Privacy policy
VestraPet is built around a single promise: your companion's health record belongs to you, and only to you. This policy explains what we collect, why, how it's protected, and what we will never do.
What we collect
- Pet profile data you enter: name, species, breed, date of birth, weight, microchip identifier, optional photo, purpose classification, vaccination history.
- Extracted passport fields from an OCR scan of a veterinary document you voluntarily submit. The original image is processed in a secure pipeline and not retained beyond 24 hours.
- Health records you add: timeline events, triage results, medication logs.
- Account data: email, phone number (optional), first and last name (optional), date of birth (optional), sex (optional), country of residence.
- Device diagnostics: crash reports, anonymous performance traces. Personally identifying fields are stripped before transmission.
- Location: only when you grant permission and only while the app is in use. Used to surface the nearest 24/7 vet network and regional outbreak alerts.
What we never do
- We do not sell your data.
- We do not share it with advertisers.
- We do not run third-party advertising in the app.
- We do not share your pet's records with a veterinary practice unless you explicitly initiate a handoff by sharing a vet-handoff link or wallet pass.
- We do not train public machine-learning models on your pet's photographs or records.
Where your data lives
All data is stored on our infrastructure provider, encrypted at rest and in transit (TLS 1.3). Each record is segmented by row-level security so one account cannot reach another's rows, enforced at the database layer.
Image and document uploads are stored in a private object store with signed, time-limited access URLs. Public access is blocked by policy.
Cross-border processing
Data is processed in the region closest to your country of residence. For users in the European Economic Area, data processing takes place in the EU, with standard contractual clauses where applicable.
Retention
- Health records are retained for as long as your account exists.
- Raw OCR source images: deleted within 24 hours of extraction.
- Deleted accounts: records are irreversibly purged within 30 days.
- Backups containing deleted data are rotated out within a 90-day window.
Your rights
- Access & export. Request a full export of your data via /export.
- Correction. Edit any field directly in the app.
- Erasure. Delete your account and all associated records via /delete-account.
- Objection & restriction. Write to privacy@vestrapet.com and we will respond within 30 days, sooner where local law requires.
Children
VestraPet is not directed at children under 13. We do not knowingly collect data from anyone in that age group. If you believe a child has created an account, email us and we will take it down.
Changes to this policy
Material changes are announced in-app and by email. The effective date at the top of this page reflects the most recent revision.
Contact
Privacy questions: privacy@vestrapet.com
Support: /support
© 2026 VestraPet. All rights reserved.