Legal Document

Privacy Policy

How CreatureHealth collects, uses, and protects your data

Effective: June 12, 2026
Last updated: July 27, 2026
GDPR compliant
๐Ÿ‘‹

1. Who We Are

This Privacy Policy explains how CreatureHealth ("we", "us", or "our") collects, uses, stores, and protects your personal data when you use our application โ€” available on the web at mycreaturehealth.com and as a mobile app for Android and iOS.

The data controller responsible for your personal data is Patryk Kuszczak (sole trader), based in Poland. You can reach us at privacy@mycreaturehealth.com (full postal address available on request).

CreatureHealth helps you organize your animals' health information โ€” lab results, vet visits, medications, and diets. It is a record-keeping tool and does not provide veterinary or medical advice. By using CreatureHealth, you agree to this Policy. If you do not agree, please discontinue use of the service.

๐Ÿ“‹

2. Data We Collect

2.1 Account & identity data

You can sign in with your email address (we email you a one-time code), or with Google or Facebook. In every case, via AWS Cognito, we receive and store:

  • Your email address
  • Your display name (if provided by your sign-in provider)
  • The sign-in method used (email, Google or Facebook) and a unique authentication identifier

If you sign in with an email one-time code, that code is sent to your email only to sign you in, is valid for a short time, and is not retained after use. Signing in with email collects nothing beyond your email address.

Setting a password is optional. If you choose one, it is managed securely by AWS Cognito โ€” we never store or see your password. We do not store your provider profile picture.

2.2 Your animals

  • Name, species, breed, date of birth and weight
  • An optional photo of your animal
  • Microchip ID and free-text notes, if you add them

2.3 Health records you add

  • Lab result files you upload (PDF documents or photos/images)
  • Test parameters and values โ€” extracted automatically by AI or entered manually (test name, value, unit, reference range, status, laboratory name, test date, result type such as blood, urine, ultrasound (USG), MRI, X-ray or cardiac)
  • Health events โ€” vet visits (veterinarian, clinic, reason, date), medications (name, dose, frequency, schedule) and symptoms
  • Diets โ€” diet type (commercial, BARF or mixed), details, dates and notes

2.4 Technical data (collected automatically)

  • Device type, operating system and app version
  • IP address and approximate region
  • Application and error logs used for debugging and security

We do not collect financial information or government IDs, we do not build advertising profiles, and we do not use advertising or cross-site tracking cookies. We use privacy-respecting product analytics and error monitoring (see Third-Party Services) to run and improve the app and fix crashes โ€” never for advertising.

โš™๏ธ

3. How We Use Your Data & Legal Bases

We use your data only to operate and improve the service:

  • To create and manage your account and authenticate you securely
  • To store and display your animals' profiles, health records, charts and history
  • To extract structured values from the lab results you upload (see Section 4)
  • To keep the service secure, prevent abuse, diagnose errors and fix bugs

๐Ÿค– We never use data that identifies you โ€” your account details, your animals' profiles or the documents you upload โ€” to train artificial-intelligence models, and we never hand them to anyone else to train theirs.

Anonymized data

Some of what you record has value beyond your own account: how a lab parameter moves over time, how often a symptom shows up in a breed, what a healthy weight curve looks like. We reserve the right to use such data โ€” only once it has been anonymized โ€” to develop and improve CreatureHealth, to build features like reference ranges, trends and comparisons, to train our own models, and to share or license the anonymized dataset to third parties, including on commercial terms.

The condition is the order: anonymization first, use second. Anonymized here means the data carries no name, email or contact details, none of the files you uploaded and none of the free text you typed, and is worked with in aggregate โ€” it is not meant to lead back to you or your animal. We never sell or share data that identifies you.

Producing that set from your records rests on our legitimate interest, so you can object at any time: email privacy@mycreaturehealth.com and we will exclude your records, with no effect on how you use the app. If you do not want anything of yours kept this way after you delete your account, tell us before you delete it โ€” afterwards your email is gone from our systems, so we can no longer tell which records were yours.

Legal bases (GDPR Art. 6)

  • Performance of a contract (Art. 6(1)(b)) โ€” providing the features you sign up for, including storing your records and running AI extraction at your request
  • Legitimate interests (Art. 6(1)(f)) โ€” security monitoring, abuse prevention, service improvement, and producing the anonymized datasets described above
  • Consent (Art. 6(1)(a)) โ€” where we ask for it; you may withdraw consent at any time
๐Ÿค–

4. AI Processing of Lab Results

When you upload a lab result, we help you turn it into structured data:

  • On the web, an initial text-recognition step (OCR) runs locally in your browser โ€” the document is not sent anywhere for this step.
  • The file is then sent to our backend and forwarded to the Google Gemini API (model gemini-2.5-flash-lite) to identify the test type and extract values (name, value, unit, reference range) and a short summary.

We send only the document to Google for this step over an encrypted connection โ€” never your name or email. Google processes it as our service provider under the Google Gemini API terms; we use the paid API and do not permit Google to use your content to train its models. The extracted values are then stored in your account. You always review the result before it is saved.

