Petter — Privacy Policy
1. Who this applies to
This policy explains how Petter (the “app”) handles your personal data when you
create an account and use the app to manage your pets' information. It applies to
the Android and iOS apps.
2. What we collect
We collect only what the app needs to work:
- Account data — your email address; an optional first name; your
language and currency preference. If you sign in with Google or Apple, we receive
the basic profile/email those services provide for sign-in.
- Pet data you enter — pet profiles (name, species, breed, sex,
dates, chip number, notes), photos you add, and the records you create:
vaccinations, vet visits, weight measurements, medications, feeding schedules,
calendar events, and spending entries.
- Notification preferences — your per-category reminder opt-ins
and your Messages push opt-in.
- Device push token — if you use messaging on Android, a Firebase
Cloud Messaging token that identifies your device (not your
identity) so we can deliver “new message” notifications while the app is closed.
It is removed when you sign out (“sign out everywhere” removes it from all your
devices) and when your account is deleted. See section 4.
- Crash and error diagnostics — if you leave crash reporting
enabled, we collect technical error reports to fix bugs. These are tied only to a
random pseudonymous identifier — never your email, name, or pet
data. You can turn this off in Settings at any time.
- Discovery data (only if you opt a pet in) — if you use the
optional “Nearby pets” or “Play” features (section 8), we store the discovery
profile you create for that pet (description, the photos you selected, and a
deliberately coarsened location) and, for Play, the likes/skips
and matches you make.
About location: we never store your precise location. Your
device's precise position is used transiently — only while you use
the discovery screens, to run the “near me” search — and is not saved. What is
saved, only for pets you explicitly opt in, is a location snapped to a coarse grid
you choose (roughly 300 m or 1 km). We do
not use advertising or third-party tracking SDKs, and we do
not sell your data.
3. Why we use it (legal bases under the GDPR)
- To provide the app (store and show your pets' data, authenticate
you, send reminders, send account emails such as verification and password reset)
— performance of a contract (Art. 6(1)(b)).
- Crash reporting — your consent (Art. 6(1)(a)); withdraw
it any time in Settings.
- Security, debugging, and preventing abuse — legitimate
interests (Art. 6(1)(f)).
4. Reminders / notifications
Reminders (calendar, vet visits, medications, feeding) are
scheduled and shown on your device (local notifications) — no server
push is involved.
New-message notifications work differently: when someone sends you
a message and your app is closed, our server sends a push through Firebase
Cloud Messaging (Google) to your device's push token. The notification
carries only the sender's username and the conversation reference —
never the message text and never anyone's account identifier. No push
is sent if you turned the Messages toggle off in Settings, or if the sender is someone
you blocked. Your push token is stored only while you're signed in (see section 2).
5. Sharing with your household
Petter lets you create or join a household and share pets with the
people in it (for example, your family). This is entirely under your control:
- Nothing is shared until you act. Sharing happens only when you
create or join a household and then explicitly share a specific pet. By default
your pets are private to your account.
- What household members can see. When you share a pet, the other
members of that household can see that pet's profile, photos, and its records —
vaccinations, vet visits (including any vet-visit cost you
record), weight, medications, feeding schedules, and calendar events — and can add
to and edit those shared records (a shared “family” calendar and budget). Members
also see your first name (if you set one) shown as the author of
items you add, and any household-level events and expenses you create.
- What stays private. Pets you do not share, and the records of
pets you have not shared, remain visible only to you. Your email address and
account credentials are never shared with other members.
- You can stop sharing at any time. Unsharing a pet, removing a
member, leaving the household, or deleting the household immediately revokes the
other members' access. Unsharing never deletes a pet or a record — the data stays
with its owner.
- Deleting your account removes your pets and their records for
everyone, including household members you had shared them with (see section 11).
