Amoleo is a sole trader operation run by Luke Bickley in the United Kingdom, and is the data controller for everything this notice describes. You can reach us at the address published on this page (JavaScript required) for any request covered by this notice.
We store the data you enter: your username, email address, hashed password, and pet records including weights, medications, vaccinations, feeding plans, and health events. Your email is used only for signing in and account recovery — it is never shared with third parties or used for marketing.
With your consent, we use Google Tag Manager (GTM) to load Google Analytics 4 (GA4), which helps us understand how the app is used — page views and a small number of anonymous usage events (e.g. a weight being logged). GTM is configured to run only the GA4 tag; no other tracking is added without updating this policy. Neither GTM nor GA4 ever receives your username, email, pet names, or any database identifiers. IP addresses are anonymised before use. GTM only loads after you accept the "Analytics" cookie category in the cookie banner; it never runs before you've made a choice. You can withdraw or change your analytics consent at any time from the cookie banner.
Google LLC (the provider of both GTM and GA4) is based in the US. Data is transferred under the UK Extension to the EU-US Data Privacy Framework (DPF), Google's approved transfer mechanism for UK personal data. See policies.google.com/privacy.
When you generate an AI health summary, your pet's data is sent to a third-party AI provider for processing. The provider used depends on server configuration and may change without notice. Where possible a locally hosted model is used, but this cannot be guaranteed. The provider and model are shown after each generation. No personal account information (username or password) is sent to any AI provider. AI consent can be withdrawn at any time from the AI Health Summary panel.
Possible providers and their privacy policies:
You can choose to publish a public profile page for a pet at a stable link you control. This is entirely opt-in and off by default. If enabled, the page is public and reachable by anyone with the link — no login is required to view it — and it stays live indefinitely until you disable it.
The page can only ever show: the pet's name, species, breed, and age (or exact date of birth, if you choose to show it instead of age). You separately choose whether to also show any of: selected photos (optionally including a prominent avatar photo), a short recent weight trend, and "Life Highlights" — a small set of facts auto-generated from data already on the pet's profile rather than anything you type yourself. It never shows weight history beyond the short trend, medications, health journal entries, body condition score, your account identity, or AI-generated summaries — under any combination of settings.
Any photo (including the avatar) shown on a public profile has its metadata (including any location/GPS data) removed before it's served — this is done automatically and can't be turned off. You can disable a public profile at any time from the pet's settings — the page stops working immediately. We ask search engines not to index these pages, but once a link has been shared, content that's already been cached or previewed by a search engine or messaging app may persist beyond our control even after you disable it.
Your data is stored for as long as your account exists. You may delete pets (and all associated records) at any time. You can permanently delete your Pets data yourself at any time from the "Delete My Pets Data" section of your User Profile — no need to contact an administrator.
To demonstrate that an erasure request was honoured, we retain a minimal pseudonymised record of a completed deletion for 12 months. It contains a protected reference derived from your username, timing, deletion method and outcome, and aggregate removal counts — never your email address, pet data, IP address, or a copy of deleted records. This is processed for our legitimate interest in demonstrating compliance. If a deletion is not completed, its record is kept until the issue is resolved. You may object to this processing by contacting us (see "Who's responsible for this service" above).
We also keep the same protected reference indefinitely in a separate list of deleted usernames, so a deleted username can never be reused by someone else and inherit access that belonged to you.
To exercise any of these rights beyond the self-service options above, contact us (see "Who's responsible for this service").
If you're unhappy with how we've handled your data, you can contact us directly first, or lodge a complaint with the UK's data protection regulator, the Information Commissioner's Office, at ico.org.uk.