feline-vitals-legal

Privacy Policy

App: FeliVitals
Effective Date: September 17, 2026
Version: 3.1.0


The Short Version (TL;DR)


1. Who We Are

FeliVitals (the “App”) is an independent mobile application for iOS and Android, built to help cat owners manage chronic health conditions, including Chronic Kidney Disease (CKD). It is developed and maintained by:

Wojciech Grygo
Email: grygo.wojtek@gmail.com


2. Information We Handle

A. Data Stored Locally on Your Device

Health records you enter are saved to your device’s internal storage using a SQLite database. This includes:

If you do not sign in, these records are not synced to FeliVitals cloud storage. The optional lab-report scanner described in Section 2B is the exception: only a report you deliberately select for scanning is sent for processing.

Your local data may also be included in your device’s system backup:

These backups are controlled by Apple or Google and are subject to their policies.

B. Optional AI Lab-Report Scanning

When you select Scan photo or PDF, the App sends the selected veterinary laboratory report through an encrypted connection to a protected Firebase Cloud Function and then to Google Cloud Vertex AI. This can happen whether or not you have signed in with Apple or Google.

The scan is used only to extract supported laboratory fields into a structured draft. It does not provide a diagnosis, treatment recommendation, or medical advice.

The report may contain information visible in the document, including:

How FeliVitals handles the report:

Technical and usage data: To secure the service and enforce free and Pro limits, FeliVitals stores limited operational data. This may include a pseudonymous Firebase user ID, a hashed installation or subscription-owner identifier, scan status, timestamps, and usage counters. It does not include the source report or extracted laboratory values. Short-lived scan reservation records expire after processing and are removed by scheduled cleanup. Usage counters are retained while needed to enforce limits and prevent abuse.

Google Cloud processing: The Cloud Function runs in us-central1, and model processing uses Google’s us multi-region. Google states that customer data is not used to train or fine-tune its AI models without the customer’s permission or instruction. Under Google’s standard abuse-monitoring rules, a prompt flagged by automated safety systems may be stored securely for up to 90 days in the selected region or multi-region and reviewed by authorised Google personnel. Such data is not used to train or fine-tune AI models. See Google Cloud AI data retention and Google Cloud abuse monitoring.

C. Cloud Account Data for Signed-In Users

When you sign in with Apple or Google, the App creates an account and syncs your health records to Firebase Firestore. This enables cloud backup, device restore, and household sharing.

Firebase Firestore may store:

Firebase Authentication may store:

Household sharing: If you join a shared household, other members can view and add records for cats in that household. The household owner controls membership and can remove members.

D. Anonymous Analytics

If you enable analytics under Settings → Analytics, the App sends aggregate usage events to Firebase Analytics. Analytics is disabled by default.

Example events include:

Analytics events do not contain cat names, notes, medication names, laboratory values, report files, diagnoses, or other health-record contents.

You can disable analytics at any time in Settings. Events collected before you disable analytics may remain according to Google’s retention rules.

E. Crash Reporting

If you give consent in the App, Firebase Crashlytics collects technical crash information, such as:

Crash reporting is disabled before consent. Reports must not include health records, report files, extracted laboratory values, or free-text notes.

F. Subscriptions and Payments

Purchases are processed by the Apple App Store or Google Play Store. FeliVitals uses RevenueCat to verify subscription status.

See the RevenueCat Privacy Policy.

G. Notifications

If you create reminders, the App uses device notification services to deliver them. Notification data is not used for advertising and is not logged on FeliVitals servers.

H. Security and App Attestation

FeliVitals uses Firebase App Check, Apple App Attest or DeviceCheck, and Google Play Integrity to help confirm that protected requests come from a genuine copy of the App. These services may process technical device, app, and attestation information. FeliVitals uses this information only for security and abuse prevention.


