Перейти до вмісту

    Політика конфіденційності

    Як ми обробляємо та захищаємо ваші дані.

    Last Updated: October 1, 2026

    This Privacy Policy describes how Pet Health+ ("we," "us," or "our") collects, uses, and protects your information when you use the Pet Health+ mobile application on iOS (iPhone, iPad, Apple Watch) and Android (phone, tablet) (collectively, the "App"). Where iOS and Android behave differently — for example, storage, sync, and payment processing — we call out those differences inline.

    Data Controller

    The data controller responsible for your personal data under the EU General Data Protection Regulation (GDPR) is PE Denys Rudiak (Private Entrepreneur / Приватний підприємець), registered in Ukraine.

    You can reach us at support@pethealthplus.app.

    EU representative (Art. 27 GDPR): We have not appointed an EU representative. EU residents can send data-protection enquiries to the support email above; we will respond within the GDPR one-month window.

    Data Protection Officer: We are not required to appoint a DPO under GDPR Art. 37 (we are a small operation, we do not carry out large-scale systematic monitoring, and we do not process special categories of personal data at scale). The developer handles data-protection questions personally.

    1. Information We Collect

    1.1 Information You Provide

    When you use the App, you enter the following information:

    • Pet profiles: name, species, breed, date of birth, avatar photo
    • Health records: vaccinations, treatments, procedures, and custom record types
    • Document attachments: photos and PDF files from your camera or from cloud storage
    • Reminder preferences: notification schedules for upcoming vaccinations and treatments
    • Vet and emergency details: clinic name, phone number, email and address, microchip number, allergies, and current medications. On iOS you can fill the vet fields from a contact you pick yourself — see § 2.2.
    • Feature requests: if you submit feedback through the in-app feature request tool (iOS only; Android users use the support email)
    • (Android only) Google account email: shown transiently during Google Drive OAuth consent when you enable Drive backup. We never store it.

    We do not collect: your real name, email address, phone number, physical address, card details, or any other direct identifier. The App does not require an account or login. Pro purchases are handled by Apple or Google (see § 4 below).

    1.2 Information Collected Automatically

    On iOS (App Store builds), Firebase Analytics and Firebase Crashlytics are active by default, except in the European Economic Area, the United Kingdom and Switzerland (decided from your App Store country): there both are off until you agree, and the app asks once, after setup, whether you want to share anonymous usage data. Nothing is sent before that choice. You can turn either off (or on) at any time in Settings → Privacy inside the app; turning analytics off also deletes the app-instance analytics identifier on the device, and turning crash reports off deletes reports not yet sent.

    They collect the following categories — none of which include your pet data, pet names, record contents, photos, documents, or any identifier we could use to contact you:

    • Firebase Analytics: anonymised usage events (for example "record created", "reminder set", "paywall shown", "Siri intent invoked"), event parameters limited to category names (record type, tab, feature name, intent name, result), app version, iOS version, device model, app language, coarse country, session timing, and a random app-instance identifier generated by the SDK.
    • Firebase Crashlytics: crash and non-fatal error reports containing stack traces, device model, iOS version, app version, the device state Crashlytics records with every report (such as free memory and free disk space, orientation, and whether the app was in the foreground), the number of pets and records, whether iCloud is signed in, and a random installation identifier. The device state is collected by Crashlytics itself; the App adds only non-identifying diagnostic values (counts, error codes, iCloud status) and no longer adds a disk-space value of its own. Error reports never contain record names, pet names, phone numbers, or email addresses.
    • Firebase Remote Config: fetches feature switches; it sends the same random app-instance identifier and app/OS version.

