Plain language.
Real practices.

Most privacy policies are written to protect the company. This one is written to tell you what actually happens to your data — and what doesn't.

Effective June 8, 2026  ·  Last updated June 8, 2026  ·  Vithropic, Inc.

We will never sell your data. Ever.
We will not sell the company for what's underneath it.
We will not compromise what this is to grow faster.

These are not policy clauses — they are decisions made before the first customer joined. The privacy practices below are the architecture of those decisions.

What this policy covers

This policy describes how Vithropic, Inc. ("Vithropic," "we," "us") collects, uses, stores, and protects information when you use vithropic.com, app.vithropic.com, the Vithropic mobile apps, and related services. It applies to all users — trial, paying, comped, and former.

This policy does not apply to third-party services we link to. Those services have their own privacy policies.

Where Vithropic operates

Vithropic is a United States-only service. This policy and your use of Vithropic are governed by the laws of the United States. If you access Vithropic from outside the United States, your data is transferred to and processed in the United States.

Our privacy promises

The first founding commitment — we will never sell your data — translates into four operational promises that govern everything below.

We don't sell. We have never sold your personal information, and we will never sell it. Not to advertisers, not to data brokers, not to insurers, not to research consortiums, not to anyone — for any consideration.

We don't share for ads. Vithropic has no advertising business. We do not share your personal information for cross-context behavioral advertising or any advertising purpose.

We don't monetize through second-order pathways. No "anonymized data" sale to third parties for their own use. No data partnerships with anyone whose business model touches user data.

No data brokers, period. We do not buy data about you from any source. The only information about you inside Vithropic is what you give us or what you authorize us to read from your device.

These are not aspirational — they are how the business is structured.

Information we collect

We collect only what is needed to build your life's intelligence layer.

Account information

  • First name (or an alias you choose)
  • Email address
  • Account creation date
  • Subscription status

We do not ask for, and do not store, your last name. We do not ask for your physical address, your phone number, your Social Security number, your full date of birth, your bank account numbers, or your routing numbers.

Profile information (you build with Cole)

Cole asks for context over time — conversationally, not via forms. Profile fields stored against your account:

  • Sex; birth year; ZIP code; income
  • Height and weight
  • Dependents; spouse or partner
  • Religious tradition (including "prefer not to say" as a first-class value)
  • Health conditions; family history
  • Retirement target age; retirement lifestyle
  • Smoking; alcohol; diet pattern; activity level
  • Income source; career stage; wealth band
  • Active goals; account types held; debt categories; insurance held
  • Longevity target; cross-domain concerns; sleep concerns; cognition concerns

Specific notes:

  • Religion includes "prefer not to say." You can decline this field without affecting anything else.
  • Family history captures coarse buckets only — long-lived family, heart conditions, cancer — each as yes / no / unsure. We do not collect specific relatives, ages of diagnosis, or specific conditions.
  • ZIP code is also used to derive your time zone (mapped to one of four coarse U.S. regions) for operational scheduling.

A note on re-identification

The combination of ZIP code, full date of birth, and sex has been shown by privacy research to uniquely identify roughly 87% of the U.S. population. We deliberately do not collect your full date of birth — only birth year. We treat the ZIP / birth-year / sex combination as sensitive and protect it accordingly.

Financial information

You upload financial documents — bank statements, paystubs, credit card statements, brokerage and retirement statements, mortgage statements, insurance declarations, tax returns, credit reports. We extract the structured line items the intelligence layer needs — transactions, balances, employer name, account types. Once extraction completes, the original document is discarded. The structured data extracted is the only persistent record.

Health and fitness data (if you connect it)

You choose whether to connect health data. The Vithropic Android app is a read-only Health Connect client — it never writes data back. Integration paths:

  • Health Connect (Android). The Android app requests 31 read-only Health Connect data types at the single permission gate, grouped below. You can revoke any permission at any time from your device's Health Connect settings; revocation stops Vithropic from reading that category from that moment forward.
  • HealthKit (iOS). When the iOS app ships, the same per-category permission model applies, with revocation from your device's Health app.
  • Keto-Mojo (direct cloud-API integration, when shipped). If you connect your Keto-Mojo glucose / ketone meter through Vithropic, the integration reads your meter test results as they sync. Keto-Mojo presents its own Terms and Privacy Policy at the authorization screen before any data flows.
Health Connect group Read-only data types requested
Activity and movement Steps, distance, floors climbed, active calories burned, total calories burned, exercise sessions (type and duration only, not routes), speed, power output, elevation gained, wheelchair pushes
Cardiovascular and respiratory Heart rate, resting heart rate, heart-rate variability, blood pressure, blood oxygen, VO₂ max, respiratory rate
Sleep Sleep sessions and sleep stages
Body composition Weight, body fat percentage, lean body mass, bone mass, body-water mass, basal metabolic rate, height
Vitals and metabolic Body temperature, basal body temperature, blood glucose, skin temperature

Raw health samples are kept in a rolling 60-day window, then dropped. From the raw samples, the intelligence layer derives baselines, variances, and patterns — the slow-moving signal Cole reasons against. Derived intelligence persists for the life of your account.

