1. Data Controller
The controller of personal data processed in connection with the use of the Whispet mobile application (hereinafter: the "App") is:
CRE8EVE Sp. z o.o.
Address: Tulipanowa 4, 72-003 Dobra, Poland
KRS (National Court Register): 0000912669 | NIP (Tax ID): 8513262229 | REGON: 389506637
Contact e-mail: hello@whispet.app
(hereinafter: the "Controller")
Data Protection Officer: The Controller has not appointed a Data Protection Officer. Under GDPR Art. 37(1), appointment of a DPO is not required — the Controller is not a public authority, its core activities do not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data. Any matters concerning the protection of personal data may be addressed directly to the Controller at the contact e-mail above.
Legal basis of processing. Processing of Users' personal data is subject to:
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR),
- the Polish Act of 10 May 2018 on the Protection of Personal Data (Journal of Laws 2018, item 1000, as amended) — the Polish national act implementing the GDPR,
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (EU AI Act) — with respect to the pet recognition feature on photos (see §9).
2. Definitions
App — the Whispet mobile application available for iOS and iPadOS devices (Android version planned).
User — a natural person using the App.
Personal data — any information relating to an identified or identifiable natural person, within the meaning of Art. 4(1) of the GDPR.
GDPR — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).
Processing — an operation or set of operations performed on personal data, within the meaning of Art. 4(2) of the GDPR.
Free Plan — the free subscription plan with basic functionality.
Premium Plan — the paid subscription plan (monthly or annual) with extended functionality.
3. Scope of data processed by the App
3.1. No user accounts
The App operates entirely locally — it does not require registration, login, or account creation. We do not collect email addresses, passwords, or any authentication data. All data is stored exclusively on the User's device.
3.2. Pet data
| Data | Purpose | Legal basis |
|---|---|---|
| Pet name | Identification within the App | Art. 6(1)(b) GDPR (contract) |
| Species (dog, cat, other) | Feature customisation | Art. 6(1)(b) GDPR (contract) |
| Breed / variety | Ideal weight calculation, recommendations | Art. 6(1)(b) GDPR (contract) |
| Sex | Pet information | Art. 6(1)(b) GDPR (contract) |
| Date of birth | Age calculation | Art. 6(1)(b) GDPR (contract) |
| Microchip number | Pet identification | Art. 6(1)(b) GDPR (contract) |
| Veterinarian address | Vet contact information | Art. 6(1)(b) GDPR (contract) |
| Neutering/spaying status | Health information | Art. 6(1)(b) GDPR (contract) |
3.3. Photos
| Data | Purpose | Legal basis |
|---|---|---|
| Photo path (local) | Timeline display | Art. 6(1)(b) GDPR (contract) |
| Photo description | Gallery organisation | Art. 6(1)(b) GDPR (contract) |
| Date taken | Chronological sorting | Art. 6(1)(b) GDPR (contract) |
| Favourite status | Favourites feature | Art. 6(1)(b) GDPR (contract) |
| Tags (automatic labels) | Photo categorisation | Art. 6(1)(b) GDPR (contract) |
| Technical asset identifier in the iOS gallery | Duplicate detection during photo history import | Art. 6(1)(b) GDPR (contract) |
| Identifier of the photo in Apple Photos (Apple PhotoKit) | Reference to the same photo in the User's Apple Photos library across devices signed into the same iCloud account — enables photo synchronisation between iPhone and iPad without transmitting image bytes through Whispet servers | Art. 6(1)(b) GDPR (contract) |
| EXIF date (DateTimeOriginal) | Placing photos on the timeline at the correct date | Art. 6(1)(b) GDPR (contract) |
Technical asset identifier in the iOS gallery is a pointer to a photo in the User's iPhone/iPad system gallery, used solely for detecting duplicates during repeated photo imports. It contains no personal data.
Identifier of the photo in Apple Photos (sync between the User's own devices) is an optional, opaque technical pointer generated by Apple (available from iOS 16). It references the same photo in the Apple Photos library on every User device signed into the same iCloud account. The Application does not transmit photo bytes through Whispet or CRE8EVE servers — synchronisation takes place exclusively through Apple iCloud Photo Library, controlled by the User in iOS Settings → iCloud → Photos. The identifier contains no personal data.