    On Android (release builds), Firebase Analytics and Firebase Crashlytics are active by default. They collect the following categories — none of which include your pet data, pet names, file content, or any identifier we can tie to you personally:

    • Default Firebase events: session_start, first_open, screen_view, app_remove
    • App version, OS version, device model, language, country-level region
    • A Firebase-internal app-instance ID (not the Android Advertising ID — that is explicitly disabled by the App)
    • Crash reports: stack traces, device model, OS version, app version, last 100 redacted log lines

    On iOS, you can turn off usage statistics and crash reports at any time in Settings → Privacy inside the App. Because analytics data is anonymous, we cannot look up or delete an individual user's analytics history; disabling analytics stops collection and resets the on-device analytics identifier. (The in-app switch ships on Android in v1.1. Until then, you can disable personalized ads and analytics at the device level via Settings → Google → Ads, and uninstalling the App removes all collected data from your device.)

    2. How We Use Your Information

    2.1 Purposes

    • App functionality: to store and display your pet health records, send reminders, and sync across your devices (iCloud on iOS; Google Drive backup on Android).
    • Bug fixes and stability: to identify crashes and errors using anonymous crash reports.
    • Aggregate product metrics: to understand which screens are used and where the App crashes, so we can prioritize fixes. Active on Android, and on iOS from version 3.6.0 unless you turn it off in Settings → Privacy (in the EEA, the UK and Switzerland, only after you opt in).
    • Product improvement: to review feature requests submitted through the in-app feedback tool.
    • Ukraine storefront override: see § 11 below.

    We do not use your information for advertising, cross-site tracking, profiling, marketing, or any purpose other than those listed above.

    2.2 Feature-Specific Processing (iOS)

    Some features touch data that the rest of the App never sees. This is what each one does.

    Vet contact import (Contacts)

    When you tap "Pick from Contacts" on a vet field, the system contact picker opens. Only the contact you choose is read, and only the vet's name or company, phone number, email, and address are copied into the pet's profile. Your contacts are never uploaded by us; the copied vet details are stored with the pet, sync through your iCloud, and are visible to anyone you share that pet with through Family Sharing.

    Scan a Record (Camera)

    "Scan a record" uses the system document camera and Apple's on-device text recognition to pre-fill a vaccination record from a printed certificate. The captured image is processed in memory on your device and discarded after recognition; it is not saved and not uploaded. Only the fields you confirm are stored in the record.

    AI Insight (Apple Intelligence)

    The AI Insight card on Pet Today is generated on your device by Apple's Foundation Models framework. The model receives a short, structured summary (pet name, species, weight trend, next reminder, overdue count, recent vet visits, active medications) and returns three sentences. Nothing is sent to Apple, to us, or to any third party. The generated text is cached on your device and cleared when the pet is deleted.

    Siri and Shortcuts

    Siri and the Shortcuts app can ask the App for a pet's next vaccine, upcoming reminders, the emergency card, or log a weight. Requests are resolved on your device against your own data. Apple processes your voice according to Apple's Siri privacy policy; we receive only the resulting action.

    Family Sharing recipients

    When you share a pet, the pet's records (vaccinations, treatments, procedures, medications, weights, notes, documents, vet details, emergency information, and photo) become readable by the people you invite, through Apple's CloudKit sharing. Stop sharing at any time from Settings → Family Sharing; participants lose access immediately.

    Apple Wallet emergency pass (iOS 3.7.0 and later, Pro)

    Apple requires every Wallet pass to be signed with a certificate whose private key cannot ship inside an app. When you tap "Add to Apple Wallet" on a pet's emergency card, the App sends the fields shown on the pass to our signing service ("pethealth-wallet", hosted on Cloudflare Workers): the pet's name, type, breed, age and photo, microchip number, vet name and phone number, allergies, conditions, current medications, vaccinations, and the pass's labels in your language. The signed pass comes straight back to your iPhone. These details are used only to build that pass; they are not stored and not logged, and Cloudflare's request logs are turned off for the service.

    To make sure only the genuine App can have passes signed, the App proves itself with Apple's App Attest. For each installation that uses the feature, the service keeps a small record: the App Attest public key, its counter, its environment, and how many passes it signed that day (at most 30). The record holds no pet data and is deleted after 180 days without use. To stop abuse, the service also counts requests per IP address for one minute; the address is not stored. Nothing is sent until you tap the button, and the pass itself lives in Apple Wallet on your device, where you can delete it at any time.

