Privacy notice
Status: launch-blocking draft. Replace bracketed operator/contact fields and obtain jurisdiction-appropriate legal review before public production use.
Controller/operator: [OPERATOR LEGAL NAME AND ADDRESS]
Privacy contact: [PRIVACY CONTACT EMAIL]
Effective date: [EFFECTIVE DATE]
The short version
Titration Vault is designed so that its core health tracker works without an account and keeps health records on your device. We do not sell your health data, use it for advertising or profiling, or use it to train AI or machine-learning models.
If you create an optional sync account, your health vault is encrypted in your browser before upload. The service stores ciphertext and does not receive your recovery secret. Authentication lets an account retrieve its ciphertext; it is not a master decryption key. Each upload is kept as an encrypted version: every version for 7 days, then one per day to 30 days, one per week to 6 months and one per month to 2 years, and named snapshots until you delete them. The service also keeps, for each version, its size, upload time, a random device ID and integrity hashes, and for each device a public signing key and an encrypted name. It stores no IP address. Deleting the account removes all of it at once. The full list is in the sync documentation (docs/SYNC.md).
Information you may choose to store locally
You can record blood pressure, pulse, weight, menstrual-cycle events, sleep, mood, symptoms/side effects, medication/dose history, device details, custom observations, notes and optional profile information. These fields are optional unless a particular entry needs a value to be meaningful.
Information processed by optional online services
If you create an account, the service processes a random account identifier, authentication-token hash, account status, timestamps and encrypted-vault metadata. If you enable Web Push, it processes your push endpoint, timezone and reminder times. Anonymous statistics, described below, carry no identifier.
Closed beta invite requests
If you ask for an invite on titrationvault.com, we keep your email address, the country or region you chose and
the day you asked, so we can review the request by hand. Once reviewed, we also keep whether we have approved or
declined it and the day we decided. Access is not automatic, and we send an invite only if we approve it. We do
not store your IP address or any other detail of the request. The record is deleted automatically 180 days after
you asked, or sooner if you ask. Cloudflare stores it for us.
Feedback
If you use Send feedback in the app, your message, your reply email if you add one, and the technical details you
choose to include are filed as a private issue in our GitHub repository. The app warns you if a message looks like
it contains health information. No IP address, account or record is sent. The report is read by us and by an
automated assistant that sorts reports and suggests fixes. Ask us to delete a report at any time.
What we do not do
- No sale or rental of health data.
- No advertising or cross-site behavioural profiling using health data.
- No data-broker use.
- No AI/model training on health data.
- No health values in anonymous statistics, server application logs by design, or public repository fixtures.
- No operator master key for decrypting synced health vaults.
When health data can leave your device
Only when you take an explicit action that requires it, such as exporting/sharing a readable file, connecting a third-party health service, or enabling encrypted sync. A third-party integration has its own privacy terms and may necessarily process data you ask to exchange with it.
Anonymous statistics
The app counts which screens and features are used, so the service can be improved. Each count is an allow-listed event name with a screen size class, whether the app is installed, the build number and the day; your country region is worked out from the connection and nothing else about it is kept. There is no identifier, cookie or IP address in what is stored, only daily totals, deleted after 25 months, so there is nothing that could be traced back to you or erased for you.
In the United Kingdom, United States, Canada, Australia and New Zealand statistics are on by default and the app tells you once, with a one-tap way to turn them off. In Ireland, the rest of Europe and elsewhere, or when your device's time zone and language say you are somewhere else, they stay off unless you choose to share. You can change this at any time in Settings > Privacy, which lists exactly what is sent. Global Privacy Control and Do Not Track switch statistics off. The site also counts app update checks and guidance pack fetches, which happen anyway, even when the switch is off; it never counts them when your browser sends Global Privacy Control or Do Not Track, and they carry no identifier. [OPERATOR: confirm the lawful basis for each country after legal review.]
Your controls
You can export your data, import it, use encrypted backups, disable integrations, disconnect sync, delete your online account/ciphertext, and erase local app state. Production backup retention and the time required for deletion from disaster-recovery copies must be stated here truthfully before launch.
Security
The design uses client-side AES-256-GCM encrypted vault bundles, high-entropy recovery secrets, least-privilege server endpoints, admin audit logging and source/repository secret scanning. No security control makes risk zero. A production service must maintain vulnerability handling, incident response, key-management and access-control procedures.
International users
The initial scope is the United Kingdom, United States, Canada, Australia, New Zealand and Ireland. Applicable privacy rules differ. The operator must document the actual lawful basis/consent model, controller/processor roles, international transfers, retention, breach obligations and user rights for each country before launch.
Contact and complaints
[INSERT OPERATOR CONTACT, PRIVACY CONTACT, AND RELEVANT SUPERVISORY-AUTHORITY INFORMATION AFTER LEGAL REVIEW]