To improve how accurately we read your documents, we measure where the AI gets it wrong: when you save, we compare what the AI extracted with what you ultimately keep, and send our product analytics only a technical signal โ€” which parameters were corrected (e.g. "protein") and what kind of change it was (a row added, removed, or a value, unit or status fixed). We do not send the values themselves, the uploaded file, or any personal data โ€” only parameter identifiers and change types, tied to a pseudonymous account identifier. This relies on our legitimate interest in improving the service; you can object at any time at privacy@mycreaturehealth.com.

๐Ÿ”’

5. Data Storage & Security

  • All your data is hosted on Amazon Web Services (AWS) in the eu-central-1 region (Frankfurt, Germany) โ€” within the European Union.
  • Data in transit is encrypted with HTTPS / TLS.
  • Uploaded files (lab results, animal photos) are stored in private Amazon S3 storage โ€” not publicly accessible โ€” and encrypted at rest (S3 server-side encryption, AES-256).
  • Your records are stored in an Amazon RDS PostgreSQL database running in a private network that is not publicly accessible.
  • Authentication is managed by AWS Cognito.
  • We never use your data for advertising.

No system can be guaranteed 100% secure. If you believe your account has been compromised, contact us immediately at privacy@mycreaturehealth.com.

๐Ÿ”—

6. Third-Party Services & International Transfers

We rely on a small number of processors, each under their own data-processing terms:

Amazon Web Services (AWS) Hosting, database, file storage and authentication (Cognito, S3, RDS, compute, CloudFront, CloudWatch), in the EU under a Data Processing Agreement. AWS Privacy Notice โ†’
Google Sign-in (Google OAuth) and the Gemini API used to extract data from lab results. Google Privacy Policy โ†’
Meta (Facebook) Used only if you choose to sign in with Facebook. Meta Privacy Policy โ†’
PostHog Product analytics โ€” how the app is used, so we can improve it. Receives a pseudonymous account identifier plus non-identifying usage events (e.g. which screens you visit, which extracted parameters you correct) โ€” never the values you enter, your email or your name โ€” and is never used for advertising. PostHog Privacy Policy โ†’
Sentry Error and crash monitoring, so we can find and fix bugs. Error reports are tagged only with a pseudonymous account identifier โ€” never your email or name โ€” and are never used for advertising. Sentry Privacy Policy โ†’

International transfers

Your data is stored in the EU. However, when you use AI extraction (Google) or sign in with Google or Facebook, those providers may process the relevant data outside the European Economic Area. Such transfers are covered by the providers' safeguards, such as the EU Standard Contractual Clauses.

๐Ÿ—‘๏ธ

7. Data Retention & Account Deletion

We keep your personal data for as long as your account is active. You can delete your account at any time from the app: Profile โ†’ Delete account.

When you request deletion, your account enters a 30-day grace period. You are signed out on all your devices straight away, but nothing is erased yet โ€” sign back in before the 30 days are up and you can cancel the deletion. After 30 days it is carried out and cannot be reversed.

When it is carried out, we permanently erase everything that identifies you or your animal:

  • Your sign-in account at AWS Cognito โ€” you can no longer log in.
  • Your email address, your name and the sign-in method you used.
  • Every file you uploaded โ€” lab-result PDFs and photos, your animals' photos, vet-visit scans and diet plans โ€” is deleted from our file storage.
  • Your animals' names, microchip IDs and notes.
  • The values read from your lab results, the laboratory's name and the original file names.
  • Free text you typed and text recognised from your documents: the veterinarian's and the clinic's name, the reason for a visit, symptom descriptions, what a medication was prescribed for, and diet notes.

To be straightforward about it: we do not delete the whole record โ€” we cut it off from you. What remains is a de-identified skeleton with no name, no contact details, no files and no free text attached to it: species and breed, dates, the type of a result or event, structured symptom choices and their severity, medication regimens, weights and diet type. We keep it because aggregated animal-health data is what makes the service better over time (for example reference ranges and trends) โ€” see Section 3 for what we may do with anonymized data โ€” and it no longer points back to you or your animal.

If you would rather that remaining record was not kept at all, email privacy@mycreaturehealth.com before you delete your account and we will remove it too โ€” see Section 3.

Separately, operational and error logs are kept only for a short period (around 7 days) and are then deleted automatically.

โš–๏ธ

8. Your Rights (GDPR)

If you are in the European Economic Area, you have the following rights:

Access (Art. 15)Request a copy of your personal data
Rectification (Art. 16)Correct inaccurate personal data
Erasure (Art. 17)Request deletion ("right to be forgotten")
Restriction (Art. 18)Limit how we process your data
Portability (Art. 20)Receive your data in a machine-readable format
Objection (Art. 21)Object to processing based on legitimate interests
Withdraw consent (Art. 7(3))Withdraw consent at any time
Lodge a complaintContact your data protection authority (in Poland: UODO)

To exercise any of these rights, email privacy@mycreaturehealth.com. We respond within 30 days.

๐Ÿ‘ถ

9. Children's Privacy

CreatureHealth is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

๐Ÿ”

10. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app. Continued use of the service after an update constitutes acceptance of the revised Policy.

๐Ÿ“ฌ

11. Contact Us

For any question about this Policy or to exercise your rights, contact us:

Patryk Kuszczak (data controller, sole trader)

Email: privacy@mycreaturehealth.com

Poland โ€” full postal address available on request

Website: mycreaturehealth.com

We aim to respond to all privacy requests within 30 days. For complex requests we may extend this by up to a further 60 days and will tell you if we do.