Privacy Policy

Effective date: September 1, 2026  ·  Last updated: September 1, 2026

This policy describes how Zhiva ("we," "our," or "the app") handles information when you use our iOS application. We are committed to keeping your pet's health data private.


1. What We Collect and Why

1.1 Diagnostic and Analytics Data

Zhiva collects pseudonymous diagnostic events, linked to your account identifier, to help us understand how the app is performing and identify problems. These events include:

These events record that something happened and when — they do not carry your pet's records or the text of your entries.

Purpose: App functionality and product analytics. This data is used solely to improve Zhiva. It is not sold and is not used for third-party advertising.

You can turn these events off at any time: Settings → Send diagnostic data. With the setting off, nothing is sent.

1.2 Account Information

When you create a Zhiva account or sign in — including with Sign in with Apple — we collect your email address and use it as your account identifier and to sign you in. Each account is also assigned a random UUID (owner_id), which is the key used to store your records and to link the diagnostic events described above to your account. Your email and account identifier are used to operate the app; they are not sold and are not shared with advertising networks.

Sign in with Apple. If you sign in with Apple, Zhiva asks Apple for your name and your email address. Apple gives us either your real email address or one of Apple's private-relay forwarding addresses, depending on what you choose in Apple's sign-in sheet. If Apple provides your name, we use it once to fill in the display name on your profile — Apple only ever sends the name on your first sign-in.

1.3 Location

If you start a walk, Zhiva collects your precise location while the walk is active to measure distance and record your route. Walk routes are uploaded to and stored in your Zhiva account. Once a walk has ended, its route coordinates are automatically cleared 90 days later; the walk's distance, pace and times are kept so your pet's activity history stays intact. Location is collected only during walks you start, and is never used for advertising or to track you.

1.4 Profile and Contact Information

Your profile has optional fields you may fill in. All of them are optional, all are entered by you, and none is collected automatically:

These are stored in your account and used to fill in documents you generate, such as a PDF record summary. They are not sold and are not shared with advertising networks. You can edit or clear them at any time in Settings → Profile.

1.5 Your Pets' Records and Content

The content you create in Zhiva is stored in your account:

Some of this content leaves your account if you choose to create a share link for a pet — see §3.

2. AI Processing of Your Documents and Entries

Several Zhiva features work by sending part of your content to Anthropic PBC ("Anthropic"), the company behind Claude, which reads it and returns a structured result. Anthropic processes this content on our instructions to deliver the feature you asked for. It is not an advertising network, and we do not sell your content to Anthropic or to anyone else.

2.1 Document scans

When you scan a document, Zhiva sends the page images and the text recognised on them to Anthropic. That includes anything printed on the page — for example the clinic's name, and your own name or address where the document shows them. The images are sent as captured; we do not filter what is printed in the pixels, and we would rather tell you that than imply a filter that does not exist.

This only happens after you accept the consent step Zhiva shows you before your first scan. The page image is saved to your pet's vault before the reading so you can open it later; if you cancel the scan instead of saving it, we delete it.

2.2 Voice logs

Speech is transcribed on your device. Only the resulting text is sent to Anthropic, and only to turn it into a structured entry. Your audio never leaves your device — Zhiva uses on-device recognition only and does not fall back to a server, and no recording is kept.

2.3 Insights and follow-up questions

For a proactive insight, we send a small set of figures derived from what you have logged — for example a weight trend, an event count, or an interval between entries. No free text and no pet name is included.

When you ask a follow-up question about an insight, we also send your pet's species and breed, the types, dates and severity of recent entries, recent weight and temperature readings, the names, doses and dates of active medications, and the question you typed. The free-text notes on your entries are not sent.

2.4 What Anthropic does with it

Anthropic deletes what we send within 30 days, and does not use it to train their models.

2.5 If you would rather not

You can decline at the consent step before your first scan. If you decline, nothing is sent for reading: your document is still saved to your pet's vault as an attachment you can open and read at any time, and you can still type in any values you want tracked. Only the automatic reading is off. Your answer is remembered on that device.

Voice logging and insights work only on entries you choose to create. Deleting your account removes your content — see §7.

3. Sharing a Pet's Record by Link

Zhiva lets you create a share link for one of your pets — a web address you can send to a vet, a sitter, or anyone else. This is the one feature that publishes your pet's information on a public web page, outside your account, so it is set out here in full.

