1. Introduction
This Privacy Policy explains what NutriPet ("we," "our," or "us") collects, why we collect it, who helps us process it, and the choices you have. NutriPet is designed for pet nutrition and food tracking, so we try to collect only what is needed to provide the app, keep it secure, and improve it with your permission.
Questions? Email support@nutripet.app. Jurisdiction: Northern Ireland, UK.
2. Information We Collect
2.1 Personal Information
- Email address and display name
- Optional private profile photo, preset avatar icon, initials, and any related review notices
- Account sign-in identifiers and app preferences
- Authentication handled by Firebase/Auth providers. NutriPet does not store your password in plain text
- Pet profiles, including name, species, breed, age, weight, sex, and ingredients to avoid
- Onboarding nutrition answers and prepared plan inputs
- Scan history and product analysis results created while Pro access or a store-confirmed trial is active
- Subscription status, entitlement details, and store transaction references from Apple, Google, or RevenueCat
2.2 Food Journal Data (Pro Feature)
If you use Food Journal, we collect the meal details you choose to log, such as:
- Meal type, such as breakfast, lunch, dinner, snack, or treat
- Portion sizes and units (cups, grams, oz, pieces)
- Calorie information for logged meals
- Meal dates and feeding times
- Product names associated with meals
- Personal notes about meals
2.3 Reaction & Symptom Data (Pro Feature)
Symptom and reaction logs are personal notes for your own tracking. They are not medical or veterinary records and should not be used for diagnosis.
- Pet reactions to food (great, good, neutral, poor, bad)
- Observed symptoms (e.g., digestive issues, skin irritation, behavioral changes)
- Reaction notes and dates
- Food patterns suggested from your own logged reactions
2.4 Prepared Plan & Smart Feeding Profile Data
To prepare your plan preview and calculate feeding recommendations when Pro is active, we collect:
- Activity level (sedentary to very active)
- Body condition score (underweight, ideal, overweight, obese)
- Life stage (puppy/kitten, adult, senior, pregnant, nursing)
- Spayed/neutered status
- Feeding goals (maintain, lose, or gain weight)
- Meals per day preference
- Treat calorie percentage allowance
2.5 Daily Tracking Data
- Daily calorie consumption progress
- Meal logging activity and streaks
- Day-over-day feeding patterns
- Weekly calorie summaries
2.6 Scout AI Assistant Data (Pro Feature)
- Scout questions you choose to ask
- Recent Scout chat turns sent as context for the current answer
- Selected pet profile context needed to personalize the answer, such as name, species, breed, age, weight, activity, allergies, sensitivities, and medical conditions saved in the app
- When Cloud Backup is enabled, a bounded summary of the selected pets' cloud-synced history: meal and reaction patterns from the last 30 days, the two most recent weights, activity from the last 7 days, and up to three recent saved scans
- The cloud-history summary may include selected pet names, but excludes free-text notes, symptom details, medication data, images, and raw log records
- Bounded food and profile facts generated locally by NutriPet, such as ingredient matches and saved ingredient triggers relevant to the question
2.7 Subscription Access
- Free or inactive account: basic account, preferences, onboarding, and plan-preview data. Scans, OCR, ingredient analysis, scan history sync, Food Journal, Smart Feeding, exports, and cloud sync require active Pro access or a store-confirmed trial.
- Pro access: Food checks, pet profiles, Food Journal, Smart Feeding, Nutrition Trends, Cloud Backup across devices, and PDF data export; current usage limits are shown in the app
2.8 Automatically Collected
- Device information, such as type, OS version, and app version
- App usage information, such as feature use and scan counts
- Camera input when you choose to scan barcodes, labels, or food photos
- Optional pseudonymous analytics and install attribution after you consent
- Crash and performance diagnostics (via Sentry) so we can detect and fix stability problems. This is on by default under our legitimate interest in a reliable, safe app. Reports use a pseudonymous account identifier, and NutriPet applies technical filters designed to exclude email, pet-profile, journal, Scout-question, and image content. You can turn it off anytime in Settings > Privacy Preferences > Essential Diagnostics
- Anonymous, non-identifying onboarding funnel metrics (which onboarding step was reached, with no user, account, or device identifier and only an ephemeral per-launch session key) collected by default so we can see where onboarding is confusing and improve it. These metrics cannot be linked back to you and are never joined to your account
2.9 Cloud Backup
Cloud Backup is on by default so your pets, scans, and Food Journal can be restored on a new device. We use Firebase and Google Cloud; your data is encrypted in transit (TLS) and at rest by the provider, kept private to your account, and never sold. Cloud Backup is not end-to-end encrypted, and you can turn it off anytime in Settings.