    WishKit (feature requests)

    The "Feature requests" screen is provided by WishKit. It stores the text you submit together with a random identifier so you can see your own requests again. No email address is collected.

    3. How Your Data Is Stored

    3.1 On-Device Storage

    All pet health records, profiles, and attachments are stored locally on your device.

    • iOS: Apple's SwiftData framework in the app sandbox, protected by iOS Data Protection (passcode, Face ID, Touch ID).
    • Android: a private Room (SQLite) database at /data/data/com.drudyak.pethealth/, inaccessible to other apps, protected by Android File-Based Encryption.

    On both platforms, on-device data is protected by the operating system's per-app sandboxing. We do not add an app-level encryption layer on top of the OS in v1.0; we are evaluating this for a future release.

    3.2 Cross-Device Sync (optional)

    • iOS (iCloud): if iCloud is enabled on your Apple devices, your pet data syncs through your personal iCloud account using Apple's CloudKit. Apple encrypts this data in transit and at rest. We do not have access to your iCloud data. See apple.com/legal/privacy.
    • Android (Google Drive): if you enable Drive backup, a ZIP archive of your pet database and attachments is uploaded to your own Google Drive using the drive.file OAuth scope (which limits access to files the App creates — it cannot read the rest of your Drive). Enabling Drive backup requires signing in with your existing Google account; the OAuth consent flow happens between you and Google directly. We do not create, collect, or store your Google account or OAuth credentials — the access token we receive is held in memory during the upload and discarded when the App closes. The backup itself lives in your Drive, not ours; uploads are transport-encrypted (TLS 1.3) and stored encrypted at rest by Google. This is server-side encryption, not end-to-end — Google can technically access the backup. To avoid this, leave Drive backup disabled. Manual Drive backup is free; scheduled automatic Drive backup is a Pro feature.

    iOS (Family Sharing): you can additionally share one pet with other people through Apple's CloudKit sharing. What the recipients can see, and how to revoke access, is described in § 2.2.

    Once data is in iCloud or Drive, it is subject to the cloud provider's terms and retention controls — not ours. You can disable sync at any time in your device settings (iOS: Settings → [Your Name] → iCloud; Android: App Settings → Backup → disable).

    4. Third-Party Services

    The App uses the following third-party services. Every transfer destination is TLS 1.3 in transit.

    Firebase Crashlytics (Google LLC, United States)

    Purpose: crash reporting and error logging.
    Data shared: anonymous crash data, device model and OS version, device state (such as free memory and free disk space), stack traces, app version, a random installation identifier — no pet data, no file content, no identifier we can tie to you.
    Platforms: iOS (since 3.6.0: on by default, opt-out via Settings → Privacy; off until you opt in in the EEA, UK and Switzerland) · Android (on by default; opt-out via Settings → Privacy in v1.1).
    Retention: 90 days.
    Transfer mechanism: EU-US Data Privacy Framework + Standard Contractual Clauses.
    Privacy policy: firebase.google.com/support/privacy

    Firebase Analytics and Remote Config (Google LLC, United States)

    Purpose: aggregate usage metrics (screen views, sessions, feature usage, version adoption) and feature switches.
    Data shared: anonymised usage events and category-name parameters, app version, OS version, device model, language, country-level region, a Firebase app-instance ID. No advertising identifier is collected: the Android Advertising ID is explicitly disabled, and the iOS build links the Firebase SDK variant that does not contain the advertising identifier at all.
    Platforms: iOS (since 3.6.0: on by default, opt-out via Settings → Privacy; off until you opt in in the EEA, UK and Switzerland) · Android (on by default; opt-out via Settings → Privacy in v1.1).
    Retention: 14 months.
    Transfer mechanism: EU-US Data Privacy Framework + Standard Contractual Clauses.
    Privacy policy: firebase.google.com/support/privacy