Giving a pet away (ownership transfer). Separately from household
sharing, you can permanently hand a pet over to another Petter user with a single-use
transfer code you give them out of band. The recipient receives a copy of the pet's
profile and care history — vaccinations, vet visits (without your
costs), weight, medications, and feeding schedules. Your photos, vet-visit
attachments, and spending records are not transferred. Your own copy of the
pet freezes as a read-only record visible only to you. A transfer is initiated only
by you and cannot be undone in the app.
Legal basis: sharing and transfer are carried out to provide the app at your
request — performance of a contract (Art. 6(1)(b)).
6. Temporary sitter access
Petter also lets you grant a sitter — a caregiver such as a friend
or neighbour — temporary, limited access to one of your pets while
you are away. This is separate from, and deliberately narrower than, household
sharing, and is entirely under your control:
- Nothing is shared until you act. A sitter gets access only when
you, as the pet's owner, create a single-use invite code for one specific pet and
give it to them out of band, and they redeem it. You set an end date when you
invite; access ends automatically then — or immediately if you revoke it.
- What a sitter can see. For the one pet you granted, a sitter can
see that pet's profile and its care records — vaccinations, weight, medications,
and feeding schedules — and the pet's calendar events and reminders, so they can
look after it. They also see your first name (if you set one) as
the person who granted access.
- What a sitter can never see. A sitter cannot
see your budget or spending, any vet-visit costs or
vet-visit history, any of your other pets, your
household, or your email address. A sitter is intentionally more limited than a
household member.
- What a sitter can do. A sitter can log the care they perform —
add a weight measurement and mark reminders done — attributed to them by first
name. They cannot edit your pet's profile, change or delete records they did not
create, share the pet, or invite anyone else.
- You can stop access at any time. Revoking a sitter, or the
automatic expiry you set, immediately ends their access on their next use of the
app. Anything a sitter added stays with your pet (it belongs to you, the owner);
ending access never deletes it.
- Account deletion. Deleting your account removes your pets and
their records, ending any sitter access to them (see section 11). If a
sitter deletes their own account, your pet and its records are
unaffected.
Legal basis: sitter access is carried out to provide the app at your request —
performance of a contract (Art. 6(1)(b)).
7. Messaging
Petter lets you send private 1-to-1 messages to another Petter
user.
- Starting a chat. You start a conversation by entering another
user's username (their handle, e.g.
alex#1234). You
do not need — and are not shown — their email address or real name; you only ever
see the handle they chose. There is no way to browse or search for
people: beyond a username you already know, the only other ways a
chat can start are a mutual Play match (section 8) — which
reveals usernames only to the two matched owners — and the chat button next to a
member of your own household.
- What is stored. The messages you send are stored so we can
deliver them and so both of you can read the conversation history. Message content
is held under the same EU hosting and access controls (Row-Level Security) as the
rest of your data — only the two people in a conversation can read its
messages.
- Who can read your messages. Only you and the person you are
chatting with. We do not use message content for any purpose other than delivering
it between the two of you; we do not profile or advertise on it.
- Delivery. Messages appear live while you have the app open.
While the app is closed, you can receive a push notification
about a new message (Android; sender's username only, never the text) — see
section 4. You can turn these off in Settings → Notifications →
Messages.
- Retention & deletion. A conversation and its messages are
kept while the conversation exists. If either participant deletes
their account, the whole 1-to-1 conversation — and all of its messages — is
deleted for both of you (see section 11). Your own messages are included in your
data export (section 12).
- Blocking. You can block another user from a conversation. Once
blocked, their messages are hidden from your view and they can no longer reach
you. To do this we store which users you have blocked (your
account and theirs, and when). This list is private to you: the person you block
is not told, and their own view of the chat is unchanged. You can unblock at any
time from Settings → Privacy → Blocked users, and the handles you
have blocked are included in your data export (section 12).
- Deleting a message for yourself. You can remove any message
from your own view of a chat (“Delete for me”). This hides it for you
only: the message itself remains stored — the other person still sees it
and is not notified — until the conversation is deleted (see above). Your data
export (section 12) includes such messages, marked as deleted-for-you.