Saving photos to the Apple Photos library. Photos taken with the in-app camera are automatically copied to the "Whispet" album in the User's Apple Photos library (the User's consent to access the Photos library is required in iOS Settings → Whispet → Photos). The save takes place locally only. Details: Help → "Are my photos safe if I uninstall the Whispet app?".
Photo History Import (Premium). This feature enables batch import of photos from the device gallery. All operations are performed exclusively on the device.
Smart Pet Photo Detection (Premium). The smart pet photo detection feature uses the Apple Vision framework to identify animal photos in the device gallery. Analysis is performed entirely on the device — no data is transmitted to external servers.
EXIF date reading. The App reads only the EXIF DateTimeOriginal date in order to place photos on the timeline at the correct date. GPS coordinates are not read or stored; location metadata is stripped on save. Reading takes place locally.
On-demand download of shared photos (Shared Care). When using Shared Care (§6a), the App downloads only metadata and thumbnails; the full content of a photo is downloaded from Apple's private iCloud database only when the photo is opened. The mechanism protects against excessive memory consumption.
3.4. Pet medical data
| Data | Purpose | Legal basis |
|---|---|---|
| Vaccinations (name, date, expiry date, dose) | Vaccination history tracking | Art. 6(1)(b) GDPR (contract) |
| Medications (name, dose, administration schedule) | Medication reminders | Art. 6(1)(b) GDPR (contract) |
| Weight (value, date, unit) | Weight monitoring | Art. 6(1)(b) GDPR (contract) |
| Allergies/allergens (name, type, symptoms) | Allergy tracking | Art. 6(1)(b) GDPR (contract) |
| Nutrition/food (name, type, rating, supplements) | Diet management | Art. 6(1)(b) GDPR (contract) |
| Veterinary visits (date, clinic, notes) | Visit history | Art. 6(1)(b) GDPR (contract) |
| Medical documents (name, photos/scans) | Document storage | Art. 6(1)(b) GDPR (contract) |
3.5. Event journals
| Data | Purpose | Legal basis |
|---|---|---|
| Journal definition (name, icon, colour, fields) | Event journal structure | Art. 6(1)(b) GDPR (contract) |
| Journal entries (field values, notes, dates) | Health/behavioural event tracking | Art. 6(1)(b) GDPR (contract) |
| Photos attached to entries (local paths) | Visual documentation of events | Art. 6(1)(b) GDPR (contract) |
Event journals allow the User to track recurring events (e.g. epileptic seizures, digestive issues) using user-defined fields (chips/tags, sliders, toggles, numeric fields, time pickers). All data is stored exclusively on the device.
Disclaimer: Medical data and event journal data pertains to animals, not natural persons. The processing of such data under the GDPR relates to it as an element of the service provided to the User.
Note on photos attached to medical records and event-journal entries: Photos attached to a medical record (e.g. a scan of a vaccination document, a photo of a medication) or to an event-journal entry are technically bound to that specific entry. Deleting the entry automatically deletes any photos attached to it — both from the User's device and from the devices of people with whom the User has shared the pet through the Shared Care feature. This operation is irreversible.
3.6. QR Pet Card — optional owner contact data
The QR Pet Card feature allows the User to optionally enter their name and phone number to include on the card. This data is not stored in the App or on the device — it is entered temporarily and embedded directly into the generated QR code image. Once the QR Card screen is closed, the entered contact data is discarded. The QR code is generated entirely on the device; no data is transmitted to any server.
3.7. Consent management
The App does not maintain its own consent registry or an audit trail of acceptance timestamps. Consents related to data processing are managed via external infrastructure:
- Access to the camera, Apple Photos library, notifications — consents are granted and revoked by the User in iOS Settings → Whispet. Managed by Apple Inc. as the iOS operating system provider.
