Privacy Policy

Last updated August 20, 2026 · v1

The honest version, in plain words: we collect what the product needs to work, we never sell it, and you can take it all out — or erase it all — from Settings, any time.

The short version

  • We collect what the product needs and nothing exploratory.
  • We never sell or rent your data, and there are no ads.
  • Your data is never used to train AI models.
  • Analytics are off in GDPR regions until you say yes.
  • Export everything and delete everything live in Settings — since day one.

What we collect

  • Account: your email address and, if you use Google sign-in, the identifier Google shares.
  • Pets: the profiles you create — species, age, weight, conditions you choose to add.
  • Activity: scans, pantry, journal entries and their optional photos, weigh-ins.
  • Documents: vet bills and records you store in the Vault.
  • Contributions: label photos and shelf prices you submit.
  • Support: messages you send us.
  • Technical: crash reports, and product analytics where you've consented.

What we never do

  • Sell or rent personal data — to anyone, for anything.
  • Run ads or track you across other sites.
  • Use your data to train AI models.
  • Use your signals for price discrimination — prices are the same for everyone.
  • Publish anything about an identifiable pet or person without your explicit choice to share it.

How we use your data

To run the product: computing scores and Fit, watching labels and recalls for what you've scanned, building your briefs and records, and sending only the notifications you've left on — every category has its own switch.

Community and market surfaces show aggregates only, above published minimum cohort sizes (community stats render only at 50+ pets, for example). Prices you contribute are stored with zero linkage back to your account — by schema, not by promise.

Documents & AI parsing

Label photos and vet bills are read once by an AI vision service to extract their text, and the result is cached — your documents aren't re-processed on every view.

Before any text extracted from a vet bill is stored, owner-identifying details — names, addresses, account and card digits — are redacted. The AI providers we use process your content under terms that bar them from training on it.

Analytics, cookies & crash reports

Product analytics run on PostHog. In GDPR regions they are off until you accept the banner — declining is one tap and just as prominent. Crash reports go to Sentry so errors get fixed. Public share pages, like Care Cards, carry no analytics at all.

Cookies & local storage, in full

Who processes data for us

Bowlmark runs on a small set of processors, each doing one job:

  • Vercel — hosting.
  • Supabase — database, file storage, and sign-in.
  • Paddle — payments, as Merchant of Record. Your card details go to Paddle, never to our servers.
  • Resend — email delivery.
  • PostHog — product analytics, where consented.
  • Sentry — crash reports.
  • Anthropic or Google — one-time document parsing, under no-training terms.
Paddle's privacy policy

Your rights & controls

Settings → Your data → Export all my data hands you everything as JSON, any time. Delete my account erases your profile, pets, and records everywhere, permanently. Neither requires writing to anyone.

If you're in the EU, EEA, or UK you additionally have the rights of access, rectification, erasure, portability, restriction, and objection — and the right to complain to your supervisory authority. Write to privacy@bowlmark.com for anything the buttons don't cover.

Retention

We keep your data while your account exists. Deleting your account removes your personal records immediately, and backup copies age out within 30 days. Contributed catalog data — published label photos and unlinked price aggregates — persists, because it carries no link to you.

Security

Every table is protected by row-level security, private files live in private buckets behind signed, expiring access, and everything travels encrypted. No system is perfect: if a breach ever affects you, we'll tell you as the law requires — plainly and quickly.

Children

Bowlmark is not for children under 16.

International transfers

Our processors run in the US and EU; where personal data leaves the EU/UK it travels under standard contractual clauses maintained by those processors.

Changes & contact

If this policy changes in a way that matters, we'll email you before it takes effect. Privacy questions and requests: privacy@bowlmark.com.