Privacy Policy

Effective date: 06/01/2026 ·  Last updated: 06/01/2026

PawVitals is a logging and organizing tool, not a medical device, and does not provide veterinary advice, diagnosis, dosing, or treatment recommendations. Any target ranges shown were entered by you from your veterinarian. Always consult your veterinarian for medical decisions. In an emergency, contact your veterinarian or an emergency animal hospital.

This Privacy Policy explains how Appsgenx Inc (also "PawVitals," "we," "us," or "our") collects, uses, discloses, retains, and protects information in connection with the PawVitals mobile application (the "App"), the PawVitals website at which this policy is published (the "Site"), and related services (together, the "Services"). It also describes the choices and rights you have.

PawVitals is built privacy-first and local-first: the pet health information you enter is stored, encrypted, on your device, and you do not need to create an account to use the core features. This policy is written to be read alongside our Terms of Service. Where the Terms and this Privacy Policy address the same subject, this Privacy Policy governs how we handle your information.

Your quick controls

1. Introduction, scope & acceptance

1.1 Purpose of this policy

This policy tells you, in plain language and in precise legal terms, what personal information the Services process, why we process it, the legal bases we rely on where applicable, with whom we share it, how long we keep it, how we protect it, and the controls and rights available to you. We have tried to keep the plain-language summary at the top of each topic and the detail below it.

1.2 Scope

This policy applies to:

This policy does not apply to third-party services you access through the Services (for example, the Apple App Store or Google Play), which are governed by their own privacy policies. See Section 20.

1.3 Who this applies to

This policy applies to everyone who uses the Services: local-only users who never create an account, users who opt into cloud features, members of a shared household, and visitors to the Site. Because PawVitals records information about pets, the "personal data" the Services process is primarily about you (the human user) — for example your account email if you create one, your device information, and your usage of the App. Information about a pet is generally not "personal data" about a human, but we treat the health logs you enter as sensitive and protect them accordingly (see Section 19).

1.4 Acceptance

By downloading, installing, or using the Services, you acknowledge that you have read and understood this policy. Where we rely on your consent (for example, for optional AI, analytics, or cloud features), we will ask for that consent separately and you may withdraw it at any time. If you do not agree with this policy, please do not use the Services.

↑ Back to top

2. Definitions

Some terms are used throughout this policy with the meanings below. Where a term is defined by an applicable law (for example, the GDPR or the CCPA/CPRA), that legal definition controls for the purposes of that law.

TermMeaning
Personal data / personal informationAny information relating to an identified or identifiable natural person (or, under some US laws, a consumer or household). Examples: an account email, a device identifier, or pseudonymous usage identifiers.
Sensitive / special-category dataCategories that many laws protect more strictly, such as health information. Pet health logs are not "health data about a human," but we treat them as sensitive as a matter of policy.
ProcessingAny operation performed on personal data, such as collecting, storing, using, transmitting, disclosing, or deleting it.
ControllerThe entity that determines the purposes and means of processing personal data. For the Services, the controller is Appsgenx Inc (see Section 3).
Processor / service provider / subprocessorA party that processes personal data on the controller's behalf and under its instructions (for example, our hosting provider). "Service provider" and "contractor" are the equivalent CCPA/CPRA terms.
De-identified dataData processed so that it can no longer reasonably be linked to a specific person, and which we do not attempt to re-identify.
Pseudonymous dataData that cannot be attributed to a specific person without additional information kept separately (for example, a random app-install identifier not tied to your name).
ConsentA freely given, specific, informed, and unambiguous indication of your agreement to processing.
Local-firstAn architecture in which your data is created and stored primarily on your own device rather than on our servers.
Sale / share (US laws)Under some US state laws, "sale" means disclosing personal information for monetary or other valuable consideration, and "share" (California) means disclosing it for cross-context behavioral advertising. We do neither.
Services, App, SiteAs defined at the top of this policy.