- Acceptance of the Terms of Service and the Privacy Policy — occurs by the fact of using the App (Terms of Service §1.3); the App does not display a click-through screen and does not record an acceptance timestamp.
- Apple ID and iCloud terms — managed by Apple Inc. as part of the User's Apple ID account.
- Premium subscription — purchase history and subscription terms acceptance are maintained by the Apple App Store.
3.8. Address suggestions and route guidance (Apple Maps)
When the User adds a veterinary clinic, the App suggests clinic names and addresses and determines their coordinates so that a map pin can be shown and navigation can be launched. The suggestions come from Apple Maps (MapKit) — an Apple system service.
| Data | Purpose | Legal basis |
|---|---|---|
| The name or address fragment typed by the User in the clinic form | Search suggestions and determination of the clinic's coordinates (geocoding) | Art. 6(1)(b) GDPR — performance of a contract (App functionality) |
- Scope: only the text typed into the clinic name or address field (suggestions) and the address or coordinates of a saved clinic — when the App displays the map preview on the clinic card or when the User launches navigation ("Navigate") — are transmitted to Apple. No pet data, medical data, photos, or the User's contact data are transmitted.
- No User location. The App does not request access to location and does not read the device's position. The search region is derived from the country set in the system settings or from the address of a clinic previously added by the User.
- Transfer: the queries are handled by Apple Inc. (USA) — see §6.
- Control: queries are sent only when the User uses the clinic features: typing in the clinic form, opening a clinic card with the map preview, or choosing "Navigate". The User may enter the address manually and not use the suggestions; if the User adds no clinic, no query is sent to Apple Maps.
Dictation. The App does not perform its own speech recognition and does not request access to the microphone. If the User dictates notes, they do so using the microphone of the iOS system keyboard — this is an Apple feature: the App receives only the finished text and never has access to the audio.
3.9. Demo Pet feature (onboarding)
The App allows the User to generate a demonstration pet (Milo / Luna) with synthetic sample data for onboarding purposes. Demo photos are generated by artificial intelligence and marked with a visible "AI" badge in accordance with Art. 50 of the EU AI Act (Regulation (EU) 2024/1689 — obligation to label AI-generated content).
Demo data is synthetic and does not constitute personal data within the meaning of Art. 4(1) GDPR. The demo is stored exclusively locally and is automatically deleted after a real pet is added or after a Shared Care invitation is accepted. Details: Help → "What are demo pets?".
4. Purposes of processing and legal bases
The Controller processes personal data for the following purposes:
4.1. Performance of a contract (Art. 6(1)(b) GDPR)
- Provision of App services (timeline, gallery, medical data, event journals, reminders, photo history import, smart pet photo detection, EXIF date reading)
- Fulfilment of paid subscription plans
4.2. Legal obligation (Art. 6(1)(c) GDPR)
- Fulfilment of User rights (Art. 15–22 GDPR)
4.3. Legitimate interest of the Controller (Art. 6(1)(f) GDPR)
- Ensuring the security and stability of the App
- Diagnosing technical issues
5. Data recipients
The User's personal data is not transmitted to any servers of the Controller. The App does not use any analytics, advertising, or third-party tracking services. To a limited extent, data may be shared with the following categories of recipients:
| Recipient | Scope of data | Purpose |
|---|---|---|
| Apple Inc. (CloudKit — private database) | Pet data, photos, medical data, journal entries | iCloud synchronisation between the User's own devices |
| Apple Inc. (CloudKit — sharing) | Pet data, photos, medical data (read-only for participants) | Shared Care (optional sharing of a pet profile with designated iCloud users — only when the owner activates the feature; requires Premium plan) |
| Apple Inc. (Vision framework) | None — on-device processing | Automatic pet photo tagging (Apple Vision framework, runs entirely on device) |
| Apple Inc. (Apple Maps / MapKit) | The clinic name or address fragment typed by the User | Address suggestions and geocoding when adding a veterinary clinic — see §3.8 |
| Apple Inc. (StoreKit) | Transaction data (payments) | In-App Purchase payment processing |
Note on iCloud synchronisation: Data is synced exclusively to the User's private iCloud database, to which Apple has no access (end-to-end encryption with iCloud Advanced Data Protection enabled). The Controller has no access to data stored in iCloud.
