SnapVitals — Privacy Policy
Important — SnapVitals is not a medical device.
SnapVitals is a consumer wellness tool. It does not measure blood pressure, diagnose, treat, provide medical advice, or analyze your readings. Readings come from your own blood pressure monitor; the app records them and shows trends for your personal reference. Always consult your doctor for medical decisions.
See our Medical disclaimer and Terms of Service for full details.
1. Information we process
We process only the information needed to provide the app's core features:
- Blood pressure readings (systolic, diastolic, pulse), including time, measuring arm, and any notes you add
- Monitor-screen photos captured for scanning, including the cropped detection image used for recognition
- Family member profiles (display name, avatar, age bracket) that you create in the app
- Feedback content you choose to submit (voice note, photos, written description)
- Basic device and app metadata (Android version, device model, app version, build number) automatically attached to feedback submissions and analytics events
- Anonymous usage events (e.g., when you open the app, open the camera, save a reading, export data) sent to our backend service for product analytics. Each event is tied only to a randomly generated anonymous device identifier — no name, email, account, precise location, blood pressure values, photos, or other health content is sent
Consumer Health Data notice. Blood pressure readings, monitor-screen photos, and any health-related notes you enter are consumer health data under Washington's My Health My Data Act (RCW 19.373), Nevada SB 370, and comparable state laws. See §7 for the additional rights that apply.
No account required. SnapVitals does not require you to create an account, log in, or provide identifying information (name, email, phone, address) to use the app.
2. Where your data is stored
On-device by default. Readings, scan results, photos, family profiles, and settings are stored on your device by default. We do not upload this data to our servers for analytics, model training, advertising, or any purpose other than the functions you directly initiate.
When data leaves your device. Data leaves your device only when:
- You use Send feedback to report an issue (sent to our support infrastructure)
- You use the Android Share sheet or Export to send data to a destination you choose
- You create a backup file via Settings → Backup & restore (saved by you through the Storage Access Framework to a location of your choosing — local storage, Google Drive, email, or any document provider)
- Android Auto Backup, a default Android platform service, automatically copies a small set of app data (your readings database and your in-app settings) to your own private Google Drive backup folder so the app can restore your data when you reinstall on the same Google account. Photos, anonymous identifiers, and temporary scan files are excluded from Auto Backup. We do not have access to this data — only you do, through your Google account
Security. We use industry-standard safeguards, including on-device storage, the Android Keystore for sensitive identifiers, and encrypted transmission (TLS) for any data submitted through Send feedback. No method of storage or transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
3. Permissions
Camera. Used solely to scan monitor readings in the Scan screen. We do not record video or access the camera in the background.
Photos. Used solely to import monitor images you already have. We use the Android system photo picker, which restricts access to only the images you explicitly select — SnapVitals never sees your full photo library. When you tap Save to Photos on a saved reading's image in History, SnapVitals writes only that single image to your photo library — nothing else is added.
Notifications. Used solely to deliver the measurement reminders you turn on in Settings. We do not send marketing or promotional notifications.
Microphone. Used solely to record a voice note that you choose to attach to a feedback submission. We do not access the microphone in the background.
4. Retention
On-device content. Readings, photos, and family profiles remain on your device until you delete them individually, use Clean up in Saved photos, restore a different backup, or uninstall the app.
Feedback submissions. Content you send through Send feedback (voice, photos, text, diagnostics) is retained only as long as needed to investigate and resolve the issue you reported, after which it is deleted. Aggregated, non-identifiable summaries may be retained longer for product improvement.
Analytics and crash logs. SnapVitals does not integrate any third-party analytics or crash reporting SDK (such as Firebase, Sentry, Mixpanel, or Crashlytics). Crash reporting is handled exclusively through Android vitals collected by Google Play, a default platform service that aggregates anonymized stability and performance metrics across all Android apps; we receive only the aggregated dashboards Google publishes to developers, and Google's handling of those metrics is governed by Google's own privacy terms. Diagnostic events that we send to our own backend (event name, app version, OS version, anonymous device identifier, basic device model) are retained only as long as needed for product analytics, after which they are deleted or aggregated into non-identifiable summaries.
5. Third-party services
No third-party sharing for marketing. We do not share your personal information with any third party for that third party's marketing purposes.
Google Play services. When you use Android system features (Share sheet, Storage Access Framework, system Share activities), or when Android Auto Backup copies app data to your private Google Drive backup folder, those features are operated by Google LLC and governed by Google's Privacy Policy. SnapVitals does not receive copies of what you send through these features and has no access to your Auto Backup data — only you do, through your Google account.
Our service providers. SnapVitals operates its own backend service to receive feedback submissions and analytics events. The backend runs on third-party cloud hosting infrastructure that acts solely as a data processor on our behalf — these hosting providers do not access or use your data for their own purposes. We do not transfer your personal information, readings, photos, or consumer health data to any third-party SDK, marketing platform, or data broker.