3.1 What the page shows

Opening a share link renders a read-only page for that one pet, assembled at that moment from the records described in §1.5:

Nothing else is on the page. It does not carry your name, email address or any other profile or contact field from §1.4; your other pets; the documents you have scanned; or any walk, route or location data.

The page always shows exactly that. The three "what to include" switches on the share screen are not connected to anything yet — whatever you set them to, the page shows the same summary. We would rather tell you that than let a switch imply a filter that is not there.

3.2 Who can see it

A share link ends in a random 26-character code, and that code is the only thing protecting the page. There is no sign-in and no password. Anyone holding the link can open it — not only the person you sent it to, but anyone they forward it to, and anyone who later reads the link out of a message, an email, or a browser history. Treat a share link as a copy of the record that you have handed out, not as an invitation to one named person.

The page is served from our Supabase infrastructure (see §6), at an address of the form …supabase.co/functions/v1/view-shared-record?slug=….

Every time the page is opened, Zhiva counts the view and records when it was last opened, and shows you both on the share screen. To keep the public address from being abused, the server also writes a log line for each request holding the time, the first four characters of the link code, and the visitor's IP address truncated to its first three octets — for example 203.0.113.0/24. The full address is not stored.

3.3 How long it lives

Every link you create in the app carries an expiry date; the app offers no link without one. The default is 24 hours. You can choose 7 days instead, and with a Zhiva subscription 30 days or a date you pick, up to a year. Once a link expires it stops working: the address then returns a generic "this link is no longer available" page, which is the same page an address that never existed returns.

3.4 How you revoke it

Open the pet in Zhiva and tap Share. Every link for that pet that is still live is listed there, each with a control to revoke it. Revoking takes effect immediately and applies to everyone holding that link. It cannot be undone — a revoked link can never be re-enabled, though you are free to create a new one.

One limit is worth stating plainly. The pet's photo is not stored in the page; the page embeds a temporary link to our storage that is valid for up to one hour. Revoking the share link stops the page at once, but a photo link that has already been handed out keeps working until that hour runs out. Everything else — the vitals, the observations, your notes — is unreachable the moment you revoke.

3.5 What we do not do with it

Creating a share link is not a transfer of your records to us for our own purposes or to anyone else's. The contents of a shared page are not sold, are not used for advertising, and are not sent to Anthropic or to any other processor — the page is built from your own records when it is opened and is not stored anywhere else. Deleting the pet, or your account, removes the records the page is built from; see §7.

4. What We Do Not Collect

5. On-Device Storage

Zhiva uses iOS UserDefaults to persist on-device preferences (selected pet, notification settings, onboarding state, your answer to the scan consent step, and the diagnostics opt-out). These values are read and written on your device only and are never transmitted off-device.

Offline scan documents are queued in your device's Application Support directory and uploaded to your account when connectivity is restored. File timestamps on these queued items are read solely to manage storage (FIFO eviction) — they are not transmitted and are not used for any tracking purpose.

6. Data Storage and Security

Pet health records, documents, photos and diagnostic events are stored on Supabase infrastructure (Supabase Inc., USA). Data in transit is encrypted with TLS. Data at rest is encrypted by the database provider. We apply Row-Level Security so that each account can access only its own records, and the storage buckets holding your photos and documents are private — reading a file requires a short-lived signed link issued to your account.

We require our processors — Anthropic and Supabase — to provide the same or equal protection of your data as this policy states.

7. Data Retention and Deletion

We retain your account data for as long as your account is active. Route coordinates from a walk are automatically cleared 90 days after that walk ends.

You can delete your account at any time from within the app: go to Settings → Delete Account. Deletion is immediate and cannot be undone. It deletes your account, your pets and all of their records, and removes the documents and photos you have stored. Diagnostic and authentication event rows are kept with the account identifier removed, so what remains cannot be tied back to you. If you cannot access the app, you may instead email support@zhiva.app to request deletion, and we will process it as soon as possible (within 30 days at the latest).

8. Children

Zhiva is not directed at children under 13. We do not knowingly collect information from children under 13. If you believe we have inadvertently collected such information, contact us and we will delete it promptly.

9. Changes to This Policy

If we make material changes, we will update the effective date above and, where feasible, notify you via the app. Continued use of Zhiva after a change takes effect constitutes acceptance of the revised policy.

10. Contact

Questions or privacy requests: support@zhiva.app