Petter — Privacy Policy
1. Who this applies to
This policy explains how Petter (the “app”) handles your personal data when you
create an account and use the app to manage your pets' information. It applies to
the Android and iOS apps.
2. What we collect
We collect only what the app needs to work:
- Account data — your email address; an optional first name; your
language and currency preference. If you sign in with Google or Apple, we receive
the basic profile/email those services provide for sign-in.
- Your username (handle) — a name you choose, shown with a short
number (e.g.
alex#1234). It is how other users can reach you
(sections 7 and 8) and it is deliberately not your email address
or your real name.
- Profile details you choose to add — an optional short
bio (up to 300 characters) and an optional profile
picture of you (an avatar). Both are written by you and can be removed by
you at any time. See section 8 for who can see them.
- Pet data you enter — pet profiles (name, species, breed, sex,
dates, chip number, notes), photos you add, and the records you create:
vaccinations, vet visits, weight measurements, medications, feeding schedules,
calendar events, and spending entries.
- Your social connections — the friend requests you send or
receive, the friendships that result, and the users you have blocked. When a friend
request is declined, we keep a private marker of that so the same person cannot
immediately re-send it (section 8).
- Your sharing choices — which pets you have chosen to show on your
public profile, and whether you turned on “friends see all my pets”.
- Notification preferences — your per-category reminder opt-ins
and your Messages and Friends push opt-ins.
- Device push token — when you sign in on a phone, a Firebase
Cloud Messaging token (Android and iOS) that identifies your device
(not your identity) so we can deliver notifications while the app is closed.
It is removed when you sign out (“sign out everywhere” removes it from all your
devices) and when your account is deleted. See section 4.
- Crash and error diagnostics — if you leave crash reporting
enabled, we collect technical error reports to fix bugs. These are tied only to a
random pseudonymous identifier — never your email, name, or pet
data. You can turn this off in Settings at any time.
- Discovery data (only if you opt a pet in) — if you use the
optional “Nearby pets” or “Play” features (section 9), we store the discovery
profile you create for that pet (description, the photos you selected, and a
deliberately coarsened location) and, for Play, the likes/skips and
matches you make.
About location: we never store your precise location. Your device's
precise position is used transiently — only while you use the discovery
screens, to run the “near me” search — and is not saved. What is saved, only for pets
you explicitly opt in, is a location snapped to a coarse grid you choose (roughly
300 m or 1 km). We do not use
advertising or third-party tracking SDKs, and we do not sell your
data.
3. Why we use it (legal bases under the GDPR)
- To provide the app (store and show your pets' data, authenticate
you, send reminders, connect you with the people you choose, send account emails
such as verification and password reset) — performance of a contract
(Art. 6(1)(b)).
- Crash reporting — your consent (Art. 6(1)(a)); withdraw
it any time in Settings.
- Security, debugging, and preventing abuse — legitimate
interests (Art. 6(1)(f)). This includes the short cooldown after a declined
friend request, which exists to stop unwanted repeat contact.
4. Reminders / notifications
Reminders (calendar, vet visits, medications, feeding) are scheduled
and shown on your device (local notifications) — no server push is
involved.
Notifications from other people work differently: our server sends
them through Firebase Cloud Messaging (Google) — which on iOS hands off
to Apple's push service — to your device's push token, so they can reach you while the
app is closed. There are three of them, and each carries the minimum
needed to show it:
| Notification | What it contains | Turn it off in |
| New message |
The sender's username and the conversation reference —
never the message text |
Settings → Notifications → Messages |
| New Play match |
That a match happened, and the matched pet's name |
Settings → Notifications |
| Friend request received / accepted |
The other person's username |
Settings → Notifications → Friends |
No push is ever sent to someone who turned that toggle off, and none is sent between
users who have blocked each other. Push notifications never carry your email address or
anyone's account identifier. Your push token is stored only while you are signed in
(see section 2).
5. Sharing with your household
Petter lets you create or join a household and share pets with the
people in it (for example, your family). This is entirely under your control:
- Nothing is shared until you act. Sharing happens only when you
create or join a household and then explicitly share a specific pet. By default your
pets are private to your account.
