Legal
Privacy Policy.
How App Vitals and Vitals OS handle your data. Plain English, no dark patterns.
Last updated · July 1, 2026
Introduction
Who we are.
App Vitals is the consulting business behind Vitals OS, the scheduling and engagement platform available at vitals-os.com. App Vitals operates Vitals OS as its owner and publisher. When this policy refers to "we," "us," or "our," it refers to App Vitals acting on behalf of both the App Vitals consulting business and the Vitals OS application.
This policy describes what information we collect when you visit app-vitals.com or use Vitals OS, how we use it, who we share it with, and the choices available to you. A separate section below covers data we access through the Google Calendar API.
Section 1
What we collect.
Account data. When you sign up for Vitals OS, we collect the information you provide — typically your name, email address, and the credentials or OAuth tokens used to connect third-party services you authorize.
Usage data. We record basic analytics about how the marketing site and the application are used — page views, device and browser metadata, and aggregate interaction events. We use Google Analytics on app-vitals.com for this purpose.
Content you create. Within Vitals OS, we store the scheduling, invoicing, and engagement records you create through the product. This content belongs to you.
Third-party integrations. If you choose to connect an external service (for example, Google Calendar), we access only the specific data scopes you authorize, as described below.
Section 2
How we use it.
We use the information above to provide and operate Vitals OS, authenticate you, deliver the features you've asked for (including calendar-aware scheduling), communicate with you about your account, and maintain the security and reliability of the service.
We do not sell your data. We do not use your data to train machine-learning models on your behalf or anyone else's. We do not use integration data (including Google Calendar data) for advertising or cross-service profiling.
Section 3
How we protect it.
Encryption in transit. All traffic to app-vitals.com and vitals-os.com, including the OAuth flow with Google, is encrypted with TLS. We do not serve the application or accept authentication traffic over unencrypted HTTP.
Encryption at rest. OAuth access and refresh tokens — including tokens granting Google Calendar access — are encrypted before they are written to our database. They are not stored in plaintext. The underlying database itself runs on infrastructure with encryption at rest enabled at the platform level.
Access controls. Application data is partitioned by service, and access to sensitive operations (such as connecting additional OAuth scopes) is gated to authorized administrators. Engineers do not have standing access to production OAuth tokens outside of the systems that need them to operate the product.
Data minimization. We request the minimum OAuth scopes required for the feature you're using, we don't run background scans or bulk exports of connected Google data, and Calendar data is only ever accessed in direct response to an action you take in the product.
Retention and deletion. Google Calendar tokens and associated data are retained only for as long as your account is active and the integration remains connected. Revoking access — either from your Vitals OS account settings or from your Google Account permissions page — stops further access and removes the stored tokens.
Section 4
Google Calendar Data.
Disclosure
Vitals OS accesses your Google Calendar data via the Google Calendar API with your explicit authorization. We use this data solely to display your calendar availability and schedule within the Vitals OS platform. We do not sell, share, or use Google Calendar data for advertising, analytics unrelated to the service, or any purpose beyond providing you the scheduling features of the app. You can revoke access at any time via your Google Account settings.
Google Calendar data is accessed only while you are actively using Vitals OS features that require it. We do not run background scans, bulk exports, or persist calendar data beyond what is required to render availability and manage events you've initiated. To revoke access, visit your Google Account permissions page.
Section 6
Your rights.
You can request a copy of the personal data we hold about you, correct inaccuracies, or ask us to delete your account and associated content. You can revoke any third-party integration — including Google Calendar — at any time from the integration provider's settings.
To exercise any of these rights, email us at the address below and we will respond within a reasonable timeframe.