Privacy policy

Your privacy and data security are our top priorities.

Effective Date: October 7, 2026
Company: Crow and Raven Inc., Boulder, CO

1. Introduction

Vitros is a health and wellness platform operated by Crow and Raven Inc. ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This privacy policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

This policy applies to all information collected through our website, mobile applications, and related services (collectively, the "Service"). By using our Service, you consent to the data practices described in this policy.

Effective Date: October 7, 2026
Company: Crow and Raven Inc., Boulder, CO

2. Information we collect

2.1 Personal identifiers

We collect the following personal identifiers to provide authentication and personalize your experience:

  • Account information: Name, email address, account credentials, and profile information
  • Contact information: Email address for communications and account recovery
  • Demographic information: Age, gender (optional, for personalized insights)

Use: Authentication, account management, and personalized content delivery. This information is never shared with third parties for marketing purposes.

2.2 Commercial information

We collect payment and subscription information to process your purchases:

  • Payment information: Credit card details (processed securely by Stripe)
  • Purchase history: Subscription tier, billing history, and transaction records

Use: Account and financial purposes only. Payment card details are handled exclusively by Stripe and never stored on our servers.

2.3 Health and wellness data (sensitive personal information)

With your explicit consent, we collect health-related information to provide personalized insights:

  • Activity tracking: Steps, exercise, sleep patterns, and daily routines
  • Biometric data: Heart rate, weight, blood pressure (if provided)
  • Nutrition information: Dietary habits and preferences
  • Mental wellness: Mood tracking, journal entries, and wellness notes
  • Health goals: Personal objectives and progress tracking
  • Connected devices: Data from third-party health apps and wearables (with your permission)

Use: Providing personalized health insights, tracking your progress, and improving Service features. This sensitive information is never sold or shared with third parties. You have the right to limit our use of this information beyond what is necessary to provide the Service.

2.4 Internet activity and usage data

We automatically collect technical information to improve the app and user experience:

  • Device information: Device type, operating system, browser type
  • Usage data: Features used, time spent in app, user interactions
  • Log data: IP address, access times, error logs
  • Cookies: Authentication cookies and essential functionality cookies

Use: Tracked within the app to improve user experience, troubleshoot issues, and optimize performance. This data is not shared with third parties except as described in Section 4.

2.5 Geolocation data (optional)

With your explicit permission, we may collect location data:

  • Precise location: GPS coordinates (only if you enable location services)
  • Approximate location: City/region based on IP address

Use: Location data is used only to enhance your experience (e.g., local recommendations) and is never shared outside the app. You can disable location tracking at any time through your device settings.

2.6 Calendar data (optional)

If you connect a calendar, Vitros adds the events you've attended to your private journal, so you can see how your days were spent alongside your mood, sleep and activity. You can connect the calendars on your phone (iCloud, and any account your phone syncs) and, separately, Google Calendar. From the calendars you choose, and only once an event has ended, we read:

  • Event details: the title, start and end time, location, and whether it had a video-call link
  • People: how many people were invited, the first names of the other people on it, and whether you declined
  • Event type: for Google Calendar, whether Google marks it as Focus time or Out of office
  • Your calendar list: the names and colours of your calendars, so you can choose which to include

Event descriptions, notes, attachments and other people's email addresses are never sent to us or stored. (On your phone, an event's notes are checked for a video-call link on the device; from Google Calendar we don't request them at all.) Our access is read-only: we can't create, change or delete anything on your calendar.

Private events. An event whose title contains a word you mark as private (by default words like “therapy” and “doctor”) is saved only as a generic label such as “Therapy”. For the calendars on your phone, its title, place and people never leave your device. For Google Calendar, they reach our server from Google but are discarded before anything is stored or sent to an AI provider. You can also keep every title on a calendar private.

AI processing. To recognise what kind of event something is (for example, that “Dinner at Chez Thuy” is a meal), we send its title, time and location to an AI provider as described in Section 4.3. Other people's names are never sent.

Your control. You choose which calendars are included and can change that at any time. You can delete any imported event, and it won't be imported again. Disconnecting a calendar stops all further access; for Google Calendar it also revokes our access at Google. Deleting your account deletes everything imported. Google Calendar access tokens are encrypted at rest.

Google user data. Vitros's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar data only to show your events in your journal. We don't sell it, use it for advertising, let people read it (except where you ask us to, for support, or where the law requires), or use it to train generalized AI models.

Use: Showing your events in your private journal and insights. Calendar data is never sold or shared with third parties except the AI processing described in Section 4.3.