- What household members can see. When you share a pet, the other
members of that household can see that pet's profile, photos, and its records —
vaccinations, vet visits (including any vet-visit cost you record),
weight, medications, feeding schedules, and calendar events — and can add to and
edit those shared records (a shared “family” calendar and budget). Members also see
your first name (if you set one) and your profile picture shown as
the author of items you add, and any household-level events and expenses you create.
A household can also have a photo, which every member of that
household can see and change.
- What stays private. Pets you do not share, and the records of pets
you have not shared, remain visible only to you. Your email address and account
credentials are never shared with other members.
- You can stop sharing at any time. Unsharing a pet, removing a
member, leaving the household, or deleting the household immediately revokes the
other members' access. Unsharing never deletes a pet or a record — the data stays
with its owner.
- Deleting your account removes your pets and their records for
everyone, including household members you had shared them with (see section 12).
Giving a pet away (ownership transfer). Separately from household
sharing, you can permanently hand a pet over to another Petter user with a single-use
transfer code you give them out of band. The recipient receives a copy of the pet's
profile and care history — vaccinations, vet visits (without your
costs), weight, medications, and feeding schedules. Your photos, vet-visit
attachments, and spending records are not transferred. Your own copy of the pet
freezes as a read-only record visible only to you. A transfer is initiated only by you
and cannot be undone in the app.
Legal basis: sharing and transfer are carried out to provide the app at your
request — performance of a contract (Art. 6(1)(b)).
6. Temporary sitter access
Petter also lets you grant a sitter — a caregiver such as a friend or
neighbour — temporary, limited access to one of your pets while you are
away. This is separate from, and deliberately narrower than, household sharing, and is
entirely under your control:
- Nothing is shared until you act. A sitter gets access only when
you, as the pet's owner, create a single-use invite code for one specific pet and
give it to them out of band, and they redeem it. You set an end date when you invite;
access ends automatically then — or immediately if you revoke it.
- What a sitter can see. For the one pet you granted, a sitter can
see that pet's profile and its care records — vaccinations, weight, medications, and
feeding schedules — and the pet's calendar events and reminders, so they can look
after it. They also see your first name (if you set one) as the
person who granted access.
- What a sitter can never see. A sitter cannot see
your budget or spending, any vet-visit costs or vet-visit
history, any of your other pets, your household, or your
email address. A sitter is intentionally more limited than a household member.
- What a sitter can do. A sitter can log the care they perform —
add a weight measurement and mark reminders done — attributed to them by first name.
They cannot edit your pet's profile, change or delete records they did not create,
share the pet, or invite anyone else.
- You can stop access at any time. Revoking a sitter, or the
automatic expiry you set, immediately ends their access on their next use of the app.
Anything a sitter added stays with your pet (it belongs to you, the owner); ending
access never deletes it.
- Account deletion. Deleting your account removes your pets and
their records, ending any sitter access to them (see section 12). If a
sitter deletes their own account, your pet and its records are
unaffected.
Legal basis: sitter access is carried out to provide the app at your request —
performance of a contract (Art. 6(1)(b)).
7. Messaging
Petter lets you send private 1-to-1 messages to another Petter
user.
- Starting a chat. You start a conversation by entering another
user's username (their handle, e.g.
alex#1234). You do
not need — and are not shown — their email address or real name; you only ever see
the handle they chose. There is no way to browse or search for
people: beyond a username you already know, the only other ways a
chat can start are a mutual Play match (section 9) — which reveals
usernames only to the two matched owners — the chat button next to a member of your
own household, and the chat button next to one of your friends (section 8).
- What is stored. The messages you send are stored so we can deliver
them and so both of you can read the conversation history. Message content is held
under the same EU hosting and access controls (Row-Level Security) as the rest of
your data — only the two people in a conversation can read its messages.
- Who can read your messages. Only you and the person you are
chatting with. We do not use message content for any purpose other than delivering it
between the two of you; we do not profile or advertise on it.
