Privacy Policy
Last updated: March 3, 2026
1. Overview
Pet Capsule ("we", "our", "us") respects your privacy. This policy explains how we collect, use, store, and protect your information when you use the Pet Capsule iOS app ("the App") and website at petcapsule.app ("the Website"). This policy applies to users worldwide, including those in the European Economic Area (EEA), United Kingdom (UK), California, and Australia.
2. Data Controller
Pet Capsule is the data controller for personal data collected through the App and Website. We are a small family-run business based in Melbourne, Victoria, Australia. As a small business, we are not required to appoint a formal Data Protection Officer (DPO) under GDPR or the Australian Privacy Act. However, we take your privacy seriously and handle all privacy matters directly.
For any privacy-related questions, contact us at privacy@petcapsule.app.
3. Information We Collect
3.1 Information You Provide Directly
| Data | When Collected | Purpose | Legal Basis (GDPR) |
|---|---|---|---|
| Email address | Waitlist signup, account creation | Account management, waitlist updates | Consent |
| Name | Affiliate signup, Sign in with Apple | Partner management, account display | Consent |
| Social media handle | Affiliate signup (optional) | Partner coordination | Consent |
| Pet information | In-app (names, breeds, health records, photos) | Core app functionality | Contract performance |
| Emergency contacts | In-app (vet/emergency contacts) | Emergency features | Legitimate interest (pet safety) |
| Care tasks & schedules | In-app (medications, grooming, vet visits) | Care management | Contract performance |
| Financial data | In-app (pet expenses, insurance info) | Expense tracking | Contract performance |
3.2 Information Collected Automatically
| Data | Source | Purpose | Legal Basis |
|---|---|---|---|
| Page views (anonymous) | Self-hosted analytics | Website analytics | Legitimate interest |
| Marketing attribution (UTM parameters) | URL parameters on signup | Measure marketing effectiveness | Consent (collected with email) |
| Referral code | URL parameter on invite pages | Referral program tracking | Consent (collected with email) |
| Theme preference | Browser localStorage | Display preference (light/dark mode) | Legitimate interest |
| Anonymous usage analytics | In-app events | Feature usage understanding | Legitimate interest |
| Error/crash diagnostics | App runtime | Reliability improvement | Legitimate interest |
3.3 Information NOT Collected
- We do not set cookies on our website. We use self-hosted, cookie-free analytics.
- We do not use advertising identifiers (IDFA) in the App.
- We do not sell, share, or trade your personal information with third parties for advertising.
- We do not use Google Analytics, Facebook Pixel, or any third-party tracking tools.
- We do not collect biometric data. Pet photos are not processed as biometric identifiers under BIPA, GDPR, or any other biometric data law.
- We do not collect human health data. Pet health records are not subject to HIPAA or similar human health data regulations.
- Fonts are self-hosted — no requests are sent to Google, Adobe, or other font CDNs.
4. How We Use Your Information
- To provide and improve Pet Capsule services (App and Website)
- To manage your waitlist position and referral rewards
- To send you waitlist updates and product announcements (you can unsubscribe anytime)
- To generate AI-powered health insights for your pets (only when you use AI features)
- To manage affiliate partnerships
- To understand website usage patterns through anonymous analytics
- To detect and prevent abuse of our services
5. AI-Specific Data Processing
Pet Capsule uses Google's Gemini AI to power features such as health scanning, breed identification, food safety checking, symptom analysis, and AI chat. This section explains exactly what data is involved.
5.1 What Data Is Sent to AI
When you explicitly trigger an AI feature, the following data may be sent to Google's Gemini API via our secure server proxy:
- Your text prompt — the question or instruction you type
- Pet context — your pet's name, species, breed, age, weight, allergies, medications, recent behaviour trends, and care statistics (used to personalise responses)
- Photos — only when you use image-based features (health scan, breed ID, food scanner)
5.2 What Is NOT Sent to AI
- Your personal identity, email, or account details
- Your location data
- Your financial or insurance information
- Your vault documents
- Data from other pets not relevant to the current query
5.3 How AI Data Is Processed
- All AI requests are routed through our secure server proxy (Supabase Edge Function) — the App never communicates directly with Google's AI
- Google's Gemini API processes data per their API Terms of Service
- Your data is not used to train Google's AI models (per Google's API data usage policy for paid API access)
- AI responses are generated in real-time and not stored by Google beyond the request lifecycle
- We store AI usage counts (for rate limiting) but not the content of your prompts or AI responses on our servers
5.4 AI Accuracy Disclaimer
AI features provide general information and may produce inaccurate results. They are not a substitute for professional veterinary advice. Always consult a qualified veterinarian for your pet's health concerns.
