🔒 Legal Document

Privacy Policy

Last Updated: April 22, 2026 · Version 2.0 · GDPR & EU AI Act Compliant · Portuguese Law
🇪🇺
GDPR & EU AI Act

Compliant with EU data protection and AI regulations

🚫
No Data Selling

Your data is never sold to third parties

🇪🇺
Data Stays in EU

All processing in europe-west1 region

🛡️ What We NEVER Do

Table of Contents
1

Who We Are

PetSense is developed and operated by an individual entrepreneur registered in Portugal ("we," "us," or "our"). PetSense is a pet care companion app that helps pet owners organize health calendars, track vaccinations, and manage their pet's care records.

We act as the Data Controller for all personal data processed through the PetSense mobile application ("App").

📧 For all privacy matters: info@petsense.app

2

What Data We Collect

We collect only the data necessary to provide the App's features.

2.1 Account Data
  • Full name
  • Email address
  • Password (stored in encrypted form, never in plain text)
2.2 Pet Profile Data
  • Pet name, species, breed, date of birth or approximate age
  • Gender and weight
  • Pet photo (optional)
  • Known medical conditions, allergies, medications (only what you choose to enter)
2.3 Health Calendar Data
  • Events you create (vaccinations, vet visits, grooming, etc.)
  • Dates, notes, and reminders you set
  • Completion status of events
2.4 AI Analysis Data (only when you use the AI Health Check feature)
  • Photos you submit for AI analysis (stored in Cloud Storage in the EU)
  • The area of concern you select (Skin, Eyes, Ears, Paws)
  • The duration you select (less than 24 hours, 2-7 days, 1+ week)
  • Optional description of symptoms you provide (max 200 characters)
  • The AI-generated assessment output (confidence score, risk level, summary, recommendations)

AI analysis is optional. If you do not use the AI Health Check feature, no photos are sent for AI processing.

2.5 Technical Data (collected automatically)
  • Device type and operating system version
  • App version
  • Anonymous usage analytics (screens visited, features used)
  • Crash reports and error logs
  • Push notification token (for sending reminders)
3

How We Use Your Data

We use your data exclusively for the following purposes:

We do not use your data for automated decision-making that produces legal or similarly significant effects on you. AI Health Check outputs are preliminary informational assessments and are explicitly labeled as such — see Section 13 for details on your rights regarding AI processing.

4

Legal Basis for Processing (GDPR)

We process your personal data on the following legal bases under Article 6 of the GDPR:

5

Data We Do NOT Collect or Sell

🛡️ Our Commitments

  • We do NOT sell your personal data to any third party, ever
  • We do NOT share your data with advertisers
  • We do NOT collect payment card details (all payments handled by Apple App Store or Google Play Store)
  • We do NOT collect your precise GPS location
  • We do NOT access your contacts, microphone, or camera without your explicit action
  • We do NOT use your data to build advertising profiles
  • We do NOT process special categories of human personal data (health, biometric, financial data about you as a person)
6

Data Sharing and Third Parties

We use a small number of trusted third-party service providers to operate the App. These providers act as data processors on our behalf and are contractually bound to protect your data.

🔥 Google Firebase (Google LLC)

Purpose: Backend infrastructure — database (Firestore), authentication, file storage (Cloud Storage), and push notifications. All data stored in EU data centers (europe-west region).

View Privacy Policy →
☁️ Google Cloud Platform — Vertex AI (Google LLC)

Purpose: AI processing via Gemini 1.5 Flash for the AI Health Check feature. Region: europe-west1 (Belgium). Photos and symptom data submitted for AI analysis are processed in the EU and are not used by Google to train their general-purpose models. A Data Processing Agreement is in place.

View DPA →
📊 Google Analytics for Firebase

Purpose: Anonymous, aggregated usage analytics and crash reporting. Data is anonymized before processing.

