OjasVault ← Back

Privacy Policy

Version 1.0 — Effective May 2026

The short version: You upload your health data; we analyse it to show you trends. We don't sell your data. We never use it to train AI models — and our vendor contracts prohibit them from doing so either. We share it only with the four vendors listed in Section 3 — and only as needed to run the service. Our infrastructure and AI vendors are bound by Business Associate Agreements (BAAs) that apply HIPAA-grade data-protection obligations. You can delete everything, permanently, at any time.

1. What we collect

Data you give us directly

Data we generate from your uploads

Data collected automatically

2. How we use your data

We do not use your data for advertising, behavioural tracking, or sale to data brokers. We never use your health data to train AI models — ours or our vendors'. Our contract with Anthropic explicitly prohibits them from using data submitted through our service for any model training purpose.

3. Who we share your data with

We share your data with exactly four vendors, and only as required to operate the service:

Vendor Data shared Purpose
Google Firebase (USA) Lab report files, extracted marker data, account document, biometric profile Secure cloud storage, authentication, and hosting. BAA in place with Google Cloud.
Anthropic (USA) Lab report text content (the text extracted from your uploaded files) AI-powered marker extraction and analysis. Contractually prohibited from using your data for model training. BAA in place.
Stripe (USA) Email address and payment method Subscription billing — we never see your card number
Resend (USA) Email address Sending panel reminders, notifications, and transactional emails

We share your data with no other third parties. We do not sell, rent, license, or broker your data.

Who can actually view your data?

Sharing data with a vendor for processing is different from that vendor's employees being able to read it. Here is a plain-language breakdown of who can see what:

Who What they can see When and why
You Everything — uploaded files, extracted markers, analysis, biometric profile Any time you are logged in. Protected by email + password + authenticator code (TOTP MFA). No one can log in as you without all three.
OjasVault staff Account metadata (email, plan status, timestamps) for support. Raw uploaded files only if you explicitly share them while reporting a problem. Only when actively diagnosing a technical issue. We do not browse customer data. Administrative access is restricted to the minimum staff needed to operate the service.
Anthropic (automated AI only) The text content of your uploaded lab report during processing Each analysis call is automated — no Anthropic employee reviews your content. The BAA prohibits retention beyond the API response and prohibits use for model training.
Google Cloud (infrastructure only) Infrastructure-level access to hosted data Governed by BAA and Google's strict internal access-control policies. No Google employee has routine access to your health data.
Law enforcement Only what is legally required by a valid court order or subpoena We will notify you before disclosing unless we are legally prohibited from doing so.
No one else Stripe sees only your email and payment method. Resend sees only your email address. No other party has access.

4. Data retention

5. Your rights

California residents (CCPA)

California residents have the right to know what personal information we collect, the right to delete it, the right to opt out of its sale (we do not sell it), and the right to non-discrimination for exercising these rights. To exercise any CCPA right, email legal@ojasvault.ai. We will respond within 45 days.

6. Security

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256 via Google Firebase). Access is restricted to your account credentials and the vendors listed above. We conduct periodic security reviews and promptly investigate any suspected incident.

7. HIPAA-grade data protection

OjasVault is a consumer health application — we are not a healthcare provider, health plan, or clearinghouse as defined by HIPAA. However, we have voluntarily adopted HIPAA-compatible standards because we believe your health data deserves that level of care regardless of regulatory classification.

In practice, this means:

8. FTC Health Breach Notification

OjasVault is subject to the Federal Trade Commission's Health Breach Notification Rule. In the event of a breach involving your personally identifiable health information, we will notify you and, where required, the FTC within 60 days of discovering the breach. Notification will be sent to the email address on your account.

9. Children's privacy

OjasVault is not intended for users under 18. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected such data, please contact us immediately at legal@ojasvault.ai and we will promptly delete it.

10. Changes to this policy

We will notify you by email before any material change to this policy takes effect, and update the version date at the top of this page. If you continue using OjasVault after a change is announced, you accept the updated policy.

11. Contact

Questions or concerns about your privacy? Email legal@ojasvault.ai. We aim to respond within 5 business days.