Meta SDK for ad install attribution. Starting with version 1.0.0 build 8, SnapVitals includes the Meta (Facebook) Android SDK (facebook-core) for the sole purpose of letting Meta recognize installs that originated from Facebook or Instagram ad campaigns. To do this, the SDK collects your device's Android Advertising ID (AAID) and reports the app install and standard app-launch events to Meta, so Meta can match your install to the ad you tapped. You can reset or delete your Advertising ID, or opt out of ad personalization, at any time in Android Settings → Privacy → Ads. Meta's Limited Data Use mode is enabled at app launch (universal CCPA-grade treatment regardless of your state of residence), which restricts Meta to using this data for measuring our own ad campaigns — it is not used to build cross-app advertising profiles, lookalike audiences, or retargeting on our behalf. SnapVitals does not transmit your personal information, readings, photos, or consumer health data to Meta; only the advertising identifier and the install / app-launch events described here are shared. We perform no in-app event tracking beyond the install and app-launch signals.
6. Your general rights
Built-in controls. Without contacting us, you can:
- View and delete any reading, photo, or family profile directly in the app
- Revoke camera, photo, notification, or microphone permissions at any time in Android Settings
- Export all your data via Settings → Export readings (PDF or CSV) or Settings → Backup & restore (full backup file)
- Disable Android Auto Backup for SnapVitals in Android Settings → System → Backup if you do not want a copy of your readings database in your Google Drive backup folder
- Uninstall the app to remove all on-device data
Requests for server-side data. To request access to or deletion of feedback content you previously submitted, email master@mysnapvitals.com with the approximate date of your submission. We respond within 45 days.
7. Consumer Health Data Rights (Washington, Nevada, and similar states)
This section applies to residents of Washington state (under the My Health My Data Act, RCW 19.373), Nevada (under SB 370), Connecticut residents for health data under the CTDPA amendments, and residents of other states with consumer health data laws that impose similar obligations.
Affirmative consent. Because all consumer health data remains on your device by default, SnapVitals does not "collect" or "process" your consumer health data within the meaning of RCW 19.373 unless you choose to transmit it to us through Send feedback. Submitting feedback that contains health-related information constitutes your affirmative, voluntary, and specific consent for SnapVitals to process that information solely to investigate the issue you reported. You may withdraw this consent at any time by deleting your existing readings, revoking camera and photo permissions in Android Settings, and uninstalling the app.
Categories of consumer health data. The following categories may be transmitted to us if you choose to include them in a Send feedback submission: blood pressure readings (systolic, diastolic, pulse); monitor-screen photos and cropped detection images; time, arm, and session context of each reading; notes you add; and any other health-related content you write in the feedback message.
Sources. All consumer health data we receive comes directly from you, through Send feedback submissions you initiate.
Purposes of processing. We process consumer health data solely to: (a) record and display your readings; (b) display your readings against the publicly published 2025 ACC/AHA reference ranges (a deterministic threshold lookup, not an analysis or per-individual clinical judgment); (c) show trends; (d) organize readings by family member; (e) allow you to export, back up, or share your own data; and (f) investigate feedback you submit.
No sale of health data. We do not sell your consumer health data. We have not sold consumer health data in the 12 months preceding the Effective date of this policy, and we do not plan to.
No sharing with third parties for their own purposes. We do not share your consumer health data with any third party for that third party's independent use. Data leaves your device only to destinations you explicitly choose (Share sheet, Export readings, Backup & restore, Send feedback) or to your own private Google Drive backup folder when Android Auto Backup is on. Auto Backup never includes your scan photos.
Retention of health data. As stated in §4.
Your rights. You have the right to:
- Confirm whether we are processing your consumer health data (we do not process such data during normal app usage; we process it only while a feedback submission containing health data is still retained — see §4)
- Access the consumer health data we process (all on-device data is visible in the app; for feedback content, email us)
- Delete your consumer health data (delete in the app; for feedback content, email us)
- Withdraw consent (revoke camera and photo permissions in Android Settings, delete existing readings, and uninstall the app — this withdraws consent for all future processing)
How to exercise. For in-app data, use the app's delete and export controls directly. For feedback submissions, email master@mysnapvitals.com. We respond within 45 days and will not charge you or discriminate against you for exercising these rights.
No geofencing. We do not use geofences around any healthcare facility, reproductive or sexual health provider, pharmacy, or similar location, as prohibited by RCW 19.373.060.
Appeals. If we deny a consumer health data request, you may appeal by replying to our response. If the appeal is denied, Washington residents may contact the Washington Attorney General at atg.wa.gov/file-complaint.
8. California Privacy Disclosures (CCPA / CPRA)
This section applies to residents of California under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (Cal. Civ. Code § 1798.100 et seq.).