6. Pet Health Data
Pet Capsule stores detailed health information about your pets, including medical records, vaccination history, medications, weight trends, and behaviour observations. We want to be clear about how this data is treated:
- Pet health data is not human health data. It is not subject to HIPAA (US), the Health Records Act (Australia), or equivalent human health data regulations.
- Despite this, we treat your pet's health data with the same level of care and security as if it were protected health information.
- Pet health data is stored locally on your device using Apple's SwiftData framework and synced to your personal iCloud. We do not have access to this data on our servers.
- Pet health data is only shared with Google's AI when you explicitly use AI health features, and only the minimum data needed for the query is sent.
7. Location Data
Pet Capsule uses location data for several features. Here is exactly how each feature uses your location:
| Feature | Location Type | Where Stored | Shared With |
|---|---|---|---|
| Walk Tracking | Precise GPS route | On-device only | No one |
| Pet Trails | Current location | Not stored | Google APIs (environmental data) |
| Vet Locator | Approximate location | Not stored | Apple Maps / Google Places |
| Lost Pet Reports | Last-seen location | Our server (Supabase) | Community members viewing the report |
| Social Posts | Optional location tag | Our server (Supabase) | Other app users (if you choose to share) |
Location permissions are requested only when you first use a location-based feature. You can revoke location access at any time in iOS Settings.
8. Data Storage & Security
8.1 App Data (On-Device)
The majority of your pet data is stored locally on your device using Apple's SwiftData framework and synced to your personal iCloud via CloudKit. This includes pet profiles, health records, memories, care tasks, walk routes, vault documents, and expenses. This data is encrypted by iOS and protected by your device passcode.
8.2 Cloud Data (Supabase)
Shared and social features use Supabase (hosted on AWS) with row-level security. Only the following data is stored server-side: user profiles (display name, avatar), caregiver invitations, lost pet reports, referral tracking, AI usage counts (for rate limiting), community posts, and subscription events. All data is transmitted via TLS encryption.
8.3 Website Data (Supabase)
The waitlist and affiliate databases are stored on Supabase with row-level security. Waitlist data includes email, marketing attribution (UTM), referral code, and position. Affiliate data includes name, email, platform, and audience size.
8.4 Document Vault
The Document Vault is protected by a local PIN you set. Vault data is stored on-device and in your iCloud. We cannot access or recover your vault PIN. If you forget your PIN, vault data cannot be recovered.
8.5 Browser Storage
We use browser storage for the following purposes only:
pc-theme(localStorage) — Your light/dark mode preferencepc-waitlist(localStorage) — Temporary fallback if a waitlist submission fails due to a network error; cleared after successful retrypc_votes(localStorage) — Which roadmap features you have voted for, to prevent duplicate votespc_fp(sessionStorage) — A non-persistent, session-only hash used to deduplicate roadmap votes; automatically cleared when you close the browser tab
No persistent tracking identifiers are stored. You can clear all browser storage at any time via your browser settings.
9. Third-Party Services
| Service | Purpose | Data Shared |
|---|---|---|
| Apple CloudKit | Data sync across your devices | Pet data (encrypted in your iCloud) |
| Supabase | Authentication, shared features, waitlist | Email, display name, user ID |
| Google Gemini API | AI features (chat, health scanning) | User prompts, selected pet photos, pet context (only when you use AI features) |
| Google Places API | Vet locator, place search | Approximate location (only during search) |
| Google Environment APIs | Air quality, pollen, UV data for Pet Trails | Current location (not stored) |
| Apple Maps | Map display, directions | Location data per Apple's terms |
| Apple StoreKit | Subscription management | Purchase data per Apple's terms |
| Self-hosted analytics | Anonymous website analytics (page views, referrer, screen width) | No personal data — no IP addresses, no cookies, no identifiers |
| Brevo (Sendinblue) | Transactional emails, CRM | Email address, referral code, signup date, UTM attribution |
| Cloudflare | Website hosting, CDN, Web Analytics | Anonymous performance metrics (no personal data) |
Note on Google Gemini: Pet data sent to the Gemini API for AI features is processed per Google's API terms and is not used to train their models. Data is sent only when you explicitly trigger an AI feature. We do not send financial data, vault documents, or personal identity information to Gemini.
Note on Brevo: When you join our waitlist, your email address and referral information are sent to Brevo for sending welcome emails and managing our contact list. Brevo processes data per their privacy policy. You can unsubscribe from emails at any time.
