This is a product-specific beta notice template. Before public launch, the operator must insert its legal identity, contact details, hosting locations, retention policy and applicable legal disclosures. Do not represent this template as a completed legal review.

What this build stores

The app stores account details, selected area and timezone, pet profiles, care schedules, observations, records and documents. Community participation can add posts, events, messages and moderation reports. Telegram users are identified by server-validated Telegram account data. Web accounts store a salted password hash, not a readable password.

Private care and public discovery are different

Pet care information is available to the owner and authorized care-circle members. Discovery is off by default. When enabled, limited public pet fields and the owner’s first name and area may appear to participating users. Location is optional; the app rounds requested coordinates before sending them, and stores only a coarse cell. This reduces precision but does not make location-related information non-sensitive.

Messaging and shared links

Private app messages require a mutually accepted connection. They are stored on the server and are not end-to-end encrypted. Expiring digital-ID and handover links are accessible to anyone holding the link. Handover pages intentionally expose the listed instructions and contacts. Review and revoke links when no longer needed.

Storage and third parties

This source build does not include advertising trackers or third-party analytics. The deployed Telegram integration communicates with Telegram; application hosting and backups depend on the operator’s chosen infrastructure. The standalone HTML preview stores fictional demo changes in the browser. It should not be used for private medical documents.

Export and deletion

Settings includes a JSON export of accessible records and an account-deletion control. Account deletion removes the account’s owned content from the active database and revokes access. Files not referenced by active records need cleanup under the documented operator process. Backup expiry and any required retention must be specified by the operator; active deletion is not a promise of instantaneous removal from every backup.

Operator completion required

Before launch: provide an identifiable operator contact, define retention and backup expiry, establish an access-request and incident-response process, review jurisdiction-specific requirements and publish the completed notice. An administrator account alone is not a substitute for these responsibilities.