PETLoves Data Safety and App Privacy Summary
PETLoves data handling and permissions for Google Play Data Safety and Apple App Privacy.
Text revision: 2026-09-08
This document supports Google Play Data Safety, Apple App Privacy, store review notes and PETLoves privacy operations. It must remain aligned with docs/privacy-data-map.md, src/config/privacyDataSafety.ts, src/config/dataRetention.ts, app.json, the public Privacy Policy and the production services enabled for the submitted build.
Release model
The current PETLoves release is privacy-first and production-connected where the user enables account, live sync, publishing, reviews, media upload, support or moderation flows. Drafts, reminders, device preferences and temporary offline state remain limited to the device until PETLoves can confirm the live service action.
Backend account sync, database storage, media storage, support, moderation, privacy-first analytics and crash diagnostics may be active in the submitted build. Payments, paid sponsor campaigns, address-book import, third-party advertising identifiers and cross-app tracking remain disabled unless explicitly enabled in the release notes, store questionnaires and privacy copy.
Google Play Data Safety answers
Technical inputs for reviewing the production-connected build, not final console selections:
- Data collection: yes. PETLoves can collect account/profile, pet profile, pet health diary, emergency profile, community content, direct chat, follower relationships, reviews, media, approximate or precise location, professional profile, booking request, support, analytics and diagnostics data. Chat is server-backed; messages belong in the Other in-app messages review and follower relationships in Contacts. Remote place/address searches also need review against provider retention.
- Data sharing: PETLoves does not sell personal data. Determine the form's sharing answer from actual recipients and the applicable service-provider or user-initiated exceptions, not from the absence of advertising alone. Provider roles and retention remain to be confirmed. User-initiated sharing, publishing, public previews and native sharing actions follow the user's action.
- Data encrypted in transit: yes for HTTPS/API calls, auth, storage, public policy pages and support flows.
- Data deletion request mechanism: yes. Users can delete account data in app where available and request account, content or support-data deletion through support@petloves.it. Delete account and account access recovery must be proven on real accounts and multi-device before public rollout.
- Sensitive-data classification: assess the fields actually requested. Pet records are not automatically human health information; requested human contacts, locations, documents and messages need their own applicable categories. Do not replace the form's specific types with a generic sensitive-data answer.
- Ads declaration: declare ads/sponsored content only if paid sponsor placements, promoted profiles or sponsored feed content are active in the submitted build. Sponsored content must remain visibly labeled.
Apple App Privacy answers
Categories to review against the actual candidate and partner practices; linkage, purposes and required/optional collection remain separate decisions:
- Contact Info: name, email, city/region and support contact details when entered.
- User Content: posts, stories, questions, answers, comments, reviews, alerts, photos, documents, professional media, support messages and legacy videos retained from earlier releases where applicable.
- Emails or Text Messages: direct in-app chat with its participants and message content. The server stores these records; they are not on-device-only.
- Health and Sensitive Info review: distinguish pet records from intentionally requested human information. Generic free text does not by itself establish every possible sensitive category. Use the applicable Store types, not a fictional catch-all category.
- Location: approximate or precise location when permission is granted for Vivi Zampa, Pet Care, alerts and nearby content.
- Identifiers: app account ID, user ID, content IDs, support diagnostic IDs and server-side sync IDs.
- Usage Data: non-essential interaction analytics require the user's confirmed opt-in. Operational error reporting is a separate flow, not a substitute for that choice.
- Diagnostics: automatic operational error tickets and crash/performance reporting are separate from a manually shared support bundle. Redaction alone does not prove that a record cannot be linked to an account or device.
- Purchases / Financial Info: not collected unless real checkout, sponsor billing or paid services are enabled.
- Contacts: PETLoves stores follower/following relationships. No device address-book import is implemented, but the stored social graph still needs this disclosure.
- Search History: remote place/address queries require a provider/log-retention decision; absence of advertising does not establish a No answer. On-device-only filters must be considered separately.
- Tracking: no cross-app tracking and no third-party advertising identifiers in the current release.
Permission declarations
- Location: used only with consent for Vivi Zampa, Pet Care, alerts and nearby content; when denied, PETLoves uses only area information already provided by the user.
- Camera: used only for user-initiated photo capture for profiles, stories, posts, questions, alerts, reviews and documents.
- Photo library: used only for user-selected photos and documents for profiles, stories, posts, questions, alerts, reviews, diary/support and professional galleries.
- Microphone: not requested by the current image-only release. New video/audio capture and upload are disabled; previously uploaded legacy videos remain available only for playback or deletion.
- Notifications: used only for useful reminders and account/service/safety updates controlled by preferences, quiet hours and opt-out.
User content and moderation
PETLoves includes user-generated content. Store review should be told that the app provides content reporting, deletion of own content where applicable, Trust & Safety guidance, moderation queues, block/limit controls, audit log, SLA tracking, appeals, reporter PII redaction and support contact. Public community launch requires operational moderation, reviewer ownership and escalation paths.
Retention and deletion
Device-only drafts and preferences remain until the user edits them, deletes them, resets app data or uninstalls the app. The register in src/config/dataRetention.ts identifies server-backed records and unresolved retention decisions; a configured default or manual-review entry does not prove executed expiry. Account deletion, media cleanup, independent support/email archives and backups must be reviewed separately. Production sync and moderation must not claim success when completion cannot be confirmed. The new source adds consent-history export, not a complete export of every cloud record.
Store review notes
Reviewer-facing notes should state:
- PETLoves uses location, camera, photo library and notifications only after user action or permission, with granular notification opt-out and reviewer-safe image limits. The image-only release does not request microphone access.
- PETLoves does not replace veterinary care.
- Sponsored content is labeled when active.
- Current release is privacy-first with production backend services for enabled account, live sync, content, support, analytics, diagnostics and moderation flows.
- Privacy, Terms, Trust & Safety, Support and Data Safety are published on petloves.it before store submission.
Review references: Apple App Privacy definitions and Google Data Safety guidance. The PETLoves-specific source findings are in docs/store-privacy-source-review-20260907.md; technical consistency does not approve the console declarations.
PETLoves
Open web app