    Google Play Billing (Google LLC) — Android only

    Purpose: processing Pro subscription payments.
    Data shared: anonymized purchase receipts (we never see your card details, address, or tax ID — those stay with Google).
    Retention: per the Google Play Developer Distribution Agreement.
    Privacy policy: play.google.com/about/play-terms

    Apple App Store Billing — iOS only

    Purpose: processing Pro subscription payments.
    Data shared: subscription receipts. Apple handles all card and billing information directly — we never see it.
    Privacy policy: apple.com/legal/privacy

    RevenueCat, Inc. (United States)

    Purpose: subscription receipt validation and Pro entitlement management.
    Data shared: an anonymous app-user ID (not your name or email), subscription product IDs, entitlement status, receipt data received from Apple or Google.
    Retention: until you request deletion via support@pethealthplus.app.
    Transfer mechanism: Standard Contractual Clauses (see revenuecat.com/dpa).
    Privacy policy: revenuecat.com/privacy

    Google Drive (drive.file scope) — Android only, optional

    Purpose: user-initiated backup of pet data to the user's own Drive account.
    Data shared: a ZIP archive containing your on-device database and attachments, uploaded only when you enable Drive backup.
    Retention: controlled entirely by you — we cannot delete Drive files on your behalf.
    Opt-out: App Settings → Backup → disable, then revoke the OAuth grant at myaccount.google.com/permissions.

    WishKit — iOS only

    Purpose: in-app feature request and feedback collection.
    Data shared: feature request text and basic device context, plus a random identifier so you can see your own requests again — no email address — submitted voluntarily by the user.
    Opt-out: do not submit feature requests. No data is sent unless you actively use the feature request tool. Android users reach us via the support email instead.
    Privacy policy: wishkit.io/privacy

    Cloudflare Workers (Cloudflare, Inc., United States) — iOS only, Apple Wallet passes

    Purpose: hosts our pass-signing service for the emergency card in Apple Wallet (see § 2.2).
    Data shared: only when you add a pass: the pass fields and photo, processed in memory to sign the pass and not stored or logged; and a per-installation App Attest record (public key, counter, daily pass count) with no pet data, deleted after 180 days without use.
    Opt-out: don't use "Add to Apple Wallet"; nothing is sent otherwise.
    Privacy policy: cloudflare.com/privacypolicy

    Apple iCloud / CloudKit — iOS only

    Purpose: cross-device sync of pet health records.
    Data shared: all App data (pet profiles, health records, attachments) synced through your personal iCloud account; encrypted by Apple in transit and at rest (end-to-end if you turn on Apple's Advanced Data Protection). Shared pets use CloudKit sharing with the people you invite.
    Opt-out: disable iCloud for the App in iOS Settings.
    Privacy policy: apple.com/legal/privacy

    Not third parties: the document scanner and text recognition behind "Scan a record", and the Apple Intelligence model behind AI Insight, run entirely on your device. They send nothing to Apple, to us, or to anyone else, so they are not listed above.

    We do not sell, rent, or share your personal information with any other third parties. We do not use advertising networks or marketing analytics tools.

    5. Legal Basis for Processing (GDPR Art. 6)

    If you are in the EEA or UK, we rely on the following lawful bases:

    PurposeLawful basis
    Storing pet records on your device (core app functionality)Art. 6(1)(b) — contract
    Firebase Crashlytics stability monitoringiOS in the EEA, UK and Switzerland: Art. 6(1)(a) — consent (asked once after setup; off until you agree). Elsewhere and on Android: Art. 6(1)(f) — legitimate interest (opt-out available)
    Firebase Analytics aggregate metrics (iOS and Android)iOS in the EEA, UK and Switzerland: Art. 6(1)(a) — consent (asked once after setup; off until you agree). Elsewhere and on Android: Art. 6(1)(f) — legitimate interest (opt-out available)
    Importing a vet from your contacts (iOS)Art. 6(1)(a) — consent, given at the system contact picker
    Sharing a pet with family members (iOS)Art. 6(1)(a) — consent, given when you send the invitation
    Google Drive backup uploadArt. 6(1)(a) — your explicit consent at OAuth time
    Apple / Google Play Billing purchaseArt. 6(1)(b) — contract
    RevenueCat subscription validationArt. 6(1)(b) — contract
    Signing an Apple Wallet emergency pass you ask for (iOS)Art. 6(1)(b) — contract (providing the feature you request); App Attest abuse protection: Art. 6(1)(f) — legitimate interest
    WishKit feature request submission (iOS)Art. 6(1)(a) — consent
    Ukraine storefront Pro overrideArt. 6(1)(f) — legitimate interest