Note on Shared Care: Data is shared with other users only at the explicit request of the User (owner). The User may revoke access at any time from within the App.
Note on address suggestions: Apple Maps receives only the text typed into the clinic name or address field. The App does not read the device's location and does not transmit any pet data or medical data to Apple Maps. See §3.8.
Note on Apple Vision framework: Smart pet photo detection is performed entirely on the User's device. No image data or analysis results are transmitted to external servers.
Note on payments: The Controller does not have access to the User's payment data (e.g. credit card number). Payments are handled entirely by the Apple App Store.
6. Data transfers outside the European Economic Area (EEA)
User data may be transferred outside the EEA in the following circumstances:
- iCloud synchronisation (CloudKit): Data is stored on Apple Inc. servers (USA) in the User's private iCloud database. Apple ensures data protection under its DPA (Data Processing Agreement) and Standard Contractual Clauses (SCCs).
- Shared Care: When the User activates Shared Care, data is stored in a dedicated Apple CloudKit sharing area on Apple Inc. servers (USA). Legal basis for transfer: as above.
- Address suggestions and geocoding (Apple Maps / MapKit): The clinic name or address fragment typed by the User is transmitted to Apple Inc. (USA) in order to return suggestions and the clinic's coordinates. See §3.8.
- Notifications of changes in iCloud (Apple Push Notification service): The information that changes awaiting synchronisation have appeared in the User's private iCloud database is delivered by an Apple service (USA). Such a notification does not contain the content of the User's data.
- Premium subscription purchase: Transaction data is processed by Apple Inc. (USA) via the StoreKit/App Store system.
The aforementioned entities ensure an adequate level of data protection based on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- EU-US Data Privacy Framework (to the extent currently in force)
Note: The App does not use Google Fonts, Firebase, any analytics servers, or any external services other than the Apple services listed above (CloudKit, StoreKit, Apple Maps, Apple Push Notification service). The Controller does not operate any servers of its own — the User's data never reaches the Controller in any form. The Nunito font is bundled directly within the App and is not downloaded from external servers.
6a. Shared Care feature (sharing a pet profile)
The App allows the account Owner (hereinafter the "Owner") to share selected pet profiles with other Users — family members or close ones (hereinafter "Participants"). The feature is implemented exclusively via Apple CloudKit sharing. Each shared pet has its own isolated sharing area within the Owner's iCloud database — all data flows directly between participants' devices through the Apple infrastructure. CRE8EVE does NOT mediate the transfer of Shared Care data and has no access to the shared content.
The maximum number of people to whom the Owner may share their pets is 10 unique Participants in total (the same person across multiple pet zones counts as one).
6a.1. Scope of Participants' access
After accepting an invitation, the Participant receives access to the following data of the shared pet:
- Basic profile: name, species, breed / variety, date of birth, avatar (read-only — the Participant cannot edit the profile).
- Photos: the Participant may add their own photos. The Participant may NOT delete any photos — not even photos they added themselves. Photo deletion is reserved for the Owner only — this rule protects the pet's history from accidental deletion by people with access.
- Medical data: read-only. The Participant sees vaccinations, medications, vet visits, allergens, nutrition, documents, and the event journal, BUT cannot edit or delete them. The Owner retains full control.
6a.2. Sharing modes (per-participant) — narrowest access by default
The Owner may select a sharing mode per participant:
- Photos only (default): The Participant sees only the pet's photos; no access to medical data. Without an explicit switch to "Full access" the Participant never gains access to medical data.
- Full access: The Participant sees all data (profile + photos + medical data — medical data remains read-only).
