Privacy Policy

Last Updated: July 27, 2026

Welcome to PetLife ("PetLife," "we," "our," or "us"). Your privacy matters to us. This Privacy Policy explains how we collect, use, store, and protect your information when you use the PetLife website, mobile application, and related services (collectively, the "Service"). Your use of the Service is also governed by our Terms of Service.

1. Information We Collect

We collect only the information needed to provide and improve PetLife.

1.1 Information You Provide

Account Information

  • Email address
  • Name or username
  • Authentication information (via Apple, Google, or email)

Pet Information

  • Pet name
  • Species, breed (optional)
  • Birthday (optional)
  • Microchip number (optional, for the PetLife Registry)
  • Photos, videos, and journal entries you choose to upload
  • Notes, moods, and event tags related to your pet

Health Records

  • Health record entries (vaccinations, treatments, weights, vet visits)
  • Pet activity, exercise, food, mood, symptom, and other care records you choose to log
  • Photos and documents you attach to health records, stored in Firebase Storage under your account

Family Member Information

  • Names, relationships, phone numbers, email addresses, and photos of family members and emergency contacts that you choose to add to a passport

This is information you provide about other people. By adding it, you confirm you have their consent for PetLife to store and use it for the passport features you select. Ordinary public-passport and expiring-share projections exclude family-member and emergency-contact information. If you explicitly designate an emergency contact and mark your pet as missing, the public passport and registry lookup may show that contact's name and phone number so a finder can reach them. You are responsible for keeping this information accurate and removing it if consent is withdrawn.

User Content

  • Photos and videos added to daily journal entries
  • Notes and descriptions you write
  • Gifts sent or received within the app

Payment Information

  • Subscription and in-app purchase history (new Plus purchases are processed by Apple in the mobile app; Stripe continues to process any legacy web subscription; PetLife does not receive or store your full card or bank-account details)

1.2 Information Collected Automatically

When you use PetLife, we may automatically collect:

  • Device type, operating system, and app version
  • A randomly generated installation identifier and, when you are signed in, your account ID
  • App and website usage events (e.g., features used, screens viewed, session activity)
  • Crash logs, performance data, and technical context used to diagnose errors (see Section 4)
  • A push notification token, if you enable notifications (see Section 5)

The mobile app sends usage events to PetLife's first-party API and includes your user ID when you are signed in. The website sends events to that API and also sends a separate, reduced copy to Google Firebase Analytics/Google Analytics 4 as described in Section 4. Our hosting provider may derive an approximate country from network information when it handles a request. If you search for a nearby clinic, we send the ZIP code or location text you enter to our API and Google Places to return local results. PetLife does not request or collect your device's precise GPS location.

2. How We Use Your Information

We use your information to:

  • Provide core app functionality (pet passports, health records, journaling, the registry)
  • Save and display your pet's memories
  • Maintain streaks, recaps, and timelines
  • Process subscriptions and purchases
  • Send notifications you opt into (e.g., reminders, updates)
  • Improve app performance and user experience
  • Ensure safety, security, and abuse prevention
  • Comply with legal obligations

We do not sell your personal data.

3. Where Your Data Is Stored

Your account data, pet profiles, health records, and journal entries are stored using Google Firebase (Cloud Firestore), and your photos and documents are stored using Google Firebase Storage. PetLife and its service providers may process data in the United States and other locations where they operate. If you use PetLife from another country, your data may be transferred across borders.

Journal media, passport-scoped images, and current health-record attachments use owner-scoped Storage paths and rules. Firebase download URLs are bearer links, however, and a person who obtains one may be able to fetch the file without signing in. Public, shared, and registry surfaces render passport images through such bearer download links rather than open storage access. We do not publish a directory of stored files, but a bearer-link file should not be treated as accessible only through your login.

3.1 AI Features

PetLife uses Google's Gemini API for features such as image analysis, voice-journal transcription, document extraction, and AI-generated insights and recaps. When you open or use an AI-backed feature, PetLife sends the inputs needed for that feature to Gemini through PetLife's servers. Some insight and recap screens request the associated analysis automatically when you open them; other features send data after you take an action such as submitting a photo, recording, document, or prompt. Depending on the feature, those inputs may include pet profile, care, health, food, mood, journal, photo, audio, or document data. When an uploaded document image needs optical-character recognition, PetLife sends its image bytes to Google Cloud Vision to extract text; Gemini then receives the extracted text or, where needed, the original document. PetLife may store the resulting analysis in your account so that the feature and its history work. Google handles those inputs and outputs under its applicable service terms, project configuration, and retention practices, which may vary by service configuration. PetLife does not use them for advertising.

4. Analytics & Crash Reporting

Mobile and PetLife-hosted analytics. The mobile app and website report usage events (such as feature usage and subscription events) to PetLife's API, hosted on Vercel, and store them in Firebase. Mobile events include an installation identifier, session and event identifiers, device and app information, and, when you are signed in, your user ID. Website events may include the event name, page path, platform, timestamp, and parameters supplied by the feature; the PetLife-hosted copy may include your user ID when the client supplies it. These first-party records are not sent to advertising networks or used by PetLife for cross-company tracking.

