Legal

Privacy Policy

Effective Date: July 29, 2026 Last Updated: July 29, 2026

VitaTrax, LLC (“VitaTrax,” “we,” “us,” or “our”) provides a software platform that healthcare practices use to deliver Remote Therapeutic Monitoring and related care management programs to their patients.

This Privacy Policy explains what information we collect, how we use it, who we share it with, and what choices you have. It applies to our websites, our patient mobile application, and our provider-facing platform.

1. Start Here: Which Rules Apply to Your Information

The rules that apply depend on why we have your information. There are three categories, and they are treated differently.

Category 1: Health information we handle for your healthcare provider

If you are a patient using the VitaTrax app, nearly all of your health information is Protected Health Information (“PHI”) that we process on behalf of your healthcare provider’s practice (your “Practice”).

For this information:

  • Your Practice controls it. Your Practice is the HIPAA “covered entity.” Its Notice of Privacy Practices, not this Privacy Policy, governs how your health information may be used and disclosed.
  • We act as a “business associate” under a signed Business Associate Agreement that limits us to using PHI only as needed to provide services to your Practice, or as required by law.
  • To exercise your HIPAA rights, contact your Practice. This includes requests to access, obtain a copy of, amend, or restrict your health information, or to receive an accounting of disclosures. We assist your Practice in responding to those requests.

Category 2: Information we control directly

This includes account registration details, website visitor information, support communications, and business contact information for practice staff. This Privacy Policy governs that information.

Category 3: De-identified information

Information that has been stripped of identifiers in accordance with HIPAA’s de-identification standard. See Section 7.

2. Information We Collect

2.1 From patients using the app

CategoryExamples
Account informationName, date of birth, email address, mobile number, login credentials, and the Practice you are enrolled with
Patient-reported health dataPain scores and locations, symptom reports, functional status and activities of daily living, therapy and exercise adherence, medication adherence, journal and free-text entries, and responses to check-in prompts
Program and engagement dataEnrollment and disenrollment dates, dates and timestamps of data submissions, transmission days, check-in streaks, notification and reminder history
CommunicationsMessages exchanged with your care team through the app, and support requests you send to us
Optional connected health dataIf, and only if, you turn it on, data from Apple Health on iOS or Android Health Connect on Android, such as step counts, activity, stand time, and sleep. You choose whether to connect this and can disconnect at any time in your device or app settings.
Technical and device dataDevice type and operating system, app version, IP address, crash logs, and diagnostic information

2.2 From practice personnel

Name, professional role and credentials, work email address and telephone number, employer, login credentials, and audit records of activity in the platform, including access events and time recorded on monitoring activities.

2.3 From website visitors

Pages viewed, referring source, approximate location derived from IP address, and information you submit through contact, demonstration request, or resource download forms. See Section 5 for the tools we use.

2.4 What we do not collect

We do not collect your search queries on other services, your browsing history outside our own properties, your precise GPS location, your contacts, your photos, or microphone or camera data, except where a specific app feature requires it and you have granted permission for that feature.

3. How We Use Information

Health information (PHI) is used only to:

  • Deliver the monitoring program your Practice has enrolled you in
  • Make your data available to your Practice and your care team
  • Generate the documentation and Evidence of Care reports your Practice needs for its records and its billing
  • Provide technical support, troubleshooting, and security monitoring
  • Operate, maintain, and secure the platform
  • Comply with law and respond to lawful requests
  • Perform other functions permitted by our Business Associate Agreement with your Practice

Account, website, and business contact information is used to create and administer accounts, provide support, send service notifications, secure our systems, understand and improve how the platform is used, communicate about our products to practice contacts, and meet legal obligations.

3.1 Artificial intelligence features

The platform includes features that use artificial intelligence to help you describe what you are experiencing, to organize what you record, and to surface relevant information to your care team. We may add, change, or remove these features over time.

AI-assisted features do not practice medicine. They do not diagnose conditions, recommend or change treatment, interpret results clinically, triage you, or make any decision about your care. They do not monitor you and cannot detect or respond to an emergency. Information recorded through them is reviewed by qualified staff in the same way as information entered directly.

We do not use identifiable patient health information to train or fine-tune general-purpose artificial intelligence models. Where AI features process patient information to deliver the service, that processing is performed by vendors bound by written agreements, including Business Associate Agreements where required, that prohibit them from using the information for their own purposes, including model training.

