Privacy Policy
This Privacy Policy explains what information PupGut ("PupGut," "we," "us," or "our") collects when you use the PupGut mobile app and the website at pupgut.app (together, the "Service"), how we use it, who we share it with, and the choices you have. By using the Service, you agree to this Policy.
1. Who this policy applies to
This Policy applies to individuals who download, install, or use the PupGut app or visit our website. PupGut is intended for adults (18 years or older) who own or care for a dog. We do not knowingly collect personal information from children under 13, and the Service is not directed to children. See Children's privacy.
2. Information we collect
Information you provide
- Account information. Your email address (for magic-link sign-in), and, if you choose, your name and avatar via Sign in with Apple or Sign in with Google. Apple's Hide-My-Email relays are supported.
- Dog profile. Your dog's name, breed, age, weight, and similar details you choose to enter.
- Stool photos and scan data. Photos you capture or select for analysis, and the analysis results we generate from them (Bristol-style scores, color, hydration estimates, notes, dates).
- Community content. If you post, comment, like, hide, or report content in the in-app community feed, we store that content and your associated activity.
- Support communications. Messages you send to support@pupgut.app.
- Waitlist sign-up. If you join our waitlist on pupgut.app, we collect your email address.
Information collected automatically
- Device and usage data. Device model, OS version, app version, language, time zone, crash logs, and high-level usage events (e.g., "scan completed").
- Push notification token. If you opt in to notifications, Apple Push Notification service provides us a device token so we can send reminders and alerts.
- Log data. Standard server logs including IP address, timestamps, and request paths, retained for security and abuse prevention.
Information from third parties
- Apple / Google identity providers. When you use Sign in with Apple or Google, we receive a stable user ID and (if you allow) your email and name.
- RevenueCat. Subscription status, purchase history, and entitlement data tied to your anonymous app user ID. Apple is the merchant of record; we do not receive your credit card or App Store payment details.
What we do not collect
- We do not collect precise location.
- We do not sell your personal information.
- We do not use third-party advertising SDKs or cross-app tracking.
- Photos saved to your device's photo library remain on your device and are not transmitted unless you submit them as a scan.
3. How we use information
- To provide the core service: analyzing stool photos, generating health scores, and showing you trends over time.
- To create and secure your account and authenticate sign-in.
- To process subscriptions and entitlements via RevenueCat and Apple.
- To send transactional and reminder push notifications you've opted into.
- To operate the in-app community feed, moderate reported content, and enforce our Terms.
- To improve the AI scoring models, as described in Section 4 (User Content and AI training).
- To respond to support requests and communicate updates.
- To detect and prevent fraud, abuse, and security incidents.
- To comply with legal obligations.
4. User Content and AI training
Under the User Content license you grant in our Terms of Service, we may use the photos, dog profile information, notes, posts, and comments you submit ("User Content") to train, fine-tune, evaluate, and improve PupGut's AI models, classifiers, and related machine-learning systems, and to fine-tune third-party foundation models for use within the Service. When we send a scan to our AI inference provider (currently Anthropic), the provider processes it under our enterprise terms and does not use it to train its own models. We do not sell your User Content or license it to third parties for training their general-purpose AI models. Your statutory rights regarding this processing are described in Section 8 (Your rights and choices).
5. Legal bases (EEA / UK users)
If you are in the European Economic Area or United Kingdom, we process your personal information under these bases:
- Performance of a contract — to provide the Service you signed up for.
- Legitimate interests — to secure the Service, prevent abuse, and improve our models.
- Consent — for push notifications, optional marketing, and any sensitive processing where consent is required.
- Legal obligations — to respond to lawful requests and meet tax and accounting requirements.
6. How we share information
We share personal information only with the categories of recipients below, and only as needed to operate the Service:
| Recipient | Purpose | Data shared |
|---|---|---|
| Supabase (database, auth, storage) | Account, scan, and community storage | Account info, dog profiles, scans, photos, community content |
| Anthropic (AI inference) | Analyzing stool photos to produce health scores | Submitted scan photos and minimal metadata |
| Apple (App Store, Sign in with Apple, APNs) | App distribution, sign-in, push notifications | Apple ID, push tokens, purchase events |
| Google (Sign in with Google) | Sign-in | Google account ID and basic profile, if used |
| RevenueCat | Subscription management | Anonymous user ID, subscription state |
| Resend | Transactional and waitlist email | Email address, message content |
| Cloudflare | Website hosting, DDoS protection | IP address, request metadata |
We may also disclose information:
- To comply with law, court order, or lawful government request.
- To protect the rights, safety, or property of PupGut, our users, or the public.
- In connection with a merger, acquisition, financing, or sale of assets — in which case we will notify you and any successor will be bound by this Policy or an equivalent one.
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law.
7. Data retention
- Account, dog profile, and scan history: retained while your account is active. You can delete individual scans at any time.
- Community posts and comments: retained until you delete them or your account.
- If you delete your account, we delete or anonymize your personal information within 30 days, except where retention is required by law (e.g., tax records of paid subscriptions).
- Server logs: up to 90 days.
8. Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your account and associated personal information.
- Export a copy of your data in a portable format.
- Restrict or object to certain processing.
- Withdraw consent at any time.
- Lodge a complaint with a supervisory authority (EEA/UK).
California residents have specific rights under the CCPA/CPRA, including the right to know, delete, correct, and limit use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising. To exercise rights, email support@pupgut.app; you may also designate an authorized agent.
9. Deleting your data
You can delete your account directly from Settings → Account → Delete Account in the PupGut app, or by emailing support@pupgut.app. When you delete your account, we delete or anonymize your scans, dog profiles, community posts, and account record within 30 days. We may retain limited information where required by law (e.g., subscription records for tax purposes) or in encrypted backups that are rotated out within 90 days. We will respond to verifiable requests within the time required by applicable law (typically 30–45 days).
10. Security
We use industry-standard administrative, technical, and physical safeguards to protect personal information, including encryption in transit (TLS) and at rest, access controls, and least-privilege practices for our team. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
11. International transfers
PupGut is operated from the United States and your data is processed there. If you access the Service from outside the U.S., you consent to the transfer of your information to the U.S. and other jurisdictions where our service providers operate. Where required, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.
12. Children's privacy
PupGut is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, please contact support@pupgut.app and we will delete it.
13. Third-party links
The Service may contain links to third-party sites (e.g., veterinary resources). Their privacy practices are governed by their own policies, not this one.
14. Changes to this Policy
We may update this Policy from time to time. If we make material changes we will notify you in-app, by email, or by updating the "Last updated" date above. Continued use of the Service after the effective date constitutes acceptance of the revised Policy.
15. Contact us
PupGut
Attn: Privacy
Email: support@pupgut.app