Complete before public release
Replace the three placeholders below with the real publisher details and use a monitored privacy email address.
Data controller
- Legal name: [TO BE COMPLETED]
- Postal address: [TO BE COMPLETED]
- Privacy email: [TO BE COMPLETED]
1. Summary
BreedPeek processes only the data needed to create an account, analyze the photos selected by the user, maintain a private scan history, and manage Premium access. Photos are not used for advertising, cross-app tracking, or facial recognition. The app contains no advertising SDK.
2. Data processed
- Account: email address, Supabase user ID, and authentication data. If Google sign-in is used, Google may provide a name, email address, and profile image. BreedPeek never has access to the user's plain-text password.
- Scans: the selected or captured photo, optional question, analysis result, date, status, and scan history. A photo may reveal people or places; users should only submit images they are authorized to use.
- Usage and security: scan attempts, quota information, technical identifiers, IP address, and logs strictly needed for operation, abuse prevention, and troubleshooting.
- Subscription: user identifier, available products, Premium status, and purchase history supplied by RevenueCat and the app store. BreedPeek does not receive bank card details.
- On the device: selected language and theme.
3. Purposes and legal bases
Data is used to create and secure the account, provide the requested visual analysis, answer an optional question, display the private history, enforce quotas, prevent abuse, manage Premium access, and respond to privacy requests.
Contract performance covers account creation, analysis, history, and subscriptions. The publisher's legitimate interests cover security, reliability, abuse prevention, and quotas without advertising profiling. Legal obligations cover rights requests and applicable transaction records. Camera or photo library access depends on the user's choice in the device settings.
4. Providers and recipients
- Supabase provides authentication, database services, private storage, and server functions. The project's main data is hosted in Ireland (
eu-west-1). - OpenAI temporarily receives the resized photo and any optional question to produce the estimate. Requests use the Responses API with
store=false. OpenAI states that API data is not used to train its models unless the API account holder has explicitly opted in to data sharing. - RevenueCat receives the account identifier and the product, transaction, and entitlement information needed for in-app purchases.
- Google is involved only if the user chooses Google sign-in. Apple or Google Play processes payment and purchase history depending on the device.
Personal data is not sold or shared with advertising networks.
5. International transfers
Although the main Supabase data is hosted in the European Union, some providers or subprocessors may process data outside the European Economic Area. Where required by the GDPR, these transfers rely on an adequacy decision, Standard Contractual Clauses, and any appropriate supplementary measures. Applicable safeguards may be requested through the privacy contact.
6. Retention periods
- The account, profile, photos, questions, results, and history are kept until the related scan or account is deleted. The quota record is kept until account deletion.
- Photo access URLs expire after 60 seconds for the OpenAI analysis and after 15 minutes for display in the app.
- With
store=false, OpenAI does not retain application state for the response. Abuse-monitoring logs may still include submitted content for up to 30 days, unless longer retention is required for legal or security reasons. Images are also subject to automated safety checks, and potentially illegal content may be retained longer for review. - Local preferences remain on the device until cleared or the app is uninstalled.
- After deletion, restricted technical backup copies may remain during backup rotation for up to 30 days. Stores and RevenueCat may retain transaction evidence as required by law.
7. Device permissions
Camera access is used only when the user chooses to photograph a dog. The photo picker is used only to select the specific image chosen by the user. BreedPeek does not request location, microphone, or contacts access and does not scan the photo library in the background. Permissions can be withdrawn in the device settings.
8. Security
Network communications are encrypted. Images are resized before transmission, stored in a private area, isolated by account, and accessed through temporary links. Database and storage access rules limit each user to their own data. Sensitive functions require an authenticated session. No online service can guarantee zero risk.
9. User rights
Depending on the situation, users may request access, correction, deletion, restriction, objection, and portability, and may withdraw consent where a processing activity relies on consent. A response is normally provided within one month. Users may also lodge a complaint with the CNIL or the supervisory authority in their country of residence. Proof of identity is requested only where there is reasonable doubt about identity.
10. Deletion
A photo and its result can be deleted from the scan screen. Under Profile, Delete account deletes the private images, profile, history, questions, results, and quota record associated with the account.
Account deletion does not automatically cancel an active subscription. The subscription must first be cancelled through the App Store or Google Play. Some purchase records may remain with the store or RevenueCat to meet legal obligations.
11. Children and photo content
BreedPeek is not specifically directed at children. Where required by law, a minor should use the service only with permission and supervision from a parent or legal guardian. Users should not upload a photo showing a child or another identifiable person. BreedPeek does not perform facial recognition.
12. Changes and contact
This policy may be updated if features, providers, or applicable law change. The date at the top identifies the current version. Material changes will be announced in the app or through another appropriate channel where required by law.
To exercise a privacy right, contact the privacy email listed above and include the request and the email address associated with the account. Never send a password, API key, or identity document unless it has been specifically requested after an identity concern.