Privacy Policy

vitals — a personal health-data application
Last updated 1 October 2026

vitals is a single-user application. It is operated by Aaron Pfauth for the sole purpose of retrieving his own health data into a private database that he controls. It has no other users, is not offered to the public, and no one else can sign in to it.

What it accesses

With the account holder's explicit authorization, vitals reads health and fitness data from connected services — currently WHOOP and Apple Health. Depending on the permissions granted, this may include sleep, recovery, strain, heart rate, heart rate variability, respiratory rate, blood oxygen, body measurements, workouts, blood glucose, and journal entries.

It requests read-only access. It does not write, modify, or delete data in any connected service.

Where the data goes

Retrieved data is stored in a private database on a server operated by the account holder. It is not sent anywhere else.

Access to the database requires authentication and is limited to the account holder. Data in transit is encrypted.

How long it is kept

Indefinitely, at the account holder's discretion — the purpose of the application is to maintain a personal long-term health history. It can be deleted at any time, by the account holder, by deleting the database.

Revoking access

Authorization can be withdrawn at any time from the connected service's own settings — for WHOOP, under the account's connected apps. Revoking access immediately stops any further retrieval.

Cookies and tracking

This page sets no cookies and contains no analytics or tracking of any kind. It stores a single light/dark theme preference in your browser, which never leaves your device.

Children

vitals is not directed at children and has no users other than its operator.

Changes

Any change to this policy will be published on this page with an updated date above.

Contact

Questions about this policy: vitalsapp@thepfauths.com