↑ Back to top

3. Who we are (data controller)

The data controller responsible for the Services is:

ControllerAppsgenx Inc (trading as PawVitals)
AddressUnited States
Privacy contactappsgenx@gmail.com
General supportappsgenx@gmail.com (currently appsgenx@gmail.com)
Data Protection OfficerNot appointed; contact appsgenx@gmail.com — appointed only if legally required or voluntarily; if not appointed, use the privacy contact above.
EU representative (Art. 27 GDPR)Not currently appointed — if applicable.
UK representativeNot currently appointed — if applicable.

Where PawVitals acts as a processor on your behalf — for example, when it stores the pet records you choose to back up — the relevant service providers listed in Section 10 act as our subprocessors.

↑ Back to top

4. Information we collect

We collect only what is needed to provide, secure, and improve the Services. Much of it never leaves your device. The tables below describe each category, examples, whether it is stored locally or in the cloud, and whether it is optional.

4.1 (a) Information you provide

CategoryExamplesWhere storedOptional?
Pet profilesPet name, species, breed, sex, neuter status, birthdate, baseline weight, color tag, photo, microchip number, and the vet/emergency contacts you enter (vet name, phone, email)On your device (encrypted); cloud only if you opt into backupRequired to use core features; individual fields optional
Condition & health logsConditions/playbooks (diabetes, CKD, seizures, arthritis, general), medications and doses, readings (glucose, weight, blood pressure, temperature, etc.), fluid logs, seizure events and timers, appetite, quality-of-life (QoL) assessments, vet-provided target ranges you enter, and notesOn your device (encrypted); cloud only with backupYou choose what to log
Vault documents & mediaPhotos and files you add — labs, vaccine records, prescriptions, insurance, and other documents; optional on-device OCR text extracted to make them searchableOn your device (encrypted); cloud only with backupOptional
Account information (cloud only)Email address (for magic-link sign-in) or an Apple/Google sign-in identifier; household/caregiver invitations you send or acceptCloud (our auth provider)Only if you create an account
CommunicationsThe content of emails or support requests you send usOur email/support systemsOnly if you contact us
Preferences & settingsUnits (glucose, weight, fluid), locale, reminder settings, and feature toggles (e.g., AI on/off, analytics on/off)On your device; cloud only with backup

4.2 (b) Information collected automatically

CategoryExamplesPurposeOptional?
Device & technical dataDevice model, operating system and version, App version, language/region, screen and locale settings, and coarse technical attributes needed for compatibilityRun the App, fix bugsSome is inherent to running an app
Pseudonymous identifiersA random install/app-user identifier used for subscription entitlement and, if enabled, for de-duplicating analytics or crash events. Not your name.Subscriptions; diagnosticsAnalytics/crash identifiers are optional
Usage & analytics eventsIf you leave analytics on: pseudonymous events such as screens viewed, features used, and error states — with no pet health valuesUnderstand usage, improve the AppOptional (opt-out)
Crash & diagnostic dataCrash stack traces, device state at crash time, and diagnostic logsDiagnose and fix crashesOptional where controllable; platform-level crash reporting may also apply
Approximate technical/location dataCoarse region inferred from device/store settings or IP at the network layer of a request. We do not collect precise GPS location.Localization, security

4.3 (c) Information from third parties

SourceWhat we receiveWhy
Apple App Store / Google Play (via RevenueCat)Subscription status (trial, active, expired), product identifier, renewal flag, and store — never your full payment card numberTo grant and manage your subscription entitlement
Apple / Google sign-in (if you use it)A sign-in identifier and, where you permit, your emailTo create/authenticate your optional account

4.4 What we do NOT collect

↑ Back to top

5. How we collect information

5.1 Directly from you

Most information is collected directly from you when you enter pet profiles and health logs, add vault documents, create an optional account, adjust settings, or contact us.

5.2 Automatically through the App

When you use the App, limited technical and (if enabled) analytics or crash data is generated automatically through software components and SDKs described in Section 6.

5.3 From third parties

We receive subscription status from the app stores through RevenueCat, and — if you use third-party sign-in — an identifier from Apple or Google, as described in Section 4.3.

