Vitals Diary
Privacy Policy
Effective date: August 6, 2026
The short version: your health data stays on your device.
Vitals Diary has no accounts, no analytics, and no server that collects your
readings. We couldn't read your blood pressure records even if we wanted to.
1. Who we are
Vitals Diary is a diary app for blood pressure, heart rate and blood glucose, available for iOS and Android, developed and operated by
an independent developer (“we”, “us”). Contact: elvismiffy@gmail.com.
2. Data stored on your device only
Everything you record in Vitals Diary is stored locally on your device and is
never transmitted to us:
- Blood pressure readings, heart rate, blood glucose, measurement context tags and notes
- Your target values, reminders and medication check-ins
- The optional name you type when generating a PDF report (it is embedded in
the PDF on your device only)
Deleting the app deletes this data. If you use iCloud or local device backups,
your data may be included in those backups under Apple's terms — that is
controlled by you and Apple, not by us.
3. Camera (heart rate measurement)
Vitals Diary can measure your heart rate by asking you to rest a fingertip over
the rear camera lens while the flash stays on. This is exactly how the camera is
used:
- No photo or video is ever taken, saved or transmitted. Each
frame is reduced, in memory on your device, to a handful of average
brightness numbers used to follow the rhythm of your pulse. Frames are never
written to storage and never leave your device.
- The camera and the flash are switched on only while you are on the heart rate
measurement screen, and are switched off again as soon as you leave it,
cancel, or the measurement finishes.
- The microphone is not used. Audio capture is disabled, and on Android the
microphone permission is explicitly removed from the app.
- The only thing that can be saved is the heart rate number itself, and only if
you tap Save. It is stored in your diary on this device like any entry you
type in yourself.
- You can revoke the camera permission at any time in your device settings.
Only the heart rate measurement stops working; the rest of the app is
unaffected.
This measurement is not a medical device. It records a number for your own
records and carries no medical meaning.
4. Apple Health and Health Connect (read-only)
If you choose to connect it, Vitals Diary can bring in readings you already took
with another app or device, so you do not have to type them twice. Connecting is
optional and the app works fully without it.
- Read-only. The app asks for read access only. It never
writes, changes or deletes anything in Apple Health or Health Connect, and it
never requests write access. On Android it declares only
READ
permissions.
- What it reads: blood pressure (systolic and diastolic),
heart rate, and blood glucose. Nothing else — no steps, no sleep, no
location, no clinical or medical records, no other health category.
- What comes in is stored in the app's diary on your device, exactly like the
entries you type. It is not uploaded anywhere.
- You can revoke access at any time — on iOS in Settings › Privacy &
Security › Health › Vitals Diary, and on Android in the Health Connect app's
permission settings. Nothing further is read after that.
5. What we do not do
Vitals Diary contains no analytics SDK, no advertising SDK and no
crash-reporting SDK. Apart from validating your purchase (section 6), the app
makes no network requests at all: none of your readings, notes, camera frames
or imported health data is ever sent to us or to anyone else.
- No account or sign-up — we never ask for your name, email or phone number
- No analytics or advertising SDKs
- No sale or sharing of personal data — we have none to sell
6. Purchases
Subscriptions and one-time purchases are processed by Apple or Google Play.
We use RevenueCat to validate purchases and manage
subscription status. RevenueCat receives an anonymous, randomly generated
identifier and your purchase receipt — never your health data or identity.
See the RevenueCat Privacy Policy
and Apple Privacy Policy.
7. Face ID / Touch ID
If you enable App Lock, authentication is performed entirely by your device's operating system.
Your biometric data never leaves your device and is never accessible to us.
8. Notifications
Measurement and medication reminders are scheduled locally on your device.
No push-notification server is involved.
9. Children
Vitals Diary is not directed to children under 13 and we do not knowingly
collect any data from children.
10. Changes to this policy
If we ever change how the app handles data (for example, an optional cloud
sharing feature in the future), we will update this policy and note it in the
app's release notes before the change takes effect.
11. Contact
Questions about privacy: elvismiffy@gmail.com