Privacy Policy
This is the live text the app links to; the same document ships in the repository that builds this site.
This document describes how Dana collects, uses, shares, and protects personal data.
Effective Date: 2026-02-23
Last Legal Review: Pending counsel review
1) Who this policy applies to
This policy applies to users of the Dana mobile application on iOS and Android.
2) Data we collect
Account and profile data
- Authentication identifiers (email or phone depending on sign-in method)
- Optional profile fields (display name, profile photo)
- Account metadata (user ID, created timestamp, subscription status)
Pet and care data
- Pet profile data (name, species, optional photo/birthdate/notes)
- Care logs (food, water, bathroom, walk, notes, symptoms, behavior)
- Tasks and completion records
- Walk session records (times and duration)
- Medication and vaccine tracking
- Optional microchip information
Health records (Pro)
- Uploaded photo/PDF veterinary files and related metadata
AI data
- AI check input text and optional image input (Pro)
- AI output metadata for safety and history
Analytics and diagnostics
- Product usage events and diagnostics
- Device/app operational metadata
- PII-scrubbed telemetry (no email/phone/name in analytics payloads)
Payment data
- Subscription lifecycle metadata (plan, status, renewal state)
- Payment credentials are handled by platform stores and billing providers, not stored by Dana
3) How we use data
We use personal data to:
- Provide core app functionality and caregiver collaboration
- Send reminders and account/system notifications
- Maintain reliability, security, and abuse prevention
- Support subscription management and entitlement checks
- Meet legal obligations and handle rights requests
4) Legal basis (GDPR)
| Data Type | Legal Basis | GDPR Article |
|---|---|---|
| Account/pet/care data | Performance of contract | Article 6(1)(b) |
| Optional marketing (if enabled) | Consent | Article 6(1)(a) |
| Security and abuse prevention | Legitimate interests | Article 6(1)(f) |
| Mandatory legal processing | Legal obligation | Article 6(1)(c) |
5) Data sharing and processors
We share data only with providers required to operate the service.
| Provider | Purpose | Data Shared |
|---|---|---|
| Backend hosting, database, and object storage providers | Hosting, auth, storage | Account, pet, care, uploaded files |
| RevenueCat | Subscription management | User ID, subscription metadata |
| PostHog | Analytics, error tracking, feature flags | PII-scrubbed diagnostics and anonymized analytics |
| Apple/Google | Push and purchase platform services | Platform-required identifiers |
DPA statement
- Processor disclosures MUST match signed agreements.
- If a provider DPA is pending, disclosure language MUST reflect that status.
Caregiver sharing
- Owners can invite caregivers and assign permissions.
- Access can be revoked by owners in app settings.
Legal disclosures and corporate transfers
- We may disclose data when required by law.
- Data may transfer during merger/acquisition with user notice where legally required.
6) User rights
GDPR rights
Users may request access, export, rectification, deletion, objection, and processing restriction.
CCPA rights
California users may request disclosure and deletion and receive non-discriminatory treatment when exercising rights.
Do Not Sell / Share disclosure
Dana does not sell personal information. Current stack uses service providers for operations, not ad-tech resale.
If future tooling introduces regulated “sale/share” obligations, Dana will add required opt-out controls and update this policy.
7) Retention
| Data Type | Retention Period |
|---|---|
| Active account data | Until account deletion request |
| Deleted account data | Purged within 30 days |
| AI session data | Max 90 days |
| Crash diagnostics | 90 days |
| Security audit logs | Up to 1 year |
| Backups | Rolling 30-day retention |
8) Security and international transfers
Security controls
- Encryption at rest for managed database/storage
- Encryption in transit via HTTPS/TLS
- Sensitive local data stored in secure OS mechanisms
- Role-based access controls and row-level authorization
International transfers
Data may be processed in regions used by core providers. Where required, transfer safeguards are applied.
9) Children’s privacy
Dana is not intended for unsupervised child use.
10) Policy changes
Material policy updates are communicated in-app and/or by email where required.
11) Contact and rights requests
- Privacy and security contact:
security@danapetcare.com - Publishing entity and legal address: legal-entity.md
- DPO contact (if legally required): pending legal confirmation before publication
Rights requests SHOULD include enough information to verify account ownership and process the request safely.
12) Publication and review status
- Draft status: legal review pending
- Launch gate: legal counsel review required before public launch signoff
