Vital Atlas

Privacy Policy

30 July 2026

Vital Software Inc.

Our privacy commitments

This summary is for your convenience; the full policy below controls.

  • We aim to collect only what we need to help you find and contact a provider.
  • We do not sell your personal information, and we do not sell your health data in any form.
  • We do not put advertising or analytics trackers on pages where you upload or view health information.
  • You can access, correct, or delete your information.
  • Health information you upload is governed by Part Two — Consumer Health Data Notice below.

Part One — General Privacy Policy

Who we are and what this covers

This Privacy Policy explains how Vital Software Inc. ("Vital", "we") handles personal information collected through https://vit.al, and the Vital Care Finder application inside third-party AI assistants such as Claude and ChatGPT.

Health information you upload is also governed by Part Two — Consumer Health Data Notice below. Where Part One and Part Two differ with respect to consumer health data, Part Two controls.

Information we collect

  • Contact information — such as your name, phone number, and email, primarily so a provider can return your callback request.
  • Search and request details — the specialty, location, insurance type, symptoms or conditions, and other inputs you provide to find a provider, and the callback or appointment requests you submit.
  • Information you upload — medical documents, lab results, and photos you choose to submit through Atlas. This is consumer health data and is described in detail in Part Two.
  • Device and usage information — limited technical information such as browser type, general location derived from IP for functionality, and pages viewed. We do not use device GPS, precise geolocation, Bluetooth, or similar signals to detect your proximity to a health facility.
  • Information from the AI assistant — when you use Vital inside Claude or ChatGPT, we receive the relevant content of your request from that platform so we can respond.

How we use information

We use information to provide the Services: to return relevant provider matches, to submit your callback or appointment requests to providers you choose, to operate and secure the Services, to comply with law, and to communicate with you about your requests. We use the minimum information necessary for each purpose.

Cookies and analytics

We use Google Analytics to measure basic traffic — how many people visit, which pages they reach, and where they arrived from — so that we can improve the site. It sets first-party cookies in your browser so that several pages viewed in a row count as one visit rather than several.

You can block these cookies with your browser's cookie controls or with Google's own opt-out browser add-on; nothing on the site depends on them.

No advertising or analytics trackers on health pages

We do not place advertising pixels or marketing SDKs anywhere on the Services, and we do not place any advertising or analytics tracker — including the Google Analytics measurement described above — on pages where you upload or view health information. We do not share health information with advertising or analytics platforms. We do not use third-party software development kits that transmit health data.

How we share information

  • With providers and clinics you choose — to fulfil a callback or appointment request, and (for health information) only after you give consent described in Part Two.
  • With service providers (processors) under contract.
  • For legal and safety reasons — to comply with law, enforce our terms, or protect rights and safety.

We do not sell personal information, and we do not sell consumer health data in any form. We do not 'share' personal information for cross-context behavioural advertising.

AI processing

Vital may use AI systems and automated tools to support provider matching, extraction, summarization, routing, and user assistance. These tools are used for healthcare navigation and information purposes, not to provide diagnosis or treatment.

We do not use consumer health data to train or fine-tune foundation AI models unless we obtain a separate, specific opt-in consent. We require service providers that process consumer health data for us to use it only as instructed by Vital and under appropriate contractual protections.

Health breach notification

If your unsecured health information held by Vital is acquired or disclosed without authorisation, we will notify affected individuals, and the FTC and/or media where required, within the timelines required by the FTC Health Breach Notification Rule (generally within 60 days) and the fastest applicable state deadline (for example, 30 days in Colorado and Florida, and 45 days for Washington consumer health data under MHMD). 'Breach' includes unauthorised disclosure, not only external hacking.

Data retention and deletion

We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, completing requests, maintaining security and audit records, complying with legal obligations, resolving disputes, and enforcing agreements. When retention is no longer needed, we delete, de-identify, or aggregate the information according to applicable law and operational requirements.

When you request deletion, we delete covered information from active systems where required by law and instruct applicable service providers to delete the information from their systems. Deletion from backups and logs may take additional time, but the information will be protected and retained only as required for security, legal, or operational purposes.

Your privacy rights

Depending on your state of residence, you may have the right to:

  • Know / access the personal information we hold about you and how we use it;
  • Correct inaccurate personal information;
  • Delete your personal information (cascading to our processors);
  • Portability — receive a copy in a portable format;
  • Opt out of any sale or sharing for targeted advertising (note: we do not sell or share for these purposes); and
  • Limit the use and disclosure of sensitive personal information, including health data.

Global Privacy Control (GPC). Where required by law, we honor Global Privacy Control and similar legally recognized browser opt-out signals as an opt-out of sale or sharing for targeted advertising. Because Vital does not sell consumer health data or use it for targeted advertising, this mainly applies to any non-health-data processing that may be subject to those laws.

How to exercise your rights. Contact us at privacy@vit.al. We will verify your request and respond within the timeframe required by your state's law. You may use an authorised agent where the law allows. If we decline a request, you may appeal by contacting privacy@vit.al (Attn: Privacy — Appeals).