↑ Back to top

6. Cookies, SDKs & similar technologies

6.1 In the mobile App

The App does not use advertising cookies. It relies on the following on-device and network technologies:

Technology / SDKProviderFunctionOptional?
Encrypted local database (SQLCipher via op-sqlite)On-deviceStores your pet records encrypted at restCore
Secure key storage (expo-secure-store)On-device (Keychain / Keystore)Stores encryption keys in the device's secure hardware where availableCore
Subscriptions SDK (RevenueCat)RevenueCat + app storesManages trial and subscription entitlementCore to paid use
AI proxy callsOur secure server → AnthropicGenerates optional AI summaries from minimal, de-identified dataOpt-in
Self-hosted analyticsOur own database (Supabase)Pseudonymous usage/diagnostic events; no third-party analytics processorOpt-out
Crash reporting (Firebase Crashlytics)GoogleCaptures crash diagnostics; platform crash reporting (Apple/Google) may also applyOpt-out where controllable

6.2 On the website

The Site is a set of static informational pages and uses only what is strictly necessary to serve those pages. It does not set advertising or cross-site tracking cookies. Your browser and our hosting provider may process standard technical request data (such as IP address) to deliver and secure the pages.

↑ Back to top

7. How and why we use information

We use information for the purposes below. We do not use it for purposes that are incompatible with those for which it was collected without providing notice or, where required, obtaining consent.

PurposeWhat this involvesData used
Provide core featuresLogging, trends and charts, reminders, seizure timer, vault, vet-brief generationInformation you provide; on-device technical data
Optional AI summariesGenerate plain-language summaries and suggested questions for your vetMinimal, de-identified structured logs (see Section 9)
Manage subscriptionsStart trials, grant/renew entitlement, restore purchasesSubscription status; pseudonymous identifier
Optional cloud featuresAccount authentication, cloud backup, family/household sharingAccount email/identifier; backed-up records
Reliability & improvementDiagnose crashes and understand feature usage in aggregateOptional analytics and crash diagnostics
Security & fraud preventionProtect the Services and detect misuseTechnical data; account data
Support & communicationsRespond to your requests and send essential service messagesCommunications; account/contact data
Legal & complianceMeet legal obligations and enforce our TermsAs necessary

↑ Back to top

8. Legal bases for processing (GDPR / UK GDPR)

If you are in the European Economic Area (EEA), the United Kingdom, or another region with similar law, we rely on one or more of the following legal bases for each purpose.

PurposeLegal basis
Providing core App features you requestPerformance of a contract (Art. 6(1)(b)); legitimate interests where no contract exists (Art. 6(1)(f))
Managing subscriptions and trialsPerformance of a contract (Art. 6(1)(b))
Optional AI featuresConsent (Art. 6(1)(a)) — you turn AI on
Optional cloud backup / accounts / sharingConsent and/or performance of a contract (Art. 6(1)(a)/(b))
Optional analytics and crash reportingConsent (Art. 6(1)(a)) where required, otherwise legitimate interests (Art. 6(1)(f)) in maintaining and improving the Services
Security and fraud preventionLegitimate interests (Art. 6(1)(f))
Legal complianceLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to such processing (see Section 15). Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.

↑ Back to top

9. AI features & automated processing

AI features are optional and opt-in. When switched off, summaries are generated locally from templates and no data is sent for AI processing.

9.1 What is sent, and what is stripped

When you enable AI and request a summary or suggested questions, the App sends a minimal, de-identified, structured extract of the relevant numbers — for example, a short window of recent readings and the pet's first name — to our AI processor, Anthropic (Claude), through a secure server we operate (a proxy) so that the AI provider's API key is never shipped in the App. Before any AI request, we strip out:

9.2 Data minimization and no model training

We send only what is necessary to produce a useful summary. Based on the AI provider's applicable API terms, data submitted through the API is not used to train the provider's models. Anthropic acts as our processor for this purpose and is bound by contractual confidentiality and security obligations.

9.3 No solely-automated decisions with legal or similarly significant effects

AI outputs are informational aids. They do not make decisions that produce legal or similarly significant effects about you, and they are not veterinary advice, diagnosis, dosing, or treatment. You remain responsible for all care decisions, which you should make with your veterinarian. You can disable AI at any time in Settings.