Default-deny invite (privacy by design and by default — GDPR Art. 25 + Art. 5(1)(c)):
Every invitation sent by the App is configured by default with the "Photos only" mode, regardless of the Owner's preference in the invitation form. This stems from two GDPR principles and from a technical constraint of Apple CloudKit Sharing API:
- Art. 5(1)(c) GDPR (data minimization) — at the moment an invitation is sent the Participant is not yet uniquely identified by Apple. The invitation is addressed to a
lookupInfovalue (iCloud email or phone number), and Apple verifies the Participant'suserRecordIDonly at acceptance time. The default narrowest access scope eliminates the risk of disclosing the pet's medical data should the invitation be sent to the wrong address by mistake. In practice the Owner shares a pet by sending a generated link via iMessage (or Mail) to a person who has an Apple device and an iCloud account; the person joins by opening the link and accepting the invitation. Optionally, the Owner may add a person in advance by entering their iCloud email or phone number ("Add person"); that data does not leave the device until acceptance. - Art. 25 GDPR (privacy by design and by default) — the App defaults the feature to the narrowest possible processing scope (photos), and any expansion of scope (medical data) requires an additional, conscious action by the Owner taken after the recipient has been positively identified.
Switching to "Full access" mode (post-accept):
After the Participant accepts the invitation, the Owner may at any time change the mode to "Full access" separately per pet. The operation is performed in Settings → Shared Care → tap the person's card. The change takes effect after a brief synchronization (typically a few seconds), without notification to the Participant.
6a.3. Revoking access — three paths
The App offers the Owner three separate, independent paths for revoking access, tailored to different real-life situations:
- Per pet per person (trash icon next to the pet on the person's card) — revokes the given person's access to one, specific pet only. Other pets shared by the Owner with that person remain accessible. The person remains on the people-with-access list.
- Per person — all pets ("Remove completely" on the person's card) — revokes that person's access to all of the Owner's pets and removes them from the people-with-access list.
- Per pet — all people (sharing toggle for the pet switched OFF) — stops sharing that pet with all Participants simultaneously. The people-with-access list stays unchanged.
In all three paths the Participant's permissions are revoked immediately on the Apple iCloud servers. The push notification about revocation on the Participant's device may be delayed by up to 15 minutes — this is a known, intentional behaviour of the Apple iCloud infrastructure (revocation notifications are deprioritised compared with invitation acceptances, which are typically delivered within 1–2 seconds). During this delay window the Participant may visually still see the pet in the local app cache, but all attempts to download new data from iCloud are rejected by the Apple servers. The Participant's app removes the pet from the view on the next successful sync.
- The Participant may at any time leave the share ("Leave") from their side. The effect on the Participant's device is immediate; the Owner's notification may be similarly delayed.
- Premium loss by the Owner: If the Owner loses their Premium subscription, Shared Care is immediately disabled for all of the Owner's pets. Participants are not notified in advance (a product decision preserving the privacy of the Owner's subscription status). Apple Billing Grace Period (3–28 days, per Apple settings) protects against failed payments — during the grace period the subscription remains active on the Apple servers and Shared Care continues to function.
6a.4. Photos after losing access
Upon access revocation the Participant loses access to all the pet's data in the sharing zone, including photos they added themselves (Apple CloudKit Sharing architecture — the zone technically belongs to the Owner). Before access loss the App offers the Participant an optional export of their own photos to the iOS system gallery.
Independently of access loss in the App, every photo taken with the in-app Whispet camera by the Participant is automatically copied to the Participant's Apple Photos library ("Whispet" album) — the mechanism described in §3.3 applies identically on the Participant's side in Shared Care mode. The copy in Apple Photos remains under the Participant's exclusive control and is not subject to access revocation — Apple Photos is a separate processing area.
Access revocation does not cause data loss on the Owner's side — the Owner retains full control over the pet (including photos added by the Participant).
6a.5. Legal basis and processing scope
The Shared Care feature uses exclusively the Apple CloudKit infrastructure (see: https://whispet.app/legal/en/subprocessors). CRE8EVE as the Data Controller:
- does NOT mediate the transfer of Shared Care data,
- has NO access to the shared content (with iCloud Advanced Data Protection enabled — end-to-end encrypted by Apple),
- does NOT store the list of sharing participants on its own servers,
- does NOT use Shared Care data for any purpose other than enabling the feature to operate within the App.
