Privacy policy

In force from 9 September 2026. This policy sets out what HeyVetto collects, for what purposes, where the data is transferred, for how long it is retained, and how it may be erased. It has been drawn up in accordance with the Law of Ukraine on Personal Data Protection and, in respect of individuals in the European Union and the United Kingdom, with the GDPR and the UK GDPR.

The terms of use are set out on a separate page: Terms of use.

In short

  • Your pet's documents remain yours. We do not sell them, do not disclose them to advertisers, and do not use them to train artificial intelligence.
  • Where no account is created, all data remains on your device.
  • Where an account is created, records are stored within the European Union. Only you and a co-parent whom you have invited may read them.
  • In order to convert a document into text, its pages are transmitted to OpenAI's reading service in the United States. This is the only transfer outside the European Union.
  • We do not use tracking cookies, and we therefore never request your consent to them.
  • You may export all of your data or delete your account yourself, on the Account screen.

We do not sell data, display advertising, collect location or payment card details, send marketing correspondence, or process special categories of your personal data. The health of an animal does not constitute a special category.

Who is responsible

The controller of the data described in this policy is HeyVetto. Full registration details are provided on request.

Enquiries concerning your data should be addressed to vettovettoapp@gmail.com. We respond within 30 days, and generally sooner. No Data Protection Officer has been appointed, as the law does not require one at this scale of operation.

HeyVetto is in an early public test and is provided free of charge.

What we collect and how long we keep it

  • Pet documents (photographs or PDFs and the text read from them: dates, findings, doses, laboratory values, clinic, veterinarian) — used to provide the service. Kept until you delete them.
  • Pet profile (name, species, details, portrait) — used to display your records. Kept until you delete them.
  • Account (email and Google identifier) — used to identify the user. Kept until you delete the account.
  • Sharing (link between accounts, co-parent's email) — used to identify who holds access. Kept for the duration of the share.
  • Invite codes — used to transfer access. Kept 48 hours, single use.
  • Wrong code attempts (account, IP, time) — used to protect against guessing. Kept 1 hour, after which they are no longer used; deleted at the next invite activity.
  • Reminders (device push address, timezone) — used to deliver at the appointed hour. Kept until you disable them.
  • Usage counts — used to assess the service. Kept 24 months.
  • Hosting logs (IP, browser type) — used for the security of the site. Kept up to 30 days.

Where no account is created, the application operates locally. An account is required solely for the backup and for sharing.

Usage counts

Events such as the photographing of a document or the tapping of a button, both in the application and on the website. No name, email address, record content, search text or photograph is recorded. Each event is accompanied by the browser, operating system, language, application version and country (determined from your IP address by the analytics provider; the address itself is not stored).

Nothing is stored on your device for the purpose of counting — the identifier exists only for as long as you are on the site. It travels with you from the landing page into the application, and back from Google when you sign in, but it is never saved: close the tab and it is gone. It is for this reason that we never ask you about cookies.

When you are signed in, an event carries a transformed version of your account identifier. Your address or name cannot be recovered from it, but it is persistent; these are therefore personal data in the formal sense, and we do not describe them as anonymous. It also enables us to locate and delete the events relating specifically to you.

If you arrived from an advertisement or a shared link, we record the campaign labels (utm_, together with the click identifiers appended by Google and Facebook) and the domain from which you arrived, but never the full address of the page you were on.

You may disable usage counts on the Account screen, whereupon the application ceases to send events.

Who we share data with

The following list is complete. Services are not added without notice: any change is announced in the application in advance.

  • Supabase — database, photograph storage and authentication. Located in the EU.
  • Netlify — website hosting. Located in the US / CDN, under the EC standard contractual clauses.
  • Google — authentication with Google. Located in the US, under the EC standard contractual clauses.
  • OpenAI — document reading. Located in the US, under OpenAI's processing terms and the EC clauses.
  • Amplitude — usage counts. Located in the EU.
  • Push services (Google, Apple, Mozilla) — delivery of reminders. Location is determined by your browser.

Push services receive the device address and an encrypted message which they are unable to read. A copy of the standard contractual clauses will be provided on request. We may disclose data where required by law, and will inform you of any such request where we are permitted to do so.

Where data lives and who can see it

Where no account is created, data is held on your device alone. Where an account is created, it is held in Supabase's database and storage within the European Union. Access rules within the database ensure that no other user, and no person holding a link, is able to read it. Photographs are held in private storage: no direct link exists that would operate in the hands of another person.

