Skip to legal document

AllDoxie · alldoxie.com

Privacy Policy

Draft for legal review

Provisional and not adopted as a final policy. Every [CONFIRM: …] marks an unresolved fact or decision. No effective date has been assigned.

View inspection findings, signup wording, and prepublication checklist

1. Responsible business and scope

AllDoxie is operated by [CONFIRM: full company legal name and entity type], located in [CONFIRM: country and state or region], with a business address at [CONFIRM: address] ("AllDoxie," "we," "us," or "our"). Contact the business responsible for your information at [CONFIRM: monitored privacy contact and request method]. [CONFIRM: data protection officer or local representative, only if applicable].

This proposed Privacy Policy covers alldoxie.com and the application at app.alldoxie.com, together the "Service." [CONFIRM: common operator, covered apps, and any distinct services]. Effective date: [CONFIRM: adoption date and version]. This is a draft, not a finalized description of all processing. Reading or acknowledging a privacy notice is not consent to all uses of information.

The inspection verified website content and reviewed application materials, not all live application settings or provider contracts. The website directs account access to a separate application whose public login page is accessible; its signed-in practices were not verified. Feature descriptions below distinguish inspected implementation from matters requiring confirmation.

2. Information about owners and other people

Account materials contain email registration and sign-in, passwords submitted to the authentication service, and user records for name, email, account identifier, and role. These support authentication, account administration, and necessary communications. The separate live login page offers email/password and Google sign-in. [CONFIRM: registration fields, other enabled sign-in methods, required versus optional fields, and identity data returned by external providers]. This review does not establish how the authentication provider stores passwords.

Dog-profile records include owner name and state or region, family member names and relationships, and linked account identifiers. These are intended to identify the owner, associate family members with a dog, and support sharing. Information another user enters about you is a third-party source of personal information. [CONFIRM: invitation, notice, permission, correction, and removal procedures for named family members].

Posts, comments, reports, support correspondence, uploads, and AI messages can also contain information about people. Do not include unnecessary human health information, financial account information, identification documents, or other sensitive details. [CONFIRM: live communication channels and any sensitive-information categories actually collected].

3. Information about dogs

Reviewed dog-profile records support name, photo, birthday, gender, breed, coat color, weight, personality, energy level, preferences, biography, family associations, food, medication and prevention brands, and dose dates. Health records support weight history; veterinary visit date, type, provider, city, cost and notes; next visit dates; and attached reports or receipts. Reminder records include dog identifiers, medication type, frequency, due date, and dismissal or active status.

These fields are intended to provide profiles, organize care records, show weight trends, and support reminders or family access where those features are live. [CONFIRM: which fields are collected in production, which are required, how reminders are delivered, and whether any further dog information is obtained from third parties].

Dog information is not necessarily anonymous. A profile, photograph, veterinary receipt, location, or sharing relationship can identify or be linked to an owner or another person. We treat the associated personal information according to its actual context and applicable law, rather than assuming that animal records fall outside privacy protection.

4. Photos, documents, location, and messages

The reviewed veterinary form accepts reports or receipts and stores an uploaded file URL with the visit record. Profile and community records also contain image URLs. Files can reveal names, addresses, clinic details, people in photographs, and embedded metadata. Their purpose is to display the material or associate it with the record you choose. [CONFIRM: storage provider, public versus authenticated file access, metadata handling, permitted upload types, and file deletion]. Database permissions do not by themselves establish that a file URL is private.

Reviewed structured location fields include owner state or region and veterinary-visit city. This inspection did not establish use of GPS or precise device location. [CONFIRM: any precise-location collection, permissions, IP-derived location, and purposes]. Photos, notes, or receipts may reveal additional location even without a location feature.

Community posts and comments are distinct from AI conversations. AI conversation interfaces were found; private user-to-user direct messaging was not verified. [CONFIRM: live message types, recipients, moderation access, message retention, and any attachments sent to AI].

5. Automatically received information

Loading web pages and remotely hosted images or fonts sends network requests to the relevant hosts, which receive the requesting IP address and request information. The inspected website references Base44-hosted assets, Google Fonts, Unsplash images, and Instagram media URLs. These requests support page rendering; a recipient’s own retention and additional use require confirmation.