- Delivery. Messages appear live while you have the app open. While
the app is closed, you can receive a push notification about a new
message (sender's username only, never the text) — see section 4. You can turn these
off in Settings → Notifications → Messages.
- Retention & deletion. A conversation and its messages are kept
while the conversation exists. If either participant deletes their
account, the whole 1-to-1 conversation — and all of its messages — is deleted for
both of you (see section 12). Your own messages are included in your data export
(section 13).
- Blocking. You can block another user from a conversation. Once
blocked, their messages are hidden from your view and they can no longer reach you.
To do this we store which users you have blocked (your account and
theirs, and when). This list is private to you: the person you block is not told, and
their own view of the chat is unchanged. You can unblock at any time from
Settings → Privacy → Blocked users, and the handles you have blocked
are included in your data export (section 13).
- Deleting a message for yourself. You can remove any message from
your own view of a chat (“Delete for me”). This hides it for you only:
the message itself remains stored — the other person still sees it and is not
notified — until the conversation is deleted (see above). Your data export
(section 13) includes such messages, marked as deleted-for-you.
Legal basis: messaging, blocking and delete-for-me are provided at your request —
performance of a contract (Art. 6(1)(b)).
8. Your public profile and Friends
Petter has an optional social layer built around your username.
Everything in it is off until you fill it in, and nothing here exposes your email address
or your real identity.
Your public profile. Any signed-in Petter user who types your
exact username can look up your profile. They see only:
- your username and the month you joined;
- your bio, if you wrote one;
- your profile picture (avatar), if you uploaded one;
- the pets you chose to show (see below);
- your first name — only if you are friends. To everyone else it is
never shown, even if you have set one.
There is no directory and no people search — a profile is reachable
only by someone who already knows the exact handle. If either of you has blocked the
other, the profile is not shown at all, and the result is indistinguishable from a
username that does not exist.
Which of your pets appear on it. None, unless you say so. There are
two independent ways to publish one:
- Per-pet: you switch a specific pet to “show on my profile”. That
pet then appears to anyone who looks up your profile.
- “Friends see all my pets” (a single switch, off by
default): when on, your friends — and only your friends —
additionally see all of your other active pets. People who are not your friends are
unaffected and cannot tell whether the switch is on.
For a published pet, a viewer sees its name, species, breed, sex, approximate age in
years, and its profile photo. Pets that have been marked deceased or transferred are
never shown, and a pet stops being visible the moment you turn its listing off. Pets
shared with you by someone else are never publishable by you — only the owner can publish
their own pet.
Friends.
- Sending a request. You add someone by typing their exact username.
They see that a request arrived, along with your username and avatar.
- Accepting. Once accepted, you appear in each other's friends list
(with usernames and avatars), you can open a chat with one tap (section 7), and you
each become able to see the other's first name and any pets covered by the switch
above. If you both happen to send a request to each other, it is accepted
automatically.
- Declining. A decline is silent — the sender is not
told. To prevent unwanted repeat contact, a request from the same person is quietly
suppressed for 7 days afterwards; to make that unobservable, the
sender's own view is unchanged. We store a private marker to do this. If you later
invite that person yourself, the cooldown is cleared.
- Removing and blocking. You can remove a friend at any time.
Blocking a user hides the friendship for both of you and stops all contact;
unblocking restores it.
- Notifications. You can receive a push when a friend request
arrives or is accepted (username only) — turn it off in Settings →
Notifications → Friends.
Deletion & export. Removing your bio, avatar, or a pet listing
takes effect immediately. Deleting your account removes your profile, bio, avatar,
friends, pending requests and listings (section 12). Your friends, pending requests, bio
and listing choices are all included in your data export (section 13).
Legal basis: the public profile and Friends are provided at your request —
performance of a contract (Art. 6(1)(b)); the decline cooldown rests on our
legitimate interest in preventing unwanted repeat contact (Art. 6(1)(f)).
