Privacy Policy
Effective date: September 1, 2026 · Last updated: September 1, 2026
This policy describes how Zhiva ("we," "our," or "the app") handles information when you use our iOS application. We are committed to keeping your pet's health data private.
1. What We Collect and Why
1.1 Diagnostic and Analytics Data
Zhiva collects pseudonymous diagnostic events, linked to your account identifier, to help us understand how the app is performing and identify problems. These events include:
- Scan lifecycle events (scan initiated, completed, accepted)
- Insight delivery and engagement events (insight delivered, expanded)
- Subscription and paywall events (paywall presented, purchase completed, purchase failed)
- Walk lifecycle events (walk started, walk ended)
- App error events (authentication failures, keychain errors)
These events record that something happened and when — they do not carry your pet's records or the text of your entries.
Purpose: App functionality and product analytics. This data is used solely to improve Zhiva. It is not sold and is not used for third-party advertising.
You can turn these events off at any time: Settings → Send diagnostic data. With the setting off, nothing is sent.
1.2 Account Information
When you create a Zhiva account or sign in — including with Sign in with Apple — we collect your email address and use it as your account identifier and to sign you in. Each account is also assigned a random UUID (owner_id), which is the key used to store your records and to link the diagnostic events described above to your account. Your email and account identifier are used to operate the app; they are not sold and are not shared with advertising networks.
Sign in with Apple. If you sign in with Apple, Zhiva asks Apple for your name and your email address. Apple gives us either your real email address or one of Apple's private-relay forwarding addresses, depending on what you choose in Apple's sign-in sheet. If Apple provides your name, we use it once to fill in the display name on your profile — Apple only ever sends the name on your first sign-in.
1.3 Location
If you start a walk, Zhiva collects your precise location while the walk is active to measure distance and record your route. Walk routes are uploaded to and stored in your Zhiva account. Once a walk has ended, its route coordinates are automatically cleared 90 days later; the walk's distance, pace and times are kept so your pet's activity history stays intact. Location is collected only during walks you start, and is never used for advertising or to track you.
1.4 Profile and Contact Information
Your profile has optional fields you may fill in. All of them are optional, all are entered by you, and none is collected automatically:
- Display name and full name
- Contact email address and phone number
- Mailing address (street, city, region, postal code, country)
- Emergency contact name and phone number
- Veterinary clinic name and phone number
These are stored in your account and used to fill in documents you generate, such as a PDF record summary. They are not sold and are not shared with advertising networks. You can edit or clear them at any time in Settings → Profile.
1.5 Your Pets' Records and Content
The content you create in Zhiva is stored in your account:
- Pet profiles — name, species, breed, sex, date of birth, colour, microchip number, weight, and your free-text notes.
- Pet photos — stored in a private storage bucket that only your account can read.
- Scanned documents — the page images you capture, stored in your pet's vault in a private storage bucket that only your account can read.
- Logged observations — meals, symptoms, stool, vomiting, behaviour, weight, and medication given, with an optional severity rating and free-text notes. Entries you create by speaking are stored the same way, marked as having come from a voice entry.
- Health records — vitals, lab results, medications, vaccinations, appointments and visit notes, whether you type them in or they are read from a document you scanned.
Some of this content leaves your account if you choose to create a share link for a pet — see §3.
2. AI Processing of Your Documents and Entries
Several Zhiva features work by sending part of your content to Anthropic PBC ("Anthropic"), the company behind Claude, which reads it and returns a structured result. Anthropic processes this content on our instructions to deliver the feature you asked for. It is not an advertising network, and we do not sell your content to Anthropic or to anyone else.
2.1 Document scans
When you scan a document, Zhiva sends the page images and the text recognised on them to Anthropic. That includes anything printed on the page — for example the clinic's name, and your own name or address where the document shows them. The images are sent as captured; we do not filter what is printed in the pixels, and we would rather tell you that than imply a filter that does not exist.
This only happens after you accept the consent step Zhiva shows you before your first scan. The page image is saved to your pet's vault before the reading so you can open it later; if you cancel the scan instead of saving it, we delete it.
2.2 Voice logs
Speech is transcribed on your device. Only the resulting text is sent to Anthropic, and only to turn it into a structured entry. Your audio never leaves your device — Zhiva uses on-device recognition only and does not fall back to a server, and no recording is kept.
2.3 Insights and follow-up questions
For a proactive insight, we send a small set of figures derived from what you have logged — for example a weight trend, an event count, or an interval between entries. No free text and no pet name is included.
When you ask a follow-up question about an insight, we also send your pet's species and breed, the types, dates and severity of recent entries, recent weight and temperature readings, the names, doses and dates of active medications, and the question you typed. The free-text notes on your entries are not sent.
2.4 What Anthropic does with it
Anthropic deletes what we send within 30 days, and does not use it to train their models.
2.5 If you would rather not
You can decline at the consent step before your first scan. If you decline, nothing is sent for reading: your document is still saved to your pet's vault as an attachment you can open and read at any time, and you can still type in any values you want tracked. Only the automatic reading is off. Your answer is remembered on that device.
Voice logging and insights work only on entries you choose to create. Deleting your account removes your content — see §7.
3. Sharing a Pet's Record by Link
Zhiva lets you create a share link for one of your pets — a web address you can send to a vet, a sitter, or anyone else. This is the one feature that publishes your pet's information on a public web page, outside your account, so it is set out here in full.
