Legal

Privacy Policy

Effective 19 July 2026 · Version 1.0

The short version. The clinical/patient data you analyze with Vivantal is processed entirely inside your own browser. It is not transmitted to Vivantal or to any third party — we do not receive it, and we could not, because there is no server anywhere in the analysis pipeline. We do run servers for hosting, sign-in, billing and email; none of them touches a clinical record. The only data that reaches us is what you provide to create an account (if you choose to), and that never includes patient information.

1. Who we are

Vivantal ("Vivantal", "we", "us") is operated by Neeraj Movva as an individual developer. A limited liability company is being formed; when it is, this section and the corresponding section of the Terms of Service will name that entity and its registered address, and the version above will change. We name the operator plainly rather than an entity that does not yet exist.

Contact us about privacy at privacy@vivantal.com. We respond to privacy requests from this address. If you require a postal address for a formal request, write to that inbox and we will provide one.

2. Patient / clinical data — processed locally, never transmitted

Vivantal's analysis engine and its de-identification tool (the "Transcriptor") run as JavaScript inside your browser tab. Any records you paste, upload, or build are read from your device and analyzed on your device. They are not uploaded to us, to our hosting provider, or to any third party. You can verify this: open your browser's developer tools → Network tab and confirm that running an analysis produces zero outbound requests carrying your data. Nothing about your records is stored by us between sessions.

You are responsible for only loading data you are authorized to handle, and for de-identifying it as required before analysis. The Transcriptor produces a candidate de-identification plus a review report; it is not a certification (see our Trust & Safety page and the Terms).

3. Account data (only if you create an account)

Creating an account is optional. If you do, we process: your email address, a securely hashed password, an organization/practice name you supply, your role, and non-clinical preferences (e.g., analysis thresholds) and audit counts (numbers of analyses run — never the underlying records). This is handled by our authentication and database provider, Supabase (see Supabase's privacy policy). No protected health information (PHI) is stored in your account.

4. Cookies & local storage

We use no advertising or analytics cookies and no third-party tracking pixels. We use:

We set no advertising, analytics or tracking cookies, and we run no third-party analytics or advertising scripts. The only browser storage we use is strictly necessary to make the product work: your on-device preferences and, if you sign in, your session token. Because none of it is used for tracking or profiling, we do not show a tracking-consent banner — there is nothing to consent to. If we ever add analytics, we will ask first and this section will change before it ships.

5. Hosting & server logs

The site is served as static files by Cloudflare Pages (Cloudflare, Inc.). Like any web host, Cloudflare may process limited technical information necessary for content delivery, security and abuse prevention — including IP address, timestamp, user-agent, and bot- and threat-detection signals — under its own retention policy. This is delivery infrastructure only; it carries no patient data.

6. Third parties we rely on

7. Your rights

You may access, correct, export, or delete your account data at any time — in-app ("Clear this device" / account settings) or by contacting privacy@vivantal.com. Where applicable law grants you privacy rights — such as the GDPR in the European Economic Area and the United Kingdom, or the CCPA/CPRA in California — we honour those rights as the law requires. Separately, and as a matter of practice rather than legal obligation, we make the following controls available to every user regardless of jurisdiction:

We aim to answer within 30 days. We will not charge you for a request, and we will not retaliate for making one. Note that we cannot access, export or delete patient data on your behalf — it never reaches us. That data lives in your browser and in whatever you exported it from, and it is yours to remove.

8. Data retention

On-device data persists only in your browser until you clear it — use "Clear this device" or your browser's own controls. We cannot clear it for you, because we cannot see it.

Backups may lag live deletion by up to 30 days before they roll over.

9. Eligibility and intended users

Vivantal is a professional tool, intended for clinicians, researchers, and quality and safety professionals acting in a professional capacity. Use requires the legal capacity to enter into our Terms of Service. The service is not directed to, and we do not knowingly collect personal information from, anyone under 18.

To state the obvious distinction plainly: this concerns who may use Vivantal. It says nothing about the patients whose de-identified records a professional user may analyse, and those records never reach us in any event.

10. How we protect account information

We maintain administrative, technical and organisational measures designed to protect account information, including encryption in transit, row-level access controls enforced at the database, server-side authorisation on every endpoint that exposes a paid capability, rate limiting, and a content security policy that blocks third-party script execution. Automated security tests run on every deployment, covering authentication, entitlement, cross-site scripting sinks, and the no-egress guarantee described in section 2.

No internet-connected service can guarantee absolute security, and we do not claim to. What we can say is narrower and more useful: the category of data most people worry about — patient records — is not in our custody to lose.

11. International users and cross-border processing

Vivantal is operated from the United States, and our service providers (Cloudflare, Supabase, Stripe, Resend) may process account data in the United States and other jurisdictions. If you access Vivantal from outside the United States, you acknowledge that account information may be transferred to and processed in jurisdictions whose data-protection laws differ from your own.

Because clinical records are analysed on your device and never transmitted, they do not cross any border by way of Vivantal. Whatever jurisdiction you are in, that data stays where you are.

12. Changes

We will post any change here and update the version and effective date above. Where a change materially affects how we handle personal information, we will say so plainly rather than relying on you to diff the document.

← Back to Vivantal · Terms of Service · Trust & Safety

Research & quality-improvement tool — not a diagnostic device. Vivantal surfaces process gaps for human review. It does not diagnose.