitalHow stores

VitalHow stores health information that you enter or explicitly sync, including blood pressure and, when you use the Android Health Connect companion, the Health Connect categories you grant: blood pressure, heart rate, steps, sleep, blood oxygen, weight and exercise.

Health Connect access

The current companion requests read-only Health Connect permissions. It does not write data back to Health Connect. Sync is initiated by you in the companion app and is limited to the supported recent-history window. You can deny or revoke Health Connect permissions at any time in Android settings.

How synced data is used

Selected Health Connect data is transmitted over HTTPS to your configured VitalHow server and stored under your VitalHow account to provide history, trends, summaries and reports. VitalHow does not use Health Connect data for advertising.

Account and device access

The Android companion uses a separate revocable mobile access token. The token is stored encrypted using Android Keystore. Disconnecting the companion revokes that device token on the VitalHow server.

Control

You can stop future syncs by revoking Health Connect permissions or disconnecting the companion. The web application will add self-service health-data deletion/export controls as the public-release privacy workflow is completed.

Important deployment note

Health information is sensitive personal data. Before opening public registration, complete the privacy notice, retention/deletion rules, consent workflow, security review and any approvals or permits applicable to your jurisdiction.