Privacy
Last updated July 27, 2026
vitals is a small, private, invite-only tool that a family uses to keep one person's medical care in one place. It is not a commercial product and it is not sold, advertised against, or open to public sign-up. This page describes exactly what it stores and who else touches that data.
What is stored
- Account details. Your name and email address, from signing in with Google, plus which patients you have been given access to and at what level.
- Health information you enter. Appointments, questions for the doctor, notes, care team contacts, lab results, medications, and uploaded documents such as pathology or imaging reports.
- Visit recordings. If you record an appointment, the audio, its transcript, and any summary generated from it.
- Connected-service credentials. If you connect Google Calendar (or, later, a patient portal or fitness account), the access tokens for that connection. These are encrypted before they are stored and are never sent to the browser.
- Feedback you send through the app, and the replies to it.
Who else processes it
vitals runs on services that necessarily see some of this data in order to do their job. No one else does.
- Vercel — hosting. Turso — the database. Cloudflare R2 — uploaded documents and recorded audio.
- AssemblyAI — turns recorded audio into a transcript. Anthropic — turns a transcript into a summary. Under both services' API terms, this content is not used to train their models.
- Google — sign-in, and calendar sync if you connect it. Resend — sends the app's email.
- Analytics is a self-hosted, cookieless Plausible instance that counts page views. It sets no cookies, follows no one across sites, and receives no health information.
Data is never sold, never shared for advertising, and never used to train anyone's models.
Data from patient portals
Where vitals connects to a health system or lab (for example Epic/MyChart or Labcorp), it does so only after the patient authorizes it through that provider's own login, and it requests read-only access. It reads lab results, medications, visit documents, and reports, and it writes nothing back. Every value keeps a label showing where it came from, and nothing is ever estimated or filled in. You can revoke that access at any time from the connected account's own security settings, or by disconnecting it in vitals.
Who can see what
Access is per patient. Someone invited to one person's circle sees that person's information and nothing else, at the level they were given. Recordings and documents are served only through access-checked links, never public URLs.
Keeping it safe
- Everything travels over HTTPS.
- Connected-service tokens are encrypted at rest with AES-256-GCM and are never serialized to a browser.
- Inbound webhooks are signature-verified before they are trusted.
- Every read and write is checked against the requester's access to that patient.
No system is perfect, and this is a family project rather than a hospital system. It is built carefully, but it should not be your only copy of anything that matters.
Keeping and deleting data
Information is kept as long as the patient's circle wants it. You can delete recordings, documents, notes, and appointments in the app, and deleting a recording deletes its audio, transcript, and summary. You can also delete a patient's entire record, or close your own account, from Settings. Both take effect immediately and cannot be undone. Whatever you delete also leaves any backups it appears in within 30 days.
Children
vitals is used by adults managing care for members of their own family. It is not offered to the general public and no one signs themselves up.
Changes
If this policy changes, the date at the top changes with it, and anyone using the app is told directly — there is a known, small number of people using it.
Contact
Questions or concerns: hoffman.esther@gmail.com. Deleting a record or closing an account is something you do yourself, in Settings — but if anything there is not working, this is the address to use.