Dossipet Privacy Policy
Version: 0.9 (draft — private beta / TestFlight)
Effective date: [DATE — beta launch day]
Status: DRAFT — to be reviewed by a lawyer before public launch
This is a courtesy translation of the Polish original. In case of any discrepancy, the Polish version prevails.
1. Data controller
The controller of your personal data is:
[FULL NAME / COMPANY NAME][ADDRESS][TAX ID — if a registered business]
(hereinafter: the “Controller” or “we”).
Contact for all matters concerning personal data:
email: [[email protected]]
The Controller has not appointed a data protection officer (DPO) — there is no such obligation given the current scale and nature of the processing.
2. What this policy covers
This policy covers the Dossipet mobile application (currently an iOS beta distributed through TestFlight) and its supporting server infrastructure. Dossipet is a digital pet health record: a pet profile, medication and dose reminders, vaccinations and other health entries, photos of documents, and AI-assisted reading of data from those documents.
Important: data about the animal (name, species, conditions, medication) is not personal data by itself. It becomes personal data in combination with your account — and that is how we treat it: everything in your account is protected as personal data.
3. What data we process
| Category | Data | Where it comes from |
|---|---|---|
| Account | email address, account identifier, registration date; the password is stored exclusively as a hash by the authentication provider | you provide it at sign-up |
| Pet profile | name, species, breed, date of birth, sex, weight, coat, distinguishing marks, microchip number, photo, time zone | you enter it, or the AI reads it from documents (after your confirmation) |
| Pet health data | medication, doses, schedules, history of given/missed doses, vaccinations and other entries (including batch numbers), notes | you enter it, confirm it after AI extraction, or check off reminders |
| Documents and photos | photos of medication packaging, health-record pages, veterinary documents, attachments | you take a photo or upload a file |
| Text/dictated notes | the text describing a medication or event that you submit for AI processing | you type or dictate it (speech recognition runs within iOS) |
| AI processing metadata | job status, model used, confidence score, validation errors, processing time | generated automatically |
| Technical data | server logs (IP address, timestamps, request identifiers), error reports | generated automatically |
What we do not collect: the app has no ads, no marketing tracking, and no profiling. We do not collect your location. We do not sell data.
A note on documents: photos of veterinary documents may incidentally contain people’s personal data (e.g. your name as the owner, the veterinarian’s details, clinic stamps). We process them solely as part of the document, for the purposes described below. Please do not upload human medical documents or other documents unrelated to your pet’s health.
4. Purposes and legal bases of processing
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and operating the account, providing all app features (record, reminders, documents, AI extraction) | Art. 6(1)(b) — performance of a contract (the Terms of Service) |
| Transactional messages (sign-up confirmation, password reset) | Art. 6(1)(b) |
| Security, abuse prevention, error diagnostics (logs, error reports) | Art. 6(1)(f) — legitimate interest: keeping the service safe and working |
| Usage limits and accounting for AI processing costs (job metadata) | Art. 6(1)(f) — protection against resource abuse |
| Handling your GDPR requests, complaints, correspondence | Art. 6(1)(b), (c), and (f) |
| Establishing, pursuing, or defending legal claims | Art. 6(1)(f) |
We do not make decisions about you based solely on automated processing that would produce legal effects (Art. 22 GDPR). AI extraction concerns the animal’s data, and its result always requires your manual confirmation.
5. AI-assisted processing
When you use the scanning feature (a photo of a medication box or a health-record page) or the text description feature, the photo or text you submit is sent to an external AI model provider to read the data (medication name, dosing, vaccination dates, etc.):
- Provider: Google Ireland Ltd. / Google LLC — Gemini API
[VERIFY before beta: API variant and terms] - What is sent: only the content you submit for scanning (the photo or text) together with a technical extraction instruction; without your email address or account identifiers.
- Model training: we use API terms under which the provider does not use the submitted data to train its models.
- Control: the extraction result is a proposal — it is saved in your record only after you review and confirm it.
6. Data recipients (processors)
We use subcontractors who process data on our behalf under data processing agreements (DPAs):
| Entity | Role | Processing location |
|---|---|---|
| Supabase, Inc. | database, authentication, file storage | EU region [VERIFY project region]; US entity |
| Render Services, Inc. | hosting of the application server and processing workers | [Frankfurt/EU — VERIFY] region; US entity |
| Google (Gemini API) | data extraction from documents (section 5) | EU/US depending on API configuration |
| Functional Software, Inc. (Sentry) | server error monitoring | US |
| Apple Inc. | app distribution (TestFlight), system notifications, any App Store payments | per Apple’s policies |
Beyond the above, we may disclose data only where the law requires it (e.g. at the request of a competent authority).
7. Transfers outside the EEA
Some of our providers are based in the US. Wherever possible, we choose processing in EU data centres. To the extent data is transferred to the US, the transfer takes place under:
- the European Commission’s EU-U.S. Data Privacy Framework adequacy decision — for providers holding a DPF certification, and/or
- standard contractual clauses (SCCs) included in the data processing agreements.
Details of a given provider’s safeguards are available on request (contact: section 1).
8. How long we keep data
| Data | Period |
|---|---|
| Account data and the entire record (profile, medication, entries, documents) | until you delete the account, or until we delete it after the contract ends |
| Database backups | up to [30] days after deletion from the production system |
| Technical logs and error reports | up to [90] days |
| Correspondence (GDPR, complaints) | for the limitation period of potential claims |
After account deletion, data is removed from production systems without undue delay, and from backups as they rotate.
9. Your rights
You have the right to:
- access your data and obtain a copy (Art. 15 GDPR),
- rectification (Art. 16),
- erasure (“right to be forgotten”, Art. 17) — including deleting the entire account,
- restriction of processing (Art. 18),
- data portability (Art. 20) — on request we will provide your data in a structured, commonly used, machine-readable format,
- objection to processing based on legitimate interest (Art. 21).
You can submit requests by email to the address in section 1. We respond without
undue delay, at the latest within one month. Account deletion is also available
directly in the app ([Settings → Account → Delete account — VERIFY before beta; App Store requirement]).
You also have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl; you may also contact the supervisory authority in your own EU member state.
10. Voluntariness of providing data
An email address is required to create an account. All other data (pet profile, documents, entries) is provided voluntarily — without it, some features simply will not work.
11. Security
Our measures include: encryption in transit (TLS), encryption at rest with our infrastructure providers, database-level isolation between accounts (row-level security), file access exclusively through signed, time-limited URLs, least-privilege access to production systems, and error monitoring.
12. Children
The app is intended for people aged 16 or over. We do not target children and do not knowingly collect their data.
13. Changes to this policy
We will announce material changes in the app or by email before they take effect. Archived versions are available on request.

