Legal

Privacy Policy

This is the live text the app links to; the same document ships in the repository that builds this site.

This document describes how Dana collects, uses, shares, and protects personal data.

Effective Date: 2026-02-23
Last Legal Review: Pending counsel review

1) Who this policy applies to

This policy applies to users of the Dana mobile application on iOS and Android.

2) Data we collect

Account and profile data

  • Authentication identifiers (email or phone depending on sign-in method)
  • Optional profile fields (display name, profile photo)
  • Account metadata (user ID, created timestamp, subscription status)

Pet and care data

  • Pet profile data (name, species, optional photo/birthdate/notes)
  • Care logs (food, water, bathroom, walk, notes, symptoms, behavior)
  • Tasks and completion records
  • Walk session records (times and duration)
  • Medication and vaccine tracking
  • Optional microchip information

Health records (Pro)

  • Uploaded photo/PDF veterinary files and related metadata

AI data

  • AI check input text and optional image input (Pro)
  • AI output metadata for safety and history

Analytics and diagnostics

  • Product usage events and diagnostics
  • Device/app operational metadata
  • PII-scrubbed telemetry (no email/phone/name in analytics payloads)

Payment data

  • Subscription lifecycle metadata (plan, status, renewal state)
  • Payment credentials are handled by platform stores and billing providers, not stored by Dana

3) How we use data

We use personal data to:

  • Provide core app functionality and caregiver collaboration
  • Send reminders and account/system notifications
  • Maintain reliability, security, and abuse prevention
  • Support subscription management and entitlement checks
  • Meet legal obligations and handle rights requests
Data Type Legal Basis GDPR Article
Account/pet/care data Performance of contract Article 6(1)(b)
Optional marketing (if enabled) Consent Article 6(1)(a)
Security and abuse prevention Legitimate interests Article 6(1)(f)
Mandatory legal processing Legal obligation Article 6(1)(c)

5) Data sharing and processors

We share data only with providers required to operate the service.

Provider Purpose Data Shared
Backend hosting, database, and object storage providers Hosting, auth, storage Account, pet, care, uploaded files
RevenueCat Subscription management User ID, subscription metadata
PostHog Analytics, error tracking, feature flags PII-scrubbed diagnostics and anonymized analytics
Apple/Google Push and purchase platform services Platform-required identifiers

DPA statement

  • Processor disclosures MUST match signed agreements.
  • If a provider DPA is pending, disclosure language MUST reflect that status.

Caregiver sharing

  • Owners can invite caregivers and assign permissions.
  • Access can be revoked by owners in app settings.
  • We may disclose data when required by law.
  • Data may transfer during merger/acquisition with user notice where legally required.

6) User rights

GDPR rights

Users may request access, export, rectification, deletion, objection, and processing restriction.

CCPA rights

California users may request disclosure and deletion and receive non-discriminatory treatment when exercising rights.

Do Not Sell / Share disclosure

Dana does not sell personal information. Current stack uses service providers for operations, not ad-tech resale.

If future tooling introduces regulated “sale/share” obligations, Dana will add required opt-out controls and update this policy.

7) Retention

Data Type Retention Period
Active account data Until account deletion request
Deleted account data Purged within 30 days
AI session data Max 90 days
Crash diagnostics 90 days
Security audit logs Up to 1 year
Backups Rolling 30-day retention

8) Security and international transfers

Security controls

  • Encryption at rest for managed database/storage
  • Encryption in transit via HTTPS/TLS
  • Sensitive local data stored in secure OS mechanisms
  • Role-based access controls and row-level authorization

International transfers

Data may be processed in regions used by core providers. Where required, transfer safeguards are applied.

9) Children’s privacy

Dana is not intended for unsupervised child use.

10) Policy changes

Material policy updates are communicated in-app and/or by email where required.

11) Contact and rights requests

  • Privacy and security contact: security@danapetcare.com
  • Publishing entity and legal address: legal-entity.md
  • DPO contact (if legally required): pending legal confirmation before publication

Rights requests SHOULD include enough information to verify account ownership and process the request safely.

12) Publication and review status

  • Draft status: legal review pending
  • Launch gate: legal counsel review required before public launch signoff