9. Finding other pets (Nearby pets & Play matching)
Petter has two optional community features: Nearby
pets (a map/list of pets whose owners chose to be discoverable) and
Play (swipe-based matching of pets for playdates). Both are
off by default and entirely under your control:
- Nothing is visible until you act. A pet appears to other users only
after you explicitly opt that pet in and create its discovery/Play
profile. A global switch in Settings → Privacy turns all
discoverability off at once. Turning a pet off (or the global switch) immediately
stops it from being shown.
- What other users can see about an opted-in pet: its name, species,
breed, sex, approximate age, the description and photos you chose for the profile,
and an approximate location/distance (the coarse grid location
described in section 2 — roughly 300 m or 1 km, your choice). They are
never shown your name, email, username, or the pet's exact
position.
- Play (matching). When you use Play, your likes/skips and any
matches are stored so matching can work. If two owners like each other's pets, a
match is created — only then do the two of you see each other's
username, and a private 1-to-1 chat opens (section 7). You can
unmatch at any time. Users you have blocked (and users who blocked you) are excluded
from your deck and can never match with you, in either direction.
- Map tiles. The Nearby map view loads its background map from
OpenStreetMap's public tile servers; like any web request, your IP
address reaches that server when tiles load. No account data is sent with it.
- Deletion & export. Opting a pet out deletes its discovery
profile. Deleting your account removes your discovery profiles, likes and matches
(section 12), and your Play data is included in your data export (section 13).
Legal basis: discovery and matching are provided at your request — performance of
a contract (Art. 6(1)(b)).
10. Who processes your data (sub-processors)
We use the following providers strictly to operate the app:
| Provider | Purpose | Region |
| Supabase |
Database, authentication, and file storage (pet photos, vet-visit attachments,
household photos, profile pictures) |
EU |
| Resend |
Delivery of account emails (sign-up verification, password reset) |
EU / US (SCC-covered) |
| Sentry |
Crash/error diagnostics (if enabled) |
EU |
| Google Firebase Cloud Messaging |
Delivery of push notifications to your device — on iOS via Apple Push
Notification service (device push token + the notification content described in
section 4) |
Global (Google infrastructure; SCC-covered) |
| Google / Apple |
Only if you use their sign-in |
per their terms |
We sign Data Processing Agreements with our sub-processors where required.
11. Where your data is stored / international transfers
Your data is hosted in the EU. Where any transfer outside the EEA
occurs, it is covered by appropriate safeguards (e.g. Standard Contractual Clauses).
12. How long we keep it
We keep your data while your account exists. When you delete your account, your pets
and all associated records are deleted (cascaded) from our database — together with your
profile, bio, username, avatar, friendships and pending requests, discovery and Play
data, push tokens, and any 1-to-1 conversations you were part of. The files you uploaded
(pet photos, vet-visit attachments, your avatar) are deleted from storage as part of the
same operation. Diagnostic events expire on the provider's retention schedule. Backups
are rotated on a routine schedule.
13. Your rights
Under the GDPR you may: access your data; correct it; delete it (“right to be
forgotten”); restrict or object to processing; receive a portable copy; and withdraw
consent. The app provides in-product account deletion and data
export; for anything else, contact us at
support@petter.pl. You also have the right to
lodge a complaint with your supervisory authority — in Poland, the President of
the Personal Data Protection Office (UODO).
14. Security
Data is encrypted in transit (TLS) and at rest by our hosting provider. Access is
isolated per user by database row-level security, so one account cannot read another's
data — other than the specific pets and records you have chosen to share with your
household or grant to a sitter (sections 5 and 6), what you publish on your profile or
share with friends (section 8), and the discovery profiles you have opted in
(section 9).
15. Children
Petter is not directed at children under 16. We do not knowingly collect data from
children under 16. If you believe a child has provided us data, contact us.
16. Changes to this policy
We may update this policy; we will revise the “Last updated” date and, for material
changes, notify you in the app.
17. Contact
Paweł Szulc — support@petter.pl.
Testing notice: during alpha/beta testing the app and its data store
may be reset or changed; do not rely on it for permanent record-keeping during this
phase.