Cole conversation history

Cole carries context across your sessions and devices. Your conversation history is stored against your account. We do not sell this content, do not share it, and do not use it to train external AI models.

Usage and operational data

To keep the service running and to fix what breaks, our servers see an authentication token on every request, the data you're sending (health batches, document uploads, deletion confirmations), and standard transport-level data every HTTP request includes — your IP address and your device's HTTP User-Agent.

The Vithropic app contains no advertising or third-party tracking technology.

Information we explicitly do not collect

  • Reproductive and cycle data. Vithropic never requests permission for menstruation, ovulation, cervical mucus, intermenstrual bleeding, or sexual-activity records. These are not in the Health Connect permission set we request.
  • Location. No GPS. No operating-system location services. No exercise routes — when we read exercise sessions, we read type and duration only, never the GPS trace.
  • Genetic markers. No genetic data is requested, ingested, or stored. This is a locked architectural exclusion, not a future feature.
  • Microphone audio, voice recordings, or video. Not collected.
  • The original financial documents you upload. Removed from our processing pipeline once extraction completes — not retained in our document storage.
  • Last name, physical address, phone number, Social Security number, account numbers, routing numbers, government identification. Never requested, never stored.
  • Login credentials to any financial institution. Vithropic has no bank-login aggregation. No third-party account aggregator. We hold no keys to your accounts.
  • Payment card numbers. Handled entirely by our payment processor; we never see or store raw card data.
  • Hardware or persistent device identifiers. No IMEI, no device serial number, no Android ID, no advertising ID. Vithropic has no advertising ID anywhere in the stack.
  • Keystrokes or screen contents. No keystroke logging. No screen recording.

How document uploads work

Documents are transmitted over an encrypted connection. They are processed only to extract the structured data the intelligence layer needs. Once extraction completes, the original document is discarded. Document text is never used to train, fine-tune, or improve any AI model — by us, or by any service provider. This is a contractual restriction, not a preference.

Observational,
not diagnostic.

Cole reads your data and recommends moves with rationale. Cole is not a credentialed professional and does not give specific advice in four regulated areas:

Specific investment picks

A licensed adviser's lane.

Specific tax filing

A CPA's lane.

Legal matters

An attorney's lane.

Medical diagnosis or treatment

A physician's lane.

When a question crosses one of these lines, Cole names the right professional and what to bring them. Cole does not substitute for credentialed counsel.

How we use your information

Every use of your data serves one purpose: building your life's intelligence layer for you.

Purpose Data used Retention
Generating your Live Funded Score, Live Funded Date, and personalized observations Profile, financial, health (raw and derived) Life of account
Calibrating the intelligence layer to your specific patterns over time Profile, conversation, derived patterns Life of account
Delivering bi-weekly briefings and account communications Email, briefing content Life of account
Detecting and responding to security threats IP address, User-Agent, session logs As long as needed for security
Improving the product through aggregated, anonymized data Aggregated, anonymized signals (never individual records) Indefinite (anonymized)

We do not use your data for advertising. We do not build advertising profiles. We do not sell, rent, lease, or trade your personal information to any third party, for any purpose, ever.

How long we keep your data

  • Original uploaded documents — discarded from our processing pipeline immediately after extraction
  • Extracted financial data — life of your account
  • Profile fields — life of your account
  • Cole conversation history — life of your account
  • Raw health samples — 60-day rolling window, then dropped
  • Derived health intelligence (baselines, patterns, trajectory) — life of your account
  • Briefing history — life of your account
  • Login records — held by our authentication provider under their retention policy
  • Billing records — held by our payment processor under their retention policy
  • Subscription transaction records — as required by applicable tax law, even after account deletion

Account deletion — what happens

You can delete your account from any state — active, paused, or locked out for non-payment.

