Legal
Privacy Policy
Last updated: October 10, 2026
Health information is sensitive. This policy explains plainly what VivoChart collects, why, who helps process it, and the choices you have.
Privacy at a glance
Your records stay private
Records are visible only to you and people you invite as viewers or admins.
No selling or ads
VivoChart does not sell health data or use it for advertising.
AI reads what you upload
Uploaded documents are sent to an AI service to extract values and explanations.
You can leave
You can ask us to delete your account and records at any time.
This summary does not replace the full policy below.
1. Introduction
VivoChart is a personal health dashboard that helps you import, organize, visualize and understand your medical information. It is operated by VIVOCHART LLC. This policy covers the VivoChart website and app at vivochart.com. Questions can be sent to support@vivochart.com.
2. Information We Collect
Account information
- Name or display name
- Email address
- Authentication information, such as a hashed password or sign-in provider identifier
- Account preferences, such as the selected board and pinned charts
Medical and health information
- Laboratory results
- Diagnoses and medical conditions
- Clinical and physician notes
- Imaging and pathology reports, including molecular profiling
- Medication records and the dates you mark as taken
- Treatment history
- Procedures and hospital encounters
- Other information imported from healthcare providers, where connected
Patient-uploaded information
- PDFs and medical documents
- Images and screenshots of reports
- Manually entered medical information
- Relevant supporting files
Technical information
- Device and browser information sent with requests
- Security and authentication events, such as sign-ins
- Server logs needed to operate and secure the Service
3. How We Obtain Medical Information
We receive information from documents you upload, from details you enter directly, and, once available, from patient-authorized connections such as Epic MyChart through SMART on FHIR and OAuth 2.0 or other supported integrations. Access to provider records always requires your authorization.
4. How We Use Information
Essential service processing:
- Displaying and organizing your records
- Tracking laboratory measurements over time
- Creating medical timelines
- Generating AI-assisted explanations
- Importing and synchronizing data
- Sending emails you trigger, such as invitations, password resets, visit briefs and out-of-range notices
- Securing accounts and preventing abuse
- Meeting legal requirements
Optional uses: we do not currently use your health information for analytics, research, model training or product marketing. We will not begin any such use without first asking for your consent.
5. Artificial Intelligence and Medical Data
- When you upload a document, its contents are sent to an AI model to read it and extract values. This content is identifiable health information.
- Requests are routed through the Lovable AI gateway to a third-party model provider. Current provider and vendor terms: [to be confirmed before publication].
- Whether AI vendors retain inputs, and for how long, depends on their contracts. We do not claim your data is never used for training until this is contractually verified.
- AI processing is part of document import and cannot currently be switched off, though you can enter information manually instead.
- Extracted values and summaries are stored with your records and are deleted when those records are deleted.
7. MyChart and FHIR Connections
Provider connections are in development. When available, the lifecycle will be:
- You start a connection to your healthcare provider.
- You sign in through your provider's own login.
- VivoChart receives authorized access to permitted records.
- VivoChart imports and processes information within those permissions.
- Connections can be refreshed or revoked under the authorization settings.
VivoChart is independent of Epic and connected healthcare organizations. OAuth tokens are encrypted at rest using AES-256, stored in a secure credential vault, and accessed only during active synchronization. You can disconnect a healthcare organization at any time from your account settings, which immediately deletes all stored access and refresh tokens and halts future data retrieval. You can also revoke VivoChart's access directly through your healthcare provider's MyChart or patient portal under external application settings. Revoking access stops future retrieval but does not automatically delete information already imported.
8. Data Storage and Security
- Data is sent over encrypted HTTPS connections.
- Access controls in the database restrict each record to its owner and invited members.
- Uploaded files are kept in private storage, not public links.
- Anonymous access to data tables is blocked.
- Encryption at rest, monitoring and auditing: [to be confirmed with the hosting provider].
No system is perfectly secure, and we cannot guarantee that a breach will never occur.
9. Data Retention and Deletion
Records are kept until you or your board admin delete them, or until your account is deleted. Disconnecting a provider does not delete prior imports. To delete your account, email support@vivochart.com. Active account data and uploaded documents are permanently deleted within 14 business days of request verification. Backup archives are automatically overwritten and purged within 30 days.
10. Patient Privacy Rights
Self-service in the app: view your stored information, correct or remove records, and remove members from your board.
By contacting us: request a copy or export of your data, delete your account, ask about our practices, and exercise rights under applicable US state privacy laws. Revoking provider authorization can also be done through your provider's portal.
11. HIPAA and Other Privacy Laws
VivoChart is an independently operated consumer health application. Apps like this are generally not covered by HIPAA simply because they retrieve records from HIPAA-covered providers. VivoChart does not claim HIPAA compliance or certification. The Federal Trade Commission's Health Breach Notification Rule and state consumer health privacy laws may apply; their applicability is subject to legal review.
12. Security Incidents
If we learn of unauthorized access or disclosure, we will investigate, contain it, and notify affected individuals and regulators as required by applicable law.
13. Children's Privacy
You must be at least 21 years old to create an account. We do not knowingly collect information from anyone under 21.
14. Changes to This Policy
We will update the "Last updated" date and notify you by email or in the app before material changes take effect.
