Nevada Consumer Health Data Privacy Policy
Effective date: August 14, 2026
This policy applies to AvoPet users who reside in Nevada or whose consumer health data is collected in Nevada, to the extent Nevada NRS 603A.400 through 603A.550 applies. For information about AvoPet’s other personal information practices, see the “AvoPet Privacy Policy.” AvoPet is not a medical provider or medical service and does not claim to be a HIPAA-covered entity.
1. Purpose of This Policy
This notice explains how AvoPet collects, uses, shares, stores, and deletes consumer health data, and how consumers may exercise rights, under Nevada’s consumer health data laws (NRS 603A.400–603A.550). It applies only where Nevada law applies and does not mean Nevada law governs every user worldwide.
2. Categories of Consumer Health Data
AvoPet may process the following categories of consumer health data. Because Nevada’s definition of consumer health data can include information processed to associate or identify health information, linking and administrative information is also listed below.
Profile, body, and diet-related information
- Gender
- Age range
- Diet goal
- Optional current weight
- Optional target weight
- Optional post-meal mood
- Optional setback factors and notes
Meal-related information
- Meal photos taken directly with the camera
- Meal type
- Meal date
- Meal verification and determination information
Analysis and inferences
- AI meal evaluation
- Nutritional-balance feedback
- Analysis of weight and meal changes
Linking and administrative information
- Supabase UUID used to associate health records with a specific user
- Health data consent and withdrawal records
- Health data rights requests and processing history
AvoPet does not send meal photos, health profile information, current or target weight, post-meal mood, setback factors, notes, meal determinations, AI feedback results, or the Supabase user UUID to AdMob as ad-request targeting values or custom parameters. Separately, identifiers used to link or administer consumer health data are included in this category for transparency.
AvoPet does not collect the following:
- Photos selected from your gallery
- Medical diagnosis or prescription records
- Genetic information
- Biometric information
- Precise location information used to identify visits to healthcare facilities
The Google Mobile Ads SDK may separately process information such as an IP address, approximate location, device or advertising identifiers, advertising data, app and ad interactions, and performance or diagnostic information for ad delivery, measurement, and fraud prevention. The actual scope may vary depending on the device settings, iOS privacy settings, SDK configuration, and Google’s policies.
3. Sources of Information
- Information you enter in your profile or meal diary
- Meal photos you take directly with the camera
- Meal determinations, diary entries, and analysis generated while you use the app
- OpenAI meal-analysis results
- User linking, consent, and rights-request records managed through Supabase
AvoPet does not buy or receive consumer health data from data brokers or third-party marketing companies.
4. Purposes of Collection and Use
AvoPet collects and uses consumer health data for the following purposes:
- Setting health-related profiles and diet goals
- Meal verification
- AI meal analysis and feedback
- Meal diary and weight-change analysis
- Feeding your AvoPet based on meal records
- Managing health data consent and withdrawal
- Processing consumer rights requests
- Security, access control, and abuse prevention
- Complying with legal obligations
AvoPet does not use consumer health data for the following purposes:
- Personalized advertising
- Providing data to data brokers
- Independent third-party marketing
- Selling consumer health data
5. How Processing Works and External Services
When you use meal verification, consumer health data is generally processed as follows:
- The meal photo is uploaded to private Supabase Storage.
- A Supabase Edge Function downloads the photo directly from Storage.
- The photo is converted into image data that can be sent to the OpenAI API.
- Only the meal image data, gender, age range, and diet goal are sent to OpenAI.
- The OpenAI analysis result is saved in Supabase and in the app.
Information not sent to OpenAI
- Supabase UUID
- Signed URL
- Storage path
- Nickname
- Email address
- Pet name and gameplay information
- Full meal diary history
- Customer support email content
AvoPet sends OpenAI API requests with store set to false and does not send the Supabase user UUID or Storage paths or separately retain an OpenAI response ID. Setting store to false does not constitute Zero Data Retention. OpenAI may retain limited information for safety, abuse prevention, or legal obligations for the periods described in its applicable policies.
