noindex until then.
Legal
Privacy policy
Last updated .
The short version
- We collect what the product needs to work, and not more.
- We do not sell your data, and we do not share it with insurers or advertisers.
- You can export everything, at any time, on any plan, at no cost.
- You can have it all erased, and erasure is real.
The rest of this page is the detail behind those four statements.
Who we are
Black Elephant Holdings LLC, [registered address], [company number]. We are the data controller for the information described here. Contact privacy@thinkpethealth.com for anything covered by this policy.
What we collect
Information you give us
- Account details — your email address, your display name, and a hashed password or an enrolled passkey. We never store a password in a form we can read.
- Animal records — everything you enter about your animals: identity, species and breed, medical history, medications and doses, vaccinations, weight, food, allergies, veterinary practice and insurance details, and emergency contacts.
- Documents you upload — the file itself, and the text extracted from it so that it can be searched.
- People you share with — the email address you invite, and the permissions you grant them.
- Messages to the assistant — what you ask, and the record context used to answer it.
Information we generate
- An audit trail of who accessed and changed which records, which exists so that you can see it.
- Session and security records — sign-in times, device and approximate location for a session, and refresh-token bookkeeping used to detect a stolen session.
- Operational logs — errors and request timings, retained briefly and used to keep the service working.
Information we do not collect
We do not use advertising trackers, we do not build a profile of you for marketing, and we do not run third-party analytics that follow you around the web.
Why we are allowed to hold it
- Performing our contract with you — your account, your animals’ records, sharing, reminders, and billing. Without these the product does not exist.
- Our legitimate interests — security, fraud prevention, abuse handling, and keeping the service running and debuggable.
- Your consent — optional emails you have opted into, which you can withdraw at any time without affecting anything else.
- Legal obligation — retaining invoices and tax records for the period the law requires.
Records about an animal are not personal data about a person in the ordinary case. We nonetheless treat them as confidential, because they are yours and because they often contain your name, address and practice details.
Who we share it with
Only the processors we need in order to operate, each under a contract that restricts them to acting on our instructions:
- Hosting and database — infrastructure inside the European Union.
- Object storage — for the files you upload.
- Payments — Stripe, and Apple or Google if you subscribed in an app store. We never see or store your card number.
- Email delivery — for reminders, verification and receipts.
- The assistant’s model provider — the question you ask and the relevant record context are sent to be answered. This is not used to train models, and applies only if you use the assistant.
We share with nobody else, unless we are legally compelled to, in which case we will tell you where we are permitted to.
Where it is stored
On servers within the European Union, with encrypted backups in the same region. Uploaded files travel from your browser directly to object storage using a short-lived signed URL, and do not pass through our application servers.
How it is kept separate
Every household’s records are separated by PostgreSQL row-level security, one layer below the application. Requests run in a transaction tagged with the signed-in identity, and the database filters every table by it. A mistake in our application code cannot return another household’s rows, because the rows are never returned to it. This is verified against a live database on every build.
How long we keep it
- Your records — for as long as your account exists.
- After you delete your account — erasure is scheduled with a grace window so an accidental deletion can be undone. When the window closes, records are erased and drop out of backups as those backups age out.
- Invoices — for the period tax law requires, regardless of account deletion.
- Security and audit logs — a limited period, then discarded.
Your rights
Under the UK GDPR and the EU GDPR you may ask for access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interests.
- Access and portability are self-service — Settings → Export, on every plan including Free, as often as you like, at no charge.
- Erasure is self-service — Settings → Account → Delete.
- Everything else — write to privacy@thinkpethealth.com. We reply within 30 days and usually much sooner.
If you are unhappy with how we have handled a request you can complain to your national supervisory authority — in the UK, the Information Commissioner’s Office. [Confirm the lead authority once the operating entity is settled.]
Cookies
This marketing site sets no cookies and runs no analytics. The application sets only what is strictly necessary to keep you signed in and to protect the session. There is no consent banner because there is nothing to consent to.
Children
The service is not directed at children under 16. If you believe a child has created an account, tell us and we will remove it.
Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect. The date at the top always reflects the current version.
Questions: privacy@thinkpethealth.com · Security reports: security@thinkpethealth.com