Zapurr Privacy Policy
Last updated: 2026-09-15
Zapurr (“we”, “our”, “the app”) is a pet care app for iOS. This policy describes what information we collect, why, who we share it with, and how you can control it.
What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Email address, authentication ID, optional name | Sign in, account recovery, account deletion |
| Pet & household data | Pet name, species, breed, photos, weight, health logs, vet records, medications, behavior incidents, journal entries | The core service — these are the records the app exists to maintain |
| Contact details | Optional phone, email, or preferred contact method for pet tags, emergency contacts, lost-pet alerts, sitters, and donor coordination | Let people you choose contact you or coordinate pet safety features |
| Location | User-chosen map points for lost pets, stray reports, playdates, and vet search; coarsened/fuzzed location for nearby routing and donor matching; and, when you report a stray, your device’s own position at that moment | Show nearby pet-safety features, notify you of nearby alerts, and let a report be checked against where it was actually made |
| Date of birth | The date you enter once at sign-up | Age gate: members under 18 are never shown exact stray locations. Used for nothing else — not advertising, not personalisation |
| Device identifier | A random UUID stored in your device keychain, attached to stray reports and reveals | Fraud prevention: it stops one phone from corroborating its own stray report, which is what keeps the exact-location reveal honest |
| Reveal history | Which exact stray location or lost-pet contact you asked to see, and when | Enforces the daily reveal limit, and lets us warn the people affected if a location is ever misused |
| Push notification token | Apple-issued device token | Deliver feeding reminders, medication reminders, and alerts you’ve opted into |
| Diagnostics | Crash reports and performance diagnostics | Detect and fix bugs |
| Purchases | Zapurr Pro subscription status and purchase history from RevenueCat/App Store | Unlock paid features and support purchase restore |
We do not collect: precise GPS history, microphone recordings without your explicit prompt (voice features only run while you hold the mic), device contacts, calendar, photos outside the ones you choose or preview locally, ad-tracking identifiers (IDFA), or data from other apps.
Where it lives
- On your device: SwiftData (local database) and the iOS keychain.
- In the cloud (Supabase): pet records, photos, health logs, and the data needed to deliver shared features (households, lost pet alerts, stray map). Encrypted at rest. Row-level security ensures only you and members of your household can read your data.
- Anthropic: the contents of your in-app Assistant messages and the photos/text you choose to submit to AI features like Spot Check or Body Scan are sent to Anthropic to generate replies. Anthropic does not retain or train on this data per their API terms.
- Apple: push notifications are delivered through APNs; APNs sees the notification payload (e.g. “Feed Luna at 6pm”) but no health-record contents.
- Sitter Mode share links: when you generate a Sitter Mode link, a time-boxed token (max 30 days) lets a sitter you choose view a read-only page of your pets’ feeding, medication, vet, and emergency contact info, and mark medication doses as given. Anyone holding the link can see what you scoped into it until it expires or you revoke it. Tokens never include your email address or owner identity. Sitter page access is rate-limited and revocations take effect immediately for the sitter’s next interaction.
- Food recall data (FDA): we sync the public FDA pet-food recall feed nightly into our database; if you scan and subscribe a pet to a product, we send you a push notification when that product is later recalled. Scans you don’t subscribe to are not stored.
What we do not do
- We do not sell your data.
- We do not share your data with advertisers.
- We do not use your data to train AI models.
- We do not track precise GPS history. When you create a map-based report or playdate, the point you choose may be stored and shown as part of that feature. Nearby routing uses coarsened or fuzzed location where possible.
Your rights
- See your data: Settings → Privacy & Data → Export My Data. Generates a complete JSON archive of everything we hold for you.
- Delete your account: Settings → Privacy & Data → Delete Account. Removes your account, all pet data, all photos, and your authentication record within 30 days. Action is irreversible.
- Opt out of any push notification category: Settings → Privacy → Notifications.
If you live in the EU/UK (GDPR), California (CCPA), or any jurisdiction with similar law, the rights above satisfy the right to access, portability, and erasure. To exercise any other right (rectification, restriction, objection), email jhonkenrick28@gmail.com.
Children
Zapurr is not directed to children under 13 and we do not knowingly collect data from them. If you believe a child has created an account, email jhonkenrick28@gmail.com and we will delete it.
Security
- All network traffic uses TLS 1.2+.
- Data at rest in Supabase is encrypted (AES-256).
- Authentication is enforced by Supabase Auth (PKCE flow).
- Row-level security policies are in place on every user-data table; a user cannot read or modify another user’s data.
We follow Apple’s App Store Review Guidelines and the iOS Data Protection APIs. No security system is perfect, but if we discover a breach affecting you, we will notify you within 72 hours.
Changes
If we change this policy materially, we will notify you in-app before the change takes effect.
Contact
- jhonkenrick28@gmail.com
- For data requests: jhonkenrick28@gmail.com