View Privacy Policy →
📱 Apple App Store / Google Play Store

Purpose: App distribution and in-app purchase processing. They handle all payment data independently. We never receive your payment card details.

✉️ Email Service Provider

Purpose: Sending transactional emails (welcome email, password reset). We share only your email address for this purpose.

6.6 On-Device Processing (Local Pet Detection)

Before any photo is sent to our servers for AI analysis, a lightweight machine learning model runs locally on your device (using TensorFlow Lite on Android or Core ML on iOS) to verify that a pet is present in the photo. This local processing happens entirely on your phone — no data is transmitted for this step. If no pet is detected, you will be asked to retake the photo or confirm sending it anyway.

6.7 Legal Disclosure

We may disclose your data if required to do so by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

7

Data Storage and Security

7.1 Storage Location

Your data is stored on Google Cloud servers in the europe-west1 region (Belgium). This applies to:

  • Firestore database (account data, pet profiles, calendar, AI diagnoses)
  • Cloud Storage (photos submitted for AI analysis)
  • Vertex AI processing (Gemini model runs in europe-west1)
  • Cloud Functions (AI analysis backend)

Data does not leave the European Union during normal processing. Google LLC provides appropriate safeguards under Standard Contractual Clauses approved by the European Commission for any residual administrative access.

7.2 Security Measures
  • All data transmitted between the App and our servers is encrypted using TLS 1.3
  • All data at rest is encrypted (AES-256) by Google Cloud default encryption
  • Passwords are hashed and never stored in plain text
  • Firebase Security Rules restrict data access — users can only read their own data
  • AI diagnoses and photos cannot be written directly by the client — only through authenticated Cloud Functions
  • API credentials are stored in Google Cloud Secret Manager, never in client code
  • We regularly review access controls and security configurations
7.3 AI System Safeguards

For the AI Health Check feature, we implement additional safeguards aligned with the EU AI Act Article 15 (accuracy, robustness and cybersecurity):

  • Prompt injection defense — user-provided symptom descriptions are sanitized and isolated before being sent to the AI model, with multiple pattern-based filters
  • Refusal protocol — the AI model is instructed to refuse processing and return a zero-confidence response if manipulation is attempted
  • Audit logging — all attempts to circumvent AI safeguards are logged for security review
  • No automated decisions — AI outputs are presented to you for your consideration; no decisions are executed automatically based on AI output
7.4 Security Limitations

No system is 100% secure. In the event of a data breach affecting your rights and freedoms, we will notify you and the relevant supervisory authority as required by GDPR (within 72 hours of becoming aware).

8

Data Retention

When you delete your account, we will delete or anonymize all your personal data within 30 days, except where we are required to retain certain data by applicable law. Anonymized AI monitoring data, which contains no personal identifiers, is not affected by account deletion.

9

Your Rights Under GDPR

As a resident of the European Union or European Economic Area, you have the following rights regarding your personal data:

👁️ Right of Access (Art. 15)

Request a copy of all personal data we hold about you.

✏️ Right to Rectification (Art. 16)

Correct inaccurate or incomplete data directly in the App settings.

🗑️ Right to Erasure (Art. 17)

Request deletion of your personal data ("right to be forgotten").

⏸️ Right to Restriction (Art. 18)

Request that we restrict processing of your data in certain circumstances.

📦 Right to Portability (Art. 20)

Request a copy of your data in a structured, machine-readable format.

🚫 Right to Object (Art. 21)

Object to processing based on our legitimate interests.

To exercise any of these rights, contact us:

📧 info@petsense.app — Subject: "Data Privacy Request"

We will respond within 30 days. We may need to verify your identity before processing your request.

You also have the right to lodge a complaint with the Portuguese data protection authority:

Comissão Nacional de Proteção de Dados (CNPD)

🌐 www.cnpd.pt

📧 geral@cnpd.pt

📞 +351 213 928 400

📍 Av. D. Carlos I, 134 — 1200-651 Lisboa, Portugal

10

Children's Privacy

PetSense is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, please contact us at info@petsense.app and we will delete such data promptly.