2.7 Health Connect data (Android, optional)

On Android, you can connect Vitros to Health Connect so the activity your phone and fitness apps record shows up in Vitros without logging it twice. Nothing is read until you connect it in Profile → Integrations and grant each permission on Android's Health Connect screen. Our access is read-only: we never write to, change or delete anything in Health Connect. With the permissions you grant, we read:

  • Steps: your daily step count, saved as a steps entry for each day in your Activities and counted toward step goals in Habits
  • Sleep: how long you slept each night, saved as a sleep entry and counted toward sleep goals in Habits
  • Resting heart rate: your daily resting heart rate, saved as an entry so you can follow it over time
  • Active calories burned: your daily active calories, saved as an entry, and the active calories for each imported workout
  • Exercise sessions: each workout's type, start time and duration, imported as an activity and counted toward exercise goals in Habits
  • Workout details: for each imported workout, the distance covered, elevation gained, total calories burned, and the heart-rate readings recorded during it (shown as average and maximum heart rate and a heart-rate chart)

We don't read cycling cadence, step cadence or any other Health Connect data type. Vitros reads Health Connect while the app is open; it doesn't read it in the background.

How it's used. Health Connect data is used only to show you your own activities, habits and the insights built from them. We don't sell it, use it for advertising or marketing, share it with data brokers, or use it to train generalized AI models. When you ask Explore a question, the entries it needs to answer, including ones imported from Health Connect, may be sent to an AI provider as described in Section 4.3.

Your control. You can turn off any permission at any time in Android's Health Connect settings, and Vitros stops reading that data type. Disconnecting Health Connect in Profile → Integrations stops all further reading. Entries already imported stay in Vitros until you delete them. You can delete any of them individually, and deleting your account deletes all of them.

Use: Showing your activity, sleep and heart-rate data in your private Activities and Habits. Health Connect data is never sold or shared with third parties except the AI processing described in Section 4.3.

3. How we use your information

We use the information we collect for the following specific purposes:

  • Service delivery: Provide, maintain, and improve our Service features and functionality
  • Personalization: Generate personalized health insights, recommendations, and content based on your activity and preferences
  • Progress tracking: Track your progress toward health and wellness goals
  • Communications: Send you important updates, notifications, and respond to your inquiries
  • Customer support: Provide technical support and respond to your questions
  • Research and analytics: Conduct anonymized research and analytics to improve our algorithms and Service (no personally identifiable information)
  • Security: Ensure security, prevent fraud, and protect user accounts
  • Legal compliance: Comply with legal obligations and enforce our terms

We will never use your health information for marketing purposes without your explicit consent.

4. Information sharing and disclosure

We do not sell your personal information for monetary compensation.

We never sell your health and wellness data, journal entries, or other sensitive personal information. We share limited content only with service providers as described in this policy for the sole purpose of operating and improving the Service. Your personal health journey is private and belongs to you.

4.1 Service providers

We share limited information with trusted service providers who help us operate our Service:

  • Cloud infrastructure: Vercel (for web hosting, data storage, and computing)
  • Payment processing: Stripe (for secure payment handling - they never share your payment details with us)
  • Analytics and monitoring: Google Analytics (with your consent) and Sentry (error monitoring, and masked session replay with your consent)
  • Email communications: Resend (to send you service notifications and updates)

All service providers are bound by strict confidentiality agreements and are prohibited from using your data for any purpose other than providing services to us. They do not have access to your health and wellness data.

4.2 Marketing and advertising (sharing under CCPA)

For marketing purposes only, we may share limited, non-sensitive information:

  • Email addresses: Shared with advertising platforms (Facebook, Instagram, LinkedIn, TikTok) for custom audience targeting and remarketing
  • Anonymous identifiers: IP addresses and device IDs may be shared with analytics and advertising services

Important: We only share identifiers (email addresses, IP addresses, device IDs) for remarketing purposes. We never share:

  • Your health and wellness data
  • Journal entries or personal notes
  • Biometric information
  • Location data
  • Any sensitive personal information

Under California law (CCPA/CPRA), this sharing of identifiers for advertising purposes may be considered "sharing" even though no money changes hands. You have the right to opt out of this sharing at any time. See Section 6 for details on exercising your privacy rights.

4.3 AI Processing Providers

To provide summaries, reflections, transcription, and other AI-powered features, Vitros securely transmits user-generated content (such as journal entries, activity descriptions, prompt responses, calendar event titles and places, and optional audio recordings) to trusted third-party AI service providers, including OpenAI, LLC and/or Anthropic PBC.

These providers process the data solely to generate responses and insights within Vitros. They do not use your data for advertising and do not use your data to train their models.

Data is transmitted securely and processed only as necessary to provide app functionality. We do not grant AI providers access to your account information beyond what is required to fulfill your request.

4.4 Other sharing circumstances

  • With your consent: When you explicitly authorize us to share information with healthcare providers, family members, or other third parties
  • Legal requirements: When required by law, court order, subpoena, or government request
  • Safety and security: To protect the rights, property, or safety of Vitros, our users, or others from harm
  • Business transfers: In connection with a merger, acquisition, or sale of assets (your data will continue to be protected under this privacy policy)

5. Data security

We implement comprehensive security measures to protect your information:

  • Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access controls: Strict role-based access controls and multi-factor authentication
  • Regular audits: Ongoing security assessments and penetration testing
  • Data centers: SOC 2 Type II certified data centers with 24/7 monitoring
  • Employee training: Regular privacy and security training for all staff
  • Incident response: Comprehensive breach response and notification procedures

While we strive to protect your information, no method of transmission over the internet is 100% secure. We encourage you to use strong passwords and keep your account credentials confidential.

