PickyCat Privacy Policy

Last updated: September 4, 2026

PickyCat helps you record what your cat eats and recommends canned food from it. This policy sets out what it collects, what it does not, and how to withdraw and delete.

The short version: by default your data stays on your own device and nothing is uploaded at all. Only if you switch on "anonymous sharing" is a copy — carrying nothing that identifies you or your cat — sent to us, and you can switch it off again at any time.

1. Data that stays on your device

Your cat's profile, every logged meal, the wishlist and the head-to-head answers are stored in your device's local storage. The app has no account by default, you do not register, and without one there is no way for us to read any of it from a server. If you choose to Sign in with Apple and share with your family, that changes — section 4 covers it on its own.

A note for the web version: this data lives in browser site storage. Safari deletes it on its own after a period of not visiting, and a private window never keeps it at all. That is browser behaviour and outside our control. Settings → "Your data" → "Back up & transfer" offers a backup you can export.

2. Anonymous sharing (off by default)

If you turn this on, the app sends a copy of the record to our server to improve the recommendations — specifically, so the app can learn what cats in similar circumstances did with the same cans.

Since 2026-09-04 that copy carries three more things: weights, the shopping list and the pantry. They are there for a different job — if you lose your phone or reinstall, this record is the only thing we can rebuild your history from, and until now weights, the list and the pantry could not be given back. Only can identifiers and numbers travel; the notes you wrote on the list and in the pantry do not.

What is sent, in full

What is never sent

The upload is built from a whitelist: the code names every field that may travel, rather than taking the whole profile and removing what should not. An automated check enforces that rule.

About those three pieces of free text

Before August 20, 2026 this page could say that no free text is ever uploaded, and a check in the code read the whole payload looking for prose, holding that sentence to the letter.

There are now three exceptions, and only three, each capped at 24 characters:

The last two travel because knowing how many owners have a cat that is not on our list tells us nothing we can act on — we have had that number since the first version. To fix the list we need to know which breeds are missing. Neither box appears unless you pick “Something else”, nothing is sent if you leave it empty, and if you later change the breed back to one on the list, what you wrote stops being uploaded and is not kept.

The check was not switched off. What it now allows is those three fields, each named by its exact path, rather than anything that looks like a supplement or a breed; every other string in the payload is still read by it. The check also pins the opposite: put the same words in any other field — including a field merely named like an exempt one — and it must still stop them. The day either assertion stops failing is the day the opening got wider.

If you would rather none of it were uploaded: use only the three built-in supplements and not “+ custom”; do not pick “Something else” for breed or coat, or pick it and leave the box empty; or switch off anonymous sharing, which stops everything.

About that random number

It is generated on your device using the system's cryptographic random source. It has no relationship to your name, email or device, and no meaning anywhere else. It exists solely so that repeated uploads from one cat are recognised as one cat rather than counted as many.

Under Apple's App Store categories this counts as "Data Linked to You", because entries are associated through that number. We declare it as such.

3. Camera answers (off by default)

You can photograph a can. The app reads the words on the label, offers three cans it might be, and you pick one. That tap is a correct answer — somebody holding the can telling us whether the camera read it right — and it is the only thing that can measure whether it works.

With Send my answer when I pick a can switched on in Settings, what is uploaded is:

The photograph is not uploaded. It stays on your phone. The table on the server has no column for an image, so there is nowhere for one to land even if a future version tried to send it, and an automated check fails the build if the upload ever mentions the photograph's path.

Nothing in it identifies anyone: no cat, no meals, not the random number described above, nothing that identifies you or your phone. A row is some words from a label, three catalog ids, and which one was right.

This is a separate switch from anonymous sharing. Both are off until you turn them on, and either can be on without the other. They are kept apart because agreeing to share what your cat ate is not agreeing to send what your camera read.

On deletion: precisely because these rows carry no identifier, we cannot find "yours" — there is no handle to look them up by. If you would rather they were not sent, switch it off; nothing further is sent from that moment.

4. Account and family sharing (optional, off by default)

This section and section 2 above describe two completely different things. The "anonymous sharing" in section 2 is a random identifier unconnected to you; it is upload-only, we never read it back, and your cat's name and photo never leave your phone. An account is the opposite: once you sign in, your full record is stored on our server and read back onto your phone and your family's. The two are independent — you may use either, both, or neither.

If you do not sign in, none of this applies. Without an account the app behaves exactly as before, and not one byte leaves your device because of this feature.

Sign-in method: Sign in with Apple only. Apple gives us a stable identifier for you (sub); we store only a hash of it, and store neither your email address nor your name. The name your family sees is one you type yourself (for example "Dad") and is visible only to members of your household.

What is stored on the server once you sign in: your cats' profiles (including the names, ages and breeds you entered), every logged meal, the pantry, the shopping list and its notes, weight readings, head-to-head comparisons, shelf rules and presets, and any cans you entered yourself. In short, a complete copy of what you have recorded in the app.

Photos are not uploaded. Cat photos and photos of cans stay on the phone that took them. They are not synced to family members and are not stored on our server.