Legal basis for processing: Art. 6(1)(b) GDPR (performance of a contract).
Scope of access in the Free and Premium plans. Sharing one's own pets with other people and adding people to the "People with access" list require a Premium subscription on the Owner's side. Available on the Free plan: participation (receiving shared pets from other Owners), viewing the Shared Care screen, and editing one's own signature (the name visible to people with access).
Terminology note: In the App's UI and internal project documentation the feature appears under the name "Shared Care". It should not be confused with the Apple iCloud Family Sharing platform service — Shared Care in Whispet is an independent feature implemented via the CloudKit Sharing API and does NOT require or use Apple Family group membership.
7. Data retention period
| Data category | Retention period |
|---|---|
| Pet data | Until deleted by the User |
| Photos | Until deleted by the User from the App |
| Pet medical data | Until deleted by the User |
| Event journals and entries | Until deleted by the User |
| iCloud data (CloudKit) | Until deleted from the device or iCloud synchronisation is disabled by the User |
Data is stored locally on the User's device and — if iCloud synchronisation is enabled — also in the User's private iCloud database. Uninstalling the App removes local data; iCloud data persists until the User removes it via the "Delete all my data" feature available in the App (Settings → Your account), which deletes all Whispet data zones from the User's private iCloud database.
Permanent deletion of a previously shared pet (Shared Care). All personal content of the pet — photos, entries, medical data, sharing records, local files — is cascade-wiped from the device and from the private iCloud database. The App retains a minimal technical token (~10–15 KB, containing no personal data) that serves as a sync anchor between the User's devices. The token is fully deletable via "Delete all my data" (Settings → Your account). The mechanism is compliant with GDPR Art. 17.
8. User rights
Under the GDPR the User is entitled to the rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent (Art. 15–21 GDPR) as well as the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).
Exercise of rights — zero-server architecture. The User's data is not stored on the Controller's servers. It is located exclusively on the User's device and — optionally — in the User's private iCloud database (Apple CloudKit), to which the Controller has no programmatic access (Apple deliberately designed CloudKit so that app developers cannot read, modify, or delete the user's data on their iCloud account). Consequently, GDPR rights are exercised as follows:
| Right | Method of exercise |
|---|---|
| Access (Art. 15) | All data is directly visible to the User in the App. Full copy of data from iCloud: privacy.apple.com → "Request a copy of your data" (Apple as the iCloud account controller). |
| Rectification (Art. 16) | The User edits data directly in the App at any time. |
| Erasure — "right to be forgotten" (Art. 17) | The "Delete all my data" feature in Settings → Your account wipes all Whispet data zones from the User's private iCloud database as well as local data. The Premium subscription remains active — Apple manages it independently. |
| Restriction of processing (Art. 18) | Disabling iCloud synchronisation in iOS Settings → Apple ID → iCloud → Whispet (limits processing to the device only). |
| Data portability (Art. 20) | In-app export of medical records from a pet's profile to PDF or XLSX and export of event journals from within each journal. Full iCloud data copy: privacy.apple.com. |
| Objection (Art. 21) | Uninstalling the App stops processing. |
| Withdrawal of consent (Art. 7(3)) | Withdrawing system consents in iOS Settings → Whispet (Camera / Photos / Notifications). |
8.1. "Delete all my data" feature (GDPR Art. 17)
The standard "iOS Settings → Apple ID → iCloud → Manage Account Storage → Whispet" path manages only iCloud Drive files and the containers of Apple's first-party apps. It does not delete data from the Whispet custom CloudKit container. For this reason, the "Delete all my data" feature built into the App (Settings → Your account) is the only verified path for exercising the right to erasure under GDPR Art. 17.
8.2. Contact with the Controller
The User may seek assistance or submit a formal request at hello@whispet.app. The Controller will process the request within one month in accordance with GDPR Art. 12(3). The Controller does not independently perform operations on the User's iCloud data (no programmatic access — see above) — the Controller assists with the process and records formal requests in the internal compliance documentation.
