Privacy Policy
Effective date: August 14, 2026
This Privacy Policy explains how AvoPet (“AvoPet,” “we,” or “us”) collects, uses, stores, shares, and deletes personal information and diet-related information. It applies to the AvoPet iOS app and the official AvoPet website.
1. About This Privacy Policy
AvoPet helps you log meals and raise a virtual pet while building healthier eating habits. It is intended for users in the Republic of Korea, the United States, Australia, New Zealand, and Singapore. This policy is based on how AvoPet actually processes information today.
AvoPet is not a medical provider and does not offer medical services. AI meal feedback is general information for reference only and is not a substitute for diagnosis, treatment, or professional medical advice. AvoPet does not use AI outputs to make automated decisions that produce legal or similarly significant effects.
The app does not offer a traditional email-and-password sign-up. When you open the app, AvoPet automatically creates a Supabase anonymous authentication user UUID. You may optionally link a Google or Apple account to protect and restore your data. If you choose to link an account, an email address may be processed. If you use Apple’s Hide My Email feature, an Apple private relay email address may be stored.
The official website does not include sign-up, sign-in, community, or payment features. There is no in-site support form; you can contact us directly at avopet.support@gmail.com. The website stores an avopet_locale cookie on your device to remember your language choice. The website does not currently use its own analytics or advertising tracking tools.
The official AvoPet website uses Cloudflare Pages and Cloudflare’s content-delivery and security services. When you visit the website, information such as your IP address, requested URL or path, access time, browser, device, operating-system or system information, traffic-routing information, and error, performance, or security logs may be processed automatically. This is done to host and deliver the website, help protect against security threats and abuse, and analyze or respond to service incidents. It does not mean AvoPet has installed its own analytics or advertising tracking tools on the website.
2. Information We Process and Why
The information AvoPet processes, and why we process it, is described below. Required information is needed to provide the service. Optional information is processed only if you choose to provide it. Health-related information—such as gender, age range, diet goal, target weight, meal photos, meal records, meal diary entries, and AI feedback—is collected and used only after you consent to health data processing.
Account and identifiers
- Supabase Auth user UUID
- Anonymous user session
- Optional Google or Apple linked email address
- Active session identifiers
Purpose: distinguish user data, restore data, manage sign-in on other devices, and support security and access control
Profile information
- Nickname
- Gender
- Age range
- Diet goal
- Optional target weight
- Optional personal commitment
Purpose: display your profile and provide personalized meal feedback and in-app features
Diet and health-related information
- Meal photos taken with the camera
- Meal type and date
- AI meal evaluation results and feedback
- Optional current weight
- Optional notes about post-meal mood and setbacks
Purpose: meal verification, the meal diary, analysis of weight and diet changes, and AI feedback
AvoPet does not claim to collect medical records. We treat the items above as health- and diet-related information. Meal verification uses only photos you take with the camera. AvoPet does not collect photos from your gallery.
Gameplay information
- AvoPet nickname
- Growth stage and affection
- Collection entries
- Items and in-game currency
- Activity records
Purpose: raise your AvoPet and save or restore gameplay progress
Device and advertising information
- App language
- Notification settings
- Device time zone identifier (IANA time zone ID, such as Asia/Seoul or America/Los_Angeles)
- Local device identifier
- IP address
- Device or advertising identifiers
- Ad impressions and interactions
- Performance and diagnostic information
Purpose: keep language and notification settings, determine available meal time windows and schedule notifications according to the device’s local time, serve and measure ads, limit ad frequency, help prevent abuse, and maintain service stability
App language, notification settings, the device time zone identifier, and the local device identifier may be read or stored by the AvoPet app on your device. The device time zone identifier is used to determine available meal time windows and schedule notifications, and it may be sent to Supabase RPCs and the meal-evaluate processing flow. It is not precise location or GPS data. IP address, device or advertising identifiers, ad impression and interaction data, and performance or diagnostic information are not information AvoPet asks you to enter. They may be processed by third-party SDKs such as the Google Mobile Ads SDK. The actual scope can vary based on your device settings, iOS privacy settings, SDK configuration, and the provider’s policies.
3. How We Collect Information
AvoPet may collect or process information in the following ways:
- You enter information in your profile and meal diary.
- You take a meal photo with the camera for meal verification. Photos selected from your gallery are not used.
- Gameplay information such as pet growth, collection entries, and items is created automatically as you use the app.
- Anonymous authentication is created when the app launches. A Google or Apple account is linked only if you choose to link one.
- The app may read the device time zone identifier (IANA time zone ID) to determine available meal time windows and schedule notifications. That identifier may be sent to Supabase RPCs and the meal-evaluate processing flow. It is not precise location or GPS data.