Reviewed product-link code records a product identifier and name, click time, placement, and source page. Stored records also have creation metadata that may link activity to an account. The stated feature purpose is product-click reporting. [CONFIRM: whether this tracking runs in production, account linkage, recipients, retention, and any use beyond aggregate reporting].

The application uses the Base44 client, but source inspection alone does not establish the complete production inventory of cookies, local storage, analytics, access logs, session recordings, device identifiers, referral data, or platform-injected tools. [CONFIRM: each automatic collection category, purpose, provider, retention, and user choice]. No claim that tracking is absent is made by this draft.

6. Information from third parties

If you use external sign-in, the identity provider supplies the information authorized in that flow. [CONFIRM: provider, exact fields and permissions, and account-linking behavior]. If another account holder links you to a dog or identifies you in a post, we can receive the information that person submits.

The website displays selected Instagram media and captions using cached media records with post identifiers, types, URLs, original timestamps, and links. This is a brand feed, not evidence that every user’s Instagram account is connected. [CONFIRM: authority to display identifiable people, treatment of removed source posts, and retention of cached media].

[CONFIRM: any payment confirmations, fraud signals, support records, veterinary imports, or other third-party data sources actually received]. Do not add a source or collection category solely because a provider could technically supply it.

7. Purposes and limits on use

Where the related features are live, the proposed purposes are: account information for sign-in and account administration; owner and dog details for profiles and requested sharing; health records and schedules for organization, trends, and reminders; community content for publication and moderation; product-click events for engagement reporting; and AI inputs for responding to a wellness question. External media requests render website content. Each purpose requires confirmation against actual operation.

Security investigations, abuse prevention, support, legal compliance, transaction administration, and service improvement may require additional processing only where actually undertaken on an appropriate legal basis. [CONFIRM: information used for each such purpose, necessity, access, and retention]. This is not authorization for unrestricted reuse.

Marketing, promotional publication of identifiable content, cross-context advertising, and AI model training are separate purposes addressed below. [CONFIRM: any profiling or solely automated decisions with legal or similarly significant effects, including logic, consequences, safeguards, and applicable rights]. Ordinary feature personalization should not be described as such a decision without evidence.

8. What other users and the public can see

Reviewed record rules distinguish owner/admin access, selected linked-account access to dog profiles, and broader reading of approved community posts and comments. These are implementation observations, not a verified promise of end-to-end privacy. [CONFIRM: live permissions, administrator access, logged-out/public visibility, linked-family access to health records, and every field displayed in each audience].

Publicly available posts, captions, photographs, or profile details can be copied, indexed by search engines, or retained by others. Share only what you intend that audience to see. [CONFIRM: available audience selectors, default settings, unlinking or revoking access, code expiration, and treatment of previously shared content]. No universal private-profile setting was verified.

A restricted record does not necessarily restrict its attached image or document URL. Confirm file permissions independently before relying on privacy settings. We cannot promise removal of independent copies held by others, but statutory privacy obligations still apply.

9. Recipients and service providers

Base44 is verified in the reviewed application as the platform client for stored records and integrations, with Base44-hosted assets present on the website. [CONFIRM: contracting legal entity, production hosting and authentication arrangements, storage and email services, provider roles, subprocessors, contractual protections, and processing countries]. Do not infer every underlying provider or certification from the platform name.

Google Fonts, Unsplash, and Instagram media hosts receive requests when their resources load. Google is offered as a sign-in option on the separate application. A provider can act as a service provider for some activities and as an independent business for others. [CONFIRM: each provider’s role and own-purpose processing]. Following external social or seller links subjects your interaction there to the recipient’s separate practices.

Other users receive information you publish or share, subject to verified access controls. Authorized personnel may require limited access for support, moderation, or operation. [CONFIRM: actual personnel access, recipient categories, and restrictions].

Payment, analytics, advertising, email, support, and AI providers must be listed or described according to their actual roles before finalization. [CONFIRM: provider inventory, data supplied, purposes, retention, contract limits, and whether each acts on our instructions or independently]. This draft does not name an unverified payment processor or model provider.

10. Cookies, analytics, and advertising choices

[CONFIRM: inventory of cookies, local storage and similar technologies, including names or categories, provider, purpose, duration, and whether required for requested functionality]. Authentication and optional measurement must be distinguished. The absence of a visible analytics script in reviewed page markup is not proof that no analytics or advertising technology runs.

