Last updated September 24, 2026
Privacy Policy
This policy explains what personal data IndieVitals collects when you use getindievitals.com, why, where it goes and how you control it. We’ve tried to be specific: if something isn’t listed here, we don’t collect it.
IndieVitals is a wellness and business analytics tool. It does not provide medical advice, diagnosis or treatment.
The short version
- We read only what the dashboard needs: daily totals from Stripe, daily scores from WHOOP or Oura, and commit and merged PR counts from GitHub repositories you choose.
- We store normalized daily numbers, not raw provider data. We never store your customers’ details, heart-rate streams or source code.
- Connection credentials are encrypted and never sent to your browser.
- We don’t sell your data, show ads or use third-party ad trackers.
- You can disconnect any integration, or permanently delete your account, at any time.
Who we are
IndieVitals is operated by Roberto Capobianco, based in Italy (“IndieVitals”, “we”, “us”), who is the controller of the personal data described here. You can reach us at hello@getindievitals.com.
What we collect
Account and settings. Your email address (to send sign-in links), timezone, primary currency, which health provider is primary, when you consented to importing wellness data and which version of the consent text you accepted, trial dates, when you finished onboarding and last used the app, and your default share-card settings.
Business data from Stripe. IndieVitals connects as a Stripe App with read-only permissions. We read balance transactions, active subscriptions with their prices and coupons, and your Stripe account’s ID, display name and default currency. We store daily revenue (successful payments minus refunds) and the number of those transactions per day and currency, plus a daily MRR figure. We don’t store individual transactions or anything about your customers.
Wellness data from WHOOP or Oura, only after your explicit consent. We store one number per day for: sleep score, recovery (WHOOP) or readiness (Oura), heart-rate variability, resting heart rate, strain (WHOOP) or activity score (Oura), and number of workouts. These are your provider’s own scores; we don’t recalculate them. We also store your account ID at that provider. We don’t request WHOOP’s profile scope or Oura’s personal-info and email scopes, so we don’t receive your name, email or body measurements from them.
Build data from GitHub. IndieVitals is a GitHub App with read-only access to metadata, contents and pull requests of the repositories you install it on. GitHub requires contents access to list commits; we never read files. We store your GitHub user ID and username, the names and IDs of the repositories the app can access (and whether each is private and selected), and, per day, the number of commits you authored on the default branch and the number of your pull requests that were merged.
Share cards. When you publish a share card we store its settings, its date range and a frozen copy of only the values you chose to make public.
Billing. Paddle runs checkout as merchant of record and collects your payment details, billing address and tax information directly. We store your Paddle customer and subscription IDs, plan, status and billing dates, and the IDs of Paddle notifications we have processed. We never see your full card number.
Security and operations. To prevent abuse we count sign-in attempts per email address and per IP address, and some actions per account, in short-lived counters that are purged after 24 hours. Our hosting provider keeps standard request logs (such as IP address, URL and browser type). Our own application logs redact tokens, codes, email addresses and metric values.
Product analytics (optional). If enabled, our servers send a small, fixed list of events to PostHog’s EU cloud, such as “signed up”, “connected an integration”, “viewed the dashboard” or “created a share card”. Events carry your account ID and simple yes/no or category values. They cannot include revenue, scores, HRV, customer details or credentials, and we don’t send your IP address. There is no analytics script in your browser. Views of the public demo use a cookieless anonymous ID, a keyed hash of IP address and browser type that changes every day and can’t be linked across days.
What we never store
- Raw responses from Stripe, WHOOP, Oura or GitHub. We keep normalized daily numbers only.
- Your customers’ names, emails, cards or addresses, or individual Stripe transactions.
- Heart-rate streams, sleep stages, temperature, location, notes or tags.
- Your WHOOP or Oura name, email or profile.
- Source code, file contents, commit messages, pull request titles, issues or comments.
- Daily insights. They are computed from your numbers each time you open the dashboard and never saved.
How we use your data
- To show your dashboard: today’s numbers, comparisons with the previous week and with your own baseline, history charts, and a one-line daily observation produced by fixed rules, not an AI model.
- To sync your connected accounts daily and when you ask, and to tell you when a connection needs attention.
- To run your trial and subscription.
- To send sign-in links and essential account or billing notices. We don’t send marketing email without your permission.
- To keep the service secure and prevent abuse.
- To understand, in aggregate, which parts of the product are used, so we can improve it.
We never sell or rent personal data, share it with advertisers, use third-party advertising trackers, use your data to train AI models, or make automated decisions about you that have legal or similarly significant effects.