Legal basis: messaging, blocking and delete-for-me are provided at your request —
performance of a contract (Art. 6(1)(b)).
8. Finding other pets (Nearby pets & Play matching)
Petter has two optional community features: Nearby
pets (a map/list of pets whose owners chose to be discoverable) and
Play (swipe-based matching of pets for playdates). Both are
off by default and entirely under your control:
- Nothing is visible until you act. A pet appears to other users
only after you explicitly opt that pet in and create its
discovery/Play profile. A global switch in Settings → Privacy
turns all discoverability off at once. Turning a pet off (or the global switch)
immediately stops it from being shown.
- What other users can see about an opted-in pet: its name,
species, breed, sex, approximate age, the description and photos you chose for the
profile, and an approximate location/distance (the coarse grid
location described in section 2 — roughly 300 m or 1 km, your choice).
They are never shown your name, email, username, or the pet's
exact position.
- Play (matching). When you use Play, your likes/skips and any
matches are stored so matching can work. If two owners like each other's pets, a
match is created — only then do the two of you see each other's
username, and a private 1-to-1 chat opens (section 7). You can
unmatch at any time. Users you have blocked (and users who blocked you) are
excluded from your deck and can never match with you, in either direction.
- Map tiles. The Nearby map view loads its background map from
OpenStreetMap's public tile servers; like any web request, your
IP address reaches that server when tiles load. No account data is sent with
it.
- Deletion & export. Opting a pet out deletes its discovery
profile. Deleting your account removes your discovery profiles, likes and matches
(section 11), and your Play data is included in your data export (section 12).
Legal basis: discovery and matching are provided at your request —
performance of a contract (Art. 6(1)(b)).
9. Who processes your data (sub-processors)
We use the following providers strictly to operate the app:
| Provider | Purpose | Region |
| Supabase | Database, authentication, account emails (verification, password reset), and photo storage | EU |
| Sentry | Crash/error diagnostics (if enabled) | EU |
| Google Firebase Cloud Messaging | Delivery of new-message push notifications to your device (device push token + the notification content described in section 4) | Global (Google infrastructure; SCC-covered) |
| Google / Apple | Only if you use their sign-in | per their terms |
We sign Data Processing Agreements with our sub-processors where required.
10. Where your data is stored / international transfers
Your data is hosted in the EU. Where any transfer outside the EEA
occurs, it is covered by appropriate safeguards (e.g. Standard Contractual Clauses).
11. How long we keep it
We keep your data while your account exists. When you delete your account, your pets
and all associated records are deleted (cascaded) from our database; diagnostic events
expire on the provider's retention schedule. Backups are rotated on a routine
schedule.
12. Your rights
Under the GDPR you may: access your data; correct it; delete it (“right to be
forgotten”); restrict or object to processing; receive a portable copy; and withdraw
consent. The app provides in-product account deletion and data
export; for anything else, contact us at
support@petter.pl. You also have the
right to lodge a complaint with your supervisory authority — in Poland, the
President of the Personal Data Protection Office (UODO).
13. Security
Data is encrypted in transit (TLS) and at rest by our hosting provider. Access is
isolated per user by database row-level security, so one account cannot read another's
data — other than the specific pets and records you have chosen to share with your
household or grant to a sitter (sections 5 and 6), and the discovery profiles you have
opted in (section 8).
14. Children
Petter is not directed at children under 16. We do not knowingly collect data from
children under 16. If you believe a child has provided us data, contact us.
15. Changes to this policy
We may update this policy; we will revise the “Last updated” date and, for material
changes, notify you in the app.
16. Contact
Paweł Szulc — support@petter.pl.
Testing notice: during alpha/beta testing the app and its data store
may be reset or changed; do not rely on it for permanent record-keeping during this
phase.