How the AI reads documents

You are interacting with an artificial intelligence system — we state this expressly, as Article 50 of the EU AI Act requires.

The pages of the document are transmitted to OpenAI's reading service, accompanied only by the date of the visit and your application language. We do not transmit your name, email address or account identifier. OpenAI uses the pages solely in order to produce the reading, does not train its models on them, and deletes them within 30 days of abuse monitoring.

The model transcribes the document; it does not assess it, diagnose, or take decisions. It is capable of error: it may omit a line or misread a digit. For that reason the original always remains alongside it, and any field that has been read may be corrected or deleted manually. Text from a document is passed to the model as data and not as instructions; if a document attempts to alter its behaviour, the reading is refused.

Sharing a pet

A co-parent whom you invite is able to view and to modify all information concerning that animal. Invite only those persons whom you trust with those documents. The co-parent sees your email address, as it is that address which identifies who holds access; we do not correspond with them and do not use that address for any other purpose.

Either party may terminate the share at any time, after which the co-parent has access to no information concerning that pet. Records added by the co-parent remain with you: everything filed in respect of your pet is stored under your account from the moment it is added, irrespective of who added it. Termination of the share withdraws their access, and their own device is cleared.

A veterinary document ordinarily names the clinic and the veterinarian. Add only documents relating to your own pets. If another person has appeared in a document or photograph and requires removal, please write to us.

Deleting data and your account

Three levels are available to you:

  • An individual record or photograph — by means of the delete button on the record itself. It is removed together with the text read from it.
  • An entire pet — this removes the profile together with all of its records and photographs.
  • Your account — Delete account on the Account screen. This removes everything: records, photographs, pet profiles, sharing links, reminder addresses, and the usage events associated with your account. Events recorded while you were not signed in remain, and contain nothing by which you could be identified. Co-parents whom you have invited lose access.

Deletion of an account cannot be reversed: there is no recycle bin and restoration is not possible. Please use Download my data beforehand — the ZIP archive remains with you once the account has been deleted.

The following does not disappear at the same moment: deletion is immediate in the live database, and HeyVetto holds no backup of its own from which your data could be restored — our hosting provider may keep system backups of its own which no one here is able to access or to read; pages already submitted for reading are deleted by OpenAI within 30 days; aggregate usage totals remain, as nothing within them identifies you.

If you are unable to open the application, please write to vettovettoapp@gmail.com from the address with which you signed in. We will delete it manually and confirm by email.

We do not delete accounts for inactivity, and there is no period upon the expiry of which your data is erased automatically.

Your rights

The most expeditious means is within the application: Download my data saves everything as a single ZIP archive, any record may be edited or deleted, and Delete account removes everything. The archive contains the profile, records and photographs from this device, together with your account email address, sharing links and reminder settings.

You have the right to be informed of and to access your data (Art. 15), to rectify what is inaccurate (16), to erasure (17), to restriction of processing (18), to portability (20), to object to processing founded on legitimate interest (21), and to withdraw consent to reminders as readily as it was given.

These rights are exercised free of charge and without any obligation to state reasons. Correspondence should be sent from the address with which you signed in. You may lodge a complaint in Ukraine with the Parliament Commissioner for Human Rights, in the European Union with your national data protection authority, and in the United Kingdom with the ICO.

Children

HeyVetto is intended for adults aged 18 and over. We do not knowingly collect data from persons below that age; should this have occurred, please write to us and the data will be removed.

Security

All data is transmitted over HTTPS. Records are protected by access rules within the database, photographs by private storage, and secrets are held on the server and never reach the application's code. Access controls are reviewed regularly and any deficiencies identified are remedied.

No system is entirely secure. Should a breach place your rights at risk, we will notify you and, where the law so requires, the supervisory authority, within 72 hours.

Finally

Should the service be discontinued, we will give at least 30 days' notice and will keep the export function operative until the final day. Should HeyVetto pass to another company, we will give notice in advance, and this policy will continue to apply until you accept a new one.

This page exists in Ukrainian and in English; in the event of any discrepancy, the Ukrainian version prevails. When it is amended, the date at the head of the page is amended accordingly. Any change to what we collect or to the purposes for which we collect it is announced in the application before it takes effect.

Contact: vettovettoapp@gmail.com