You are never required to use a conversational feature to receive care. If you prefer not to, tell your Practice.

3.2 What we never do

  • We do not sell personal information or health information. We have not sold personal information in the preceding twelve months.
  • We do not share personal information for cross-context behavioral advertising.
  • We do not serve advertising in the patient app, and we do not use health information to target advertising.
  • We do not use patient content in marketing, promotional materials, or public demonstrations.
  • We do not share information with data brokers.

4. How We Share Information

We share information only as described below.

WhoWhy
Your Practice and care teamTo deliver your care program. This is the primary purpose of the platform.
Service providers and subcontractorsCloud hosting, infrastructure, product analytics, communications delivery, and support tooling, in each case under written contracts that limit them to acting on our instructions. Any subcontractor that receives PHI is engaged under a Business Associate Agreement imposing the same obligations that apply to us.
Legal and regulatoryWhen required by law, subpoena, court order, or lawful government request, or to establish or defend legal claims. Where we receive a request for PHI that is not accompanied by a court or tribunal order, we notify the affected Practice within the timeframe set out in the Business Associate Agreement so that it may object.
SafetyTo prevent or address a serious and imminent threat to health or safety, as permitted by law.
Corporate transactionsIn connection with a merger, acquisition, financing, or sale of assets. Any successor remains bound by the commitments in this policy with respect to information transferred, and PHI transfers only as permitted by HIPAA and the applicable Business Associate Agreement.

A current list of the subprocessors that handle information on our behalf is available on request to practices and to patients at info@vitatrax.co.

We do not share your information with advertising networks or social media platforms for their own purposes.

5. Cookies, Analytics, and Tracking Technologies

On our websites. We use cookies and similar technologies that are necessary to operate the site, remember your preferences, and understand how visitors find and use our pages. Pages that embed third-party functionality, such as our demonstration scheduling tool, may set cookies from that provider. You can control cookies through your browser settings. Blocking necessary cookies may prevent parts of the site from working.

In the patient app and provider platform. We use product analytics to understand how features are used, diagnose errors, and improve the software. The providers we currently use for this are Mixpanel and Segment, and we use Amazon CloudWatch for application and infrastructure logging. These tools receive usage and event information. Where any of them receives information that constitutes PHI, that provider is engaged under a Business Associate Agreement and is contractually prohibited from using the information for its own purposes.

We do not use advertising cookies, advertising pixels, or cross-site tracking technologies in the patient app or the provider platform, and we do not use analytics data to build advertising profiles.

Opt-out preference signals. We honor the Global Privacy Control and similar browser-based opt-out preference signals for the personal information we control.

6. Where Information Is Stored and How It Is Protected

We maintain administrative, physical, and technical safeguards designed to protect information against unauthorized access, use, alteration, and destruction, consistent with the HIPAA Security Rule. These include:

  • Encryption of data in transit and at rest
  • Role-based access controls and unique user credentials
  • Audit logging of access to patient information
  • Workforce training on privacy and security, and background screening of personnel with access to patient information where applicable
  • Vendor security review, and written data protection and business associate agreements with vendors that handle PHI
  • Documented incident response and breach notification procedures

Data location. Patient information is stored and processed in the United States.

Clinical personnel location. Clinical staff performing monitoring services under a Practice’s program are required to be located within the United States or its territories.

No system is perfectly secure. If we discover a breach of unsecured PHI, we notify the affected Practice without unreasonable delay and within the timeframe set out in the applicable Business Associate Agreement, and the Practice provides notice to affected individuals as required by law.

7. De-Identified Information

We may create de-identified information from data in the platform in accordance with the de-identification standard at 45 C.F.R. § 164.514.

De-identified information does not identify you and cannot reasonably be used to identify you. We use it to improve our products, understand how programs perform, and conduct research and analytics. We do not attempt to re-identify it, and we require anyone we share it with to agree not to attempt re-identification.

8. How Long We Keep Information

Health information is retained for as long as we provide services to your Practice, and afterward as set out in the Business Associate Agreement, which requires us to return or destroy PHI when it is no longer needed, retaining only what is necessary for our proper management and administration or to carry out legal responsibilities. Your Practice’s own record retention obligations apply independently to the copy in your medical record.

Account information is retained for the duration of the account and for a reasonable period afterward to handle support, audit, and legal matters.

Website and analytics information is retained for no longer than needed for the purposes in Section 5.

Business contact information is retained for as long as the relationship continues and afterward as needed for legal, tax, and audit requirements.

