Privacy Policy
Last updated: 2026-04-23
This Privacy Policy explains how CatMD ("we", "us", "our") collects, uses, and protects information when you use the CatMD mobile application (the "App"). CatMD is an informational triage assistant for cat parents — it is not a substitute for professional veterinary advice. See the Medical Disclaimer and Terms of Service.
1. Summary in plain English
- We collect as little as possible. By default you use CatMD with an anonymous account — no email, no name, no real-world identity.
- Your cat's profile and scan history live on your device first. We mirror them to our secure database so you can recover them if you change phones, but we never sell or share them.
- Photos you scan are sent to our AI processing partner (OpenAI) to produce the triage. We do not keep the photos on our servers after the scan completes, unless you choose to save them to your history.
- You can delete everything at any time. The "Forget everything about my cat" button in Settings permanently erases your cats, scans, and photos from our servers and your device.
2. Who we are
The App is operated by Amit Raina ("CatMD"), an independent developer based in Singapore. For privacy questions, email nativemason01@gmail.com.
3. What we collect and why
3.1 Data you provide directly
- Cat profile: name, breed (optional), date of birth / age (optional), weight (optional), sex, spay/neuter status, indoor/outdoor, known medical conditions, current medications, photo, free-text notes, emergency vet contact. Why: so CatMD can tailor triage to your specific cat.
- Scan inputs: the text you type describing symptoms and any photo you attach. Why: to analyse the situation.
- Follow-up answers: replies you give to our AI's clarifying questions. Why: to sharpen the triage output.
- Account email + password (only if you choose to upgrade from an anonymous account). Why: to let you recover your data on a new device.
- Health-log entries: vaccinations, medications, weights, appointments, symptom photos, water intake, litter-box use, respiratory rate, pain scores, outcome check-ins, feeding notes — all optional and owner-entered.
3.2 Data we generate for you
- Triage results: urgency tier, health score, explanation, differentials, suggested next steps, vet questions, source citations — stored with your scan.
- Reminders: if you enable a medication or check-in reminder, we schedule a local notification on your device. These are not sent through our servers.
3.3 Data we automatically receive
- Anonymous account identifier — a randomly generated user ID that lets the App persist your data without knowing who you are.
- Technical data: app version, OS version, device model, crash reports, anonymised usage analytics. Helps us fix bugs and improve the App.
- We do NOT collect: your precise location, contacts, calendar, microphone input, or camera roll beyond what you explicitly attach to a scan.
4. Who we share data with
We use the following sub-processors. Each is contractually obliged to handle your data for our purposes only.
| Processor | Purpose | Data shared |
| Supabase, Inc. | Hosting, database, authentication | Cat profile, scan + health history, account identifier, optional email |
| OpenAI, LLC | AI triage + image analysis | Scan text and (when attached) scan photo, sent at the moment of the scan |
| Cloudflare, Inc. | Network proxy, landing pages | All API + web traffic (metadata only, not bodies at rest) |
| PostHog, Inc. (if analytics enabled) | Product analytics | Anonymous usage events |
| RevenueCat, Inc. (if you subscribe) | Subscription management | Anonymous user ID + purchase receipts |
| Google LLC / Apple Inc. | Store billing | Purchase receipts via the platform you buy on |
We do not sell your personal data. We do not share your data with advertisers.
5. How long we keep data
- Cat profiles, scans, health logs, reminders: kept until you delete them or your account.
- Photos attached to scans or symptom timelines: kept with the record. Deleting the record deletes the photo.
- Anonymous analytics: retained for 24 months maximum.
- Crash reports: retained for 90 days.
- Scan-usage counters (for fair-use limits): retained indefinitely, tied to your user ID only.
6. Your rights
Depending on your location, you have the right to access, rectify, erase, port, restrict, or object to the processing of your data, and to withdraw consent at any time. In Singapore, the Personal Data Protection Act 2012 (PDPA) governs these rights; residents of the EU/UK also have rights under the GDPR. To exercise any right, email nativemason01@gmail.com. You can also use Settings → Forget everything about my cat to hard-delete your data immediately. We respond to rights requests within 30 days.
7. Children
CatMD is not intended for users under 13 (under 16 in the EU/UK or equivalent jurisdictions). We do not knowingly collect data from children. If you believe a child has used CatMD, email us and we will delete the associated data.
8. Security
- Data in transit is encrypted with TLS 1.2+.
- Data at rest in our database is encrypted (AES-256, managed by Supabase).
- Photos you attach are sent over TLS to OpenAI for processing. See OpenAI's API data-usage policy at openai.com/policies/api-data-usage-policies.
- You can run the App entirely anonymously. No identifier ties your scans to a real-world identity unless you add an email address.
No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you within 72 hours as required by law.
9. International transfers
Your data may be processed in the United States, the European Union, or other locations where our sub-processors operate. Where required, we rely on Standard Contractual Clauses or an adequacy decision for transfers out of your home jurisdiction.
10. Changes to this policy
If we change this policy we will update the "Last updated" date above and, for material changes, notify you in-app before the change takes effect.
11. Contact
For any privacy question or request, email nativemason01@gmail.com.
Contact: nativemason01@gmail.com
· Operator: Amit Raina, independent developer, Singapore.