1. Our Data Sharing Principles
At Paw AI, we believe in radical transparency about data. This page provides a complete, plain-language disclosure of every third-party service we use, what data is shared with each, and why. We follow three core principles:
- Minimum necessary data: We share only the data strictly required for each service to function.
- No data selling: We do not sell, rent, or monetize your personal data or your pet's data to any third party.
- No data brokers: We do not share your location history or personal data with advertising networks or data brokers.
2. Summary Table
| Service | Category | Data Shared | Server Location | Required? |
|---|---|---|---|---|
| Supabase | Backend / Database | All user & pet data, uploaded media, auth tokens | AWS us-east-1 (US) | Required |
| OpenAI API | AI Processing | Text prompts, image data, conversation history | United States | Required (for Dr. Paw) |
| Google Places API | Location Search | Lat/lng coordinates, search keywords | Google Cloud (US) | Required (for Explore) |
| Apple WeatherKit | Weather Data | Lat/lng coordinates | Apple infrastructure | Required (for AI context) |
| Open-Meteo | Weather Fallback | Lat/lng coordinates | EU-based | Fallback only |
| Apple StoreKit | Payments | Transaction data (handled by Apple) | Apple infrastructure | Required (for subscriptions) |
| Apple SFSpeechRecognizer | Speech-to-Text | On-device only — no data uploaded | On-device | Required (for voice diary) |
3. Supabase
Data Shared: All user account data, pet profiles, health diary entries, uploaded photos/videos, AI conversation history, and authentication tokens.
Server Location: AWS us-east-1 (N. Virginia, United States).
Supabase Project URL:
https://yvzmpvvohulnqnxmxusy.supabase.coData Processing Agreement: Supabase is GDPR-compliant and provides a Data Processing Agreement (DPA). See supabase.com/privacy.
4. OpenAI API
Models Used: GPT-4o (complex analysis), GPT-4o-mini (routing, simple chat).
Data Shared: Text prompts, pet photo/image data (base64-encoded), and conversation history for the current session.
Server Location: United States.
AI Training: Per OpenAI's API data usage policy (effective March 2023), API inputs and outputs are not used to train OpenAI's models. OpenAI retains API data for a maximum of 30 days for abuse monitoring, then permanently deletes it.
OpenAI Privacy Policy: openai.com/policies/privacy-policy
5. Google Places API
Data Shared: Device GPS coordinates (latitude/longitude) and search keywords.
Server Location: Google Cloud infrastructure (United States).
Google Privacy Policy: policies.google.com/privacy
6. Apple WeatherKit
Data Shared: Device GPS coordinates (latitude/longitude).
Server Location: Apple infrastructure.
Apple Privacy Policy: apple.com/legal/privacy
7. Open-Meteo
Data Shared: Device GPS coordinates (latitude/longitude). No API key required; requests are anonymous.
Server Location: EU-based (open-source project).
Open-Meteo Privacy Policy: open-meteo.com/en/terms
8. Apple StoreKit (In-App Purchase)
Data Shared: Transaction data is handled entirely by Apple. Paw AI receives only a transaction receipt to verify subscription status. We do not receive or store your payment card details.
Server Location: Apple infrastructure.
Note: All refunds and subscription management must be handled through Apple ID Account Settings. Paw AI cannot process refunds directly.
Apple Privacy Policy: apple.com/legal/privacy
9. Apple SFSpeechRecognizer
Data Shared: None. Speech recognition is performed entirely on-device. No audio data is uploaded to any server for speech-to-text processing.
Server Location: On-device (no cloud upload).
Note: The resulting text transcript may subsequently be sent to OpenAI for AI parsing and diary generation.
10. Services We Do NOT Use
We explicitly confirm that Paw AI does not use any of the following services:
| Service | Category | Status |
|---|---|---|
| Firebase / Google Analytics | Analytics | Not used |
| Mixpanel | Analytics | Not used |
| Amplitude | Analytics | Not used |
| Sentry | Crash Reporting | Not used |
| Crashlytics | Crash Reporting | Not used |
| Facebook SDK / Meta Pixel | Advertising | Not used |
| Google AdMob | Advertising | Not used |
| Stripe / PayPal | Payment | Not used |
| Google Play Billing | Payment (Android) | Not used (iOS only) |
| Any China-based cloud service | Infrastructure | Not used |
11. Data Brokers Policy
Paw AI has a strict policy against sharing user data with data brokers or advertising networks. Specifically:
- We do not sell your personal data to any third party.
- We do not share your location history with data brokers.
- We do not use your data for targeted advertising.
- We do not participate in any data exchange or data marketplace programs.
The only circumstances under which we may disclose your data to third parties are: (a) with your explicit consent; (b) to the service providers listed on this page, for the stated purposes only; (c) to comply with a legal obligation or valid court order; or (d) to protect the rights, property, or safety of the Company, our users, or the public.
12. Data & Mainland China
Although Paw AI is developed and operated by a Shenzhen-based company, no user data is ever transmitted to or stored on servers located in mainland China. All data processing occurs on servers in the United States (Supabase on AWS us-east-1) and, for weather fallback only, in the EU (Open-Meteo).
This design decision was made intentionally to ensure compliance with international privacy standards including GDPR and CCPA, and to provide our global user base with the highest level of data protection.
13. Contact Us
If you have any questions about our data sharing practices or wish to exercise your data rights, please contact us:
| Purpose | Contact |
|---|---|
| Privacy & data inquiries | support@otalktech.com |
| Business inquiries | info@otalktech.com |
Shenzhen OTalk Technology Co. Ltd.
Shenzhen, China · Established 2018