↑ Back to top

10. How we share and disclose information

We do not sell your personal information and do not share it for cross-context behavioral advertising. We disclose information only as described here.

10.1 Service providers / subprocessors

We use the following providers to run the Services. They process data on our behalf, under contract, and only as needed for the stated purpose.

ProviderPurposeData involvedLocationSafeguards
SupabaseDatabase, storage, authentication, and functions for optional cloud features and the AI proxy; self-hosted analytics storeBacked-up records (if you opt in); account data; pseudonymous analytics eventsUnited States (us-east-1)Row-level security; encryption in transit; access controls; contractual terms
AnthropicAI summaries and suggested questionsMinimal de-identified structured logs (Section 9)United StatesProcessor terms; no model training; data-transfer safeguards
Apple / Google + RevenueCatSubscription purchase and entitlement managementSubscription status; pseudonymous identifier (no full card details)United States / globalStore and processor terms; standard contractual protections
Firebase Crashlytics (Google)Crash reporting and diagnosticsCrash traces and device state; pseudonymous identifierUnited States / globalGoogle data-processing terms; transfer safeguards

This list may change as the Services evolve. We keep an up-to-date list and will update this policy when we add or change a material subprocessor.

10.2 Legal and compliance disclosures

We may disclose information if we believe in good faith that it is necessary to comply with a law, regulation, legal process, or enforceable governmental request; to enforce our Terms; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of PawVitals, our users, or the public. Because your health logs are stored locally and encrypted, in most cases we do not have access to them.

10.3 Business transfers

If PawVitals is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction. We will require the recipient to honor this policy or provide notice and choices consistent with applicable law.

10.4 Aggregated or de-identified data

We may create and use aggregated or de-identified data (which cannot reasonably identify you) for analytics, research, and improving the Services. We will not attempt to re-identify such data except to test de-identification.

10.5 With your consent or at your direction

We share information in other ways when you ask us to — for example, when you invite a caregiver to a shared household, or when you export and send your own vet brief.

10.6 No sale; no cross-context behavioral advertising

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under US state privacy laws.

↑ Back to top

11. International data transfers

Your local data stays on your device. When you use optional cloud, AI, subscription, or crash-reporting features, limited data may be processed in countries other than yours, including the United States, which may have different data-protection laws than your home country.

Where we transfer personal data out of the EEA, the UK, or Switzerland to a country not subject to an adequacy decision, we use appropriate safeguards, including:

You may request a copy of the relevant safeguard by contacting us (Section 24).

↑ Back to top

12. Data retention

We keep personal data only as long as necessary for the purposes described in this policy, to comply with legal obligations, to resolve disputes, and to enforce our agreements. Because the App is local-first, most of your data is retained on your device under your control.

CategoryRetention
Local pet records (profiles, logs, vault)Stored on your device until you delete them in the App or uninstall the App
Cloud backup (if enabled)Retained until you delete it or close your account; after deletion, residual copies are purged within about 30 days
Account data (if you create an account)Retained for the life of the account; deleted on account closure subject to legal holds
Raw analytics eventsAuto-purged after approximately 7 days; only aggregated, non-identifying statistics are retained afterward
Crash diagnosticsRetained for a limited period consistent with the crash-reporting provider's defaults, then deleted or aggregated
Subscription statusRetained while your entitlement is active and for a limited period thereafter for accounting, support, and legal purposes
AI request dataSent only at request time; not retained by us for training; subject to the AI provider's limited operational retention
Support communicationsRetained as long as needed to handle your request and for a reasonable follow-up period
Legal holdsWhere required, data may be retained longer to comply with law or preserve evidence

↑ Back to top

13. Security

We design the Services to minimize what leaves your device and to protect what remains. Measures include:

We maintain a commitment to notify affected users and, where required, regulators of a personal-data breach in accordance with applicable law (see Section 22).

