Last updated: April 27, 2026
VitalTrack is a personal health tracking app built by Bulwark Agent. Your health data stays on your device. We do not sell, share, or monetize your personal information.
VitalTrack is developed and operated by Bulwark Agent, an independent software company based in Seattle, WA. You can reach us at lucas@bulwarkagent.com.
VitalTrack collects health and fitness data that you voluntarily enter, including:
All health data is stored locally on your device using your browser's local storage. Data is associated with your user account on our Cloudflare Workers infrastructure solely to enable sync and backup features.
We do not build advertising profiles. We do not sell data to third parties. Your health information is never used for purposes other than delivering the VitalTrack service to you.
If you connect your Garmin account, VitalTrack uses the Garmin Connect API to read activity data including steps, heart rate, sleep, and workouts. This connection uses OAuth 2.0 — your Garmin credentials are never shared with or stored by VitalTrack. You can disconnect Garmin at any time from the Settings tab.
Garmin data is used only to populate your VitalTrack dashboard and coaching context. It is not shared with third parties.
VitalTrack uses Claude (by Anthropic) to power food parsing, workout analysis, and coaching. When you use AI features, the text of your request is sent to Anthropic's API to generate a response. Anthropic's privacy policy governs their handling of API data. We do not send your full health history to the AI — only the context needed to answer your specific query.
We do not sell, rent, or share your personal health data with third parties, except:
Each of these providers processes data only as necessary to deliver the service and is bound by their own privacy policies.
Your data is retained as long as your account exists. You can delete all of your data at any time from the Settings tab inside VitalTrack ("Clear All Data"). This permanently removes all locally stored and server-side data associated with your account.
All data in transit is encrypted via HTTPS/TLS. Server-side data is stored in Cloudflare KV with access controls scoped to your user account. We do not expose health data in URLs or logs.
VitalTrack is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
We may update this policy as the app evolves. We will update the "Last updated" date at the top of this page when changes are made. Continued use of VitalTrack after changes constitutes acceptance of the updated policy.
Questions or concerns about this privacy policy? Contact us at lucas@bulwarkagent.com.