  1. Initiation. Request deletion from your account settings, or ask Cole.
  2. Confirmation. Type "DELETE MY DATA" exactly. Case-sensitive, no abbreviations. This is the single-step gate against accidental deletion.
  3. Soft-delete. Your account is immediately marked deleted. From your point of view, it is gone.
  4. 30-day grace window. If you change your mind during this window, contact us — recovery is possible via a manual admin process.
  5. Permanent purge. After the 30-day grace window, your data is permanently and irreversibly purged from Vithropic. This includes financial data, profile fields, health data (raw and derived), Cole conversation content, account history, and the account record itself. Your subscription with our payment processor is cancelled. Your authentication provider deletes your login credentials.
  6. Compliance audit record. A minimal anonymized compliance record is retained as required by law — and nothing else. Subscription transaction records may be retained as required by applicable tax law.

Permanent purge is permanent going forward. Standard operational backups age out under their normal lifecycle and are not used to restore deleted accounts.

Free and comped accounts

Some accounts are granted access at no cost — for example, founding-member programs, internal testing groups, or specific community initiatives. Comped accounts collect, store, and handle data identically to paid accounts. The privacy practices in this policy apply uniformly. A comped account does not create a payment-processor customer record.

Third parties

We use a small number of service providers to operate. Each receives only the data they need for their specific function. Each is contractually bound to use that data solely for the function we engage them for. None is paid for, or shares with us, your data for any purpose unrelated to operating Vithropic.

  • Authentication provider — email address, session tokens; for secure sign-in and account management.
  • Payment processor — first name, email, payment card details, billing address; we never see or store raw card data.
  • Cloud hosting and storage — all data, encrypted at rest; for operating the service.
  • AI processing layer — document text during processing only, scoped extraction prompts; for extracting structured fields from uploaded documents.
  • Error tracking — anonymized error logs, system telemetry; for detecting and fixing application failures.
  • Transactional email — email address, briefing content; for delivering briefings and account notifications.
  • Health-data platforms (Health Connect, HealthKit) — read-only access to permissions you have granted on your device.
  • Keto-Mojo (if connected) — account linking via OAuth; reads your meter test results as they sync.

We do not share your data with data brokers, marketing platforms, analytics resellers, ad networks, or any party whose business model involves selling or monetizing data.

We may disclose information if required by law, court order, or lawful government request. We will notify you of such requests unless prohibited by law from doing so.

Security

We encrypt your data in transit and at rest. We apply additional protections on the most sensitive fields. Access to user data is strictly limited to authorized personnel for operational purposes. We follow industry-standard security practices and continuously evaluate our posture.

A general overview of how Vithropic is architected for security — including how data is separated across our infrastructure to limit the impact of any single point of compromise — is available at vithropic.com/security.

No system is invulnerable. We invest in architectural limits so that any single compromise has the smallest possible blast radius.

What you can do
at any time.

Most rights can be exercised directly from your account settings without contacting us.

See what we hold

View every category of data Vithropic holds about you. No hidden categories.

Correct inaccuracies

Tell Cole what we got wrong; the intelligence layer updates. Or contact us — corrections are made promptly, within the timeframes required by law.

Export your data

Request a complete, machine-readable export of all data we hold about you. Delivered to your registered email promptly, within the timeframes required by law.

Delete your account

From any state, with the confirmation flow above. Soft-delete is immediate; permanent purge follows after the 30-day grace window.

Stop data collection

Stop uploading documents at any time. Disconnect health data from your device's health-platform settings to stop health data flow immediately. Previously stored data remains until you delete it.

Opt out of communications

Unsubscribe from non-essential communications using the unsubscribe link in any email. Transactional communications (account security, trial expiry, billing notices) cannot be opted out of while your account is active.

California residents

You have additional rights under the California Consumer Privacy Act (CCPA), as amended by the CPRA — including the rights to know, delete, correct, and obtain a portable copy of your information. See the California Privacy Addendum at the bottom of this policy.

Cookies and tracking

Vithropic uses only the cookies required to operate the service:

  • Session cookies — required to maintain your authenticated session. Expire when you close your browser or sign out.
  • Security cookies — short-lived tokens for CSRF protection and secure form submission.
  • Preference cookies — store UI preferences such as your selected billing period on the pricing page.

We do not use advertising cookies, third-party tracking cookies, or cross-site tracking. No third-party analytics. No advertising pixels. No behavioral advertising technology. No browser fingerprinting.

You can disable cookies in your browser settings. Session and security cookies are required for the authenticated portal to function — disabling them will prevent sign-in.

Children's privacy

Vithropic is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, contact us immediately and we will delete it.

For users aged 13 to 17, we recommend parental review of this policy before use.

Changes to this policy

When we make material changes to this policy, we will notify you by email at least 30 days before the changes take effect. Minor clarifications that do not affect your rights or our practices may be made without advance notice.