    6. International Data Transfers (GDPR Chapter V)

    Our third-party vendors (Google LLC, RevenueCat Inc., Cloudflare Inc.) are headquartered in the United States. When you use the App, the categories of data described in § 4 may be transferred to the US.

    We rely on these transfer mechanisms:

    • Google LLC (Firebase, Google Play, Google Drive): EU-US Data Privacy Framework (DPF) adequacy decision, with Standard Contractual Clauses as a fallback.
    • RevenueCat, Inc.: Standard Contractual Clauses per their Data Processing Addendum.
    • Cloudflare, Inc. (website hosting, the Apple Wallet signing service): EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback.

    All transfers are protected in transit by TLS 1.3 and at rest by vendor-level encryption.

    7. Data Retention

    DataRetention
    Pet health records (on device)Until you delete them or uninstall the App
    iCloud / Google Drive backupsControlled by you; follow Apple / Google retention settings
    Firebase Crashlytics data90 days, then automatically deleted
    Firebase Analytics data (iOS and Android)14 months
    Scanned certificate image (iOS)Not retained — held in memory during recognition, then discarded
    AI Insight text (iOS)Cached on your device until the insight is regenerated or the pet is deleted
    Apple Wallet pass contents sent for signing (iOS)Not retained — used in memory to sign the pass, then discarded; not logged
    App Attest key record for Wallet signing (iOS)Deleted after 180 days without use
    RevenueCat anonymous app-user IDUntil you request deletion via email
    Google / Apple billing receiptsRetained by the payment processor (typically 7 years for tax and accounting)
    WishKit feature requests (iOS)Until the feature is addressed or the request is withdrawn
    Deleted pets and records (iOS)Hidden at once (you can undo for a few seconds). Deleted pets are kept on your device and in your iCloud for 30 days so a sync mistake can't lose them, then erased. Other deleted records are erased once the undo window closes

    8. Data Security

    We take reasonable technical and organizational measures to protect your information:

    • All data is stored on-device with OS-level encryption (iOS Data Protection / Android File-Based Encryption)
    • iCloud sync is encrypted by Apple in transit and at rest (end-to-end with Apple's Advanced Data Protection)
    • Google Drive backup is transport-encrypted (TLS 1.3) and encrypted at rest by Google
    • All vendor communication uses TLS 1.3
    • Our only server is the Apple Wallet pass-signing service: it receives a pass's fields only when you add a pass, keeps none of them, and verifies each request with Apple's App Attest
    • The App does not require or store login credentials (OAuth tokens for Drive are held in-memory only)

    No method of electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

    9. Children's Privacy (GDPR Art. 8)

    The App is not directed at children under 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has used the App, please contact us at support@pethealthplus.app and we will take reasonable steps to comply with your request, including deleting any data you identify.

    For users in the United States, we follow the COPPA threshold of 13 years old where applicable. For all other users, the GDPR threshold of 16 applies.

    10. Your Privacy Rights

    10.1 All Users

    Regardless of your location, you can:

    • Delete any or all pet records and data within the App at any time
    • Disable cloud sync (iCloud on iOS; Drive backup on Android) to keep data on-device only
    • Turn off usage statistics and crash reports in Settings → Privacy inside the App (iOS since 3.6.0; the Android in-app toggle ships in v1.1 — meanwhile use the device-level settings described in § 1.2). Because analytics data is anonymous, we cannot look up or delete an individual user's analytics history; disabling analytics stops collection and resets the on-device analytics identifier.
    • Uninstall the App entirely — this removes all locally stored data. See our data deletion guide for step-by-step instructions on iOS and Android.

