Privacy
Draft, pending legal review. Not yet published as final.
Aniis ("Aniis", "we", "us") operates the Aniis pet-care application at aniis.ai and its companion mobile apps ("the Service"). This policy explains what personal data we collect from you and your household when you use the Service, why we collect it, who we share it with, and the rights you have over it. It applies to the web app, the iOS/Android apps, and aniis.ai.
[Operator/legal to insert: the registered legal entity name, jurisdiction of incorporation, and registered address that will be the data controller for purposes of UAE PDPL.]
We collect the information you and your household give us directly, plus a small amount generated automatically as you use the Service.
Name, email address, phone number, preferred language, and country, collected when you sign up and used to authenticate you and personalize the Service.
If you share a pet's care with family members or a caregiver, we store who has access to the household and their role (owner, caregiver, or view-only), and any email invitations you send. We also store any emergency contact details (name and phone number) you add for a household, for example, a vet or a neighbor to call in an emergency.
Species, breed, date of birth, sex, neuter status, weight, microchip number, and insurance details you choose to add; medical conditions, allergies, medications, vaccination records, vet-visit notes, weight history, and body-condition scores; day-to-day logs you create (feeding, water, walks, weight, behavior, medication, grooming, bathroom habits, and other notes) including any photos, voice recordings, or documents you attach to them. This is the most sensitive category of data we hold, and it exists because it is the core purpose of the product: tracking your pet's wellbeing over time.
Vaccination certificates, vet reports, prescriptions, lab results, insurance documents, pet passports, and photos you upload to your pet's vault. Files are stored in encrypted object storage (Cloudflare R2) and only accessible via short-lived, signed links that we generate on demand; we do not make files public.
When you use Aniis' chat or photo/stool-analysis features, we store the messages you send, any photos or voice clips you provide, and the responses Aniis gives, so a conversation can continue across sessions and so Aniis can remember relevant facts about your pet (see "AI processing" below). We also store the answers you give in a symptom check and the result it returned, so the record stays on your pet's file. A symptom check is not an AI feature and is not covered by "AI processing" below: it runs on a fixed table of clinical rules inside Aniis, and nothing you enter into it is sent to an AI provider.
If you track pet-related spending in Aniis, we store the amount, category, vendor, and any receipt you attach. If you contact support, we store your message and the ticket's status so we can help you.
If you subscribe to a paid plan, our payment processor (Stripe) collects your card or payment-method details directly; we never see or store your full card number. We keep a record of your subscription tier, billing period, and a Stripe customer reference so we can manage your subscription.
Device and browser information, IP address, and the actions you take in the app (recorded in an internal audit log for security and accountability). If you have opted in to analytics, we also receive anonymized product-usage events (see "Cookies & analytics").
We use the information above to:
We do not sell your personal data, and we do not share it with advertisers or use it for third-party advertising. Any AI or analytics processors we use are described below and are bound to process your data only to provide the Service to you.
Aniis uses third-party AI models to power its assistant, photo and stool analysis, nutrition guidance, voice transcription, and search features. Symptom triage is not one of them: it runs on a fixed table of clinical rules inside Aniis, so nothing you enter into a symptom check is sent to an AI provider. When you use the AI features, the relevant text, photo, or audio, together with the minimum pet context needed to make the response useful (species, breed, age, conditions, allergies, medications, and recent logs), is sent to the AI provider handling that request:
Every AI response passes through a safety layer before you see it: it is screened for emergency language and, for anything health-related, carries this notice, in your language:
"Aniis isn't a substitute for veterinary care. If your pet's condition changes or doesn't improve, please consult a vet."
Aniis is not a diagnostic tool and its output is not a medical diagnosis or prescription. It is designed to help you track your pet's wellbeing and decide when to see a real, licensed veterinarian, never to replace one. See our Terms of Service for more.
We instruct our AI processors to use your data only to provide the response you requested, and [operator/legal to confirm: whether each provider's data-processing agreement also excludes your data from being used to train their general-purpose models; this must be verified and confirmed in writing before this sentence is finalized].