Non-discrimination. We will not deny you service or charge you differently for exercising your rights.

Children's privacy (COPPA)

The Services are intended for adults. We do not knowingly collect personal information from children under 13 without required parental consent. If you believe a child has provided information without required consent, contact us and we will take appropriate steps.

Security

We use administrative, technical, and physical safeguards designed to protect personal information. No system is perfectly secure. You should use caution when submitting information online, including through third-party AI assistant platforms.

Part Two — Consumer Health Data Notice

Why this notice exists

When you upload medical information to Vital directly (rather than through your hospital or clinic), Vital is acting as a direct-to-consumer personal health record provider, not as a HIPAA business associate. Your information is protected by consumer health data privacy laws rather than HIPAA. This notice explains what consumer health data we collect, how we use it, who we share it with, and the rights and consents that apply.

Consumer health data we collect

  • Health-related search inputs, such as symptoms, conditions, specialty needs, reason for visit, insurance type, location, and care preferences.
  • Information contained in documents, images, photos, or other content you submit.
  • Information extracted or inferred from submitted materials, such as medical conditions, procedures, medications, lab values, specialties, or care needs.
  • Provider matching and navigation outputs generated from health-related information.
  • Consent records and records of disclosures to providers or service providers.

Sources of consumer health data

We collect consumer health data directly from you, from information you submit through an AI assistant or MCP-compatible platform, from materials you provide, and from derived or inferred information created to provide the Services.

How we use consumer health data

We collect and process consumer health data only as needed to provide the services you request and for the purposes described in this Notice. This may include using consumer health data to:

  • provide provider search, matching, comparison, and callback request services;
  • extract limited information needed to support healthcare navigation and provider matching;
  • generate informational summaries or explanations to help you understand provider options;
  • transmit request information to a provider or clinic after any required consent;
  • operate, secure, debug, support, and improve the Services in a manner consistent with this Notice; and
  • comply with law, enforce our terms, protect safety, and maintain required records.

We do not use consumer health data to train or fine-tune AI models unless you give separate, specific opt-in consent.

We do not sell consumer health data to clinics, data brokers, advertisers, or any other third party.

We may use automated processing to help match you with providers. This is a healthcare navigation and information-retrieval function. It does not provide a medical diagnosis, recommend a course of treatment, or replace the judgment of a licensed healthcare professional.

How we disclose consumer health data

  • Providers and clinics you choose or match with, when you request outreach or appointment help and provide any required sharing consent.
  • Service providers and processors under contract, such as hosting, storage, AI processing, fax, SMS, telephony, security, and support vendors.
  • Legal and safety recipients, when required by law or necessary to protect rights, safety, or security.

Consent and withdrawal

We obtain consent where required before collecting, using, or sharing consumer health data. We use separate consent for sharing consumer health data with a provider or clinic when required by law.

You may withdraw consent at any time by contacting privacy@vit.al. Withdrawal will not affect processing that occurred before withdrawal, but we will stop future processing covered by the withdrawn consent unless another legal basis applies.

Sensitive categories

Consumer health data may include sensitive categories, such as reproductive or sexual health information, genetic information, mental health information, or substance use disorder information. Where applicable law requires separate consent or authorization for these categories, Vital will request it before the relevant collection, use, or disclosure.

Substance use disorder records

If information appears to include substance use disorder records subject to 42 CFR Part 2 and you ask us to disclose it to a provider, Vital will apply any required separate consent and include any required prohibition-on-redisclosure notice.

No sale, no targeted advertising, and no geofencing

  • We do not sell consumer health data.
  • We do not use consumer health data for targeted advertising or cross-context behavioral advertising.
  • We do not use geofencing around healthcare facilities to identify, track, collect data from, or send targeted content to consumers based on proximity to a healthcare facility.

Your rights over consumer health data

You have the right to:

  • Access or confirm whether we process your consumer health data.
  • Correct inaccurate consumer health data.
  • Delete consumer health data, subject to legal and operational limits.
  • Withdraw consent where processing is based on consent.
  • Receive a portable copy of covered data where required by law.
  • Receive information about third parties or affiliates with whom consumer health data has been shared where required by law.
  • Appeal a denied request where required by law.

How to exercise rights

Contact privacy@vit.al. We will respond within the timeframe required by applicable law.

Health breach notification

If a breach of unsecured health information occurs and we are required to provide notice under the FTC Health Breach Notification Rule or state consumer health data laws, we will notify affected individuals, regulators, and media where required and within applicable timeframes.

State-specific rights

Residents of certain states, including Washington, Nevada, Connecticut, California, Maryland, Virginia, Oregon, Colorado, and others, may have additional consumer health data or sensitive data rights. Where a state law grants greater protection, Vital will apply that protection as required.

Changes and contact

We may update this policy and will post the new effective date. Questions or requests:

Vital Software Inc.
Privacy: privacy@vit.al