11

Push Notifications

We send push notifications to remind you of upcoming calendar events and care activities you have scheduled. We will ask for your permission before sending push notifications.

You can disable push notifications at any time through your device's notification settings:

Disabling notifications does not affect your account or data — it only means you will not receive reminders on your device.

12

Cookies and Analytics

The App itself does not use browser cookies. We use Firebase Analytics to collect anonymized, aggregated data about how the App is used (e.g., which screens are visited most, feature usage frequency).

This analytics data:

You can opt out of analytics data collection by contacting us at info@petsense.app with the subject line "Analytics Opt-Out."

13

AI Processing & Your AI Rights

13.1 AI Transparency (EU AI Act Article 50)

When you use the AI Health Check feature, you are interacting with an Artificial Intelligence system. We make this clear throughout the feature:

  • A one-time disclaimer is shown before you first use the feature
  • Every AI Health Check result displays a persistent disclaimer card that cannot be hidden
  • Shared results include a mandatory disclaimer that the content is AI-generated

AI Health Check outputs are preliminary informational assessments only. They are not veterinary diagnoses. Always consult a licensed veterinarian for health concerns about your pet.

13.2 AI Model Used

We use Google's Gemini 1.5 Flash model via Vertex AI (europe-west1). The model receives your photo, pet profile information, and selected context (area, duration, optional description) and returns a structured assessment. The model does not learn from individual user interactions in real time — your data is not used to modify Google's general-purpose models.

13.3 Training Data Contribution — Your Consent

During onboarding, we ask whether you wish to help improve PetSense AI by allowing anonymized versions of your photos and analysis results to be used for training future AI models. This is optional.

If you consent:

  • Your personal identifiers are removed (name, pet name, userId, petId)
  • Any text description you provided is reviewed for personal information before use
  • Photos are evaluated to ensure they do not contain identifiable human faces or home interiors

Withdrawing consent is simple: go to Settings → Privacy → toggle off "Help improve PetSense AI". Changes take effect immediately (GDPR Article 7(3)). Withdrawal does not affect past consent-based processing but prevents any future use.

13.4 Right to Challenge AI Output

If you disagree with an AI Health Check result or believe the assessment was inaccurate, you can:

  • Contact us at info@petsense.app with the subject "AI Output Review"
  • Request that the specific analysis be deleted from your records
  • Provide feedback to help us improve the system
13.5 Automated Decision-Making (GDPR Article 22)

AI Health Check does not make decisions that produce legal or similarly significant effects on you. The AI provides informational output; any decision about your pet's care remains with you and your veterinarian. Because no significant automated decisions occur, GDPR Article 22 rights to human review are not directly triggered, but we still provide the mechanisms in Section 13.4 above as best practice.

13.6 AI Safeguards

We maintain technical safeguards to ensure the integrity of AI outputs (detailed in Section 7.3 above):

  • Prompt injection defense at multiple layers
  • Server-side validation of AI responses
  • Continuous monitoring of AI output quality
  • Audit logs of security events
14

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notification or email before the changes take effect, and update the "Last Updated" date at the top of this document.

For significant changes that affect your rights — for example, if we begin processing new categories of data or sharing data with new third parties — we will request your explicit consent where required by GDPR.

15

Contact and Complaints

For any questions, requests, or concerns regarding this Privacy Policy or how we handle your personal data:

📧 info@petsense.app

🌐 petsense.app

Subject: "Privacy Request" or "Data Protection" — We aim to respond within 30 days.

If you are not satisfied with our response, you have the right to lodge a complaint with:

Comissão Nacional de Proteção de Dados (CNPD)

🌐 www.cnpd.pt

📧 geral@cnpd.pt

📞 +351 213 928 400

📍 Av. D. Carlos I, 134 — 1200-651 Lisboa, Portugal