- Third-party SDKs such as Google AdMob may automatically process information for advertising and related purposes.
- You may email avopet.support@gmail.com for support.
- If you choose a language on the website, an avopet_locale cookie is stored on your device.
- When you visit the official website, access, security, and performance-related information may be processed automatically through Cloudflare’s network.
Health Data Consent
On first launch, after the story ends and before you enter a profile, AvoPet shows a separate health data consent screen. That screen explains the health-related information we process, the purposes of processing, processing by Supabase and OpenAI, that we do not sell health data or use it for personalized advertising, and what happens if you refuse or withdraw consent.
- If you do not consent, you can still adopt a pet and use general gameplay features that do not rely on health features.
- Without consent, health profile entry, feeding, meal verification, the meal diary, and analysis features are restricted.
- You can withdraw or give consent again in Settings.
- If you withdraw consent, AvoPet stops collecting new health data and stops AI meal analysis going forward.
- Withdrawing consent does not automatically delete existing health data.
- Existing health data is deleted when a separate health data deletion request is completed or when your account is deleted.
Health data is retained until your account is deleted or a separate health data deletion request is completed. Withdrawing consent stops future collection and AI analysis but does not automatically delete existing data.
4. AI Meal Analysis
If you use meal verification, the meal photo you take is used for AI analysis. The process works as follows:
- You take a meal photo with the in-app camera.
- The photo is uploaded to private Supabase Storage.
- A Supabase Edge Function downloads the photo directly from private Storage.
- The Edge Function converts the downloaded photo into image data that can be sent to the OpenAI API.
- Only the meal image data and the gender, age range, and diet goal needed for analysis are sent to OpenAI.
- The OpenAI analysis result is saved in the app and in your meal records.
Information sent to OpenAI
- Meal image data
- Gender
- Age range
- Diet goal
Information not sent to OpenAI
- Supabase user UUID
- Supabase signed URL
- Supabase Storage path
- Nickname
- Email address
- Pet name and pet information
- Collection, items, and other gameplay information
- Your full meal diary history
- Customer support email content
AI results are not medical diagnoses or treatment advice, and they do not make a definitive assessment of your health.
AvoPet sends OpenAI API requests with store set to false and does not send the Supabase user UUID or Storage paths or separately retain an OpenAI response ID. Setting store to false does not constitute Zero Data Retention. OpenAI may retain limited information for safety, abuse prevention, or legal obligations for the periods described in its applicable policies.
Data sent to the OpenAI API is not used to train OpenAI models by default, unless you separately agree to data sharing. AvoPet does not claim that Zero Data Retention currently applies. Under OpenAI’s default API data-processing settings, request data may be retained for a period of time for purposes such as safety and abuse prevention, and exceptions may apply. The exact third-party retention terms follow OpenAI’s API data policy in effect at the time.
When required by applicable law, AvoPet uses OpenAI’s official support or privacy-request channels to notify OpenAI of an authenticated health-data deletion request, and may keep limited operational records of that notice or related handling. AvoPet does not represent that such notice automatically results in the immediate deletion of records that OpenAI may retain for security, abuse-prevention, or legal purposes, and does not claim that an automated API deletion notice is implemented. Supabase operational database and Storage deletions are performed directly by an Edge Function, while OpenAI is handled through official channels where required.
5. Third-Party Services and International Processing
AvoPet uses the third-party services below to operate the app and website. Some information may be processed outside the Republic of Korea. AvoPet does not claim that all data is stored only in a particular country, or that third parties delete data immediately. The external services that process the app’s health content—such as meal photos, health profile information, and meal records—are Supabase and OpenAI. AvoPet does not send meal photos, health profile information, meal or weight content, or the Supabase user UUID to Apple account linking, Google account linking, or AdMob as ad-request targeting values or custom parameters.
AvoPet requires third-party service providers that process or receive personal information to provide the same or equivalent level of protection required by this Policy and applicable law.