Honest limitation. No method of transmission or storage is 100% secure. We cannot guarantee absolute security, and you are responsible for safeguarding your device (screen lock, OS updates, and, if used, your account credentials).

↑ Back to top

14. Your privacy rights (general)

Depending on where you live, you may have some or all of the following rights. Many of them you can exercise yourself directly in the App.

14.1 How to exercise your rights

Use the in-App controls for export, correction, and deletion. For requests we must handle for you, email appsgenx@gmail.com or write to By email: appsgenx@gmail.com. We will respond within the timeframe required by applicable law (generally within 30 to 45 days, extendable where permitted, with notice).

14.2 Verification

To protect your data, we may need to verify your identity before acting on a request — for example, by confirming control of the account email. We ask only for information reasonably necessary to verify you. Because local data is under your own control, most verification is unnecessary for on-device actions.

14.3 Authorized agents

You may use an authorized agent to submit certain requests where the law allows. We may require proof of the agent's authorization and, where permitted, verification of your identity.

↑ Back to top

15. EEA & UK rights (GDPR / UK GDPR)

If you are in the EEA or the UK, in addition to the rights above you have the rights to access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time.

15.1 Right to lodge a complaint

You have the right to lodge a complaint with your local supervisory authority. In the EEA this is your national data-protection authority; in the UK it is the Information Commissioner's Office (ICO). We would appreciate the chance to address your concern first — please contact us at appsgenx@gmail.com.

15.2 Representative

Where required, our EU representative is Not currently appointed and our UK representative is Not currently appointed.

↑ Back to top

16. United States state privacy rights

16.1 California (CCPA / CPRA)

If you are a California resident, you have rights regarding your personal information.

Notice at collection. The categories of personal information we may collect are: identifiers (e.g., account email, pseudonymous identifiers); internet/network activity (usage and diagnostic events); device/technical information; commercial information (subscription status); and the contents of communications you send us. We collect these for the business purposes in Section 7. We retain them as described in Section 12.

Sensitive personal information. We do not seek to collect sensitive personal information as defined by the CPRA, and we do not use or disclose any such information for purposes that would trigger the right to limit its use. Pet health logs are not personal information about a human, but we treat them as sensitive (Section 19).

Do not sell or share. We do not sell personal information and do not share it for cross-context behavioral advertising. There is therefore no "Do Not Sell or Share My Personal Information" mechanism to invoke, but we honor opt-out preference signals such as Global Privacy Control (Section 21) as a do-not-sell/share signal.

Your California rights. To know/access, to delete, to correct, to opt out of sale/share (not applicable, as above), and to limit use of sensitive personal information (not applicable, as above). We will not discriminate against you for exercising these rights.

Shine the Light. California Civil Code § 1798.83 lets California residents request information about disclosures to third parties for their direct marketing. We do not disclose personal information to third parties for their direct marketing.

Authorized agents and appeals. You may use an authorized agent (Section 14.3). If we deny a request, you may appeal by replying to our decision or emailing appsgenx@gmail.com with "Appeal" in the subject line.

16.2 Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana & other states

If you are a resident of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), or another US state with a comparable consumer privacy law, you may have rights to:

How to exercise and appeal. Submit requests as described in Section 14.1. If we decline, you may appeal within a reasonable time by emailing appsgenx@gmail.com. If your appeal is denied, you may contact your state Attorney General. We honor recognized universal opt-out mechanisms such as Global Privacy Control where applicable (Section 21).

↑ Back to top

17. Other jurisdictions

17.1 Canada (PIPEDA)

We handle personal information in a manner consistent with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws, including obtaining consent where appropriate, limiting collection, and providing access and correction. You may complain to the Office of the Privacy Commissioner of Canada.

17.2 Australia (Privacy Act / APPs)

We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth), including openness, access, and correction. You may complain to the Office of the Australian Information Commissioner (OAIC).

17.3 Brazil (LGPD)

If you are in Brazil, we process personal data consistent with the Lei Geral de Proteção de Dados (LGPD), including rights of confirmation, access, correction, anonymization, portability, deletion, and information about sharing. You may contact the Autoridade Nacional de Proteção de Dados (ANPD).