Website Firebase Analytics. The website also sends a separate copy of usage events to Google Firebase Analytics/Google Analytics 4 for dashboarding. Before this copy is sent, PetLife removes parameters whose keys are uid, userId, user_id, email, petId, passportId, or petName. This key-based filter does not guarantee that a differently named or free-form value contains no identifier. Google's analytics software may still process the event name and remaining parameters, page path, and browser, device, cookie, or analytics identifiers it collects itself. These Google Analytics records follow the project's Google retention settings and are not part of the first-party Firebase records swept by PetLife's automated account-deletion route.

Crash reporting. We use Sentry to collect crash logs, performance traces, and error context so we can fix bugs. Before sending ordinary error events, configured mobile, browser, Node-server, and edge-server hooks attempt to remove the structured user-email field and structured Cookie and Authorization request fields when those fields are present. These hooks are not content classifiers and do not guarantee that every free-form value, differently shaped field, replay item, or item of request context is excluded. We associate signed-in mobile reports with an internal user ID. Error context can include the screen or feature involved and other technical details; if user or pet content is part of an error, that content may appear in a report. On the website, Sentry may also capture browser interaction context around an error. We do not use this information for advertising.

5. Push Notifications

Push notifications are optional and consent-first: we only register your device for notifications after you allow them in the system permission prompt. If you enable them, we store an Expo push token for your device linked to your account. When you sign out, we attempt to deregister that device's token so notifications for your account stop reaching it. You can turn notifications off at any time in your device settings.

6. Privacy by Design

PetLife is built with privacy as a default.

  • Pet journals are private by default
  • You choose whether a pet profile is:
    • Private
    • Shared via passport link
    • Public
  • You control who can see your content
  • New passports use the visibility choice shown in the product. A legacy passport created before the explicit visibility field was introduced may still be treated as public when that field is absent. Open the passport's sharing controls and set it to private if you do not want its limited public page to remain accessible.

7. Public Passports, Share Links & QR Codes

A standard public-passport page and its printed QR code remain accessible while you keep that passport public. They use a limited public projection and exclude owner identifiers, microchip numbers, private health information, and ordinary family-member or emergency-contact information. If you explicitly designate an emergency contact and mark your pet as missing, that public surface and the registry lookup may show only the designated contact's name and phone number so a finder can reach them. Setting the passport to private replaces the public page with a limited attestation that the passport exists.

An expiring share link or QR code is a separate, owner-created access grant. Anyone who has it can view its limited projection without a PetLife account until the link expires or you revoke it. The expiring projection may include the pet's name, species, breed, country, photo, and the sex or date of birth fields you choose to display; it excludes owner identifiers, the microchip number, and all family-member and emergency-contact information. A share link can keep working until it expires or is revoked even if you later make the public passport private. Please share it thoughtfully. Photo files that were previously shared or viewed may remain accessible to someone who holds their direct file links even after the share grant expires or is revoked.

8. Sharing of Information

We share your information only in limited circumstances:

8.1 With Service Providers

We use service providers to operate the Service: Google Firebase and Google Sign-In (database, storage, and authentication), Google Firebase Analytics/Google Analytics 4 (website usage analytics), Google reCAPTCHA (spam and abuse detection, which may process browser, device, interaction, and network information), Google Gemini (AI processing), Google Cloud Vision (document-image OCR), Google Places (clinic search), Sentry (crash and performance reporting), Apple (sign-in, subscriptions, and push delivery), Stripe (legacy web subscription billing), Resend (transactional and support email), Expo (mobile build, update, and push-notification services), and Vercel (website and API hosting). The data a provider receives depends on the feature you use and may include the categories described above. Providers process that data under their applicable terms, configuration, and retention practices.

8.2 Legal Requirements

We may disclose information if required by law, court order, or to protect the rights, safety, or security of users or PetLife.

8.3 Business Transfers

If PetLife is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.

9. Data Storage & Security

We use industry-standard security measures to protect your data, including encryption in transit, access rules tied to your account, and secure storage practices.

However, no system is 100% secure. We cannot guarantee absolute security but we work hard to protect your information.

10. Data Retention & Deletion

Your data is retained as long as your account is active.

You may delete:

  • Individual pet journals
  • Photos and videos
  • Your entire account

You can request deletion using the in-app account deletion flow or by contacting us. For consumer accounts, the automated process attempts to delete your login credentials and sweep your account, passports, pet health and care records, journals, moments, uploaded files, and PetLife-hosted analytics records linked to your account or pets from PetLife's active systems. It does not remove website Firebase Analytics/Google Analytics 4 events already sent to Google; PetLife applies the exact key-based filter described in Section 4 before sending that copy. Accounts connected to a clinic, shelter, affiliate, payout, credential, or other shared legal record may require support-assisted review so deleting one person's account does not destroy another person's records. We do not automatically match and delete public, unauthenticated email-only leads or waitlists because an address may have been mistyped or supplied by someone else.

