Vitamin GPT

Privacy Policy for “Vitamin GPT”

Last updated: May 18, 2025

1. Who We Are

Vitamin GPT (“we,” “us,” “our”) is an open‑source chatbot hosted on Vercel. Source code is publicly available at https://github.com/kevink520/vitamin-gpt. To contact us, email kevin@digitalmedia.nyc.

2. Scope

This Privacy Policy explains how we collect, use, disclose, and safeguard information obtained when you interact with the chatbot located at https://vitamin-gpt.vercel.app (the “Service”).

3. Information We Collect

CategoryExamplesCollected HowPurpose
Chat ContentFree‑form text you enterDirectly from youProvide responses, improve Service
Analytics DataPage‑views, anonymised IP (last octet removed), device/OS, geographic region (city/country)Google Analytics 4 JavaScript (gtag.js) cookies & local‑storageMeasure traffic patterns, improve performance
Device & UsageIP address, browser type, timestamps, referrerAutomated logsSecurity, analytics
Optional IdentifiersEmail (if voluntarily provided)Directly from youAccount linking, support

We do not intentionally collect special categories of personal data (e.g., health, biometric).

4. Legal Bases for Processing (GDPR)

Consent – when you click the “Send” button, you consent to processing the text you enter.

Legitimate Interests – to prevent abuse, maintain logs, and improve the Service.

Contract – if you sign up for an account or API key.

5. How We Use Information

Generate and display chatbot responses.

Analyse usage trends via Google Analytics 4 to understand which prompts and pages are most helpful and to diagnose errors.

Monitor performance and debug errors.

Anonymize conversations for research or documentation.

Comply with legal obligations.

6. Sharing & Sub‑Processors

We share data only with:

ProviderRoleSafeguards
Google LLC (Google Analytics 4)Web analytics & performance metricsIP-anonymisation, no PII per GA ToS, EU Standard Contractual Clauses for cross-border transfers
Amazon Web Services (DynamoDB, Region us-east-1)Primary databaseEncryption at rest (KMS); AWS DPA
Vercel Inc.Hosting & edge cachingStandard Contractual Clauses (for EU data)
GitHub Inc. (Actions logs)Continuous deploymentAccess restricted

No data is sold or rented.

7. Retention

Chat logs are kept for 30 days, then irreversibly anonymized; system backups are deleted within 90 days. Aggregated statistics may be kept indefinitely.

Google Analytics reports are automatically set to 26-month rolling deletion, the shortest GA4 retention period, after which only aggregated statistics remain.

8. Security

We employ TLS 1.3 for all network traffic, encryption at rest via AWS KMS, IAM least‑privilege policies, and routine vulnerability scans.

9. Your Rights

GDPR/UK GDPR: access, rectification, erasure, restriction, data portability, object.

California: right to know, delete, correct, and opt‑out of selling/sharing personal info.

To exercise any right, email kevin@digitalmedia.nyc or open an issue on the GitHub repo. We will respond within 30 days.

Users may also opt out of analytics tracking at any time via the methods listed in §10 or by e‑mailing us.

10. Cookies & Tracking

The Service itself sets no first‑party cookies, but Google Analytics 4 places the following cookies or uses local‑storage keys:

NameLifetimePurpose
_ga24 monthsDistinguish users
_ga_<container‑id>24 monthsPersist session state
_gid24 hSession counter

Opt‑out: Visitors can install the Google Analytics Opt‑out Browser Add‑on or use browser Do Not Track settings. We honour these signals by disabling GA4 collection when consent is not granted (see banner on first visit).

11. Children’s Privacy

The Service is not directed to children under 13. We do not knowingly collect info from children. If you believe we have inadvertently collected such info, contact us for deletion.

12. Changes to This Policy

We may update this Policy from time to time. Material changes will be announced on the GitHub repository’s Releases page and take effect 14 days after posting.

13. Contact

Questions? Email kevin@digitalmedia.nyc.