| Provider | Purpose | Information that may be processed | Country or primary storage region | When and how | Retention |
|---|---|---|---|---|---|
| Supabase Inc. | Anonymous authentication, Google and Apple account linking, database, private photo storage, Edge Functions | Account UUID, profile, meal records, photos, device time zone identifier (IANA time zone ID), gameplay progress | Primary storage region: Northeast Asia (Seoul), ap-northeast-2. Operations and support data may be processed in other countries under the provider’s policies and subprocessor arrangements | Encrypted transmission over the network when you use the app. The device time zone identifier may be sent to Supabase RPCs and the meal-evaluate processing flow | Until account deletion, completion of a health data deletion request, or the purpose of processing for each item is fulfilled |
| OpenAI, L.L.C. | AI analysis of meal photos | Meal image data, gender, age range, diet goal | The United States and other countries where OpenAI operates its services | When a meal analysis request is made, an Edge Function downloads the image from Storage, converts it, and sends it over an encrypted network | For the period set by OpenAI’s API data policy |
| Google LLC (Google Sign-In) | Optional account authentication and data restoration | Email address, authentication tokens, and account identifiers | The United States and other countries where Google operates its services | Processed only if you choose to link a Google account. Health profile and meal content are not disclosed | While the account remains linked, and according to Google’s policies |
| Google LLC (Google AdMob) | Ad serving, frequency control, ad performance measurement, and abuse prevention | IP address, approximate location, device identifiers, advertising data, ad and app interactions, performance and diagnostic information | The United States and other countries where Google operates its services | May be processed by the SDK when ads are loaded or shown. AvoPet does not send meal photos, health profile information, current or target weight, post-meal mood, setback factors, notes, meal determinations, AI feedback results, or the Supabase user UUID to AdMob as ad-request targeting values or custom parameters | According to Google’s advertising and privacy policies |
| Apple Inc. | Optional account authentication and data restoration | Email address or private relay email, authentication tokens, and account identifiers | The United States and other countries where Apple operates its services | Processed only if you choose to link an Apple account. Health profile and meal content are not disclosed | While the account remains linked, and according to Apple’s policies |
| Cloudflare, Inc. | Hosting and delivering the official website, maintaining security, preventing abuse, and responding to service incidents | IP address, requested URL or path, browser, device, operating-system or system information, and access, traffic, error, and security logs | The United States and other countries where Cloudflare operates its global network | Automatically through network communications when a visitor accesses the official website | For periods determined by Cloudflare’s policies, AvoPet’s service configuration, and applicable law |
Google Sign-In
Google Sign-In is used only if you choose to link an account. An email address, authentication tokens, and account identifiers may be processed for authentication and data restoration. AvoPet does not disclose health profile or meal content to Google account linking.
Google AdMob
Google AdMob may be used to serve ads, manage frequency, measure ad performance, and help prevent abuse. For its initial iOS release, AvoPet does not request App Tracking Transparency (ATT) authorization or access to the IDFA, and configures its AdMob requests for non-personalized ads only. AvoPet does not send meal photos, health profile information (gender, age range, or diet goal), current or target weight, post-meal mood, setback factors, notes, meal determinations, AI feedback results, or the Supabase user UUID to AdMob as ad-request targeting values or custom parameters.
Even when ads are requested as non-personalized, the Google Mobile Ads SDK may process an IP address, approximate location, app- or device-scoped identifiers, advertising and app interactions, and performance or diagnostic information for ad delivery, measurement, frequency capping, and fraud prevention. The actual scope may vary depending on the device settings, iOS privacy settings, SDK configuration, and Google’s policies.
Sign in with Apple
Sign in with Apple is used only if you choose to link an account. An email address or Apple private relay email, authentication tokens, and account identifiers may be processed for authentication and data restoration. AvoPet does not disclose health profile or meal content to Apple account linking.
Cloudflare
The official website uses Cloudflare Pages and Cloudflare’s content-delivery and security services. When a visitor accesses the website, an IP address, requested URL or path, browser, device, operating-system or system information, and access, traffic, error, or security logs may be processed automatically. Processing may occur in the United States and other countries where Cloudflare operates its global network. AvoPet does not claim that all of this information is stored only in the United States.
Supabase operations and support data may be processed outside the primary storage region under the provider’s policies and subprocessor arrangements.
6. Retention and Deletion
AvoPet keeps information only for as long as needed for the purposes described in this policy. Information is deleted through our deletion procedures when your account is deleted, when a health data deletion request is completed, or when the purpose of processing no longer applies. If a law requires retention, we keep the information for that legally required period. Operational backups may retain data for a limited time before it is deleted or overwritten.
Health data is retained until your account is deleted or a separate health data deletion request is completed. Withdrawing consent stops future collection and AI analysis but does not automatically delete existing data.