2.10 Private Account Profile Photos
Profile photos are optional. They are private to your account, not shown in a public profile, and can be seen only by you and authorized NutriPet team members when needed for support, security, or photo review. They are stored separately from optional Pro cloud sync and are available to free and paid accounts.
NutriPet does not use profile photos for facial recognition, biometric templates, identity matching, attribute inference, advertising, sale, or AI model training.
2.11 Smart Scan Data (Pro Feature)
When Smart Scan or ingredient OCR uses the camera, NutriPet analyzes and saves only the orientation-normalized, unobstructed part of the live preview: unseen aspect-filled sensor edges and the areas behind the header and capture controls are excluded. The on-screen label guide helps composition and is not a crop boundary. When you choose a gallery image, the complete selected image is analyzed. Before third-party processing, that analyzed artifact is resized when needed, re-encoded, and stripped of embedded metadata. Alibaba Cloud Model Studio (Qwen), through our Germany (Frankfurt) workspace, receives the Smart Scan artifact and a dog, cat, or mixed-species label derived from the pets selected for that scan. Google Cloud Vision receives the same Smart Scan artifact through its EU OCR endpoint to provide independent label text evidence. When you separately use food-photo recognition, Google Cloud Vision receives its processed artifact through the EU label-detection endpoint. Neither provider receives pet names, pet IDs, or other pet-profile details with these photos. NutriPet does not save raw provider responses. To recover a successful scan after a lost network response without processing the photo again, NutriPet keeps the bounded, normalized scan response—not image bytes or a raw provider response—in a user-scoped server cache for up to 15 minutes. The cache expires automatically and is included in account-deletion cleanup. The analyzed artifact saved with a successful result can remain in local scan history and, when enabled, private Cloud Backup until you delete the scan. Registered users may separately opt in to the Scan Quality Observatory in Privacy Preferences. It is off by default, and Smart Scan works the same if you decline. When enabled, NutriPet may retain the exact metadata-stripped, resized artifact sent to the scan providers, the structured extraction, provider timings, and your structured accuracy feedback solely to diagnose and improve Smart Scan extraction accuracy. The artifact is pseudonymized, quarantined for privacy review, and kept in isolated CMEK-encrypted EU object storage. The bounded diagnostic record is kept in a separately access-controlled restricted backend collection. Authorized privacy reviewers may inspect quarantined evidence before ordinary accuracy reviewers receive access. Observatory data is never used for general model training and is deleted when no longer needed or no later than 90 days after capture. You may delete retained evidence or withdraw consent at any time; NutriPet immediately blocks new reviewer access, any already-issued short-lived evidence link expires within at most two minutes, and deletion is confirmed or durably queued for retry. Account deletion includes this evidence and its consent records.
3. How We Use Your Information
- Sign you in and manage your account
- Create your onboarding nutrition profile and show your plan preview
- Analyze pet food products for safety and allergies when Pro access is active
- Derive ingredient grades and safety alerts from recognized product evidence
- Calculate feeding recommendations from your pet's profile
- Track calorie progress and feeding patterns you choose to log
- Provide meal insights and highlight possible problem foods based on your entries
- Answer Scout AI assistant questions using the question, recent Scout chat, selected pet profile context, bounded food/profile facts, and—only when Cloud Backup is enabled—a bounded summary of selected pets' meal/reaction patterns, recent weights, activity, and saved scans
- Process subscription status through Apple, Google, and RevenueCat
- Apply Pro access rules for scans and paid features
- Improve performance, fix bugs, and understand feature usage with your consent where required
- When you separately opt in, review pseudonymized sanitized scan evidence and structured extraction data to diagnose and improve Smart Scan accuracy
- Prevent fraud, abuse, and security issues
- Store, display privately, protect, and review an optional profile photo
Legal Basis (GDPR)
- Contract performance: provide account services and requested features
- Legitimate interests: improve reliability, prevent fraud, secure accounts, review uploaded content, run essential crash and performance diagnostics (Sentry), and measure anonymous onboarding drop-off. You can opt out of essential diagnostics in Settings
- Consent: optional analytics, the separate Scan Quality Observatory, and other optional processing where consent is required
- Legal obligation: comply with applicable law
4. Health-Related Data Disclaimer
NutriPet does not collect veterinary medical records. Symptom and reaction entries are personal notes you create for your own reference.
