Vimetra legal
Privacy Policy
Effective: September 3, 2026 · Last updated: September 3, 2026
This Privacy Policy explains how Vimetra: Health Tracker & Scan ("Vimetra", "Application", "we", "us", or "our") processes information on Android, this website, and related support services. Vimetra is a general-wellness product, not a medical device; its estimates are not medical diagnoses, treatment recommendations, or emergency guidance. This policy does not replace the privacy notices of Google Play or third-party services you choose to use.
1. Face Data We Process
When you start a camera scan, Vimetra processes short-lived front-camera video frames containing your face and temporary face-region positioning information needed to assess scan quality. For AI-assisted analysis, Vimetra also sends one compressed facial photograph selected from that scan and the minimum necessary scan values (such as wellness estimates) through Vimetra's Cloud Run gateway in the United States to Google Cloud Vertex AI for Gemini to generate the analysis you requested.
We do not collect or create facial-recognition templates, biometric identifiers, stored face maps, or identity-verification records. We do not use face data to identify you.
Other information we handle
Profile and wellness information: We process age, sex selection, height, weight, unit preference, and other settings you provide to calculate or interpret selected wellness indicators. We do not require your name, account credentials, contacts, or precise location for the core experience. Reports may include wellness scores; heart-rate, breathing-rate, and heart-rate-variability estimates; stress or exertion context; body-composition calculations; investigational risk estimates; confidence information; and 7-day or 30-day trends.
Support and technical information: If you contact us, we receive your email address, message, and files you choose to include. Optional diagnostics may include app version, device model, operating-system version, and an anonymous error ID.
2. How Face Data Is Collected
Face data is collected only after you grant the device camera permission and actively begin a scan. The camera is not used to collect face data in the background. On Android, where an AI gateway is configured, the app may generate and transfer one compressed facial photograph as part of an AI-enabled scan after camera permission is granted and the user starts that scan.
Website information: This website does not use advertising cookies or cross-site tracking. Our hosting provider may process limited network and device information, such as IP address, browser type, request time, and security logs, as necessary to deliver and protect the website.
3. Purpose of Processing
Vimetra processes face data only to provide the function you request: to assess scan quality, use rPPG and temporary facial feature/region detection to extract optical signals associated with pulse and skin-vitality estimates, and, when AI-assisted analysis is used, produce the requested wellness report, summary, and lifestyle guidance. Face data is not used to diagnose, treat, cure, mitigate, or prevent disease.
All estimates, including Heart Rate, Respiration Rate, HRV, Stress Level, Heart Effort, Skin Age, BMI, BSI, and WtHR, are for general wellness, fitness, and lifestyle reference only. Vimetra does not measure or scan blood pressure, blood glucose, or blood oxygen (SpO2). Do not disregard professional medical advice based on information from the Application.
We do not use face data to train or improve Vimetra AI models. Under Google Cloud's Vertex AI terms, Google does not use customer data to train or fine-tune its AI/ML models without prior permission or instruction.
We also use information to personalize units, reference context, and explanations; maintain safety; diagnose errors; prevent abuse; provide support; meet legal obligations; and enforce our Terms of Service. We do not use camera, face, health, or fitness data for insurance decisions, employment decisions, or unrelated data mining.
4. Data Shared With Third Parties
Vimetra does not upload raw scan video to its servers. For AI-assisted analysis, one compressed facial photograph and the minimum necessary scan/profile values are securely transmitted from the app to Vimetra's Google Cloud Run report gateway in us-central1, United States. The gateway processes the request in volatile memory and forwards the necessary content to Google Cloud Vertex AI for Gemini-based processing in us-central1, United States. Google Cloud acts as our service provider for this limited purpose.
We do not share face data with AdMob, Firebase, Crashlytics, Adjust, advertising platforms, analytics providers, data brokers, or any other third party. We do not sell face data. Google Cloud and our other service providers must protect personal data at least as described in this policy and may use it only to provide the services to us.
Separately from face data, Vimetra uses Google AdMob to serve in-app advertisements using standard advertising identifiers with the consent required by your device and applicable law; Google Firebase and Crashlytics to collect anonymous performance metrics, session length, and crash diagnostics; and Adjust for anonymous attribution and marketing-campaign analytics. These services do not receive face data.
Infrastructure, encrypted network-delivery, and operational services may process the minimum technical information needed to run and protect Vimetra. We may disclose information if required by law or reasonably necessary to protect users, our rights, or the service. Information may also transfer as part of a merger, financing, reorganization, or sale, subject to this policy and applicable law.