Before inventory, billing cancellation, or erasure, PetLife writes a deletion lock that pauses new direct Firebase database and file writes while deletion runs or awaits retry. PetLife then inventories pet identifiers and checks for issued health credentials; credential-linked accounts are routed to support-assisted review. The automated sequence stops before active-account erasure if every Stripe subscription associated with the stored PetLife Stripe customer cannot be canceled or the required deletion audit cannot be written. Uploaded-file removal must finish before Firestore records and the login credential are removed; if a file prefix fails, later phases stop and the credential remains available for a retry, although files removed earlier in that attempt may already be gone. Firestore failures preserve pet identity roots until all account- and pet-linked query sweeps have succeeded, so a retry can reconstruct the remaining identifiers. After the authentication credential is removed, PetLife retries the final audit update and does not show or email a completion claim unless that final state is durably recorded. If that final audit update cannot be confirmed, the app reports an incomplete state, signs the local app session out, and provides a support reference even though the login and active account data may already have been removed.

Backup copies and provider logs may remain according to the applicable backup configuration and provider retention schedule. We may also retain records required by law, such as payment-processor transaction records for tax, accounting, dispute, and fraud-prevention purposes, and aggregated or de-identified analytics that do not directly identify you. Where a shared payment, booking, commission, fulfillment, payout, registry report, adoption, or issued health-credential record must survive, PetLife removes or replaces the deleting consumer's direct account identifier, pet linkage, and contact fields where the automated process can safely identify them, while preserving the shared or legally required record. PetLife also retains pseudonymous Apple purchase-ownership bindings to prevent a deleted purchase from being claimed by another account. For support and audit follow-up, PetLife retains a deletion-request record containing your account ID, a server-secret-keyed one-way hash of your email address rather than the address itself, the reason you submitted, per-collection deletion counts, internal error markers, Stripe subscription and customer identifiers and the cancellation outcome, and the attempted Firebase Authentication deletion status and timing. A minimal deletion-lock document keyed by your account ID is retained to reject cached credentials from recreating active data after deletion. The deletion-audit, purchase-ownership binding, and deletion-lock records currently have no fixed automatic deletion date. Internal error markers and storage paths are not returned to the app. To follow up on a partial deletion or request removal of remaining data, contact support@petlife.live.

10.1 What Our Service Providers Retain After Deletion

If your account has a legacy subscription billed through Stripe, retrieval and cancellation of every subscription associated with the stored PetLife Stripe customer is a required gate before PetLife removes uploaded files, Firestore account data, or the login credential. A retrieval, pagination, or cancellation error stops the later phases and leaves the operation retryable; cancellation and already-canceled results are retained in the deletion audit. Deleting PetLife does not cancel an App Store subscription; you must manage that subscription through your Apple account. Providers may retain limited records for legal, security, backup, billing, or operational purposes under their own schedules. For example:

  • Stripe (payments) — retains transaction and bookkeeping records to meet legal obligations such as tax, accounting, and fraud-prevention requirements. Laws such as GDPR Article 17(3)(b) permit this retention despite a deletion request.
  • Resend (transactional email) — retains email delivery logs in accordance with its own retention schedule.
  • Sentry (crash reporting) — retains crash, performance, and error events according to the retention configured for PetLife's Sentry project.
  • Google, Expo, Apple, and Vercel — may retain security, request, delivery, AI-service, or operational logs according to the service and account configuration.

These records are held by the providers under their own retention practices and legal obligations and are not part of your active PetLife account. PetLife does not sell these records or use them for advertising.

11. Your Rights & Choices (including GDPR & CCPA)

Depending on your location — including if you are in the European Economic Area, the United Kingdom, or California — you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate information (most profile and pet data can be edited directly in the app)
  • Delete your data (via the in-app account deletion flow or by contacting us)
  • Portability — request a copy of your data in a usable format
  • Restrict or object to certain processing
  • Non-discrimination — we will not treat you differently for exercising these rights

We do not sell personal data, so there is no need to opt out of sale. To exercise any of these rights, use the in-app tools or contact us at support@petlife.live — we respond to verified requests within the timeframes required by applicable law.

The data controller for personal data processed through the Service is Sheung Ventures Inc., Dallas, Texas, USA.

12. Children's Privacy

PetLife is not intended for children under 13.

We do not knowingly collect personal data from children. If we become aware of such data, we will delete it promptly.

13. Subscriptions & Purchases

New subscriptions and in-app purchases are handled by Apple's App Store in the mobile app. Website checkout is paused; Stripe continues to process any legacy web subscription.

PetLife does not store your full payment details.

14. Changes to This Policy

We may update this Privacy Policy from time to time.

If changes are significant, we will notify you through the app or via email.

The "Last Updated" date at the top indicates when the policy was last revised.

15. Contact Us

If you have questions about this Privacy Policy, or want to make a privacy request (access, correction, deletion, or portability), contact us at:

Email: support@petlife.live

Company: Sheung Ventures Inc.
Location: Dallas, Texas