These tools are meant to help you notice patterns and talk with your veterinarian. This data:
- Is not clinical or medical data
- Is not shared with veterinarians, insurers, or advertisers
- Is backed up privately to your account by default (Cloud Backup); turn Cloud Backup off to keep it only on this device
- Can be deleted from the app, subject to the backup, security, and legal-retention limits explained below
- Should not be used for diagnosis or treatment decisions
5. Data Storage & Security
Local Storage
Without active Pro access, NutriPet stores basic account, preferences, onboarding, and plan-preview data. Product scans, OCR, Food Journal, Smart Feeding, exports, and cloud sync are available only with active Pro access or a store-confirmed trial. If cloud sync is off, Pro feature data stays on your device.
Cloud Storage (Cloud Backup)
Firebase and Google Cloud host your Cloud Backup data. Records are encrypted in transit (TLS) and at rest by the provider and kept private to your account. International transfers are handled under Google data-processing terms and transfer safeguards, and we review deployment regions against the live service configuration.
Security Measures
- Cloud Backup data is encrypted in transit (TLS) and at rest by the provider
- Secure local key storage through the device keychain where supported
- TLS for network communications
- For Smart Scan and ingredient OCR, camera artifacts are limited to the unobstructed visible preview while gallery artifacts use the complete selected image; the label guide is a composition aid, not a crop boundary. For separate food-photo recognition, camera photos use the visibly dimmed object frame while gallery photos use the complete selected image. Each artifact is orientation-normalized, resized when needed, re-encoded to a standard image format, and stripped of embedded metadata before processing. Smart Scan uses Alibaba Cloud Model Studio (Qwen) in Germany (Frankfurt) and Google Cloud Vision EU OCR; food-photo recognition uses Google Cloud Vision EU label detection. NutriPet does not save raw provider responses. A bounded, normalized successful response is held in a user-scoped server cache for no more than 15 minutes so an interrupted request can be recovered without another provider call. The analyzed artifact saved with a successful result can remain in local scan history and, when enabled, private Cloud Backup until you delete the scan. Separately, registered users can opt in to the default-off Scan Quality Observatory. With consent, the exact metadata-stripped, resized provider artifact may be held in isolated CMEK-encrypted EU object storage, while the bounded diagnostic record is held in a separately access-controlled restricted backend collection. Both are available only for restricted privacy and accuracy review, solely to improve extraction accuracy, never for general model training, and for no longer than 90 days. Withdrawal, delete-evidence, and account-deletion requests immediately block new reviewer access; any already-issued short-lived evidence link expires within at most two minutes; deletion is completed directly or through a durable retry queue
- Profile photos are resized, stripped of metadata, and stored privately until replaced, removed, or the account is deleted
- Access to your Cloud Backup data is restricted to your account
6. Data Sharing
We do not sell your data. We do not share Food Journal entries, reactions, or symptom logs with advertisers. We share limited data only with:
- Google Cloud/Firebase, which provides app infrastructure and cloud sync
- Authorized NutriPet support, security, and review team members when access to a private profile photo is necessary; access and actions are restricted and audited
- Apple, Google, and RevenueCat for subscription entitlement and payment processing
- AppsFlyer and analytics providers for consented install attribution and pseudonymous usage measurement. We do not send personal pet journal content
- Legal authorities, only when required by law
- Sentry (Functional Software, Inc.) for crash and performance diagnostics, processed under our legitimate interest in app reliability. Reports use a pseudonymous account identifier and filtered technical context designed to exclude email, pet-profile, journal, Scout-question, and image content; you can opt out in Settings
- Alibaba Cloud Model Studio (Qwen), which provides Scout and Smart Scan extraction through our Germany (Frankfurt) workspace. Scout sends your question, recent Scout chat, selected pet profile context, bounded food/profile facts and, only when Cloud Backup is enabled, the bounded cloud-history summary described above. Smart Scan sends the processed photo plus only dog, cat, or mixed-species context; Alibaba does not receive pet IDs or other profile details with the photo
- Google Cloud Vision, which receives processed Smart Scan photos through its EU OCR endpoint and processed food-recognition photos through its EU label-detection endpoint. It does not receive pet names, pet IDs, Scout questions, or pet-profile details with those photos