The external services that process the app’s health content—such as meal photos, health profile information, and meal records—are Supabase and OpenAI. They act as processors or service providers that process data to provide services AvoPet requests. AvoPet does not treat them as third-party sale or marketing recipients that independently use consumer health data.
| Service | Role | Categories that may be processed |
|---|---|---|
| Supabase Inc. | Authentication linking, database, private photo storage, Edge Functions, and consent and request records | User UUID, profile health information, meal records and photos, AI results, weight and diary data, and consent and request history |
| OpenAI, L.L.C. | AI analysis of meal images you request | Meal image data, gender, age range, and diet goal |
- AvoPet has no affiliates.
- AvoPet does not send meal photos, health profile information (gender, age range, or diet goal), current or target weight, post-meal mood, setback factors, notes, meal determinations, AI feedback results, or the Supabase user UUID to AdMob as ad-request targeting values or custom parameters.
- For its initial iOS release, AvoPet does not request ATT authorization or access to the IDFA, and configures AdMob requests for non-personalized ads only. Before requesting ads, the app updates UMP consent information and checks canRequestAds.
- AvoPet does not disclose health profile or meal content to Apple account linking or Google account linking.
6. Third-Party Collection Over Time or Across Sites
AvoPet does not allow a third party to collect consumer health data over time or across different websites or online services through AvoPet’s website or app. Even when ads are requested as non-personalized, the Google Mobile Ads SDK may process an IP address, approximate location, app- or device-scoped identifiers, advertising and app interactions, and performance or diagnostic information for ad delivery, measurement, frequency capping, and fraud prevention. AvoPet does not provide meal photos, health profile information, weight, mood, meal determinations, AI feedback results, or the Supabase user UUID as targeting values or custom parameters for that advertising processing.
7. Consent to Process Health Data
- After the first-launch story ends and before you enter a profile, AvoPet shows a health data consent screen.
- If you do not consent, you can still adopt a pet and use general gameplay features.
- Without consent, health profile, feeding, meal verification, meal diary, and analysis features are restricted.
- You can withdraw consent or consent again in Settings.
- If you withdraw consent, AvoPet stops future health data collection and AI analysis.
- Existing data is not automatically deleted when you withdraw consent.
- Existing data is deleted through a separate health data deletion request or account deletion.
Health data is retained until your account is deleted or a separate health data deletion request is completed. Withdrawing consent stops future collection and AI analysis but does not automatically delete existing data.
If AvoPet adds new categories of information, new processing purposes, or new sharing recipients, AvoPet will provide any notice required by Nevada law and obtain voluntary consent. AvoPet does not sell consumer health data today and does not claim that a separate sale-consent or sharing-consent screen already exists beyond what is currently implemented.
8. No Sale, No Ad Targeting, and No Geofencing
- AvoPet does not sell consumer health data.
- AvoPet does not send meal photos, health profile information (gender, age range, or diet goal), current or target weight, post-meal mood, setback factors, notes, meal determinations, AI feedback results, or the Supabase user UUID to AdMob as ad-request targeting values or custom parameters, and does not use that information for health-based personalized advertising.
- For its initial iOS release, AvoPet does not request ATT authorization or access to the IDFA, and configures AdMob requests for non-personalized ads only.
- AvoPet does not provide consumer health data to data brokers.
- AvoPet has no affiliate sharing.
- AvoPet does not use geofencing to collect consumer health data around healthcare facilities or to send health-related advertisements.
Because AvoPet does not sell consumer health data, AvoPet does not currently use a consumer health data sale authorization form.
9. Rights of Nevada Consumers
Where applicable, consumers may request the following under Nevada law:
- Confirm whether AvoPet collects, shares, or sells consumer health data
- Obtain a list of entities with which consumer health data has been shared or sold
- Request that future collection, sharing, or sale stop
- Request deletion of consumer health data
- Appeal a refused request
- Not be discriminated against for exercising these rights
Because AvoPet does not sell consumer health data, there is no list of sale recipients. The external services that currently process the app’s health content for requested services are Supabase and OpenAI.
The app may also let you review access results and edit your profile or meal diary. Those are product features and are not presented as additional statutory rights beyond Nevada law.
10. How to Submit a Request
The primary request method is the health data request feature in app Settings, which authenticates you with your current Supabase session. AvoPet does not require you to create a new account to exercise these rights, and your existing app session may be used for authentication.
Supported in-app requests include:
- Access your health data
- Delete health data
- Appeal a refused request
In the app, you can review request status, the operator’s response, and access results. Supplemental contact methods are email at avopet.support@gmail.com and phone at +82 10-4491-7410. If an email request is not authenticated, AvoPet may ask only for the minimum additional information needed to verify your identity.
