1. Introduction
NutriPet ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application.
Contact: support@nutripet.app • Jurisdiction: Northern Ireland, UK
2. Information We Collect
2.1 Personal Information
- Email address and display name (optional)
- Password (encrypted, never stored in plain text)
- Pet profiles (name, species, breed, age, weight, sex, allergies)
- Scan history and product analysis results
- Subscription status and payment info (via Apple/Google)
2.2 Food Journal Data (Pro Feature)
When using the Food Journal feature, we collect meal tracking data to help you monitor your pet's diet:
- Meal logs (type: breakfast, lunch, dinner, snack, treat)
- Portion sizes and units (cups, grams, oz, pieces)
- Calorie information for logged meals
- Meal dates and feeding times
- Product names associated with meals
- Personal notes about meals
2.3 Reaction & Symptom Data (Pro Feature)
IMPORTANT: This data is for your personal tracking only. It is NOT medical data and should NOT be used for diagnosis.
- Pet reactions to food (great, good, neutral, poor, bad)
- Observed symptoms (e.g., digestive issues, skin irritation, behavioral changes)
- Reaction notes and dates
- Problem food identification based on your logged reactions
2.4 Smart Feeding Profile Data
To calculate personalized feeding recommendations, we collect:
- Activity level (sedentary to very active)
- Body condition score (underweight, ideal, overweight, obese)
- Life stage (puppy/kitten, adult, senior, pregnant, nursing)
- Spayed/neutered status
- Feeding goals (maintain, lose, or gain weight)
- Meals per day preference
- Treat calorie percentage allowance
2.5 Daily Tracking Data
- Daily calorie consumption progress
- Meal logging activity and streaks
- Day-over-day feeding patterns
- Weekly calorie summaries
2.6 Plan Limits
- Free Plan: 3 scans/day, 1 pet maximum, local storage only
- Pro Plan: Unlimited scans/pets, Food Journal, Smart Feeding, cloud sync (optional), data export
2.7 Automatically Collected
- Device info (type, OS version, app version)
- Usage data (scan frequency, features used)
- Camera access (for barcode scanning - images processed locally)
- Analytics (anonymized, opt-out available)
2.8 Cloud Sync (Pro Only)
Pro users can enable optional cloud sync via Firebase. All data including Food Journal entries, feeding profiles, and reactions are encrypted end-to-end (AES-256). Can be disabled anytime in Settings.
3. How We Use Your Information
- Authenticate accounts and manage access
- Analyze pet food products for safety and allergies
- Generate safety ratings and recommendations
- Calculate personalized feeding recommendations based on your pet's profile
- Track daily calorie progress and feeding patterns
- Provide meal insights and identify potential problem foods
- Process subscriptions via Apple/Google
- Enforce plan limits (3 scans/day for free users)
- Improve app performance and fix bugs
- Prevent fraud and ensure security
Legal Basis (GDPR)
- Contract Performance (provide services)
- Legitimate Interest (improve services, prevent fraud)
- Consent (cloud sync, analytics, Food Journal)
- Legal Obligation (comply with laws)
4. Health-Related Data Disclaimer
IMPORTANT: NutriPet does NOT collect medical or veterinary health records. The symptom and reaction data you log is for your personal reference only.
Symptom tracking (such as digestive reactions or skin irritation observations) is provided as a personal journaling tool to help you track patterns and communicate with your veterinarian. This data:
- Is NOT clinical or medical data
- Is NOT shared with veterinarians, insurers, or third parties
- Is stored locally by default (cloud sync optional for Pro users)
- Is fully under your control and can be deleted at any time
- Should NOT be used for diagnosis or treatment decisions
5. Data Storage & Security
Local Storage
Free users: All data stored locally on device, encrypted (AES-256). No transmission to servers. Food Journal and feeding profiles are stored locally.
Cloud Storage (Pro with Cloud Sync)
Firebase (Google Cloud) infrastructure. End-to-end encryption (AES-256-CBC + HMAC-SHA256). Data stored in EU/US data centers (GDPR compliant). Includes pet profiles, scan history, Food Journal entries, feeding profiles, and reaction data.
Security Measures
- PBKDF2 key derivation (10,000 iterations, mobile-optimized with secure key caching)
- Secure key storage via device keychain
- TLS 1.3 for all network communications
- No raw image storage (processed and discarded)
- Authentication tags on all encrypted data
- Sensitive data (symptoms, reactions) encrypted at rest
6. Data Sharing
We do NOT sell your data. Your Food Journal entries, reactions, and symptom logs are NEVER shared with third parties. We only share data with:
- Google Cloud/Firebase (infrastructure provider - encrypted data only)
- Apple/Google (payment processing)
- Analytics services (anonymized usage data only, no personal pet data)
- Legal authorities (when required by law)
7. Data Retention
- Active accounts: Data retained while account exists
- Deleted accounts: Data deleted within 30 days
- Scan history: Automatically cleaned after 90 days (configurable)
- Food Journal entries: Retained up to 500 entries per pet, oldest auto-archived
- Analytics: Aggregated data retained, personal data deleted after 24 months
8. Your Rights
GDPR/CCPA Rights
- Access: Request copy of your data (including Food Journal exports)
- Rectification: Correct inaccurate data
- Erasure: Delete your account and all data (including journal entries)
- Portability: Export your data (pets, scans, journal entries)
- Restrict Processing: Limit how we use your data
- Object: Opt-out of certain processing
- Withdraw Consent: Revoke permissions anytime
How to Exercise Rights
- Settings → Data & Storage → Export/Delete
- Food Journal data can be exported separately
- Email: support@nutripet.app
- We respond within 30 days
9. Children's Privacy
NutriPet is not intended for users under 13 (or 16 in EEA). We do not knowingly collect data from children. If we discover child data, we will delete it immediately.
10. Cookies & Tracking
- We do NOT use third-party cookies
- We do NOT track users across apps or websites
- Analytics is anonymized and can be disabled in Settings
- No advertising identifiers used
11. Changes to This Policy
We may update this policy from time to time. Material changes will be notified in-app. Continued use after changes constitutes acceptance.
12. Contact Us
- Email: support@nutripet.app
- Data Controller: NutriPet
- Jurisdiction: Northern Ireland, UK