Privacy Policy
This policy explains what data VitaLog processes, why, where it lives, and the choices and rights you have over it.
Effective July 25, 2026 · Version 1.0.0
On this page
Overview
This Privacy Policy applies to the VitaLog mobile application and this website, operated by Greymet Technology("VitaLog," "we," "us"). It is written to align with India's Digital Personal Data Protection Act, 2023 (DPDP Act), and to reflect principles found in the General Data Protection Regulation (GDPR), the U.S. Health Insurance Portability and Accountability Act (HIPAA), and the California Consumer Privacy Act (CCPA).
This document is provided for general informational purposes and does not constitute legal advice. Before publishing this policy for a live product handling real user data, it should be reviewed by qualified legal counsel in every jurisdiction VitaLog operates in.
Our core principle
VitaLog is built offline-first. Your health records are processed and stored on your device by default, inside an encrypted local database. Cloud backup, AI features, and wearable sync are optional, independently revocable features you choose to turn on — VitaLog does not operate a central server that stores your health records by default.
Data we process
Depending on how you use VitaLog, the following categories of data may be processed:
- Profile information — name, date of birth, gender, blood group, medical conditions, and allergies you choose to enter.
- Health records — lab reports, prescriptions, vitals, symptoms, medications, appointments, and any images or documents you scan or import.
- Wearable data — steps, heart rate, sleep, and similar metrics, only if you connect Apple Health or Health Connect.
- AI interaction content — the specific text or document content sent to a configured AI provider when you use an AI-powered feature.
- Technical & usage data — device type, crash reports, and basic diagnostic information used to keep the app reliable.
- Contact details — only if you reach out to us directly, for example through the contact form on this website.
How your data is stored
Health records are stored locally in an encrypted database protected by a 256-bit key held in your device's secure hardware storage. If you enable cloud backup, an encrypted copy is written to a private folder and spreadsheet inside your own Google account. VitaLog does not store a copy of your health records on infrastructure it operates.
AI features & your data
AI Document Processing is an independently revocable consent option. When enabled, only the specific content relevant to a single request — for example, the text of one report or one chat message — is sent to the configured AI provider to generate a response. This content is used to service your request and is not used by VitaLog to build an advertising profile of you. With AI features disabled, scanning and extraction still work using on-device processing only.
Legal basis & consent
Where the DPDP Act applies, VitaLog relies on your free, specific, informed, and unconditional consent — given through a clear affirmative action — as the basis for processing personal data, consistent with Section 6 of the Act. Consent is collected separately for four purposes: core local processing, AI document processing, cloud backup and sync, and wearable sync. Each can be withdrawn independently at any time from within the app, with the same ease it was given.
Where GDPR applies, the equivalent legal bases are your consent (Article 6(1)(a)) and, for basic app functionality, the performance of a contract with you (Article 6(1)(b)).
Your rights
Subject to applicable law, you may have the right to:
- Access a summary of the categories of data held about you.
- Correct inaccurate or outdated information.
- Erase your account and all associated local and cloud data.
- Withdraw consent for any optional processing purpose at any time.
- Nominate another individual to exercise your rights on your behalf in the event of death or incapacity, consistent with Section 14 of the DPDP Act.
- Lodge a complaint with us, and where applicable, with your local data protection authority.
Most of these actions are available directly inside the app. For anything else, contact us using the details below.
Children's data
Where a profile is created for a minor, VitaLog requires the name and contact details of a parent or lawful guardian before that profile can be used, consistent with Section 9 of the DPDP Act. VitaLog does not use children's data for behavioural monitoring, tracking, or targeted advertising.
Data sharing & third parties
VitaLog does not sell personal data, and does not share it with advertising networks or data brokers. Data may be processed by the following categories of service providers, only for the purposes you've enabled:
- Google (Drive, Sheets, Sign-In, Health Connect) — only if you enable cloud backup or Android wearable sync, writing to your own Google account.
- Apple (HealthKit) — only if you enable Apple Health sync on iOS.
- AI providers — only for the specific request content described above, when AI features are enabled.
- Crash reporting and infrastructure providers — limited technical diagnostic data used to keep the app stable.
We may also disclose data where required to comply with a valid legal obligation, such as a lawful court order.
Data retention
Your health records are retained locally on your device for as long as you keep them, or until you delete your account. Deleting your account removes local data immediately and, where cloud backup was enabled, initiates removal of the corresponding backup. Limited technical logs may be retained for a short period for security and reliability purposes.
International transfers
Where an AI provider or infrastructure service processes data outside your home country, we take steps intended to ensure an equivalent standard of protection, such as relying on providers with recognized data-protection safeguards. If you have questions about a specific transfer, contact us using the details below.
Security measures
We apply layered technical safeguards including on-device encryption, biometric and PIN locking, secure hardware-backed credential storage, and optional zero-knowledge backup encryption. The full technical detail is available on our Security & Compliance page.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by an updated effective date and version number at the top of this page, and where required by law, we will prompt you to review and re-consent before continuing to use affected features.
Contact & grievance officer
For privacy questions or data-rights requests, contact us at support@greymet.in. For formal grievances under the DPDP Act, our designated Grievance & Data Protection Officer can be reached at support@greymet.in.