Legal
Privacy Policy
1. Our Commitment to Your Privacy
Vector Ventures Holdings Pty Ltd (ACN 698 553 758) ("Vector", "we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, store, and protect information about you when you use the Vector application ("App").
We handle your information in accordance with the Privacy Act 1988(Cth), the Australian Privacy Principles ("APPs"), and the Health Records Act 2001 (Vic). Health information is treated as sensitive information under both Acts and is handled with additional care.
"Services" in this Policy means the Vector mobile application, website, and all associated health analysis features, including biological age estimation, biomarker tracking, health scoring, personalised wellness insights, lab referral ordering, and any other features we make available from time to time.
2. What Information We Collect
2.1 Account Information
When you create an account, we collect:
- First name and last name
- Email address
- Date of birth
- Biological sex (used to apply sex-specific reference ranges)
2.2 Pathology and Biomarker Data
When you upload a pathology report, we process it to extract biomarker readings (e.g. glucose, cholesterol, HbA1c). Vector is designed to keep the useful health record, not a library of source documents. Reports captured in the App are read on-device where possible. A report handed off through our website is encrypted in private storage only until the App downloads it and you save the reviewed result; Vector then removes the source, with automated cleanup retrying any transient deletion failure. We store the extracted numerical values, units and collection date, together with report metadata printed on the document where available (patient name, date of birth and laboratory reference) so the saved record can be identified and reviewed. This constitutes health information for the purposes of the Privacy Act.
To improve how reports are read, the App may also send a de-identified record of a report's structure: the test names printed on it and coarse layout counts. It never includes a result value, a reference range, a collection date or any identifying detail — the App checks for those before it sends, and our server checks again before it stores. That record is linked to your account only so it is deleted when your account is, and to limit abuse; it is not used to identify you.
2.3 Apple HealthKit Data
With your explicit permission through iOS, we access the following data from Apple HealthKit:
- Heart rate variability (HRV)
- Resting heart rate
- VO2 max estimates
- Sleep data (deep sleep, REM sleep, sleep efficiency, sleep timing, and sleep regularity)
- Activity and exercise data (light, moderate, and vigorous intensity minutes)
- Active energy expenditure
Raw wearable history and device-timezone history remain on your device. To provide longitudinal trends, AI-generated insights, and your daily briefing, Vector may transmit and retain derived numerical summaries linked to your account identifier. These may include a sleep-regularity score and its data-coverage or travel-adjustment indicators. We do not retain raw sleep epochs, location history, or timezone identifiers on our servers, and no name or contact detail is included in the health-data payload sent for AI processing. HealthKit data is never used for advertising or marketing, or shared for any purpose unrelated to providing the Services.
2.4 Lab Referral Data
If you use the lab referral feature, we transmit the details required to place a pathology order to our referral provider, Eirly: your first name, last name, email address, date of birth, biological sex, phone number, and postal address (including postcode). This is the minimum information the pathology provider requires to create an Australian referral. Vector keeps that referral payload only while an order is being placed or needs human resolution, then removes it from our order record once the referral is placed or refunded. Eirly and the collecting laboratory retain the clinical referral and result records they are independently required to hold.
2.4.1 Payment Data
Lab orders are paid for through the App. Payments are processed by our payment provider, Stripe, which collects your card details directly through its secure payment interface. Vector does not receive or store your full card number; we retain only a Stripe customer reference, the payment/transaction identifier, and the amount charged, in order to fulfil and, where necessary, refund your order.
2.5 Technical Data
We collect app version and operating system version to diagnose technical issues, and record a small set of first-party product events — an event name such as completing onboarding or saving a report, together with non-identifying properties limited to counts, flags and fixed categories — against your account identifier in our own database.
Runtime errors are recorded the same way: a fingerprint that groups identical failures, the part of the App the failure came from, whether it was fatal, how many times it recurred, and the build and update channel it happened on. No message text, stack trace, URL, file, report content, biomarker value or free text you typed is recorded. Vector runs no third-party analytics or crash-reporting SDK; this data stays in Vector's own infrastructure and is never sold or shared for advertising.
2.6 Attribution and Marketing Measurement Data
To understand how people find Vector and which campaigns are effective, Vector uses Apple's SKAdNetwork and AdAttributionKit aggregate attribution systems. Vector does not request Apple's App Tracking Transparency permission. The App sends Apple only a finite conversion value representing a broad campaign outcome or retention band. It does not send Singular, TikTok or another advertising partner an advertising identifier, vendor-scoped device identifier, account identifier, event name, transaction identifier, price, click identifier or device fingerprint.