- Account, nickname, and gameplay data: until account deletion or the purpose of use is fulfilled
- Health data (including meal photos, meal records, meal diary entries, and related profile fields): until account deletion or a separate health data deletion request is completed
- Uploaded photos for failed verification, unrecognized meals, duplicate verification, or verification outside the allowed time window: deleted during server processing
- Customer support emails: deleted after the inquiry is resolved, unless a legal retention obligation applies
- Website language cookie (avopet_locale): up to one year, or until you delete it in your browser
- Local in-app settings: until you reset settings or delete the app
Health Data Deletion
Health data deletion is a separate function from full account deletion. When an authenticated health-data deletion request is processed, a health-data deletion Edge Function deletes the requested health data directly from AvoPet’s operational Supabase database and Storage. The request is marked completed only after that deletion succeeds. The health data covered by the request—including any results previously provided in response to a data access request—is deleted. The items deleted or reset include:
- Meal photos in Supabase Storage
- Meal records
- Meal diary entries
- Meal verification attempt records
- Gender in your profile
- Age range
- Diet goal
- Target weight
- Current weight
- Health data results previously provided through an access request
- Any other health data payloads or attachments covered by the deletion request
While a health-data deletion request is being processed, the existing consent status remains in effect. Once the requested health data has been successfully deleted and the request is completed, AvoPet also deletes the existing health-data processing consent history and resets the health-data consent status to not consented. AvoPet does not create a new withdrawn or declined consent record solely to record the deletion. Health-related local caches in the app are also cleared, and the consent or profile-entry screen is not shown automatically immediately after deletion. If the user later opens a health feature, the consent screen is shown, and a new consent record is created only if the user consents again.
The following items remain after health data deletion:
- Your Supabase Auth user account
- Nickname
- Pet
- Pet name
- Collection entries
- Adoption rights
- Items and gameplay progress
- Limited request-processing information, such as request ID, request type, submission and completion times, and processing status
To document the handling of privacy-rights requests and comply with legal obligations, AvoPet may retain limited request-processing information, such as the request ID, request type, submission and completion times, and processing status. This record does not contain deleted health data, access results, attachments, Storage paths, signed URLs, OpenAI response IDs, or the previous health-data processing consent history. It is retained only to confirm how requests were handled and to respond to appeals, and it is not used to infer health status, provide health features, advertise, or market to the user.
Full Account Deletion
If you request full account deletion in the app, AvoPet deletes information linked to your account—including administrative request records—and then resets to a new anonymous session. Deletion is generally handled in this order:
- Delete photos under meal-photos/{userId}/
- Delete the user’s database records
- Delete the Supabase Auth user
- Reset to a new anonymous session
7. Your Rights and How to Exercise Them
You may request access, correction, deletion, withdrawal of consent, or restriction of processing, and you may raise complaints about how your personal information is handled.
- Access your personal information
- Correct inaccurate information
- Delete your information
- Restrict processing or withdraw consent
- Ask questions or raise a complaint about our handling of personal information
Health Data Requests
The app settings include a health data request feature that authenticates you with your current Supabase session. Authenticated in-app requests are the primary way to access health data, delete health data, or appeal a refused request.
- Access your health data
- Delete health data
- Appeal a refused request
In the app, you can review the status of your request, the operator’s response, and materials provided when an access request is completed.
Other Ways to Exercise Your Rights
- Editing your profile and meal diary in the app
- Withdrawing or re-granting health data consent in Settings
- Using full account deletion in Settings
- Emailing avopet.support@gmail.com for supplemental support and general personal information requests
- Calling +82 10-4491-7410 for privacy-related inquiries
Email is a supplemental contact and support channel. You may also use email for general personal information inquiries or rights requests. You may also contact us by phone at +82 10-4491-7410 for privacy-related inquiries. We may ask only for the minimum information needed to confirm your identity before fulfilling a request.
For instructions on managing your personal information and health data, see Privacy Choices.
Your rights, response timeframes, and any extension conditions may vary depending on where you live and the laws that apply. AvoPet does not treat an App Store language setting alone as proof of your country of residence. If we refuse a request, we will, where possible, explain the reason and tell you about any available appeal or complaint options.
Republic of Korea
Users in the Republic of Korea may, under applicable law, request the following:
- Access to personal information
- Correction or deletion
- Suspension of processing
- Withdrawal of consent
- An appeal or complaint about how personal information is handled
For users in the Republic of Korea, AvoPet generally responds to access requests within 10 days of receiving the request. For correction, deletion, and suspension-of-processing requests, AvoPet generally notifies you of the outcome within 10 days of receiving the request, or explains any limitation and how you may appeal. These are response and notification timeframes, not a guarantee that all information will be deleted within 10 days. If a legal restriction or a valid reason for delay applies, AvoPet will inform you of that fact and the reason.
United States
Residents of the United States may have rights under applicable federal and state privacy laws. Additional rights and request procedures relating to consumer health data may also apply. For additional information about consumer health data rights in the United States, see our “Washington Consumer Health Data Privacy Policy” and “Nevada Consumer Health Data Privacy Policy.” AvoPet does not claim that all U.S. users have the same rights.