For instructions on submitting a request and managing your privacy choices, see Privacy Choices.
11. Nevada Response Timeframes
The timeframes below apply only to requests covered by this Nevada consumer health data notice. They do not mean every AvoPet personal information request is answered within 45 days.
- Authenticated requests receive a response without undue delay and no later than 45 days after authentication.
- If reasonably necessary because of the complexity of the request and the number of requests from the same consumer, AvoPet may extend the period by up to an additional 45 days.
- If extended, AvoPet will notify you of the extension and the reason within the first 45 days.
- Health data deletion is completed in operational databases and Storage within 30 days after authentication.
- Where required by applicable law, AvoPet may notify OpenAI of an authenticated health-data deletion request through OpenAI’s official support or privacy-request channels. AvoPet does not claim that an automated API deletion notice is already implemented, and does not represent that such notice automatically results in the immediate deletion of records that OpenAI may retain for security, abuse-prevention, or legal purposes.
- Appeals receive a written response within 45 days after receipt.
- Information provided in response to a request is provided free of charge as required by law. Where permitted by law, we may charge a reasonable fee for requests that are manifestly unfounded, excessive, or repetitive.
12. Deletion Scope and Account Deletion
Health data deletion is a separate function from full account deletion.
Health Data Deletion
When an authenticated health-data deletion request is processed, a health-data deletion Edge Function deletes the requested health data directly from AvoPet’s operational Supabase database and Storage. The request is marked completed only after that deletion succeeds. The health data covered by the request—including any results previously provided in response to a data access request—is deleted. The items deleted or reset include:
- Meal photos in Storage
- Meal records
- Meal diary entries
- Verification attempt records
- Gender
- Age range
- Diet goal
- Target weight
- Current weight
- Health data results previously provided through an access request
- Any other health data payloads or attachments covered by the deletion request
- Existing health-data processing consent history (upon successful deletion)
While a health-data deletion request is being processed, the existing consent status remains in effect. Once the requested health data has been successfully deleted and the request is completed, AvoPet also deletes the existing health-data processing consent history and resets the health-data consent status to not consented. AvoPet does not create a new withdrawn or declined consent record solely to record the deletion. If the user later opens a health feature, the consent screen is shown, and a new consent record is created only if the user consents again.
The following items are retained:
- Supabase Auth account
- Nickname
- Pet
- Collection entries
- Adoption rights
- Gameplay data
- Limited request-processing information, such as request ID, request type, submission and completion times, and processing status
To document the handling of privacy-rights requests and comply with legal obligations, AvoPet may retain limited request-processing information, such as the request ID, request type, submission and completion times, and processing status. This record does not contain deleted health data, access results, attachments, Storage paths, signed URLs, OpenAI response IDs, or the previous health-data processing consent history. AvoPet may retain it only to confirm how requests were handled and to respond to appeals. It is not used to infer health status, provide health features, advertise, or market to the user.
Full Account Deletion
Full account deletion removes photos, the user’s database records—including request-processing records—and the Supabase Auth user in sequence, then resets to a new anonymous session.
Data remaining in backups is not reused to operate the service and, under AvoPet’s current operating standard, is deleted within a maximum of six months. AvoPet does not treat a longer backup period that Nevada law may allow as AvoPet’s actual retention period.
13. Appeals and the Nevada Attorney General
If a request is refused, you may use the in-app appeal feature. Appeal results are provided in writing within 45 days after receipt. If an appeal is also refused, AvoPet will explain the reason and how you may contact the Nevada Attorney General or file a complaint. Official complaint guidance is available at https://ag.nv.gov/Complaints/CSU_Complaints___FAQ/.
14. Notice of Material Changes
- If there is a material change to the categories, sources, purposes, sharing recipients, or processing methods for consumer health data, AvoPet will update this page.
- Material changes may also be announced in the app or on the website.
- The updated effective date will appear on this page.
- If the law requires additional consent for a change, AvoPet will obtain that consent before starting the changed processing.
15. Contact
- Data Controller: WonGyu Jang
- Privacy Officer / Data Protection Officer: WonGyu Jang
- Location: Republic of Korea
- Email: avopet.support@gmail.com
- Phone: +82 10-4491-7410
16. Effective Date
Effective date: August 14, 2026