    10.2 European Economic Area, UK, Switzerland (GDPR / UK-GDPR / FADP)

    If you are in the EEA, UK, or Switzerland, you have the following rights:

    • Access (Art. 15): obtain a copy of your personal data and information about how we process it.
    • Rectification (Art. 16): correct inaccurate data. You can do this directly in the App for pet records.
    • Erasure / "right to be forgotten" (Art. 17): request deletion. Most data is user-deletable directly in the App; for vendor-held data (RevenueCat app-user ID, WishKit submissions) we will action your request.
    • Restriction (Art. 18): ask us to pause processing while a concern is investigated.
    • Portability (Art. 20): receive your pet records in a machine-readable format. The App's PDF export covers this today; JSON export is planned.
    • Object (Art. 21): object to processing based on legitimate interest (Firebase Analytics / Crashlytics). We will honor the objection by disabling telemetry for your installation.
    • Withdraw consent (Art. 7(3)): withdraw any consent you gave (usage statistics and crash reports — on iOS in Settings → Privacy; WishKit submission; Google Drive OAuth). Withdrawal does not affect processing that already occurred.
    • Automated decisions (Art. 22): we do not carry out automated decision-making or profiling.
    • Lodge a complaint (Art. 77): you can complain to your local supervisory authority. A directory is available at edpb.europa.eu.

    To exercise any of these rights, contact us at support@pethealthplus.app. We will respond within one month of receipt. Where a request is complex or voluminous, we may extend by up to two further months and will tell you within the first month.

    10.3 German users (BDSG)

    German residents may enforce the GDPR rights listed above through their state data-protection authority ( Bundesbeauftragter für den Datenschutz und die Informationsfreiheit or the relevant Landesbeauftragter). We are not required to appoint a Data Protection Officer under § 38 BDSG (our headcount and processing volumes are below the mandatory thresholds).

    10.4 California Residents (CCPA / CPRA)

    If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with specific rights:

    • Right to Know: the categories and specific pieces of personal information we have collected.
    • Right to Delete: you may request deletion. Since most data is on your device and in your own iCloud or Drive, you can delete it directly; for vendor-held data, email us.
    • Right to Opt-Out of Sale / Sharing: we do not sell or share personal information for cross-context behavioral advertising. You have nothing to opt out of.
    • Right to Non-Discrimination: we will not discriminate against you for exercising your privacy rights.
    • Right to Correct: correct inaccurate personal information directly in the App.
    • Right to Limit Use of Sensitive Personal Information: we do not process sensitive personal information as defined under CPRA.

    Categories of personal information collected (past 12 months):

    • Internet or other electronic network activity information (anonymous crash and diagnostic data, and aggregate usage analytics on iOS and Android)
    • Identifiers (random Firebase app-instance and installation identifiers; the anonymous RevenueCat app-user ID)
    • Approximate geolocation (country or region derived by Google Analytics from the IP address; the IP address itself is not stored by us)
    • Commercial information (anonymous Pro subscription status via RevenueCat, if you purchased Pro)

    To exercise your CCPA rights, email support@pethealthplus.app. We will respond within 45 days.

    10.5 California "Shine The Light"

    California Civil Code § 1798.83 allows California residents to request information about disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for direct marketing purposes.

    11. Storefront-Based Pro Access (Ukraine)

    If your Google Play account or Apple App Store account is registered in Ukraine, Pro features are unlocked free of charge as our way of supporting pet parents at home. We determine your storefront from your App Store or Play Billing country code, not from your IP address or device location. We do not use your storefront for any other purpose and do not retain it after the check.

    Legal basis: Art. 6(1)(f) — legitimate interest in honoring a brand commitment to Ukrainian users during wartime.