Australia
Users in Australia may, under applicable law, request the following:
- Access to the personal information we hold about you
- Correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading
- If a request is refused, written reasons and information about available complaint options
AvoPet responds to access and correction requests within a reasonable period. We generally aim to respond to access and correction requests within 30 calendar days, subject to applicable law and the circumstances of the request. This is an operational target, not an unconditional legal guarantee of a 30-day deadline. Applicable law may also permit refusal in certain cases.
New Zealand
Users in New Zealand may, under applicable law, request the following:
- Access to personal information
- Correction of personal information
- If information is not corrected, a request that a statement of the correction request be attached to the information
- Lodge a complaint about how personal information is handled
Decisions on access or correction requests are generally made within 20 working days. In limited circumstances permitted by law, the timeframe may be extended. If extended, AvoPet will explain why and provide a new expected response timeframe. If access is refused, AvoPet will explain the reason and that you may raise the matter with the Office of the Privacy Commissioner.
Singapore
Users in Singapore may, under applicable law, request the following:
- Access to personal information
- Information about how personal information has been or may be used or disclosed
- Correction of personal information
- Withdrawal of consent
- Inquiries or complaints about how personal information is handled
AvoPet responds to access and correction requests as soon as reasonably possible. If a request cannot be completed within 30 calendar days, AvoPet will, within those 30 calendar days, provide a written estimate of when a response can be expected. If you withdraw consent, AvoPet will inform you of any reasonably foreseeable consequences and, except where processing is needed for legal or business purposes, stop the relevant processing within a reasonable period.
Unlinking a Google or Apple account in AvoPet may not remove information those providers hold separately. You may need to manage that information in Google’s or Apple’s own settings.
8. Children Under 16
AvoPet is not intended for anyone under the age of 16. If you are under 16, you should not use the service.
If we learn that we have collected personal information from someone under 16, we will take reasonable steps to delete it. Please contact us at avopet.support@gmail.com if you believe this has happened.
9. How We Protect Information
AvoPet applies reasonable technical and administrative safeguards to help prevent loss, theft, unauthorized disclosure, and alteration of personal information. No internet or mobile service can be guaranteed to be completely secure.
- Row Level Security (RLS) on Supabase so users can access only their own data
- Private storage and photo paths based on the user UUID
- Transmission over HTTPS/TLS
- Operational secrets kept in the server environment, not in the app
- Least-privilege access
- Sequential deletion of photos, database records, and Auth users when an account is deleted
- Limiting access to personal information to what is needed
References to user-UUID-based paths inside Supabase Storage describe access control within Storage. They do not mean that those paths or UUIDs are sent to OpenAI.
10. Advertising and Privacy Choices
AvoPet may use Google AdMob ads. For its initial iOS release, AvoPet does not request App Tracking Transparency (ATT) authorization or access to the IDFA. AvoPet configures its AdMob requests for non-personalized ads only. Before requesting ads, the app updates the UMP consent information and checks canRequestAds, and requests ads only when that status permits it. Where required, privacy messaging is presented through the UMP flow.
AvoPet does not sell consumer health data. AvoPet does not send meal photos, health profile information (gender, age range, or diet goal), current or target weight, post-meal mood, setback factors, notes, meal determinations, AI feedback results, or the Supabase user UUID to AdMob as ad-request targeting values or custom parameters, and does not use that information for health-based personalized advertising. AvoPet does not disclose health profile or meal content to Apple account linking or Google account linking. The external services that process the app’s health content are Supabase and OpenAI.
Even when ads are requested as non-personalized, the Google Mobile Ads SDK may process an IP address, approximate location, app- or device-scoped identifiers, advertising and app interactions, and performance or diagnostic information for ad delivery, measurement, frequency capping, and fraud prevention. The actual scope may vary depending on the device settings, iOS privacy settings, SDK configuration, and Google’s policies.
You may be able to manage some advertising privacy settings in iOS privacy settings and Google’s ad settings. The AvoPet app does not currently include a separate in-app menu to withdraw advertising consent.
11. Contact and Complaints
- Data Controller: WonGyu Jang
- Privacy Officer / Data Protection Officer: WonGyu Jang
- Location: Republic of Korea
- Email: avopet.support@gmail.com
- Phone: +82 10-4491-7410
If you have a privacy concern or complaint, please email or call us using the contact details above. Depending on where you live, you may also have the right to contact your local data protection authority.
12. Changes to This Policy
We may update this policy if the law, app features, or our third-party services change. If we make material changes, we will provide notice in the app or on the website. The updated effective date will appear on this page.
13. Effective Date
Effective date: August 14, 2026
