Pawma ("we", "us") is an owner-held pet health record. This policy explains what we collect, why, and your choices. Questions: swagwithus@thewaglabco.com.
Pawma is operated by Hataikan Kamolsirisakul in Thailand. Hataikan Kamolsirisakul is the data controller for Pawma.
We receive information when you create an account, type or upload content, record a visit, use a feature, contact support, or accept a Care sharing invitation. If you choose Apple or Google sign-in, that provider supplies the account identifier, name, and email information you authorize it to share.
We do not sell your data, and we do not use it for advertising.
We do not use the content of veterinary records, notes, transcripts, pictures, or audio for general product analytics.
On iPhone, vet-visit recordings are transcribed on the device. Pawma requires on-device recognition, which prevents the recording from being sent over the network for transcription. Android version 1 does not offer Pawma's recording transcription; users may use their keyboard's own voice typing where available. The original recording is uploaded only to Pawma's private Supabase storage when you choose to attach it to a visit. Short field dictation is held only in the app cache and deleted after the words are added to the field.
When you ask Pawma to organize captured information, the following content is sent to our processor solely to structure it into an editable record:
OpenAI states that API inputs and outputs are not used to train its models by default. Standard API abuse-monitoring logs may be retained for up to 30 days unless a longer period is legally required. Pawma sends these requests with storage disabled. Only record what you are comfortable capturing, and obtain consent before recording other people (e.g. your veterinarian).
Records and files are stored with our infrastructure provider, Supabase (Postgres database, authentication, private file storage, and server functions). Per-user access rules prevent one Pawma user from accessing another user's account data. Pet photos, veterinary documents, observation photos, and audio are stored in private buckets. When Pawma needs to display a private file, it creates a short-lived signed link. The link expires automatically and is not a public file address.
Encrypted operational copies of private files are kept in a separate, access-restricted Google Cloud Storage project for disaster recovery. A limited number of authorized Pawma administrators may access data only when necessary to operate, secure, support, recover, or comply with legal obligations for the service. Product analytics are provided to administrators only as aggregate counts.
These providers may process data in countries outside your own. We require service providers to protect personal data consistently with this policy and applicable law and to use it only to provide their contracted services.
If you use Care sharing, the person you invite must sign in with the invited email address. After acceptance, that person receives read-only access to the selected pets and their recorded visits, vaccinations, lab results, notes, and next care. Caregivers cannot edit, delete, invite, or reshare through Pawma. Private veterinary documents, observation photos, and audio remain owner-only in this release. The owner can revoke Care sharing at any time.
If you export a Vet summary, Pawma creates a temporary PDF on your device and opens the operating system share sheet. Pawma deletes its temporary copy after sharing finishes. The recipient and destination are chosen by you, and Pawma cannot retrieve a copy after it leaves the app.
We otherwise share data only with the service providers listed above to run Pawma, with a person you direct us to share it with, or where required by law. We never sell personal data.
We keep your complete pet record while your account is active unless you explicitly delete a record. Pawma does not delete older records because of their age, account inactivity, or a future subscription change. Care sharing invitation and access history is kept while the owner's account remains active.
When you delete your account, Pawma removes the live account, records, private files, sessions, and Care sharing access. Supabase may retain restricted database backup copies for up to seven days. Independent file backup copies are retained for no longer than 30 days after live deletion. Backup copies are not available through the app and are not used for analytics or ordinary service operations.
OpenAI's standard API abuse-monitoring retention is described above. Support messages are kept only as long as reasonably needed to respond, maintain a support history, protect the service, or meet a legal obligation.
You can delete your account and all associated data at any time, in-app: Settings, Account, Continue to delete account. This removes your live records, photos, documents, audio, sharing access, sessions, and account and cannot be undone. Restricted backup copies expire within the periods described above. The optional fixed account-exit response does not delay deletion and is stored only after deletion succeeds, without a direct or stable identifier. You can also email swagwithus@thewaglabco.com to request access, correction, a copy, or deletion of your data. If you no longer have Pawma installed, use the Pawma account deletion request page.
You can revoke Care sharing in the app. You can turn local reminders off in Pawma or in device Settings. You can change or withdraw camera, photo, microphone, speech-recognition, and notification permissions in device Settings. You may also revoke Apple or Google sign-in access through that provider's account controls.
Pawma is not directed to children under 13 and we do not knowingly collect their data.
We will update this policy as the product evolves and note the date above.