# Vitanexia Activity Audit Guide

Owner and operator: My Life Spark P.C.  
Effective date: August 20, 2026  
Contact: connect@myheartspark.com

## Purpose

The Vitanexia activity audit supports security, system integrity, abuse prevention, access administration, troubleshooting, service improvement, legal compliance, intellectual-property protection, Terms enforcement, and confidential dispute resolution.

## Server request events

Supported server requests are designed to create a durable audit event containing:

- A server-generated request identifier
- Server receipt date and time
- Connecting IP address received by the hosting environment
- Request method
- Requested path
- Browser user-agent information
- Source classification
- Available consent-mode information

## Interface activity events

Supported interface events are designed to add:

- Client-reported activity date and time
- Server receipt date and time
- Random browser-session identifier
- Connecting IP address derived by the server receiving the event
- Activated control or destination
- Internal or external navigation destination category
- Download initiation
- Form-submission occurrence
- Policy access
- Non-content technical-error metadata
- Consent mode available at the time of the event

## Content exclusions

The audit payload is designed to exclude:

- Access passwords
- Journal text
- Daily Pulse text
- Assessment answers
- Companion free-form reflections
- Email content
- Search terms
- Names, diagnoses, medical-record numbers, and protected health information entered into free-form fields
- Other free-form field values

A submission or control change can be recorded as an occurrence without recording the words or answers supplied by the visitor.

## Storage and access

Audit events are stored in a hosted structured database. The protected administrative viewer requires ChatGPT sign-in and authorization as the designated Vitanexia Site owner. The viewer displays up to the most recent one thousand records and supports CSV export of the displayed data. Service providers supporting hosting, security, storage, and operations can process records according to their role and applicable terms.

## Retention

The standard audit retention period is up to twelve months from collection. Records are then deleted or de-identified through the applicable operational process. A longer period can apply when reasonably required for security investigation, legal compliance, Terms enforcement, preservation of claims, or confidential dispute resolution.

## Technical completeness

The audit is comprehensive by design across supported HTTP requests and interface events. Network interruption, browser controls, offline use, content blockers, transmission errors, device settings, platform limitations, or service outages can affect capture or delivery. Failed client events can be held temporarily in bounded session storage for a later transmission attempt during the same browser session.

## Individual requests

Applicable access, correction, deletion, restriction, objection, appeal, and complaint rights vary by jurisdiction. Requests may be sent to connect@myheartspark.com with sufficient information to verify identity and locate the relevant records. Helpful information can include the approximate date range, Site used, and network address when known.