5. Storage Location and Security
Video frames are processed transiently in your device's memory. Vimetra's Cloud Run gateway does not write facial photographs or scan values to a database or file storage; it processes the request in volatile memory. Your scan history, historical logs, and preferences, if you choose to keep them, are stored locally on your device and do not include facial photographs.
For an AI-assisted analysis, the transferred photograph and scan values are processed by Vimetra's Cloud Run gateway and Google Cloud Vertex AI in us-central1, United States. Transfers use TLS 1.3 encryption over HTTPS. Google Cloud provides the security controls for its processing environment; access is limited to the service operation and safety controls described below.
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted transport and data minimization. No method of storage or transmission is completely secure. Service providers may process information in countries outside your own; where required, we use recognized transfer safeguards and contractual protections.
6. Retention Period
- On your device: Scan frames are discarded from temporary memory when the scan ends. On Android, the temporary facial photograph is not saved to the photo library, database, or file storage.
- In Vimetra systems: The Cloud Run gateway processes the request body and facial photograph only in volatile memory during the request and does not write them to a server database or file storage. Once the request is complete, the data is no longer intentionally retained and becomes eligible for normal runtime memory reclamation. Locally stored scan-history values remain on your device until you delete them in the Application or uninstall the Application.
- At Google Cloud Vertex AI: Google's published Gemini models may cache inputs, outputs, and derived data in project-isolated memory for up to 24 hours to provide the service. Where Google Cloud's abuse-monitoring prompt logging applies to the project, if its automated safety systems flag suspicious activity requiring investigation, Google may retain the relevant prompt content, including the image input, in
us-central1for up to 90 days solely to investigate potential violations of its policies. This data is not used to train or fine-tune AI/ML models. Vimetra uses Gemini 2.5 Flash and does not use the Advanced AI models or features subject to separate prompt-and-response logging. We do not enable Google Search or Google Maps grounding for this feature, and we do not enable Gemini Live session resumption. Those features are therefore not used to retain face data.
Google's applicable service terms and technical controls govern its processing. We do not authorize Google Cloud to use face data for advertising, marketing, profiling, identity recognition, or model training.
Our report service does not write request or response bodies to a Vimetra database or disk. Its application logs contain only an anonymous request ID, processing provider, result category, and elapsed time; they do not contain request bodies, health values, images, credentials, or IP addresses. Google Cloud Run may automatically create standard request and platform logs. The current Google Cloud Logging _Default bucket retains those logs for 30 days, and the _Required audit-log bucket retains audit logs for 400 days. The gateway also uses IP addresses only in an in-memory rate-limit cache for the lifetime of a running service instance; IP addresses are not included in Vimetra's application logs. Support emails are retained only as long as reasonably necessary to respond to and document your request, unless a longer period is required by law.
7. Deletion and Withdrawal of Consent
You can withdraw camera permission at any time in your device's Settings.
Use Delete All Local Data in Vimetra Settings to remove your profile, scan history, reports, and local preferences from your device. Because Vimetra does not maintain a facial-photograph database, there is no Vimetra-hosted facial photograph for us to delete. The local deletion controls do not retroactively remove an in-flight request or service logs retained under the periods described in Section 6. Google Cloud's short, limited retention described in Section 6 expires according to its service controls. To make a privacy request, contact us using the details in Section 9.
You may also ask us to delete support correspondence, subject to legal retention requirements. Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, withdraw consent, appeal a decision, or complain to your local data-protection authority. Because most Vimetra data stays on your device and Vimetra does not require an account, we may not be able to identify or retrieve local data from our systems. Do not attach optional diagnostics or files to a support request that you do not want us to receive.
8. Advertising and Prohibited Uses
Vimetra may display advertisements through Google AdMob. Advertising uses standard advertising identifiers only as permitted by your device settings and applicable consent requirements. Face data is never used for advertising, marketing, targeting, attribution, or use-based data mining, and is never shared with advertising partners.
We do not use face data for authentication, identity verification, user profiling, cross-app tracking, or to reconstruct or identify anonymous users. We do not sell, rent, license, or otherwise provide face data to data brokers, information resellers, advertisers, or analytics providers.
Vimetra is intended for adults age 18 and older. We do not knowingly collect personal information from children. If you believe a minor has provided information to us, contact us so we can investigate and delete it where required.
9. Contact Information
We may update this policy as Vimetra changes. We will post the revised version with a new “Last updated” date and provide additional notice when required by law.
For questions, consent withdrawal, or privacy and deletion requests, contact us at:
