1. Introduction
NutriPet ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application.
Contact: support@nutripet.app • Jurisdiction: Northern Ireland, UK
2. Information We Collect
2.1 Personal Information
- Email address and display name (optional)
- Password (encrypted, never stored in plain text)
- Pet profiles (name, species, breed, age, weight, sex, ingredients to avoid)
- Scan history and product analysis results
- Subscription status and payment info (via Apple/Google)
2.2 Food Journal Data (Pro Feature)
When using the Food Journal feature, we collect meal tracking data to help you monitor your pet's diet:
- Meal logs (type: breakfast, lunch, dinner, snack, treat)
- Portion sizes and units (cups, grams, oz, pieces)
- Calorie information for logged meals
- Meal dates and feeding times
- Product names associated with meals
- Personal notes about meals
2.3 Reaction & Symptom Data (Pro Feature)
IMPORTANT: This data is for your personal tracking only. It is NOT medical data and should NOT be used for diagnosis.
- Pet reactions to food (great, good, neutral, poor, bad)
- Observed symptoms (e.g., digestive issues, skin irritation, behavioral changes)
- Reaction notes and dates
- Problem food identification based on your logged reactions
2.4 Smart Feeding Profile Data
To calculate personalized feeding recommendations, we collect:
- Activity level (sedentary to very active)
- Body condition score (underweight, ideal, overweight, obese)
- Life stage (puppy/kitten, adult, senior, pregnant, nursing)
- Spayed/neutered status
- Feeding goals (maintain, lose, or gain weight)
- Meals per day preference
- Treat calorie percentage allowance
2.5 Daily Tracking Data
- Daily calorie consumption progress
- Meal logging activity and streaks
- Day-over-day feeding patterns
- Weekly calorie summaries
2.6 Plan Limits
- Preview Access (no active subscription): account preview only. Scans, OCR, cloud sync, exports, Food Journal, and scan history sync require an active Pro subscription.
- Pro Plan: Unlimited scans/pets, Food Journal, Smart Feeding, Pet Analytics, cloud sync + encryption (optional), PDF data export
2.7 Automatically Collected
- Device info (type, OS version, app version)
- Usage data (scan frequency, features used)
- Camera access (for barcode scanning - images processed locally)
- Analytics (anonymized, opt-out available)
2.8 Cloud Sync (Pro Only)
Pro users can enable optional cloud sync via Firebase. Synced records are protected in transit and may use an additional app-level encryption layer before upload, but cloud sync should not be treated as end-to-end encrypted. Can be disabled anytime in Settings.
3. How We Use Your Information
- Authenticate accounts and manage access
- Analyze pet food products for safety and allergies
- Generate safety ratings and recommendations
- Calculate personalized feeding recommendations based on your pet's profile
- Track daily calorie progress and feeding patterns
- Provide meal insights and identify potential problem foods
- Process subscriptions via Apple/Google
- Enforce plan limits and access rules for scans and Pro features
- Improve app performance and fix bugs
- Prevent fraud and ensure security
Legal Basis (GDPR)
- Contract Performance (provide services)
- Legitimate Interest (improve services, prevent fraud)
- Consent (cloud sync, analytics, Food Journal)
- Legal Obligation (comply with laws)
4. Health-Related Data Disclaimer
IMPORTANT: NutriPet does NOT collect medical or veterinary health records. The symptom and reaction data you log is for your personal reference only.
Symptom tracking (such as digestive reactions or skin irritation observations) is provided as a personal journaling tool to help you track patterns and communicate with your veterinarian. This data:
- Is NOT clinical or medical data
- Is NOT shared with veterinarians, insurers, or third parties
- Is stored locally by default (cloud sync optional for Pro users)
- Is fully under your control and can be deleted at any time
- Should NOT be used for diagnosis or treatment decisions
5. Data Storage & Security
Local Storage
Without an active subscription, app data is stored locally on your device and is not transmitted to NutriPet servers unless you enable cloud features available on the Pro plan. Food Journal and feeding profiles are stored locally for Pro users with cloud sync disabled.
Cloud Storage (Pro with Cloud Sync)
Firebase (Google Cloud) infrastructure. Data is protected in transit and at rest, and supported sync records may use an additional app-level encryption layer before upload. Data stored in EU/US data centers (GDPR compliant). Includes pet profiles, scan history, Food Journal entries, feeding profiles, and reaction data.
Security Measures
- PBKDF2 key derivation (10,000 iterations, mobile-optimized with secure key caching)
- Secure local key material storage via device keychain where supported
- TLS 1.3 for all network communications
- No raw image storage (processed and discarded)
- Authentication tags on all encrypted data
- Supported synced records can use app-level encryption with authentication tags
6. Data Sharing
We do NOT sell your data. Your Food Journal entries, reactions, and symptom logs are NEVER shared with third parties. We only share data with:
- Google Cloud/Firebase (infrastructure provider for cloud sync data, including app-level encrypted payloads when enabled)
- Apple/Google (payment processing)
- Analytics services (anonymized usage data only, no personal pet data)
- Legal authorities (when required by law)
7. Data Retention
- Active accounts: Data retained while account exists
- Deleted accounts: Data deleted within 30 days
- Scan history: Automatically cleaned after 90 days (configurable)
- Food Journal entries: Retained up to 500 entries per pet, oldest auto-archived
- Analytics: Aggregated data retained, personal data deleted after 24 months
8. Your Rights
GDPR/CCPA Rights
- Access: Request copy of your data (including Food Journal exports)
- Rectification: Correct inaccurate data
- Erasure: Delete your account and all data (including journal entries)
- Portability: Export your data (pets, scans, journal entries)
- Restrict Processing: Limit how we use your data
- Object: Opt-out of certain processing
- Withdraw Consent: Revoke permissions anytime
How to Exercise Rights
- Settings → Data & Storage → Export/Delete
- Food Journal data can be exported separately
- Email: support@nutripet.app
- We respond within 30 days
9. Children's Privacy
NutriPet is not intended for users under 13 (or 16 in EEA). We do not knowingly collect data from children. If we discover child data, we will delete it immediately.
10. Cookies & Tracking
- We do NOT use third-party cookies
- We do NOT track users across apps or websites
- Analytics is anonymized and can be disabled in Settings
- No advertising identifiers used
11. Changes to This Policy
We may update this policy from time to time. Material changes will be notified in-app. Continued use after changes constitutes acceptance.
12. Contact Us
- Email: support@nutripet.app
- Data Controller: NutriPet
- Jurisdiction: Northern Ireland, UK