VitaLog
Security & compliance

Designed so even VitaLog can't read your records without you

Every layer below — device, unlock, and optional backup — is built around one principle: your health data should require your presence to be useful to anyone, including us.

Defense in depth

Four layers, each independently protective

1

On your device

Your local database is encrypted at rest with a 256-bit key held in your device's secure hardware storage — not in ordinary application storage.

2

Getting back in

The app locks automatically after a period in the background. Biometric authentication or a 6-digit PIN is required to unlock it again.

3

If backup is enabled

An optional zero-knowledge layer can encrypt data with a passphrase only you know before it's ever uploaded — that passphrase is never stored anywhere, including on VitaLog's own systems.

4

Where it's backed up

Structured backups go to a private folder and spreadsheet inside your own Google account. There is no central VitaLog database holding your records.

Technical controls

What's actually protecting your data

AES-256 encryption at rest

The full local database is encrypted, not just individual fields.

Biometric & PIN lock

Auto-lock after inactivity with Face ID, fingerprint, or PIN to resume.

Panic wipe

Five failed PIN attempts (or an emergency gesture) trigger a safety backup, then secure key deletion.

Minimal AI exposure

Only the specific content needed for a single AI request is ever sent to a provider — never your full record.

Secure credential storage

Tokens and API keys are kept in hardware-backed secure storage, never plain preferences.

Your own cloud, not ours

Optional backup writes only to a Google Drive and Sheets you own and control.

Compliance principles

Aligned with DPDP, HIPAA, GDPR, and CCPA

VitaLog's data-handling model draws on India's Digital Personal Data Protection Act, 2023 as its primary framework, applying HIPAA, GDPR, and CCPA-style protections throughout.

Granular, revocable consent

Core local processing, AI document processing, cloud backup, and wearable sync are four independent toggles — not one bundled agreement.

Right to access

A live, in-app summary shows exactly how many records of each type are stored about you.

Right to correct & erase

Correct any record yourself, or permanently delete your entire account and all associated data in one action.

Grievance redressal

A dedicated channel routes data-protection concerns to a named contact, with every request logged for your own reference.

Found a security issue? We want to know.

Please report vulnerabilities responsibly to support@greymet.in rather than filing a public issue. We aim to acknowledge every report within a few business days.