VitalCore

Privacy Policy

Effective date: June 3, 2026 · Version 1.0

Summary: VitalCore processes clinical tools and optional camera/OCR features entirely on your device. We do not operate backend servers that receive, store, or analyze your photos, videos, or patient health information.

1. Who we are

VitalCore is developed by Abdulrazaq Alonazi as a clinical reference and professional education application for cardiac surgery and perfusion teams. Contact: A.razaq017@GMAIL.COM.

2. Scope — not a covered entity

VitalCore is software provided directly to end users. The developer is not a HIPAA covered entity and does not offer business associate agreements (BAAs). VitalCore is designed with privacy-conscious, on-device processing aligned with common HIPAA technical safeguard principles (minimum necessary, local processing, no central PHI repository), but using VitalCore does not, by itself, make you HIPAA compliant. Covered entities and business associates remain responsible for their own compliance programs, policies, and workforce training.

3. Information we do not collect

4. Information processed on your device

The following may be stored locally on your phone, tablet, or computer using browser or app storage (e.g., localStorage, UserDefaults) or optional offline cache (Service Worker):

Camera and photo-library features (ABG OCR, ECMO scanner, ECG strip analyzer) process images in memory on your device. When you close the app or reset a tool, captured frames are discarded unless you explicitly export or save them using your device's share/save functions.

5. Camera and photo library

With your permission, VitalCore may access:

You will see in-app consent before first use. Apple/iOS also displays system permission dialogs with our usage descriptions. You can revoke access anytime in device Settings. We recommend using de-identified images and avoiding patient names, MRNs, or faces in captures.

6. Third-party libraries and CDNs

Some optional features load open-source JavaScript libraries from public CDNs (for example, Tesseract.js for on-device OCR). When loaded, your browser downloads those library files from the CDN provider; no clinical image content is sent as part of that download. OCR analysis runs locally after libraries are loaded. Network availability may affect whether OCR features initialize.

7. Your responsibilities

8. Children's privacy

VitalCore is intended for trained healthcare professionals, not children under 13. We do not knowingly collect information from children.

9. International users (GDPR awareness)

Because VitalCore does not centrally process personal data on developer-operated servers, data subject access requests to the developer generally do not apply to patient content that never leaves your device. You may clear local app data by removing the app or clearing site data in your browser.

10. Changes

We may update this policy as the app evolves. Material changes will be reflected in the effective date above and, where appropriate, in-app notices.

11. Contact

Privacy questions: A.razaq017@GMAIL.COM