3.1 What the page shows
Opening a share link renders a read-only page for that one pet, assembled at that moment from the records described in §1.5:
- The pet's name and photo, and its species, breed, sex, date of birth and latest weight.
- The pet's five most recent vitals — the date of each, with weight, temperature and heart rate.
- The observations you logged in the last 30 days (up to 100 of them) — the type of entry, its date, its severity rating, and the free-text note you wrote on it.
Nothing else is on the page. It does not carry your name, email address or any other profile or contact field from §1.4; your other pets; the documents you have scanned; or any walk, route or location data.
The page always shows exactly that. The three "what to include" switches on the share screen are not connected to anything yet — whatever you set them to, the page shows the same summary. We would rather tell you that than let a switch imply a filter that is not there.
3.2 Who can see it
A share link ends in a random 26-character code, and that code is the only thing protecting the page. There is no sign-in and no password. Anyone holding the link can open it — not only the person you sent it to, but anyone they forward it to, and anyone who later reads the link out of a message, an email, or a browser history. Treat a share link as a copy of the record that you have handed out, not as an invitation to one named person.
The page is served from our Supabase infrastructure (see §6), at an address of the form …supabase.co/functions/v1/view-shared-record?slug=….
Every time the page is opened, Zhiva counts the view and records when it was last opened, and shows you both on the share screen. To keep the public address from being abused, the server also writes a log line for each request holding the time, the first four characters of the link code, and the visitor's IP address truncated to its first three octets — for example 203.0.113.0/24. The full address is not stored.
3.3 How long it lives
Every link you create in the app carries an expiry date; the app offers no link without one. The default is 24 hours. You can choose 7 days instead, and with a Zhiva subscription 30 days or a date you pick, up to a year. Once a link expires it stops working: the address then returns a generic "this link is no longer available" page, which is the same page an address that never existed returns.
3.4 How you revoke it
Open the pet in Zhiva and tap Share. Every link for that pet that is still live is listed there, each with a control to revoke it. Revoking takes effect immediately and applies to everyone holding that link. It cannot be undone — a revoked link can never be re-enabled, though you are free to create a new one.
One limit is worth stating plainly. The pet's photo is not stored in the page; the page embeds a temporary link to our storage that is valid for up to one hour. Revoking the share link stops the page at once, but a photo link that has already been handed out keeps working until that hour runs out. Everything else — the vitals, the observations, your notes — is unreachable the moment you revoke.
3.5 What we do not do with it
Creating a share link is not a transfer of your records to us for our own purposes or to anyone else's. The contents of a shared page are not sold, are not used for advertising, and are not sent to Anthropic or to any other processor — the page is built from your own records when it is opened and is not stored anywhere else. Deleting the pet, or your account, removes the records the page is built from; see §7.
4. What We Do Not Collect
- No tracking: Zhiva does not use Apple's App Tracking Transparency framework, does not share data across apps or websites for advertising, and does not use any third-party tracking SDKs.
- No phone number collected automatically: we collect a phone number only if you add one to your profile (see §1.4).
- No location tracking: Outside of walks you start (see §1.3), Zhiva does not collect your location, and your location is never used for advertising or to track you.
- No browsing or search history within or outside the app.
- No health or medical data beyond what you enter for your pets, and what is read from the documents you choose to scan. Those records are analysed to provide the app's features — reading your scans, generating insights, and turning voice entries into structured events — including by Anthropic as described in §2. They are not sold and are not used for advertising.
5. On-Device Storage
Zhiva uses iOS UserDefaults to persist on-device preferences (selected pet, notification settings, onboarding state, your answer to the scan consent step, and the diagnostics opt-out). These values are read and written on your device only and are never transmitted off-device.
Offline scan documents are queued in your device's Application Support directory and uploaded to your account when connectivity is restored. File timestamps on these queued items are read solely to manage storage (FIFO eviction) — they are not transmitted and are not used for any tracking purpose.
6. Data Storage and Security
Pet health records, documents, photos and diagnostic events are stored on Supabase infrastructure (Supabase Inc., USA). Data in transit is encrypted with TLS. Data at rest is encrypted by the database provider. We apply Row-Level Security so that each account can access only its own records, and the storage buckets holding your photos and documents are private — reading a file requires a short-lived signed link issued to your account.
We require our processors — Anthropic and Supabase — to provide the same or equal protection of your data as this policy states.
7. Data Retention and Deletion
We retain your account data for as long as your account is active. Route coordinates from a walk are automatically cleared 90 days after that walk ends.
You can delete your account at any time from within the app: go to Settings → Delete Account. Deletion is immediate and cannot be undone. It deletes your account, your pets and all of their records, and removes the documents and photos you have stored. Diagnostic and authentication event rows are kept with the account identifier removed, so what remains cannot be tied back to you. If you cannot access the app, you may instead email support@zhiva.app to request deletion, and we will process it as soon as possible (within 30 days at the latest).
8. Children
Zhiva is not directed at children under 13. We do not knowingly collect information from children under 13. If you believe we have inadvertently collected such information, contact us and we will delete it promptly.
9. Changes to This Policy
If we make material changes, we will update the effective date above and, where feasible, notify you via the app. Continued use of Zhiva after a change takes effect constitutes acceptance of the revised policy.
10. Contact
Questions or privacy requests: support@zhiva.app