Specific retention periods by data category are available on request at info@vitatrax.co.

9. Your Choices and Rights

9.1 If you are a patient

  • Health information rights. Contact your Practice to access, obtain a copy of, amend, or restrict your health information, or to request an accounting of disclosures. Your Practice’s Notice of Privacy Practices explains these rights.
  • Withdraw from the program. Participation is voluntary. You may withdraw at any time by notifying your Practice, without affecting the care you receive. Deleting the app does not by itself end your enrollment.
  • Connected health apps. Turn any optional health data connection on or off in your device or app settings.
  • Notifications. Adjust reminder and notification preferences in the app, or opt out of non-essential messages. Discuss changes to care-related communications with your Practice first, since they may affect your program.
  • Close your account. Contact your Practice, or write to us at info@vitatrax.co.

9.2 State privacy rights

Depending on where you live, you may have rights regarding personal information we control, including the rights to know what we collect, to request access or deletion, to request correction, to opt out of sale or targeted advertising, and to be free from discrimination for exercising those rights.

Note that information we hold as a business associate for a Practice is subject to HIPAA, and most state privacy laws exempt it. For that information, HIPAA rights apply and are exercised through your Practice.

To make a request about information we control, write to info@vitatrax.co with “Privacy Request” in the subject line. We will verify your identity before responding. You may use an authorized agent where state law allows.

Appeals. If we deny your request, you may appeal by writing to info@vitatrax.co with “Privacy Appeal” in the subject line. If your appeal is denied, you may contact your state Attorney General. You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights.

9.3 California

The following describes the personal information we have collected in the preceding twelve months for individuals whose information we control. Information we hold as a business associate for a Practice is exempt from the California Consumer Privacy Act and is not included.

CategoryCollectedSourcePurposeDisclosed to
Identifiers (name, email, phone, IP address, account identifier)YesYou, your Practice, your browserAccount administration, support, security, communicationsService providers
Professional or employment informationYesPractice personnel, practicesAccount administration, platform access, business communicationsService providers
Internet or network activityYesYour browser and deviceSite and product operation, diagnostics, product improvementService providers
Geolocation (approximate, from IP address)YesYour browserSecurity and general analyticsService providers
Commercial information (services purchased or considered)YesPracticesContract administration, billingService providers
Sensitive personal informationAccount login credentials onlyYouAuthenticationService providers

We do not sell or share personal information as those terms are defined under California law, and we do not use sensitive personal information for any purpose other than those permitted without a right to limit. California residents may exercise the rights in Section 9.2.

9.4 Consumer health data

Some states, including Washington and Nevada, provide specific rights regarding consumer health data. Nearly all health information we hold is PHI processed on behalf of a Practice under HIPAA, which those laws exempt, and rights in that information are exercised through your Practice as described in Section 1.

For any consumer health data we control that is not PHI, we collect and use it only to provide the services described in this policy, we do not sell it, we do not use it for advertising, and we share it only with the service providers described in Section 4. You may request access to or deletion of that information, and withdraw any consent you have given, by writing to info@vitatrax.co. We will not condition the provision of services on your consent to collect consumer health data beyond what is necessary to deliver them.

10. Children

The platform is not directed to and may not be used by children under 13. A patient between 13 and 17 may be enrolled only by a Practice with the consent of a parent or legal guardian, in accordance with applicable law. We do not knowingly collect information from a child under 13 outside of a Practice-directed enrollment. If you believe we have, contact info@vitatrax.co and we will investigate and delete as appropriate.

11. Third-Party Services

The platform may link to or integrate with services operated by others, including your device’s health platform, your Practice’s electronic health record system, and scheduling tools on our website. Those services are governed by their own privacy policies. We are not responsible for their practices, and we encourage you to review them.

12. Where We Operate

Our services are intended for use in the United States. We do not offer them to individuals located outside the United States, and information is stored and processed in the United States.

13. Changes to This Policy

We may update this policy. We will revise the “Last Updated” date and, for material changes, provide notice through the app, by email, or by another reasonable method before the change takes effect. Changes to how we handle PHI remain subject to HIPAA and to our Business Associate Agreements with Practices.

14. Contact Us

VitaTrax, LLC

Attn: Privacy
3130 Aldridge Court
Cumming, GA 30040

For questions about your care, your enrollment, your bill, or your medical record, contact your healthcare provider’s office.

In an emergency, call 911.