Apple delays these postbacks and may reduce or omit conversion detail to protect crowd anonymity. The signed copy Vector receives may contain aggregate network/source, publisher or source-domain, marketplace, install-country, interaction/impression, conversion-type, redownload, sequence and fine/coarse outcome fields when Apple's data tier permits. Vector stores those bounded fields for up to 400 days, never the raw signed body, and does not link the postback to a Vector account or device. Singular remains configured to receive TikTok campaign-cost data. Its ability to receive Apple's aggregate postbacks without a client SDK is awaiting written provider confirmation, so Vector does not currently rely on that path. We do not use this system for user-level matching, retargeting, deferred deep-link matching or probabilistic attribution.
For Apple Ads campaigns only, Vector also uses Apple's AdServices Attribution API. Apple may return standard campaign, ad group, ad, keyword, country, placement and conversion metadata. We associate that metadata with your Vector account to measure aggregate activation, retention and purchase outcomes. The short-lived Apple token is exchanged by Vector's server and immediately discarded; we reject detailed click or impression timestamps, do not send the result to Singular or another advertising partner, and delete retained attribution metadata after 400 days. This is used for Vector's own advertising measurement, not cross-company tracking.
Your health data is never part of this.Vector does not sell your information or use health information for advertising. We do not send Apple's attribution system, Singular or advertising platforms health information, pathology results, biomarker values, your name, contact details, date of birth or report content. We also do not send payment-card details, a StoreKit receipt or a signed purchase record. You can read Singular's privacy information. See Section 5.1 for Singular's role as a service provider.
2.7 Push Notification Data
If you enable notifications, we register a push notification token for your device. This is a device identifier issued by Apple's Push Notification service and Expo's push service, and it lets us deliver notifications to your device. The token is linked to your account identifier and is used solely to send notifications. Signing out disconnects that device from push delivery by removing its server registration and invalidating its operating-system token; unreachable tokens are also pruned from deferred delivery receipts. It is never sold or shared with third parties for advertising. You control notifications through the App (Account → Notifications) and your device settings.
3. How We Use Your Information
We use your information to:
- Create and manage your account
- Analyse your biomarker data and deliver health metrics, scores, and insights
- Generate personalised wellness insights and recommendations
- Pre-fill and submit lab referral orders on your behalf (with your authorisation)
- Send transactional communications related to your account
- Send push notifications, if you enable them, for transactional purposes, such as when a pathology report you uploaded from the website is ready to review
- Measure the effectiveness of our advertising through a marketing measurement partner (see Section 2.6)
- Improve and develop the App (using de-identified or aggregated data)
- Comply with our legal obligations
Push notifications are currently limited to transactional messages about your account and your reports; we do not send promotional or marketing notifications. You can turn notifications off at any time in the App (Account → Notifications) or in your device settings. We do not use your personal information for direct marketing without your separate consent.
4. AI Processing
The App uses Gemini 2.5 Flash through the Gemini Enterprise Agent Platform, Google Cloud's enterprise AI platform, to generate contextual health insights and, when the on-device parser cannot confidently read a difficult pathology report, to extract that report. AI requests are routed through Google Cloud's australia-southeast1 region, keeping your health data within Australia in compliance with Privacy Act APP 8. The platform is configured with zero data-retention: your health data is processed to generate your result and is not used to train or improve Google's models.
When you request AI-generated insights, your daily briefing or the Vector Profile, the following information is transmitted via our servers: biomarker values, units, and status classifications; your age and biological sex; pathology history; wearable health metrics; and derived sleep-timing and reliability summaries. Raw sleep epochs, location history, and timezone identifiers are not transmitted.
Most pathology reports are parsed on your device. If a report is empty, weak, rotated or otherwise cannot be read confidently on-device, the original report page is sent to the same Australian, zero-retention AI service for layout-aware extraction. That page may include the patient name, date of birth and laboratory reference printed on the report. We do not mask the header before this fallback because doing so can remove adjacent result rows and reduce extraction accuracy. The source is processed only to return the extracted result and is then discarded.
The contextual insight payload does not include your name, email address, or any account identifier. Your account identity is known to our servers but is never forwarded to Google. The difficult-report exception above is limited to information printed on the source report.