Browser controls can block or clear cookies and site storage, potentially affecting sign-in or preferences. They do not necessarily stop server logs, external resource requests, or every form of tracking. [CONFIRM: working consent/preferences controls, blocking of nonessential tools before consent where required, withdrawal, and any applicable browser opt-out signal handling]. No operational cookie preference center was verified.

[CONFIRM: whether advertising, targeted advertising, cross-context behavioral advertising, or disclosures constituting a “sale” or “sharing” under applicable laws occur, including exchanges for nonmonetary value]. Do not interpret this draft as a “we never sell or share” representation. Add legally required notices and working opt-out mechanisms if the assessed practices trigger them.

11. AI processing and training

Reviewed wellness interfaces send user messages to a Base44 agent conversation. The reviewed agent is configured to read dog profiles and health-guide records and has memory enabled. Its ability to access a data category does not establish that every record is sent for every response. [CONFIRM: live availability, actual retrieved information, account isolation, memory behavior, retention, and human review].

If offered, AI processing uses relevant inputs to generate answers, and outputs become conversation content. Do not put unnecessary personal or sensitive information into a prompt. Generated answers are not veterinary advice. [CONFIRM: actual model/service providers and their legal identities, transmitted data, processing locations, provider retention and abuse monitoring, and available deletion controls]. A model selection in application settings does not establish provider contractual terms.

Inference to answer a question is distinct from using data to develop or train a model. [CONFIRM: whether AllDoxie or any provider uses messages, profiles, uploads, outputs, or memories for model training or product improvement; applicable defaults, opt-outs, permissions, and withdrawal consequences]. Do not claim that data is never used for training without verifying those practices. The Terms’ operating license is not permission for training.

12. Communications and promotional content

Reviewed application code includes welcome-email calls and reminder-related records and functions; successful delivery, production settings, and complete message categories were not verified. [CONFIRM: email providers, required service messages, optional reminders, marketing categories, lawful basis, and preference controls]. Marketing choices should not prevent necessary account, security, or legal messages, while messages genuinely classified as marketing must respect applicable choices.

The reviewed newsletter form collects an address in page state and displays a success message without a verified save or delivery operation in that form. This does not establish a functioning subscription, consent record, or unsubscribe process. [CONFIRM: whether another production implementation exists; otherwise implement or withdraw newsletter claims].

[CONFIRM: operational marketing unsubscribe method and suppression retention]. Promotional use of identifiable owner or dog content requires a separate assessment and, where appropriate, a specific permission describing the selected material, channels, purpose, duration, and withdrawal process. Publishing content in a community is not automatically permission to use it in advertising.

13. Retention and deletion

[CONFIRM: actual retention schedule for accounts; dog profiles and health records; photos and documents; posts, comments and reports; AI messages and memories; product-click events; access/security logs; support records; billing records; newsletter permissions; and cached social media]. For each category, specify a period or meaningful trigger and criteria—not only “as long as necessary.”

Proposed criteria for review include the duration of the requested account or feature, a documented inactivity period, completion of a support or moderation matter, a required tax or transaction period, and a specific unresolved legal claim. [CONFIRM: the actual period and necessity for each criterion]. Legal holds should be limited to relevant information, purpose-restricted, reviewed, and lifted when no longer justified.

The reviewed “Delete Account” action archives dog profiles and logs the user out; it does not demonstrate account or data erasure. Archiving is retention, not deletion. [CONFIRM: a real request channel, verification, deletion timelines, linked data and uploaded-file removal, provider deletion, and when backups expire]. Do not rely on that reviewed action as a complete deletion method.

Deletion from active systems may differ from removal from backups or recipients’ independent copies. [CONFIRM: backup cycle, access restrictions, re-deletion after restoration, and precise legal-retention exceptions]. Account closure does not itself establish subscription cancellation. We do not promise immediate or universal erasure where that has not been verified.

14. Privacy rights and requests

Depending on applicable law, you may have rights to know about or access your information, obtain a portable copy, correct inaccuracies, request deletion, restrict or object to processing, withdraw consent without affecting prior lawful processing, or opt out of specified uses or disclosures. Additional rights can apply to sensitive information or qualifying automated decisions. These rights are subject to the conditions and exceptions in the relevant law; the draft does not assume every right applies everywhere.