7. Data Retention
- Active accounts: kept while your account exists
- Deleted accounts: access is blocked first; removal from active systems starts immediately and is completed within 30 days, subject to the limited records described below
- Profile photos: the active photo is kept while selected. Replaced or removed photos are hidden immediately and queued for deletion; disaster-recovery backups may keep copies for up to 30 days
- Moderation, security, and account-deletion audit records: limited records may be kept for up to 365 days to manage appeals, reconcile deletion, prevent stale-token account recreation, enforce restrictions, prevent abuse, or handle legal claims. Account-deletion audit records keep the deleted account identifier but not the deleted email address and are subject to an enforced 365-day expiry
- Scan history: kept while your account exists or until you delete it, subject to app retention limits
- Temporary scan-response recovery cache: a bounded, normalized successful response—not image bytes or a raw provider response—is kept in a user-scoped server cache for up to 15 minutes so a lost network response can be recovered without processing the photo again. It expires automatically and is included in account-deletion cleanup
- Optional Scan Quality Observatory: consented sanitized scan evidence and bounded diagnostic records are deleted when no longer needed and no later than 90 days after capture. Withdrawing consent, deleting shared evidence, or deleting the account immediately blocks new reviewer access; any already-issued short-lived evidence link expires within at most two minutes; deletion is confirmed or durably queued for retry
- Food Journal entries: kept up to 500 entries per pet; when the limit is reached, the oldest entries are removed locally and queued for deletion from Cloud Backup
- Raw pseudonymous analytics: kept for up to 13 months; reporting aggregates may be kept for up to 36 months
- Financial transaction records: kept as legally required and unlinked from the account when deletion law permits
- Alibaba Cloud Model Studio API inputs and outputs: Alibaba Cloud states that it does not use customer data for model training and encrypts transmitted data; provider handling is governed by its Model Studio terms and privacy notice
- Google Cloud Vision online OCR and label-detection requests: Google states that submitted content is not used to train its models and is normally deleted after processing, but it may be cached temporarily for service reliability, typically for a few hours; provider handling is governed by Google Cloud terms and its data-use documentation
8. Your Rights
GDPR/CCPA Rights
- Access: ask for a copy of your data, including profile-photo metadata and review notices
- Correction: fix inaccurate data
- Deletion: delete your account and associated profile photo, subject to limited lawful retention
- Export: download your data, including pets, scans, journal entries, avatar metadata, and policy status
- Limit processing: ask us to limit how we use your data
- Object: object to certain processing
- Withdraw consent: revoke optional permissions anytime
How to Exercise Rights
- In the app: Settings > Data & Storage > Export/Delete
- Food Journal data can be exported separately
- Email: support@nutripet.app
- We aim to respond within 30 days
9. Children's Privacy
NutriPet is not intended for children under 13, or under 16 in the EEA. We do not knowingly collect data from children. If we learn that a child has provided personal data, we will delete it.
10. Cookies & Tracking
- Optional analytics and attribution start only after you consent and can be turned off in Settings
- AppsFlyer may process a pseudonymous installation identifier and campaign or deep-link details to measure app acquisition
- NutriPet does not enable mobile advertising identifiers by default and does not sell personal data
- RevenueCat receives the AppsFlyer installation identifier and campaign fields so subscription events can be attributed without client-side revenue duplication
- Essential crash and performance diagnostics (Sentry) run by default under legitimate interest and can be switched off in Settings > Privacy Preferences > Essential Diagnostics; turning them off stops crash reporting from this device
- Anonymous onboarding funnel metrics run by default but carry no user, account, or device identifier (only an ephemeral per-launch session key) and therefore cannot be linked to you
11. Changes to This Policy
We may update this policy from time to time. If we make a material change, we will notify you in the app or another appropriate channel. If a choice requires consent, we will ask separately instead of treating this policy as consent.
12. Contact Us
- Email: support@nutripet.app
- Data Controller: NutriPet
- Jurisdiction: Northern Ireland, UK