Zapurr Privacy Policy
Last updated: 2026-07-04
Zapurr (“we”, “our”, “the app”) is a pet care app for iOS. This policy describes what information we collect, why, who we share it with, and how you can control it.
What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Email address, authentication ID | Sign in, account recovery, account deletion |
| Pet & household data | Pet name, species, breed, photos, weight, health logs, vet records, medications, behavior incidents, journal entries | The core service — these are the records the app exists to maintain |
| Approximate location | Coarse latitude/longitude (used only when you opt into Stray Map or Lost Pet alerts) | Show you nearby strays/lost pets and notify you of nearby alerts |
| Push notification token | Apple-issued device token | Deliver feeding reminders, medication reminders, and alerts you’ve opted into |
| Diagnostics | Crash reports, anonymous usage events | Detect and fix bugs |
We do not collect: precise GPS history, microphone recordings without your explicit prompt (voice features only run while you hold the mic), contacts, calendar, photos outside what you upload, ad-tracking identifiers (IDFA), or data from other apps.
Where it lives
- On your device: SwiftData (local database) and the iOS keychain.
- In the cloud (Supabase): pet records, photos, health logs, and the data needed to deliver shared features (households, lost pet alerts, stray map). Encrypted at rest. Row-level security ensures only you and members of your household can read your data.
- Anthropic: the contents of your in-app Assistant messages are sent to Anthropic to generate replies. Anthropic does not retain or train on this data per their API terms.
- Apple: push notifications are delivered through APNs; APNs sees the notification payload (e.g. “Feed Luna at 6pm”) but no health-record contents.
- Sitter Mode share links: when you generate a Sitter Mode link, a time-boxed token (max 30 days) lets a sitter you choose view a read-only page of your pets’ feeding, medication, vet, and emergency contact info, and mark medication doses as given. Anyone holding the link can see what you scoped into it until it expires or you revoke it. Tokens never include your email address or owner identity. Sitter page access is rate-limited and revocations take effect immediately for the sitter’s next interaction.
- Food recall data (FDA): we sync the public FDA pet-food recall feed nightly into our database; if you scan and subscribe a pet to a product, we send you a push notification when that product is later recalled. Scans you don’t subscribe to are not stored.
What we do not do
- We do not sell your data.
- We do not share your data with advertisers.
- We do not use your data to train AI models.
- We do not share precise location with anyone — even shared features like Stray Map only use a coarse geohash.
Your rights
- See your data: Settings → Privacy & Data → Export My Data. Generates a complete JSON archive of everything we hold for you.
- Delete your account: Settings → Privacy & Data → Delete Account. Removes your account, all pet data, all photos, and your authentication record within 30 days. Action is irreversible.
- Opt out of any push notification category: Settings → Privacy → Notifications.
If you live in the EU/UK (GDPR), California (CCPA), or any jurisdiction with similar law, the rights above satisfy the right to access, portability, and erasure. To exercise any other right (rectification, restriction, objection), email jhonkenrick28@gmail.com.
Children
Zapurr is not directed to children under 13 and we do not knowingly collect data from them. If you believe a child has created an account, email jhonkenrick28@gmail.com and we will delete it.
Security
- All network traffic uses TLS 1.2+.
- Data at rest in Supabase is encrypted (AES-256).
- Authentication is enforced by Supabase Auth (PKCE flow).
- Row-level security policies are in place on every user-data table; a user cannot read or modify another user’s data.
We follow Apple’s App Store Review Guidelines and the iOS Data Protection APIs. No security system is perfect, but if we discover a breach affecting you, we will notify you within 72 hours.
Changes
If we change this policy materially, we will notify you in-app before the change takes effect.
Contact
- jhonkenrick28@gmail.com
- For data requests: jhonkenrick28@gmail.com