Submit a request through [CONFIRM: monitored privacy request channel]. Identify the request and relevant account without sending unnecessary identification or credentials. [CONFIRM: proportionate verification, response deadlines, recordkeeping, authorized-agent procedures, and accessibility arrangements]. An authorized agent may act where applicable law allows, with appropriate proof of authority and verification.

If a request is refused, provide reasons and any available appeal method: [CONFIRM: appeal channel and timing where required]. You may complain to the competent privacy or consumer regulator where applicable. [CONFIRM: relevant regulators and contact links once user jurisdictions are known]. Do not disadvantage users for exercising protected rights, except for differences lawfully permitted and properly disclosed.

15. Jurisdiction-specific disclosures and legal bases

[CONFIRM: where users live, applicable privacy laws, business thresholds, and whether jurisdiction-specific supplements are required]. No GDPR, CCPA, or other compliance claim is made by this draft.

If European, UK, or comparable legal-basis rules apply, map each actual purpose to a valid basis: steps requested before a contract or necessary performance; a specified legal obligation; a documented and balanced legitimate interest; or valid consent for an optional purpose. These are candidate bases for counsel to assess, not a declaration that every basis applies to every activity. Identify each legitimate interest, any required-information consequences, withdrawal method, and any additional condition for special-category information.

If relevant US state privacy laws apply, add the required collection/recipient/retention disclosures, applicable reporting periods, sensitive-data details, sale/sharing or targeted-advertising assessment, consumer rights, appeals, and opt-out controls. [CONFIRM: required notice at collection and any incentive-program disclosures].

16. International processing

[CONFIRM: countries in which AllDoxie, its staff, and each provider store or access personal information]. Information may cross a border through hosting, remote support, authentication, or media and AI requests only to the extent those arrangements actually operate.

Where cross-border safeguards are legally required, identify the verified mechanism for each relevant transfer and how a user can obtain information or a copy: [CONFIRM: applicable adequacy decision, executed contractual clauses, additional safeguards, or other lawful mechanism]. Do not assume encryption, a provider contract, or mere use of the Service establishes a lawful transfer.

17. Children’s privacy

Intended audience and minimum age: [CONFIRM: countries, permitted ages, and whether children are likely to access the Service]. [CONFIRM: actual age checks, parental authorization where needed, treatment of child family members named in dog profiles, and procedures for information submitted by or about children].

An age restriction alone does not resolve children’s privacy obligations. If information has been collected contrary to applicable requirements, contact [CONFIRM: monitored child-privacy contact] so the matter can be investigated and appropriate action taken. [CONFIRM: response, parental verification, deletion, and safeguarding procedures]. This draft makes no unverified claim that no child information is collected.

18. Security

Reviewed application materials include sign-in and record-level access rules. Inspection of those materials is not a security audit and does not verify all deployed permissions, uploaded-file access, administrative practices, or provider controls.

[CONFIRM: security practices actually implemented, such as access review, staff authorization, patching, backup protection, incident response, and encryption only if verified]. Describe supported measures accurately without claiming certifications or guaranteed prevention of access, loss, or misuse. No system can promise absolute security. [CONFIRM: security-reporting contact and applicable incident-notification process].

19. Legal disclosures, business transfers, and updates

Where permitted or required by applicable law, relevant information may be disclosed in response to a valid legal obligation, to establish or defend a legal claim, or to address a serious safety or security issue. Requests and disclosures should be assessed and limited to what is justified. [CONFIRM: actual request-review and user-notice procedures].

If the business is reorganized, sold, merged, or involved in insolvency proceedings, relevant information may be reviewed or transferred subject to applicable law, appropriate confidentiality restrictions, and required notice or consent. A transfer does not authorize unrestricted new uses or remove existing privacy rights.

Finalized policy changes must have a version and effective date and accurately describe the practices at that time. [CONFIRM: notice method, advance notice for material changes where required, and obtaining new permission when legally necessary]. Posting an updated policy does not retroactively supply consent or make a new use lawful. Privacy questions and requests: [CONFIRM: company name, mailing address, and monitored privacy contact].