This design follows the transparency and human-oversight principles set out in the UAE Charter for the Development and Use of Artificial Intelligence (2024) and Saudi Arabia's SDAIA AI Ethics Principles (2023): you should always be able to tell when you're talking to Aniis' AI rather than a person, you should see the "not a substitute for a vet" boundary before you act on health-adjacent output, and a human path, your own vet, or Aniis support, is always available if the AI gets something wrong. [product: the vet-deference notice currently appears as trailing text after the AI's response; consider also surfacing it as a persistent label on health-adjacent screens so the caution is visible before the user reads the AI's output, not only after.]
Our primary database is hosted in the European Union (Frankfurt). Some of the processors listed above, including our AI providers, process data in the United States. Where we transfer personal data outside the UAE, we take steps intended to ensure it receives an equivalent standard of protection, consistent with UAE PDPL. [operator/legal to confirm: the specific transfer mechanism relied on for each cross-border processor, e.g., Standard Contractual Clauses or an equivalent safeguard, and to insert the confirmed mechanism here before publishing.]
Because Aniis processes health-adjacent data about you and your pet through AI providers based in the United States, a small number of GCC countries impose extra conditions before that kind of transfer is permitted:
Until each of these is confirmed in writing, we are not able to represent that Aniis fully satisfies Saudi, Qatari, or Omani transfer requirements for sensitive data; we disclose that here rather than leave it silent. See also Your local data protection authority.
Aniis's data controller is registered in the United Arab Emirates, and this policy is written primarily around UAE Federal Decree-Law No. 45 of 2021 (PDPL). Aniis is built for pet owners across the GCC, so if you live in another GCC country, your own national law may also apply to how we handle your data, and you can raise a concern with your local authority directly:
[operator/legal to confirm: whether Aniis needs a registered local representative, or a Data Protection Officer/Guardian-equivalent point of contact, in Saudi Arabia and/or Bahrain given the scale of sensitive health-data processing described above.]
We keep your data for as long as your account is active, so the Service can work as intended. When you delete your account, we mark it for deletion immediately (you can no longer sign in) and your data is permanently erased after 30 days.
We stop using your data the moment you ask, not 30 days later. From that point your pets drop out of our automated health scans, reminders and AI features, and nothing new is generated from your records. The 30 days are not a period in which we carry on working with your data. They are how long it takes us to complete the erasure across every system we hold it in, including our backups, on a schedule we keep to.
Deleting your account takes effect straight away and cannot be undone from the app: your sign-in is removed at the same moment, so there is no account left to sign back in to. If you deleted your account by mistake, contact us before the 30 days are up and we will tell you what, if anything, can still be recovered.
Backups. We keep backups of our database for up to about four weeks so we can restore the Service after a failure, and each one is replaced on a fixed schedule. A backup is never used to bring back data you asked us to delete. If we ever do have to restore from one, we re-apply your deletion to the restored system.
Some records may be kept for longer where the law requires it, or where we need them to establish or defend a legal claim, for example billing and audit records. We also keep a minimal marker of a deleted sign-in identity, containing no name, email, pet or health information, so that a deleted account cannot be silently recreated.
Under UAE PDPL, and depending on where you live, you have the right to:
You can exercise most of these rights directly from Settings in the app. For anything else, contact us, see "Contact us" below. Because a data export or account deletion touches sensitive health records, we may ask you to verify your identity before acting on a request.
Aniis is intended for adults. By creating an account, you confirm that you are at least 18 years old (or the age of majority in your jurisdiction, if higher). We do not knowingly collect personal data from children. If you believe a child has created an account or provided us data, contact us and we will remove it.
We use industry-standard technical and organizational measures to protect your data, including encryption in transit, access controls scoped to your household so other users can't see your pets' records, short-lived signed links for file access rather than public URLs, and an internal audit log of sensitive actions. No system is 100% secure, and we encourage you to use a strong, unique password and keep your device secure.
We may update this policy as the Service evolves. If we make a material change, we'll let you know, for example, by email or an in-app notice, before it takes effect. The "last updated" date at the top of this page always reflects the current version.
Questions about this policy, or a request relating to your data, can be sent to [email protected]. [Operator/legal to confirm whether a dedicated [email protected] inbox and a named UAE PDPL point of contact should be established before launch.]