3. Trusted Service Providers

Service Purpose Privacy information
Firebase Firestore (Google) Optional cloud storage and OCR usage limits Google Privacy
Firebase Authentication (Google) Signed-in accounts and pseudonymous authentication for protected services Google Privacy
Firebase Cloud Functions (Google) Secure server-side processing for features including lab scanning Google Cloud Privacy
Vertex AI (Google Cloud) AI-assisted extraction from user-selected lab reports Google Cloud AI data retention
Firebase App Check / Apple App Attest / Google Play Integrity App attestation, security, and abuse prevention Google Privacy
Firebase Analytics (Google) Opt-in aggregate usage analytics Google Privacy
Firebase Crashlytics (Google) Opt-in technical crash reports Google Privacy
RevenueCat Subscription verification and standard Apple Ads attribution on iOS RevenueCat Privacy
Apple Sign In Authentication for Apple users Apple Privacy
Google Sign In Authentication for Google users Google Privacy
Apple App Store App distribution and iOS payment processing Apple Privacy
Google Play Store App distribution and Android payment processing Google Privacy

Google’s processing of customer data is also governed by the Google Cloud Data Processing Addendum.


4. Data Retention and Deletion

You can control or delete your data as follows:

  1. Delete a cat profile: Use Profile → Edit → Delete Profile. This removes records associated with that cat locally and, if signed in, from cloud sync.
  2. Delete your account: Use Profile → Account → Delete Account. This deletes your Firebase account and cloud health records managed by FeliVitals. Limited records that must be retained for security, subscription verification, fraud prevention, or legal obligations may remain for the required period.
  3. Delete local data: Uninstalling the App removes its local database. Copies may remain in iCloud or Android system backups according to Apple or Google’s retention rules. If you are signed in, uninstalling alone does not delete cloud data.
  4. Delete saved OCR results: AI-extracted values are ordinary lab records after you save them. Delete the relevant lab record or cat profile to remove them.
  5. Source reports: FeliVitals does not permanently store source photos or PDFs used for scanning, so there is no FeliVitals copy to delete after processing. Google may retain a report flagged by abuse-monitoring systems for up to 90 days as described in Section 2B.
  6. OCR usage data: Pseudonymous quota and security records may remain after a scan to enforce limits and prevent abuse. You may request deletion by email, subject to records that must be retained for fraud prevention or legal obligations.
  7. Disable analytics and crash reporting: Change your choice in Settings to stop future collection.
  8. Request assistance: Email grygo.wojtek@gmail.com to request access, correction, deletion, or an export of data associated with your account.

5. Children’s Privacy

FeliVitals is not directed at children under 13, or under 16 in the European Economic Area. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can review and remove it where required.


European Union and European Economic Area

Depending on the feature, FeliVitals relies on the following legal bases under the GDPR:

You may have rights to access, correct, delete, restrict, object to processing, and receive a portable copy of your personal data. You may also withdraw consent and lodge a complaint with your local data-protection authority.

To exercise these rights, email grygo.wojtek@gmail.com. We may need to verify your identity before completing a request.

International Transfers

Cloud processing may transfer data outside your country, including to the United States. The OCR Cloud Function runs in us-central1, and Vertex AI uses Google’s us multi-region. Google states that international transfers are protected through its contractual and legal safeguards, including applicable Standard Contractual Clauses. See the Google Cloud Data Processing Addendum.

California

FeliVitals does not sell personal information or share it with third parties for their own cross-context behavioural advertising. California residents may contact us to request access, correction, or deletion where applicable.


7. Security

FeliVitals uses measures including encrypted network connections, Firebase security rules, authentication, app attestation, restricted service accounts, and access controls. No system is completely secure, but we work to reduce unauthorised access, disclosure, alteration, and loss.


8. Changes to This Policy

If we materially change this Privacy Policy, we will update the Effective Date and version above. Where required, we will also provide an in-app notice or request new consent.


9. Contact

Questions, requests, or concerns about privacy:

Wojciech Grygo
Email: grygo.wojtek@gmail.com