Legal bases (EEA and UK)
- Contract (Art. 6(1)(b) GDPR): your account, syncing Stripe and GitHub, the dashboard, share cards you create, and billing.
- Explicit consent (Art. 9(2)(a) and 6(1)(a)): wellness data from WHOOP or Oura may be health data. We ask before you connect and record when you agreed and to which version of the text. You can withdraw consent at any time by disconnecting the provider, which deletes the wellness data we hold, or by deleting your account. Withdrawal doesn’t affect processing that happened before it.
- Legitimate interests (Art. 6(1)(f)): securing the service, preventing abuse and fraud, rate limiting, operational logs, and minimal product analytics. You can object to these at any time.
- Legal obligation (Art. 6(1)(c)): where the law requires us to keep or disclose information.
Who processes your data
We use these sub-processors to run IndieVitals:
- Vercel: hosting and serverless functions (EU region), including request logs.
- Supabase: Postgres database and authentication, including sending sign-in emails. Production data is hosted in the EU.
- Paddle: merchant of record for subscriptions. Paddle handles checkout, payments, taxes, invoices and refunds, and processes payment data under its own privacy notice.
- PostHog (optional): product analytics, EU cloud, as described above.
Stripe, WHOOP, Oura and GitHub are data sources that you choose to connect. We send them only what is needed to authorize and read your data, and their own terms and privacy policies govern what they do. We may also disclose information when the law requires it, or to a successor if IndieVitals is sold or merged, in which case we’ll tell you first.
International transfers
We keep production data in the EU where we can. Some sub-processors, or their own providers, may process data outside the EEA or UK, for example in the United States. Where a country lacks an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (with the UK addendum where relevant) or another lawful transfer mechanism.
How long we keep data
- Account data, settings, metrics, encrypted credentials and share cards: for as long as your account exists. If your trial ends without a subscription, your data stays until you delete it.
- Disconnecting a provider deletes its credentials, connection record and metrics immediately.
- Revoking a share card deletes its public snapshot immediately.
- Rate-limit counters: 24 hours.
- Hosting request logs: kept by Vercel for a limited period under its retention settings.
- Database backups kept by Supabase may contain deleted data until they expire on their regular schedule.
- Product analytics events (only when analytics is enabled) are tied to a random account ID and contain no personal details, health or revenue values. They are not erased automatically when you delete your account; they are kept for at most 12 months, and we delete them sooner on request.
- Paddle keeps transaction records for as long as tax and accounting law requires.
Disconnecting and deleting
Disconnect any integration from Settings. We revoke our access at the provider where it supports this (WHOOP, Oura and GitHub), then delete the stored credentials, the connection and that provider’s metrics (and, for GitHub, the repository list). Stripe Apps can’t uninstall themselves, so for Stripe we delete our credentials and ask you to remove IndieVitals in Stripe Dashboard → Settings → Installed apps.
Delete your account from Settings → Account. Deletion is permanent and immediate; there is no soft delete. We cancel any Paddle subscription immediately, delete your sign-in account, revoke every connection, and delete your profile and everything linked to it (connections, credentials, metrics, repository list, share cards and billing state). This can’t be undone. If we can’t cancel your subscription or delete your sign-in account, we tell you and don’t report your account as deleted; if a later step is interrupted we finish it automatically within a day. Product analytics events are handled as described under “How long we keep data”.
Security
- Provider credentials are encrypted with AES-256-GCM in our application using a key stored outside the database. Each encrypted value is bound to its own record, and credentials are never sent to your browser.
- Database row-level security: browser-facing database roles can’t read credentials at all, and can only read your own rows.
- Every provider connection is read-only and limited to the minimum scopes listed above.
- HTTPS everywhere with HSTS, a strict content security policy, signed short-lived OAuth state cookies, and share links with unguessable 256-bit tokens.
No system is perfectly secure. If a breach affects your personal data, we’ll notify you and the relevant authorities as the law requires.
Your rights
Depending on where you live, including under the GDPR and UK GDPR, you have the right to access, correct, delete or port your data, to restrict or object to processing, and to withdraw consent at any time. You can edit your timezone and currency, disconnect providers and delete your account yourself in Settings. For anything else, including a machine-readable copy of your data, email hello@getindievitals.com. We’ll reply within one month and may need to verify your identity first.
You also have the right to complain to a data protection supervisory authority, in particular in the country where you live or work, or where you believe an infringement occurred.
Children
IndieVitals is for adults using it for their business. It is not intended for anyone under 18.
Changes to this policy
When we change this policy we update the date at the top, and we’ll tell you by email or in the app before material changes take effect. See also our Terms of Service.
Contact
Questions or requests: hello@getindievitals.com.