Legal

Privacy policy

Last updated .

The short version

  • We collect what the product needs to work, and not more.
  • We do not sell your data, and we do not share it with insurers or advertisers.
  • There are no advertising SDKs, no third-party analytics, and no crash-reporting services in the app. Nothing about your use of it is streamed to anyone.
  • The free plan shows sponsored links. We do not hand the merchants behind them your identity or any record — see Sponsored links.
  • Our servers are in the United States. If you are in the UK or the EU, that is a transfer, and how it is protected is set out below.
  • You can export everything, at any time, on any plan, at no cost.
  • You can have it all erased, and erasure is real.

The rest of this page is the detail behind those statements.

Who we are

PetHealth Pro is operated by Black Elephant Holdings LLC. We are the data controller for the information described here. Contact privacy@thinkpethealth.com for anything covered by this policy.

What we collect

Information you give us

  • Account details — your email address, your display name, and a hashed password or an enrolled passkey. We never store a password in a form we can read.
  • Animal records — everything you enter about your animals: identity, species and breed, medical history, medications and doses, vaccinations, weight, food, allergies, veterinary practice and insurance details, and emergency contacts.
  • Documents you upload — the file itself, and the text extracted from it so that it can be searched.
  • People you share with — the email address you invite, and the permissions you grant them.
  • Messages to the assistant — what you ask, and the record context used to answer it.

Information we generate

  • An audit trail of who accessed and changed which records, which exists so that you can see it.
  • Session and security records — sign-in times, device and approximate location for a session, and refresh-token bookkeeping used to detect a stolen session.
  • Operational logs — errors and request timings, retained briefly and used to keep the service working.

Information we do not collect

  • No advertising identifiers, no ad networks, and no ad SDKs. The sponsored links on the free plan are described in Sponsored links; nothing third-party runs in the app to serve them.
  • No third-party analytics, and no cross-site or cross-app tracking.
  • No third-party crash-reporting or error-monitoring service. The app streams nothing about a session, a screen or an error to anyone.
  • No profile of you for marketing.
  • No contacts, no calendar, and no photos beyond the pictures you deliberately add to a record.

Your location

The emergency card has a “where am I” button, for reading a coordinate to an out-of-hours vet over the phone. Tapping it asks the device for your location and shows it to you on that screen. The coordinate is not sent to us, not stored, and not attached to any record. Nothing about your location is collected in the background or included in any request the app makes. The app also notes an approximate city-level location for each sign-in, derived from your IP address, as a security signal — that is the only location data we hold.

Why we are allowed to hold it

  • Performing our contract with you — your account, your animals’ records, sharing, reminders, and billing. Without these the product does not exist.
  • Our legitimate interests — security, fraud prevention, abuse handling, and keeping the service running and debuggable.
  • Your consent — the tips-and-offers newsletter, if you opted in at sign-up or in Settings. Every one of those emails has an unsubscribe link, and you can also turn it off in the app; doing so affects nothing else. Reminders about your animals are not this — they are part of the service, not marketing.
  • Legal obligation — retaining invoices and tax records for the period the law requires.

Records about an animal are not personal data about a person in the ordinary case. We nonetheless treat them as confidential, because they are yours and because they often contain your name, address and practice details.

Who we share it with

Only the processors we need in order to operate, each under a contract that restricts them to acting on our instructions:

  • Cloud hosting and managed database — our application servers and PostgreSQL database, run by our infrastructure provider in its United States (Northern Virginia) region.
  • Object storage — the provider that holds the files you upload, in a United States region.
  • Payments — Stripe, and Apple or Google if you subscribed in an app store. Card details go straight to the payment processor and never reach our servers; we hold only a customer identifier and your subscription status.
  • Email delivery — the provider that sends reminders, verification links and receipts.
  • The assistant’s model provider — Anthropic, in the United States, and only if you use the assistant. The question you ask and the relevant record context are sent to generate the answer. Under our commercial terms with Anthropic that content is not used to train models, and we do not store the conversation on our servers.

Each of these acts only on our instructions under a written data-processing agreement. We do not sell personal information and we do not share it for advertising. We share with nobody else, unless we are legally compelled to, in which case we will tell you where we are permitted to.

Where it is stored

On servers in the United States (Northern Virginia), with encrypted backups in the same region. Uploaded files travel from your browser directly to object storage using a short-lived signed URL, and do not pass through our application servers.

International transfers

If you are in the United Kingdom or the European Economic Area, using PetHealth Pro involves transferring your personal data to the United States. We rely on the UK International Data Transfer Addendum and the European Commission’s Standard Contractual Clauses with each processor that receives it, together with the technical measures described in How it is kept separate and encryption in transit and at rest. You can ask us for more detail at privacy@thinkpethealth.com.

On the free plan, some screens show a single sponsored card — a product link from a retail partner, always labelled Sponsored. Paid plans never see one.

  • There is no ad network and no ad SDK. Nothing third-party runs in the app. Which card to show is chosen on our own server.
  • No advertising identifier is read, and no profile is built for targeting.
  • If you follow a sponsored link we record that the click happened, which product it was, and whether it later resulted in a purchase, so the commission can be attributed to us. The retail partner receives an opaque click reference only — never your email address, your name, or anything about an animal or its records. Once you are on the partner’s site, their own privacy policy applies.

How it is kept separate

Every household’s records are separated by PostgreSQL row-level security, one layer below the application. Requests run in a transaction tagged with the signed-in identity, and the database filters every table by it. A mistake in our application code cannot return another household’s rows, because the rows are never returned to it. This is verified against a live database on every build.

How long we keep it

  • Your records — for as long as your account exists.
  • After you delete your account — erasure is scheduled with a grace window so an accidental deletion can be undone. When the window closes, records are erased and drop out of backups as those backups age out.
  • Invoices — for the period tax law requires, regardless of account deletion.
  • Security and audit logs — a limited period, then discarded.

Your rights

Under the UK GDPR and the EU GDPR you may ask for access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interests.

  • Access and portability are self-service — Settings → Export, on every plan including Free, as often as you like, at no charge.
  • Erasure is self-service — Settings → Account → Delete.
  • Everything else — write to privacy@thinkpethealth.com. We reply within 30 days and usually much sooner.

If you are unhappy with how we have handled a request you can complain to your national supervisory authority — in the UK, the Information Commissioner’s Office.

Cookies

This marketing site sets no cookies and runs no analytics. The application sets only what is strictly necessary to keep you signed in and to protect the session. There is no consent banner because there is nothing to consent to.

Children

The service is not directed at children under 16. If you believe a child has created an account, tell us and we will remove it.

Changes

If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.


Questions: privacy@thinkpethealth.com · Security reports: security@thinkpethealth.com