AI-generated insights are cached on our servers for continuity between devices and are automatically removed after no more than 120 days. Our AI usage ledger records only the model, token count, latency, product surface and a pseudonymous account identifier. It never records prompt text, a report, a direct identifier or a health value. Where AI processing is unavailable, the App falls back to deterministic, rules-based insights that run entirely on-device.
5. How We Share Your Information
We do not sell your personal information to third parties. We share your information only in the following circumstances:
5.1 Service Providers
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, and data storage | United States |
| Google LLC (Gemini Enterprise Agent Platform) | AI-powered health insight generation and difficult-report extraction via Gemini 2.5 Flash on Google Cloud enterprise infrastructure | Australia (australia-southeast1) |
| Eirly | Pathology referral processing (lab orders) | Australia |
| Stripe | Payment processing for lab orders | United States |
| Apple Inc. (HealthKit) | Health data framework (on-device only) | N/A |
| Apple Inc. (AdAttributionKit, SKAdNetwork, and AdServices) | Privacy-preserving aggregate attribution and standard Apple Ads campaign measurement | United States |
| Singular | Campaign-cost aggregation; aggregate Apple reporting pending provider confirmation | United States |
5.2 Legal Requirements. We may disclose your information if required by law, court order, or a lawful request from a government authority.
5.3 Business Transfers. If Vector is involved in a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
5.4 With Your Consent. We may share your information for other purposes with your express consent.
6. Health Information: Additional Protections
Health information is sensitive information under the Privacy Act 1988 (Cth) and the Health Records Act 2001 (Vic). We collect and use health information only with your consent, and only for the primary purpose for which it was collected.
7. HealthKit: Apple Requirements
In compliance with Apple's guidelines:
- HealthKit data is used only to provide and improve health and fitness features
- HealthKit data is not used for advertising or marketing
- HealthKit data is not sold or disclosed to third parties for advertising or data brokers
- HealthKit metrics are stored as numerical values only, never as raw files, and are never sold, shared with data brokers, or used for advertising
8. Data Security
We implement appropriate technical and organisational measures including encrypted data transmission (TLS/HTTPS), Supabase row-level security, password hashing, secure authentication, and restricted internal access on a need-to-know basis.
Reaching a private report file requires more than a valid token: the request must also belong to a sign-in session that is still live. An access token cached on a device that has since been signed out, had its sessions revoked, or whose account has been deleted cannot read those files, even before that token would have expired on its own.
9. Data Retention
- Account, biomarker, wearable, briefing, notification and secure upload data: deleted when in-App account closure completes. Account closure does not report success while a secure source file remains in Vector storage
- Website report sources: removed after the reviewed extraction is saved; abandoned pre-finalisation uploads are automatically cleaned up
- Lab referral details held by Vector: removed from the order record once the referral is placed or the order is refunded. Before account closure, any paid order that is not confidently placed is reconciled with Eirly and, when confirmed unplaced, refunded
- Subscription records: retained in de-identified form (transaction ID and product only; your name, email, and account ID are removed) for financial audit purposes
- Completed lab-order records: retained in de-identified form (payment identifier, amount, product, provider reference and status) for refund, financial and audit integrity. Vector does not retain the patient referral payload in that record
- AI insight and daily-briefing cache: retained for up to 120 days and removed automatically thereafter
- Product and error telemetry: detached from your account identifier when your account closes, and kept only as anonymous aggregate counts for product and reliability reporting
- De-identified report-structure records: deleted with your account. The test-name vocabulary mined from them carries no link to any account and stays in the parser
10. Your Rights
10.1 Access. Request access to the personal information we hold about you (APP 12). We will respond within 30 days.
10.2 Correction. Request correction of inaccurate, out-of-date, or incomplete information (APP 13). We will respond within 30 days.
10.3 Deletion. Delete your account and associated Vector data directly through the App settings, or request help at legal@vector.healthcare. The in-App flow securely resolves any paid-but-unplaced lab order, removes private report files and revokes your active sessions before completing. It will not report success while any of those remain outstanding. A lab referral or result already held by Eirly or a pathology laboratory remains subject to that provider's legal retention obligations. Support-assisted requests are processed within 30 days.
10.4 Complaints. If you believe we have breached the Privacy Act, contact us first. If unsatisfied, lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
11. Children
The App is not directed at children under 18 years of age. We do not knowingly collect personal information from children under 18.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the App or by email. Continued use of the App after the effective date constitutes your acceptance of the changes.
13. Contact Us
Privacy Officer
Vector Ventures Holdings Pty Ltd · ACN 698 553 758
Email: legal@vector.healthcare
Last updated 21 August 2026.