17.4 Residents elsewhere

If you are in a jurisdiction with its own data-protection law not specifically named here, you may have additional rights. Contact us and we will honor rights that apply to you under applicable law.

↑ Back to top

18. Children's privacy

The Services are intended for adults managing pet care and are not directed to children. We do not knowingly collect personal information from children under 18 years of age. (Choose 16 to align with the higher GDPR default, or 13 to align with the US COPPA threshold; ensure the choice matches your App Store/Play age ratings and Terms.)

Consistent with the US Children's Online Privacy Protection Act (COPPA) and the GDPR's provisions on children, if we learn that we have collected personal information from a child below the applicable age without required consent, we will delete it promptly. If you believe a child has provided us personal information, contact us at appsgenx@gmail.com and we will take appropriate action.

↑ Back to top

19. Health-related data notice

PawVitals records information about the health of pets, not humans. Pet health information is generally not "protected health information" under laws such as the US Health Insurance Portability and Accountability Act (HIPAA), and PawVitals is not a HIPAA-covered entity or business associate and does not claim HIPAA compliance. Nevertheless, we recognize this information is meaningful and sensitive, so we treat it with heightened care: it is stored encrypted on your device, is minimized before any AI processing, and is not sold or used for advertising.

Your responsibility for accuracy. You are responsible for the accuracy of the information you enter, including any vet-provided target ranges. The App is a logging and organizing tool and does not provide veterinary advice, diagnosis, dosing, or treatment. Always rely on your veterinarian for medical decisions. See our Terms of Service.

↑ Back to top

20. Third-party links & services

The Services may link to or interoperate with third-party sites and services (for example, the Apple App Store and Google Play). We do not control and are not responsible for the privacy practices of those third parties. Their handling of your information is governed by their own privacy policies, which we encourage you to review.

↑ Back to top

21. Do Not Track & Global Privacy Control

Some browsers offer a "Do Not Track" (DNT) signal. Because there is no common industry standard for how to interpret DNT, the Site does not respond to DNT signals. However, because we do not sell or share personal information, there is no cross-site tracking to disable.

Where applicable law requires, we treat recognized opt-out preference signals, including the Global Privacy Control (GPC), as a valid request to opt out of any "sale" or "sharing" of personal information for the browser or device that sends the signal.

↑ Back to top

22. Data breach handling & notification

We maintain processes to detect, investigate, and respond to security incidents. If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify affected users and, where required, the relevant supervisory authority or regulator, within the timeframe required by applicable law (applicable law). Notifications will describe, to the extent known, the nature of the incident, the likely consequences, and the measures taken or proposed. Because most health data is stored locally and encrypted, the scope of any breach affecting server-side data is inherently limited.

↑ Back to top

23. Changes to this policy

We may update this policy from time to time to reflect changes in the Services, the law, or our practices. When we make material changes, we will update the "Last updated" date and, where appropriate, provide additional notice (for example, an in-App notice). Your continued use of the Services after an update takes effect constitutes acceptance of the revised policy, except where additional consent is required by law, in which case we will ask for it.

↑ Back to top

24. Contact us & complaints

For privacy questions, requests, or complaints:

Privacy emailappsgenx@gmail.com
Support emailappsgenx@gmail.com (currently appsgenx@gmail.com)
PostalBy email: appsgenx@gmail.com
ControllerAppsgenx Inc, United States
DPO (if any)Not appointed; contact appsgenx@gmail.com

If you are in the EEA or UK and are not satisfied with our response, you may lodge a complaint with your local supervisory authority (Section 15.1). US residents may contact their state Attorney General as described in Section 16.

This policy is governed by the laws of the State of Wyoming, United States, consistent with our Terms of Service, without prejudice to mandatory consumer or data-protection rights available to you under the law of your place of residence.

↑ Back to top

25. Quick controls recap

See also our Terms of Service and Support pages. Complete the App Store "App Privacy" and Google Play "Data safety" disclosures so they match this policy before publishing.

↑ Back to top