zapurr

Zapurr Privacy Policy

Last updated — 2026-07-04

Zapurr ("we", "our", "the app") is a pet care app for iOS. This policy describes what information we collect, why, who we share it with, and how you can control it.

What we collect

CategoryExamplesWhy
AccountEmail address, authentication ID, optional nameSign in, account recovery, account deletion
Pet & household dataPet name, species, breed, photos, weight, health logs, vet records, medications, behavior incidents, journal entriesThe core service — these are the records the app exists to maintain
Contact detailsOptional phone, email, or preferred contact method for pet tags, emergency contacts, lost-pet alerts, sitters, and donor coordinationLet people you choose contact you or coordinate pet safety features
LocationUser-chosen map points for lost pets, stray reports, playdates, and vet search; coarsened/fuzzed location for nearby routing and donor matchingShow nearby pet-safety features and notify you of nearby alerts
Push notification tokenApple-issued device tokenDeliver feeding reminders, medication reminders, and alerts you've opted into
DiagnosticsCrash reports and performance diagnosticsDetect and fix bugs
PurchasesZapurr Pro subscription status and purchase history from RevenueCat/App StoreUnlock paid features and support purchase restore

We do not collect: precise GPS history, microphone recordings without your explicit prompt (voice features only run while you hold the mic), device contacts, calendar, photos outside the ones you choose or preview locally, ad-tracking identifiers (IDFA), or data from other apps.

Where it lives

  • On your device: SwiftData (local database) and the iOS keychain.
  • In the cloud (Supabase): pet records, photos, health logs, and the data needed to deliver shared features (households, lost pet alerts, stray map). Encrypted at rest. Row-level security ensures only you and members of your household can read your data.
  • Anthropic: the contents of your in-app Assistant messages and the photos/text you choose to submit to AI features like Spot Check or Body Scan are sent to Anthropic to generate replies. Anthropic does not retain or train on this data per their API terms.
  • Apple: push notifications are delivered through APNs; APNs sees the notification payload (e.g. "Feed Luna at 6pm") but no health-record contents.
  • Sitter Mode share links: when you generate a Sitter Mode link, a time-boxed token (max 30 days) lets a sitter you choose view a read-only page of your pets' feeding, medication, vet, and emergency contact info, and mark medication doses as given. Anyone holding the link can see what you scoped into it until it expires or you revoke it. Tokens never include your email address or owner identity. Sitter page access is rate-limited and revocations take effect immediately for the sitter's next interaction.
  • Food recall data (FDA): we sync the public FDA pet-food recall feed nightly into our database; if you scan and subscribe a pet to a product, we send you a push notification when that product is later recalled. Scans you don't subscribe to are not stored.

What we do not do

  • We do not sell your data.
  • We do not share your data with advertisers.
  • We do not use your data to train AI models.
  • We do not track precise GPS history. When you create a map-based report or playdate, the point you choose may be stored and shown as part of that feature. Nearby routing uses coarsened or fuzzed location where possible.

Your rights

  • See your data: Settings → Privacy & Data → Export My Data. Generates a complete JSON archive of everything we hold for you.
  • Delete your account: Settings → Privacy & Data → Delete Account. Removes your account, all pet data, all photos, and your authentication record within 30 days. Action is irreversible.
  • Opt out of any push notification category: Settings → Privacy → Notifications.

If you live in the EU/UK (GDPR), California (CCPA), or any jurisdiction with similar law, the rights above satisfy the right to access, portability, and erasure. To exercise any other right (rectification, restriction, objection), email jhonkenrick28@gmail.com.

Children

Zapurr is not directed to children under 13 and we do not knowingly collect data from them. If you believe a child has created an account, email jhonkenrick28@gmail.com and we will delete it.

Security

  • All network traffic uses TLS 1.2+.
  • Data at rest in Supabase is encrypted (AES-256).
  • Authentication is enforced by Supabase Auth (PKCE flow).
  • Row-level security policies are in place on every user-data table; a user cannot read or modify another user's data.

We follow Apple's App Store Review Guidelines and the iOS Data Protection APIs. No security system is perfect, but if we discover a breach affecting you, we will notify you within 72 hours.

Changes

If we change this policy materially, we will notify you in-app before the change takes effect.

Contact

  • jhonkenrick28@gmail.com
  • For data requests: jhonkenrick28@gmail.com
zapurrPrivacyTermsContact© 2026