10. Automated Decision-Making
Pet Capsule uses AI-powered features that involve automated processing of pet-related data (health scans, breed identification, symptom analysis). Important clarifications:
- These features involve automated processing of pet data only — not profiling of humans
- No automated decisions are made that produce legal effects or similarly significant effects on you as a person
- AI results are presented as suggestions only — you always have final decision-making authority
- You can choose not to use AI features at any time without losing access to core app functionality
11. Data Retention
| Data Type | Retention Period |
|---|---|
| Waitlist signups | Until app launch + 90 days, or until you request deletion |
| Affiliate data | Duration of partnership + 12 months, or until you request deletion |
| App account data | Until you delete your account |
| On-device pet data | Until you delete it from the app or uninstall |
| Anonymous usage analytics | 90 days, then automatically purged |
| Error/crash reports | 30 days, then automatically purged |
| Website analytics (self-hosted) | Aggregated indefinitely (no personal data) |
| Browser localStorage | Until you clear your browser data |
12. Your Rights
12.1 All Users
Regardless of your location, you can:
- Access your personal data — request a copy of what we store
- Correct inaccurate data
- Delete your account and all associated data
- Export your pet data from the App (PDF, CSV, or JSON)
- Unsubscribe from marketing emails at any time
- Clear browser localStorage via your browser settings
- Opt out of AI features without losing core app functionality
12.2 European Economic Area & UK (GDPR)
If you are in the EEA or UK, you additionally have the right to:
- Withdraw consent at any time (without affecting prior processing)
- Restrict processing of your data
- Object to processing based on legitimate interest
- Data portability — receive your data in a structured, machine-readable format
- Lodge a complaint with your local Data Protection Authority
- Information about automated processing — request meaningful information about AI logic used in our features
To exercise any GDPR right, email privacy@petcapsule.app. We will respond within 30 days.
12.3 California Residents (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know — request disclosure of what personal information we collect, use, and share
- Right to Delete — request deletion of your personal information
- Right to Correct — request correction of inaccurate personal information
- Right to Opt-Out of Sale/Sharing — we do not sell or share personal information for cross-context behavioural advertising
- Right to Limit Use of Sensitive Information — we do not use sensitive personal information beyond what is necessary to provide our services
- Right to Non-Discrimination — we will not discriminate against you for exercising your rights
Do Not Sell or Share My Personal Information: Pet Capsule does not sell your personal information. We do not share personal information for cross-context behavioural advertising. No opt-out is required because no sale or sharing occurs.
To exercise any CCPA right, email privacy@petcapsule.app. We will verify your identity and respond within 45 days.
12.4 Australian Privacy Act
Pet Capsule complies with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). As a small business operator, we may be exempt from certain APP obligations, but we voluntarily comply with all 13 Australian Privacy Principles as a matter of best practice:
- APP 1 (Open & transparent) — This privacy policy describes our data handling practices
- APP 2 (Anonymity) — You can use core app features without providing your real name
- APP 3 (Collection) — We only collect personal information reasonably necessary for our functions
- APP 5 (Notification) — We notify you at the point of collection about how your data will be used
- APP 6 (Use & disclosure) — We use your data only for the primary purpose for which it was collected
- APP 8 (Cross-border disclosure) — Data may be processed in the US (Supabase/AWS) and by Google (AI features). We ensure appropriate safeguards are in place
- APP 11 (Security) — We take reasonable steps to protect your data from misuse, interference, and loss
- APP 12 (Access) — You can request access to your personal information at any time
- APP 13 (Correction) — You can request correction of inaccurate personal information
To exercise any rights under the Australian Privacy Act, email privacy@petcapsule.app.
13. Data Breach Notification
In the unlikely event of a data breach that is likely to result in serious harm:
- GDPR (EU/UK): We will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay where the breach poses a high risk to their rights and freedoms
- Australian NDB Scheme: We will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable, and in any event within 30 days of becoming aware of the breach
- CCPA (California): We will notify affected California residents in the most expedient time possible and without unreasonable delay
- All users: We will notify you via email and/or in-app notification, explaining what happened, what data was affected, and what steps we are taking
14. International Data Transfers
Your data may be processed in the United States (where Supabase servers are hosted) and by Google (for AI features). We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) where required by GDPR
- Supabase and Google's compliance with applicable data protection frameworks
- Encryption in transit (TLS) and at rest for all server-side data
15. Children's Privacy
Pet Capsule is not directed at children under 13 (or 16 in the EEA). We do not knowingly collect personal information from children. If we discover that a child has provided us with personal data, we will delete it promptly. Contact us at privacy@petcapsule.app if you believe a child has provided us with their data.
16. Changes to This Policy
We may update this policy from time to time. For significant changes, we will notify you via email (for account holders) or a prominent notice on the Website at least 30 days before the changes take effect. The "Last updated" date at the top will always reflect the latest revision.
17. Contact Us
For any privacy questions, data requests, or concerns:
- Privacy: privacy@petcapsule.app
- General: hello@petcapsule.app