PetLife Privacy Policy
This draft Privacy Policy describes the planned data practices of the PetLife iOS application. PetLife is offered by Maksim Yaromau, Individual Entrepreneur, Georgia IP No. 302239897, 70 M. Tsinamdzgvrishvili street, Georgia ("PetLife", "we", "us", or "our"). Contact: Yaromaum@gmail.com.
Draft status
This document is a public pre-release draft and is not effective. It must be reconciled with the released binary, production regions, provider agreements, veterinary and legal review, App Privacy answers, and final retention settings before App Store submission.
Guest and account data
PetLife is planned to support a local Guest profile and optional Sign in with Apple. Authenticated use may process an Apple account identifier, Supabase account identifier, session tokens, installation identifiers, workspace membership, invitation state, and role information. PetLife does not plan to collect an owner's date of birth, address-book contacts, precise location, or advertising identifier. Age eligibility is confirmed without storing a birth date.
Pet and care information
Depending on your use, PetLife may process pet name, species, breed or type, age information, care-plan answers, tasks, completion history, reminders, weight records, allergies, conditions, medications, microchip information, veterinary contacts, notes, tags, emergency-card details, and related timeline information.
Some of this information may be sensitive. PetLife is a consumer planning tool, not a clinical record system. You decide what to enter and share and should avoid adding information that is not needed for your care workflow.
Documents, photos, video, and OCR
PetLife may process documents, photos, and short videos that you choose to import. Planned OCR features may extract text to help you organize a document. Original media and eligible shared files may be stored in private Supabase Storage and cached locally. OCR text, filenames, notes, document titles, signed storage links, and imported photo metadata are not permitted in ordinary analytics or diagnostic breadcrumbs.
Local storage and synchronization
PetLife is designed as offline-first. The local read model and outbox are stored on the device using Apple data-protection controls. Shared authoritative records are planned for Supabase PostgreSQL, with private Supabase Storage for uploaded files and Supabase Realtime for an active workspace. Network traffic is planned to use encrypted transport and short-lived signed file URLs.
Family sharing
If an Owner invites a Caregiver, permitted workspace information is shared through the PetLife backend. Role and row-level security rules are designed to limit each member's access. Owners control invitations, assignments, membership, and workspace deletion. Caregivers do not receive destructive workspace controls.
Analytics and diagnostics
PostHog in the European region is planned for pseudonymous product analytics with session replay disabled and an in-app opt-out. User-entered titles, notes, names, document text, pet names, microchip numbers, allergies, conditions, and medications are prohibited analytics properties.
Sentry in the European region is planned for diagnostics with PII scrubbing. Authentication data, request bodies, email, names, signed URLs, storage paths, OCR text, filenames, notes, document titles, and invitation links are designed to be removed from diagnostic events.
Service providers
The planned processors are Apple for authentication, notifications, and platform services; Supabase for authentication, database, realtime, functions, and private storage; PostHog for opt-out analytics; and Sentry for diagnostics. Final provider regions, retention, agreements, and production configuration require verification before this draft becomes effective. RevenueCat is reserved for a possible post-beta subscription system and is not planned to control first-beta access.
Retention, export, and deletion
PetLife is planned to provide data export, in-app sign-out, Trash, and account or workspace deletion. Soft-deleted objects are designed to remain recoverable for 30 days. A workspace deletion request is designed to enter a 30-day deletion-pending state and may be cancelled during that period. After the deadline, scheduled purge removes applicable database and private-storage data except minimal financial, security, or legally required records.
Signing out clears shared local data and credentials while preserving only non-sensitive preferences. Pending unsynchronized changes require an explicit sync, export, or discard choice.
Notifications and permissions
Notification permission is used for reminders and care-plan activity you configure. Photos, camera, and file access are requested only when you choose a related import or capture feature. PetLife does not automatically send medical files to support; you decide whether to attach a safe export or diagnostic summary.
Contact
Privacy, access, export, and deletion questions: inmyfridge.app/apps/petlife/support