    12. Data Breach Notification (GDPR Art. 33 / 34)

    In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach per Art. 33 GDPR, and we will inform affected users without undue delay where the risk is high (Art. 34). Because we hold no pet data at rest on our side (the Wallet signing service keeps only per-installation App Attest records), the realistic breach scenarios are limited to vendor-side incidents; we will relay those notifications to you in the same timeframe.

    13. This Website, Do Not Track and Global Privacy Control

    This website. pethealthplus.app is hosted by Cloudflare, Inc. (United States), which processes your IP address and request details to deliver the site and to block abusive traffic, and counts visits with Cloudflare Web Analytics, which sets no cookies. Google Analytics 4 (Google LLC, United States) is loaded only if you accept analytics in the cookie banner: it then sets two cookies (_ga and _ga_<id>) to count visits and see which pages are read and how far people scroll, and Google receives your IP address to do this. If you deny, Google Analytics is not loaded at all. Your cookie choice and your language are kept in your browser. You can change your choice at any time under Cookie Settings in the footer. The lawful basis for Google Analytics is your consent (Art. 6(1)(a) GDPR); for hosting and security it is our legitimate interest in running a safe website (Art. 6(1)(f)).

    Do Not Track and GPC. Neither the App nor the website tracks you across other companies' apps or websites, and we do not sell or share personal information or run advertising. The website does not change its behavior for Global Privacy Control signals; to keep Google Analytics off, choose Deny in the cookie banner, or leave it unanswered.

    14. Changes to This Policy

    We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page, and for significant changes we will surface a notice inside the App before you can continue using it. Your continued use of the App after changes are posted constitutes acceptance of the updated policy.

    15. Contact Us

    For any questions, concerns, or rights requests under this Privacy Policy:

    Pet Health+

    Email: support@pethealthplus.app

    Changelog

    • October 1, 2026: We have not appointed an EU representative; the section no longer says one is being appointed. Added Cloudflare to the international transfers, and the per-IP rate limiting of the Wallet signing service.
    • October 1, 2026: Corrected the retention of deleted data in the app: only deleted pets are kept for 30 days; other deleted records are erased once the undo window closes.
    • September 30, 2026 (website): Added the website section (§ 13): Cloudflare hosting and cookieless analytics, and Google Analytics only after you accept it in the cookie banner. Corrected the Global Privacy Control statement. Corrected the retention of deleted pets and records, which are kept for 30 days before they are erased.
    • September 30, 2026: iOS 3.7.0: added the Apple Wallet emergency pass. Described what is sent to our pass-signing service on Cloudflare Workers, the App Attest record it keeps, and their retention; added Cloudflare to the third-party list and the lawful-basis table. Corrected the Data Security and breach sections, which said we operate no servers.
    • September 25, 2026: iOS 3.6.0: in the EEA, the UK and Switzerland, Firebase Analytics and Crashlytics are off until you opt in (the lawful basis there is consent). Described the device state Crashlytics records (such as free memory and free disk space). Corrected the iCloud encryption wording: Apple encrypts iCloud data in transit and at rest, and end-to-end only with Advanced Data Protection. Expanded the CCPA categories to include identifiers and approximate location.
    • September 16, 2026: Corrected the iOS analytics description: Firebase Analytics and Crashlytics are active by default on iOS and can be turned off in the new Settings → Privacy screen (app version 3.6.0). Added feature-specific disclosures for vet contact import, "Scan a record", AI Insight (on-device Apple Intelligence), Siri and Shortcuts, Family Sharing recipients, and WishKit. Updated the third-party, lawful-basis, and retention tables accordingly.
    • April 16, 2026: Rewritten to cover the Android release (May 2026). Added GDPR lawful-basis table, Chapter V transfer disclosures, 72-hour breach notification, retention table, Data Controller and children's-data (Art. 8) sections. Replaced CCPA-only 45-day response window with the GDPR one-month default for EU users (CCPA retained for California residents). Added Google Drive, Google Play Billing, Firebase Analytics, RevenueCat disclosures. Split iCloud / SwiftData sections into iOS + Android versions.
    • March 21, 2026: iOS-only edition.