6. Your privacy rights

You have the following rights regarding your personal information:

6.1 General privacy rights

  • Right to access: Request a copy of your personal information
  • Right to correction: Update or correct inaccurate information
  • Right to deletion: Request deletion of your personal information
  • Right to portability: Export your data in a machine-readable format (JSON or CSV)
  • Right to restriction: Limit how we process your information
  • Right to object: Object to certain types of processing
  • Right to withdraw consent: Withdraw consent for data processing at any time

6.2 California residents (CCPA/CPRA rights)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

  • Right to know: Request information about the categories and specific pieces of personal information we collect, use, disclose, or sell
  • Right to delete: Request deletion of your personal information (with certain exceptions)
  • Right to correct: Request correction of inaccurate personal information
  • Right to opt out: Opt out of the sale or sharing of your personal information for advertising purposes
  • Right to limit: Limit the use and disclosure of sensitive personal information beyond what is necessary to provide our Service
  • Right to non-discrimination: Not be discriminated against for exercising your privacy rights

Do not sell or share my personal information

While we do not sell your personal information for money, we may share email addresses and identifiers with advertising platforms for remarketing purposes. Under California law, this may be considered "sharing."

To opt out of this sharing:

  • Email us at hello@vitros.app with "Do Not Share My Information" in the subject line
  • Adjust your preferences in your account settings
  • Use the Global Privacy Control (GPC) signal in your browser (we automatically honor GPC signals)

Important: Opting out only affects email remarketing. We will never share your health and wellness data, journal entries, or other sensitive information regardless of your opt-out choice.

Learn more about this.

6.3 How to exercise your rights

To exercise any of your privacy rights:

  • Email: support@vitros.app (for general inquiries and support)
  • Privacy requests: hello@vitros.app (for privacy-specific requests)
  • Phone: Available upon request for California residents
  • Account settings: Manage many preferences directly in your app settings
  • Mail: Crow and Raven Inc., Attn: Privacy Officer, 630 Cree Cir, Boulder, CO 80303 USA

We will respond to your request within 45 days. For GDPR requests, we will respond within 30 days. If we need additional time, we will notify you and explain the reason for the delay.

6.4 Non-discrimination

We will not discriminate against you for exercising any of your privacy rights. We will not:

  • Deny goods or services to you
  • Charge different prices or rates for goods or services
  • Provide a different level or quality of goods or services
  • Suggest that you will receive a different price or quality of services

7. Data retention

We retain your information for as long as necessary to provide our Service and fulfill the purposes outlined in this policy. Here are our retention periods by data category:

  • Account information: Retained while your account is active and for 3 years after account deletion (for legal and business purposes)
  • Health and wellness data: Retained according to your preferences. You can request immediate deletion at any time through your account settings
  • Payment and billing data: Retained for 7 years after your last transaction (for tax and accounting purposes)
  • Usage and analytics data: Raw logs retained for 90 days; aggregated and anonymized data may be retained indefinitely for research
  • Cookie consent records: Each time you accept, change, or withdraw cookie consent on our website we keep a record of the choice, the policy version, the time, a random identifier stored in your browser, and a truncated network address. We keep these for 5 years so we can demonstrate what you consented to. Withdrawing consent adds a record; it does not erase the earlier ones
  • Support communications: Retained for 3 years after your last interaction with our support team
  • Marketing email lists: Retained until you unsubscribe or request deletion
  • Legal requirements: Some data may be retained longer to comply with legal obligations, resolve disputes, or enforce our terms

You can request deletion of your data at any time through your account settings or by contacting us at hello@vitros.app. We will process deletion requests within 30 days.

Note: Even after deletion, anonymized data used for research and analytics may be retained indefinitely as it cannot be linked back to you.

8. International data transfers

Your information may be transferred to and processed in countries other than your own, including the United States. We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for countries with equivalent privacy protections
  • Certification schemes and codes of conduct
  • Additional safeguards as required by applicable law (GDPR, etc.)

9. Children's privacy

Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at support@vitros.app and we will delete the information.

For users between 13 and 18, we require parental or guardian consent before collecting any health or sensitive information.

10. Changes to this privacy policy

We may update this privacy policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:

  • Posting the updated policy on our website with a new "Last Updated" date
  • Sending you an email notification to the address associated with your account
  • Displaying a prominent notice in our Service or mobile app

We encourage you to review this privacy policy periodically. Your continued use of the Service after the effective date of the revised policy constitutes your acceptance of the changes.

For significant changes that materially affect your rights, we may require your explicit consent before the changes take effect.

11. Contact us

If you have any questions, concerns, or requests regarding this privacy policy or our data practices, please contact us:

Crow and Raven Inc.

Privacy Officer

630 Cree Cir

Boulder, CO 80303

United States

General inquiries: hello@vitros.app

Support: support@vitros.app

Account matters: accounts@vitros.app

Phone: Available upon request (for California residents)

We are committed to resolving any privacy concerns promptly and transparently. We will respond to all privacy inquiries within 30-45 days.

Last updated: Sep 30, 2026