Privacy Policy
Last updated: March 10, 2026
1. Data We Collect
When you use Vitals, we collect the following data:
- Google OAuth: Email address, display name, and profile picture from your Google account.
- YouTube Data API v3: Channel ID, channel title, Shorts metadata (video IDs, titles, view counts, likes, comments, duration, publish dates).
- YouTube Analytics API v2: Impressions, click-through rate, average view percentage, subscribers gained (when you grant Analytics access).
- Stripe: Customer ID and subscription status. We do not store your payment card details — those are handled entirely by Stripe.
2. How We Use Your Data
Your data is used exclusively to:
- Generate AI-powered diagnostic reports for your YouTube Shorts.
- Store diagnostic history so you can track changes over time.
- Manage your subscription and billing status.
We do not sell, rent, or share your data with third parties for marketing purposes.
3. Third-Party Services
Vitals uses the following third-party services that may process your data:
- Google (YouTube API Services): Channel and video metadata access. Subject to the Google Privacy Policy.
- Supabase: Database hosting (EU, Frankfurt). Stores your profile, diagnostic runs, and Short-level results.
- Stripe: Payment processing. Subject to the Stripe Privacy Policy.
- OpenAI: AI analysis. Your Shorts metadata (titles, view counts, engagement data) is sent to OpenAI for scoring. Subject to the OpenAI Privacy Policy. Data sent via API is not used by OpenAI for model training.
- Vercel: Application hosting. Subject to the Vercel Privacy Policy.
4. YouTube API Services Disclosure
Vitals' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can revoke Vitals' access to your YouTube data at any time by visiting the Google Security Settings page and removing the Vitals app.
5. Cookies
Vitals uses essential cookies only: a session cookie for authentication. We do not use tracking cookies, advertising cookies, or analytics cookies. No cookie consent banner is required because we only use strictly necessary cookies.
6. GDPR Rights
If you are located in the European Economic Area (EEA), you have the right to:
- Access: Request a copy of all personal data we hold about you.
- Rectification: Request correction of inaccurate data.
- Erasure: Request deletion of your personal data.
- Portability: Request your data in a machine-readable format.
- Objection: Object to processing of your personal data.
To exercise any of these rights, contact us at support@vitals.dev. We will respond within 30 days.
7. Data Retention
Active accounts: data is retained for the lifetime of the account. Cancelled subscriptions: diagnostic history is retained for 90 days, then permanently deleted. Deleted accounts: all associated data is permanently deleted within 30 days.
8. Children
Vitals is not intended for users under 13 years of age. We do not knowingly collect data from children under 13. If we learn that we have collected data from a child under 13, we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy at any time. Material changes will be communicated via email. Continued use of the Service after changes constitutes acceptance.
10. Contact
For privacy-related inquiries, contact us at support@vitals.dev.