Furbinder

Privacy Policy

Effective date: [DATE] · Last updated: [DATE]

Draft — pending legal review. This document is a working skeleton prepared by the product team. It must be reviewed and approved by qualified counsel (including GDPR/CCPA specialists) before publication. Bracketed items are placeholders.

1. Who we are

Furbinder ("Furbinder", "we", "us") provides a personal health record app for pets. For the purposes of the EU/UK General Data Protection Regulation (GDPR), the data controller is [LEGAL ENTITY NAME, ADDRESS]. You can reach our privacy team at privacy@furbinder.com.

2. Information we collect

3. How we use your information

GDPR legal bases: performance of a contract (core service), consent (marketing, optional features), and legitimate interests (security, product improvement) — [COUNSEL TO CONFIRM MAPPING].

4. AI processing

Documents and symptom descriptions you submit are processed by third-party AI providers under data-processing agreements to deliver OCR, triage, and chat features. Your data is not used to train their models [COUNSEL: confirm provider DPA terms]. AI output is informational only and is never veterinary advice, diagnosis, or treatment.

5. Who we share data with

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We use these processors:

ProcessorPurpose
SupabaseDatabase, authentication, encrypted file storage
Anthropic (Claude)Document extraction (OCR), symptom triage, AI chat
RevenueCatSubscription management and billing
StripePayment processing for web purchases (via RevenueCat)
ResendTransactional and reminder email
ExpoPush notification delivery
PostHogProduct analytics
SentryCrash and error reporting

We may also disclose data when required by law, or in a merger/acquisition (with notice to you).

6. Data retention

We keep your data while your account is active. If you delete your account, personal data and uploaded documents are permanently deleted within [30] days, except records we must retain for legal, tax, or security purposes. Backups roll off within [35] days.

7. Security

Data is encrypted in transit (HTTPS/TLS) and at rest. Documents live in a private storage bucket accessible only via short-lived signed URLs. Database access is protected by row-level security scoped to your account. We maintain audit logs and follow OWASP ASVS-aligned practices.

8. Your rights

8.1 GDPR (EEA/UK residents)

8.2 CCPA/CPRA (California residents)

8.3 How to exercise your rights

Export or delete everything yourself, anytime: in the app, go to Settings → Data & privacy → Export my data / Delete my account. Or email privacy@furbinder.com — we respond within 30 days (GDPR) / 45 days (CCPA), and verify identity before acting. Step-by-step instructions and exactly what is deleted: Delete your account & data.

9. International transfers

Data is hosted in [REGION]. Where data leaves the EEA/UK, we rely on Standard Contractual Clauses and processor safeguards [COUNSEL: confirm transfer mechanism per processor].

10. Children

Furbinder is not directed to children under 16 (or the applicable age of digital consent), and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

11. Changes to this policy

We will notify you of material changes in-app and by email at least [14] days before they take effect. The "Last updated" date above always reflects the current version.

12. Contact

privacy@furbinder.com · [LEGAL ENTITY NAME] · [POSTAL ADDRESS] · [EU/UK REPRESENTATIVE, IF REQUIRED]