Privacy policy
VitalSpoke gives you control over which Apple Health records you view and export. This policy explains what the app and the VitalSpoke service handle when you use those features.
Who operates VitalSpoke
The hosted service at vitalspoke.ai is operated by myrandomcompany Incorporated, a Delaware corporation in the United States. Company website: myrandomcompany.com.
Registered office: c/o Firstbase Agent LLC, 1007 N Orange St, 4th Floor Ste 1382, Wilmington, DE 19801, United States.
Mailing address: 447 Broadway, 2nd FL 2913, New York, NY 10013, United States.
Contact: admin@myrandomcompany.com · +1 859 251 3498.
The Apple developer account currently used for the iOS app is held by Freedom Technologies Pty Ltd. The hosted-service operator identified above handles the VitalSpoke service and privacy requests described on this site.
Health information
With your permission, the iPhone app reads these Apple Health categories: steps, heart rate, resting heart rate, heart-rate variability, active energy, sleep, and workouts. Access is read-only. You choose the categories and date range for each manual export; VitalSpoke does not claim continuous or background collection.
The app sends only the records you select to the VitalSpoke server you configure. A local demo can use sample data without uploading it. Apple may make a denied HealthKit permission look the same as an empty result, so VitalSpoke cannot treat a missing result as proof that no data exists.
Information the service handles
- Exported records: selected values, units, dates, source names, and sample identifiers, plus the category and date range needed to provide the export.
- Account information: an account identifier, an Apple or Google provider subject identifier when you use those sign-in methods, sessions, and account settings. Email accounts also store your email address, a salted password hash, email-verification state, and hashed verification or recovery codes with expiry times. Passwords are not stored in plain text. Accounts are not implicitly linked because email addresses match.
- Provider sign-in data: Google Sign-In’s bundled SDK may process name, email address, phone number, user or device identifiers, coarse location or IP-related metadata, and other usage data for sign-in functionality, fraud prevention, and the analytics purposes declared by that SDK. VitalSpoke does not read every Google profile field and does not operate Google Analytics or Firebase.
- Connector information: the selected scope, date window, creation and expiry times, revocation state, and a hash of a connector key. The raw connector key is shown once for you to copy and is not included in connector instructions.
- Device and export identifiers: a persistent per-install device identifier used with exported records for idempotent record identity.
- Purchase history: StoreKit transaction evidence and product or entitlement state sent to the configured Vital server for account-scoped subscription access. Apple and Stripe handle payment details.
How we use information
We use this information to display your selected records, complete exports, authenticate your account, enforce connector scope and expiry, provide support, protect the service, and provide subscription features. VitalSpoke does not use health information for advertising, analytics, or model training; sell it to advertising platforms, data brokers, or resellers; or use it for cross-app tracking. VitalSpoke does not add an advertising SDK or separate analytics product, but the bundled Google Sign-In SDK declares limited analytics-purpose collection in its own privacy manifest. VitalSpoke does not store Apple Health records in iCloud.
Sharing with connected tools
You can explicitly create a read-only connector for Muse. It is limited to the categories and dates you choose, expires after no more than 30 days, and can read records already exported to your VitalSpoke server. The connector key is separate from your account owner token.
Revoking a connector stops future reads by that key. It cannot recall information the connected service already retrieved. Copies already retrieved may remain in that service and must be deleted there using that service’s controls. Apple, Google, Stripe, and any connected tool process information under their own privacy notices.
Muse settings matter: Meta states that Muse conversations and tool activity may be used for model training by default, with an opt-out in Muse settings. Information retrieved through a connector may enter that activity. Review those settings before sharing; VitalSpoke cannot verify or enforce your Muse settings or delete Muse’s copies. Read Meta’s Muse safety and data-use explanation and Meta’s privacy information. VitalSpoke’s own no-training commitment does not describe Meta’s practices.
When email accounts are enabled, our configured email-delivery provider processes your recipient email address and account verification or password-reset message. Those messages contain a short-lived code; they do not contain Apple Health records or your password.
Hosting and service providers
The hosted VitalSpoke service and its local database backups run on a Hetzner server in Falkenstein, Germany. We use HTTPS for uploads and restrict access to the database and backups. Account, email, payment and connected-service providers may process their own data in other countries; German hosting does not mean all processing stays in Germany.
Optional sign-in uses Google or Apple. The server validates provider tokens against those providers and stores provider subject identifiers; when Apple sign-in is enabled it also stores an encrypted Apple refresh token so account deletion can revoke the provider grant.
ZeptoMail is the configured email-delivery provider for verification and password-reset messages. Stripe is the separate web-billing provider and receives billing/customer/subscription identifiers needed for checkout, portal access and webhook reconciliation; Stripe handles payment details. Their privacy notices describe their processing; we are reviewing the contractual safeguards that apply to our use of these providers before public launch. Muse/Meta can retrieve selected records only after you explicitly create and connect a scoped connector; its retention, training, telemetry and review practices are described by Meta and are not controlled by VitalSpoke.
Security and storage
Production traffic is sent over HTTPS. Account sessions are scoped to an account, and connector keys are stored as hashes on the server. The server stores its application database in SQLite. The deployed SQLite files and local backups are protected by filesystem permissions; this policy does not claim encryption at rest.
The production backup job makes a daily consistent SQLite backup in a private directory and removes files older than seven days. Because backups are made daily, the practical local retention is roughly eight to nine days, depending on job timing. These backups are plaintext files protected by filesystem permissions. The operator controls access to the host, database, logs, and backups.
Deletion and retention
You can sign out, revoke a connector, and request account deletion from the app’s account controls. Account deletion removes the active server account, sessions, exported records, and connector keys from the live database. A backup may retain a copy until it expires under the backup process described above. Information already retrieved by a connected tool and records retained by Apple or Stripe for their own service or accounting must be handled with those services.
To ask about a privacy request or account deletion, email admin@myrandomcompany.com. Please do not send an owner token, connector key, or full health export by email.
Your choices and privacy rights
You can withdraw Apple Health access in your iPhone’s Health settings, stop making exports, or revoke a connector in VitalSpoke. Withdrawing access stops the relevant future activity; it does not by itself delete records previously exported or information already retrieved by another service.
Depending on the law that applies to you, you may have rights to access, correct, erase, or receive a copy of your personal information, restrict or object to its processing, withdraw consent, and complain to your data-protection authority. Contact the privacy address above to exercise a right. We may need to verify that a request concerns your account; do not send sensitive identity documents or health records unless a suitable verification process has been agreed.
VitalSpoke provides record access and export tools. It does not make automated medical, insurance, employment, or eligibility decisions about you.
Changes
We will update this page when the product’s data handling changes. The updated date above indicates the current version.
For Apple’s HealthKit requirements, see Protecting User Privacy, the HealthKit Human Interface Guidelines, and the App Review Guidelines.