Categories collected (past 12 months):
- Identifiers: an anonymous device identifier and basic device/app metadata (Android version, device model, app version, build number) automatically attached to feedback submissions and analytics events
- Internet or other electronic network activity information: anonymous usage events (e.g., app open, camera open, scan attempted, reading saved, export) sent to our backend service for product analytics
- Protected classification or health information: blood pressure readings and health-related notes — classified as Sensitive Personal Information under Cal. Civ. Code § 1798.140(ae)(2)
- Visual information: monitor-screen photos you capture or select
- Audio information: voice notes you attach to feedback
- Inferences: visual reference-range markers (e.g., color-coded against the publicly published 2025 ACC/AHA ranges) shown on your device only — none of this is transmitted to our backend, used to build a profile, or used for any decisional purpose
Sources. All categories above are collected directly from you.
Business and commercial purposes. We collect the above categories solely to provide the app's features as described in §1 and §2, and to investigate feedback you submit.
No sale or sharing. We do not sell (as defined in Cal. Civ. Code § 1798.140(ad)) or share (as defined in Cal. Civ. Code § 1798.140(ah), including cross-context behavioral advertising) your personal information. We have not done so in the 12 months preceding the Effective date. Because no sale or sharing occurs, we do not display a "Do Not Sell or Share My Personal Information" link.
Sensitive Personal Information. Blood pressure readings, monitor-screen photos, health-related notes, and voice notes are Sensitive Personal Information. We use Sensitive Personal Information only for purposes you directed or that are necessary to provide the services — we do not use it for inferring characteristics about you beyond the app's stated functions. You may limit our use of Sensitive Personal Information by deleting the data, uninstalling the app, or emailing master@mysnapvitals.com.
Your rights. As a California resident you have the right to:
- Know what personal information we collect, use, disclose, and retain
- Delete personal information we have collected from you
- Correct inaccurate personal information we maintain
- Opt out of sale or sharing (inapplicable — we do not sell or share)
- Limit use of Sensitive Personal Information
- Non-discrimination for exercising these rights
How to exercise. Email master@mysnapvitals.com. We verify your request using information already associated with any feedback submission you made. If you have never contacted us and have never submitted feedback, SnapVitals holds no personal information about you off of your device — we have nothing to access, correct, or delete beyond what remains under your sole control on your device.
Shine the Light. We do not share personal information with third parties for their direct marketing purposes (Cal. Civ. Code § 1798.83).
Authorized agents. California residents may designate an authorized agent to submit requests on their behalf. The agent must provide written authorization signed by you and verifiable proof of identity.
Response timing. We respond to California privacy requests within 45 days, extendable once by 45 additional days with notice.
9. Other state privacy rights
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Florida (FDBR), Delaware (DPDPA), New Jersey (NJDPA), Tennessee (TIPA), Iowa (Iowa CDPA), Indiana (Indiana CDPA), Minnesota (MCDPA), Maryland (MODPA), New Hampshire (NHDPA), Rhode Island (RIDTPPA), Kentucky (KCDPA), Nebraska (NDPA), or any other state with a comprehensive consumer privacy law may have rights, including rights to access, delete, correct, obtain a copy, and opt out of certain processing (including sale, targeted advertising, and profiling in furtherance of decisions producing legal or similarly significant effects). SnapVitals does not engage in targeted advertising, sale of personal information, or profiling of that kind.
To exercise any state-law right, email master@mysnapvitals.com. We respond within the time frame required by your state's law (generally 45 days, extendable once by 45 additional days with notice). If we deny your request, you may appeal by replying to our response; if we deny the appeal, you may contact your state Attorney General.
10. Children's privacy
SnapVitals is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you are under 13, do not use the app. If we become aware that we have collected personal information from a child under 13 in violation of the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. § 6501 et seq.), we will delete it.
Parents or guardians who believe their child has provided information to us should contact master@mysnapvitals.com so we can investigate and, if applicable, delete the information. Family member profiles you create in the app (including any profile you make for a child under 13) are on-device records that you manage for your household; they are not collected by us unless you include them in a feedback submission.
11. Business transfers
If SnapVitals is acquired, merged, sold, or undergoes any similar transaction, we will notify users in the app before any change affects the handling of personal information or consumer health data. Any successor will be bound by terms no less protective than this Privacy Policy, or will obtain renewed consent where required by law.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced in the app. Continued use of the app after an update indicates acceptance of the updated policy. The Effective date at the top indicates the most recent revision. A changelog of past revisions is available on request.
13. Contact
SnapVitals is operated by Puwell Technology Inc., a Delaware corporation.
Privacy questions, data rights, consumer health data rights requests, and general support: master@mysnapvitals.com
Mailing address: Puwell Technology Inc., 98 Cuttermill Rd, Ste 466S, Great Neck, NY 11021, USA