The effective date at the top of this page reflects when the current version took effect. Previous versions are available on request.

Questions about your data?

Questions about your data are handled personally and responded to promptly, within the timeframes required by law. Account-deletion requests follow the lifecycle described above.

Vithropic, Inc.  ·  Contact form

Submit a privacy request →

California Privacy Addendum

This addendum supplements the rights above with disclosures and rights specific to California residents under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). If you are a California resident, the rights in this addendum apply to you.

Categories of personal information we collect

In the preceding 12 months, Vithropic has collected the following categories of personal information from California residents:

CCPA category What Vithropic collects
IdentifiersFirst name, email address, IP address, account identifier
Customer recordsSubscription billing data held by our payment processor
Protected classificationsSex, birth year
Commercial informationSubscription status, payment history
Internet activityOperational request logs, User-Agent string
Biometric and health informationConnected health-platform data — only if you grant permission
InferencesDerived intelligence (baselines, patterns, projections) generated only for you, not used to characterize you for any third party

We do not collect: precise geolocation, racial or ethnic origin, audio or visual recordings, professional or employment-related information beyond income source, education information, or biometric identifiers used for identification.

Sources of personal information

We collect personal information from (a) you directly — account information, profile fields, financial documents you upload, conversations with Cole; (b) your devices — health data you authorize, IP and User-Agent on requests; and (c) our service providers — subscription status from our payment processor.

Purposes for collecting personal information

Each category above is collected for the purposes described in the "How we use your information" section above. We do not use personal information for purposes beyond those described.

Sensitive personal information

The CPRA designates certain categories as sensitive personal information. Vithropic collects the following sensitive categories:

  • Account access credentials — authentication tokens (not your password)
  • Health information — only if you grant permission to connect a health data source
  • Financial information — extracted structured data from documents you upload

We do not collect: precise geolocation, racial or ethnic origin, religious beliefs (except religious tradition as an optional profile field you can decline), sexual orientation, union membership, contents of mail or messages, citizenship or immigration status, or government identifiers.

Sensitive personal information is used only for the purposes for which you provided it — operating the intelligence layer for you. We do not use sensitive personal information to infer characteristics about you for any third party.

Sale and sharing

Vithropic has not sold personal information for monetary or other valuable consideration in the preceding 12 months.

Vithropic has not shared personal information for cross-context behavioral advertising in the preceding 12 months.

Vithropic does not anticipate selling or sharing personal information in the future. The "Our privacy promises" section above is a binding commitment, not a temporary state.

Your California rights

  • Right to know — the categories and specific pieces of personal information we have collected about you, the categories of sources, the purposes for collection, and the categories of third parties with whom we have shared or disclosed personal information.
  • Right to delete — request deletion of personal information we have collected from you. Exceptions apply for information needed to complete a transaction, detect security incidents, comply with legal obligations, or other purposes permitted by law.
  • Right to correct — request correction of inaccurate personal information we hold about you.
  • Right to opt out of sale or sharing — not applicable to Vithropic, because we do not sell or share personal information as defined by CCPA/CPRA.
  • Right to limit use of sensitive personal information — not applicable to Vithropic, because we use sensitive personal information only for the purposes for which you provided it and for legally permitted business purposes.
  • Right to non-discrimination — we will not deny you service, charge you differently, or provide you a different quality of service because you exercised a California privacy right.
  • Right to portability — receive a copy of personal information we have collected from you in a portable, machine-readable format.

How to exercise your California rights

Most rights are exercisable directly from your account settings. For rights that require contact, submit a request through the contact form at vithropic.com/contact and identify the request as a "California Privacy Request."

  • Identity verification. We verify your identity through your account login. For requests submitted without account login, we may ask for additional information sufficient to confirm you are the person whose data is the subject of the request.
  • Authorized agents. You may designate an authorized agent to submit a request on your behalf. We will require written authorization signed by you and may verify your identity directly.
  • Response timeline. We acknowledge verifiable requests within 10 business days and respond substantively within 45 calendar days. If we need additional time (up to 45 more days), we will notify you in advance with the reason.
  • Frequency limits. Right-to-know and right-to-correct requests are limited to twice per 12-month period.
  • Denials. If we cannot fulfill a request — for example, if we cannot verify your identity, if the request is excessive or manifestly unfounded, or if a legal exception applies — we will explain our reasoning in writing.
  • No charge. We do not charge a fee for verifiable California privacy requests, unless a request is excessive, repetitive, or manifestly unfounded, in which case we will provide a cost estimate in advance.

Contact for California requests

Contact form at vithropic.com/contact. Mark your request as a "California Privacy Request."