8.3. Complaint to a supervisory authority (GDPR Art. 77)
President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl. A User with habitual residence in another EEA Member State may also lodge a complaint with the competent supervisory authority of that State (list: https://www.edpb.europa.eu).
9. Profiling and automated decision-making
The App does not engage in profiling or automated decision-making within the meaning of Art. 22 GDPR.
AI features. Smart pet photo detection (Apple Vision framework) is used for photo categorisation and gallery filtering. Analysis is performed entirely on the device, without identifying persons, without facial recognition, and without processing biometric data within the meaning of Art. 4(14) and Art. 9 GDPR.
EU AI Act (Regulation EU 2024/1689). The App's AI features (animal recognition on photos — see above) are classified as minimal risk. Art. 50 of the EU AI Act (transparency, applicable from 2 August 2026) does not apply to them — they are not chatbots, they do not perform emotion recognition, and they do not generate or manipulate content.
10. Age requirement
The App is intended for persons aged 16 years or older (Art. 8 GDPR). Persons under 16 may use the App only with the consent of a parent or legal guardian.
The Controller does not knowingly collect personal data from persons under 16 without the consent of their parent/guardian.
11. Data security
The Controller applies appropriate technical and organisational measures to ensure the security of personal data, including:
11.1. Local architecture with iCloud synchronisation
- Data is stored locally on the User's device in the App's local database.
- The App synchronises data with the User's private iCloud database (Apple CloudKit) — data is held exclusively on the User's iCloud account, not on the Controller's servers. Apple has no access to content when iCloud Advanced Data Protection is enabled.
- The App does not use Firebase, Google, Amplitude, or any other external analytics or advertising services.
- No user accounts on the Controller's systems — there is no risk of login credential leakage on the Controller's side.
11.2. Encryption
- On the device (at-rest): data is protected by the operating system's encryption mechanisms (iOS / macOS Data Protection plus iOS Keychain / macOS Keychain for selected items).
- In transit: synchronisation with iCloud uses Apple CloudKit protocols protected by encryption (Apple uses TLS for communication with the iCloud infrastructure).
- In iCloud (at-rest on Apple's side): data stored in the User's private iCloud database is encrypted in accordance with Apple's policy. With iCloud Advanced Data Protection enabled, synchronisation is covered by end-to-end encryption — in that case even Apple has no technical access to the content.
11.3. Data minimisation
- The App collects only the data necessary to provide its services.
- Photo analysis (pet photo detection, EXIF date reading) is performed on the device — data does not leave the device.
- Photo history import processes photos in chunks with resizing — all operations are performed locally on the device.
11.4. Data integrity protection
- Before each iCloud synchronisation, the App verifies data integrity (corruption guard). Corrupted data is blocked and is not pushed to iCloud, preventing error propagation between devices.
11.5. Notifications
- The App uses local notifications (reminders for vaccinations, medications, photos) and the Apple Push Notification Service (APNS) for silent Shared Care synchronisation notifications. The App does not use any other external push notification services (e.g. Firebase Cloud Messaging).
12. Changes to the Privacy Policy
The Controller reserves the right to make changes to this Privacy Policy.
- The User will be informed of material changes via the App (in-app notification) at least 14 days before they take effect.
- Continued use of the App after changes take effect constitutes acceptance of the new Privacy Policy.
- The current version of the Policy is always available in the App settings.
13. Contact
For matters concerning personal data protection, please contact:
- E-mail: hello@whispet.app
- Postal address: CRE8EVE Sp. z o.o., Tulipanowa 4, 72-003 Dobra, Poland
14. Legal bases
This Privacy Policy has been prepared in accordance with:
- Regulation (EU) 2016/679 (GDPR) — General Data Protection Regulation
- Act of 10 May 2018 on the Protection of Personal Data (Journal of Laws 2018, item 1000, as amended)
- Act of 18 July 2002 on the Provision of Electronic Services (Journal of Laws 2002, No. 144, item 1204, as amended)
- Act of 16 July 2004 — Telecommunications Law (Journal of Laws 2004, No. 171, item 1800, as amended)