Family sharing: you can generate an invite code that is valid for 24 hours and can be used once. Anyone who joins your household with it can see and change everything listed above. That is the purpose of the feature — one household feeding one cat. Only give the code to family you trust.

Signing in includes the consent described in section 2. (Since 2026-09-04.) Once signed in, your record is not only kept for you: it also joins the figures described in section 2 — what other cats eat, which is where match scores come from. The sign-in screen says so. Signing out puts that consent back to whatever it was before you signed in; it is not left on. If you would rather not take part, do not sign in — nothing else in the app changes.

Once you sign in, we link the anonymous identifiers this phone already has to your account (since 2026-09-04): the device code used for submissions, and each cat's anonymous record identifier. This is so that when you write to us saying “my records are gone” or “delete my data”, we can reach what you left before you signed in — until now that depended on you copying a number to us, which somebody who has lost their phone cannot do.

Only what already exists is reported; signing in does not create either identifier. If you never made a submission and never turned anonymous sharing on, you do not have them, and signing in does not mint one.

The link is not a key. It is the first clue a person uses when handling a support request; on its own it cannot read, delete or restore anything — those steps still require confirming who you are separately. It is deleted with your account.

What is not synced: your language, notification settings, which cat is currently selected, and local caches all stay on the device.

5. Diagnostics when something goes wrong (sent automatically)

When the app cannot open, or a screen fails, it sends us a short diagnostic on its own. This section is what is in it, and why it is automatic.

What is sent:

What is not sent: the value in any drawer. Not your cat's name, not a meal, not a weight, not the wishlist, not a photograph. The above are readings off a ruler, not the thing being measured.

Why automatic? Until now it took a tap, and the button only ever appears when the app will not open at all. The two common cases — it hung once and worked next time, and it took twenty seconds and then opened — do not look like a failure from your side, so nobody was ever going to press anything. That made the two commonest faults ones we could not learn about by design. What changed is who decides to send; what is sent did not change.

There are limits: at most two automatic reports per episode, one "slow launch" report per app version per phone, and one report per distinct error per session.

The Copy my data button stays manual, always. That one is your full record, and no automatic process touches it.

6. What we do not do

7. Third parties

Shared records are stored on our own server in Guangzhou, China (Tencent Cloud). We run the database ourselves; no database hosting provider is involved any more. No other third party receives this data. The app contains no analytics, advertising or social SDKs.

Before August 20, 2026 this data was held on Supabase, outside China. Copies of the app already installed keep uploading there until their owner updates: the address is compiled into the app at build time, and we cannot change it remotely on an installed copy.

One thing worth stating plainly: as with any web service, the server sees the IP address of the request, and the hosting provider's access logs may retain it briefly. We do not use it in connection with the uploaded content.

8. How long it is kept

Shared records are kept indefinitely, because studying how taste changes requires the history. As they contain nothing identifying, they do not become a profile of you over time.

The diagnostics in section 5 are kept for one year. Their whole value is "what went wrong on which version", and that stops meaning anything once a version is retired.

9. Withdrawing and deleting

Deleting your account: open the app → Settings → Account & family → Delete my account. This permanently deletes your account and your copy of the record on our server. Nothing on your phone is affected. If anyone else is still in your household, the shared record stays — it is theirs too; if you are the last member, the whole household's record is deleted with you.

Deleting your account does not include the anonymous copy described in section 2. (Zhuo's decision, 2026-09-04.) That copy has the names, photos and free text stripped out of it and exists to improve the recommendations; deleting it follows the route section 2 describes. What has changed is this: if you have ever signed in, we can find it ourselves — that is what the link in section 4 is for — so you no longer need to copy the identifier to us. Just say so in the email.

Signing out: on the same screen. Signing out only stops syncing. It deletes nothing on the server and touches nothing on your phone.

To stop sharing: open the app → Settings → Anonymous sharing → switch off "Share [your cat's name]'s record and learn from others". It takes effect immediately; nothing further is uploaded, and anything still queued is discarded.

To delete what has already been shared: on that same screen, while the switch is on, a number is displayed. That number is the only identifier your record carries on the server. Copy it and email it to the address below, and we will delete the matching records. Copy it before you switch sharing off, since it is only on screen while the switch is on. If you have already switched it off, turning it back on shows the same number again — it is stored on your phone and does not change.

Please understand why it has to work this way: precisely because the server holds nothing that points to you, we cannot find "your" rows from a name or an email address. That number is the only handle. If you have already deleted the app or cleared its data, the number is gone with it and we can no longer locate those records — at that point they are anonymous data that cannot be connected to any person.

To delete diagnostics: those are the easy ones, because section 5's reports are filed under a device code. Email the address below and we will remove them. If you have ever sent us a message or a submission from the app, those carry the same code, so we can match them up.

10. Children

This app is not directed at children under 13 and does not knowingly collect information from them.

11. Changes to this policy

If what we collect changes, this page is updated and the date at the top changes with it. If collection is broadened, we will ask for your consent again rather than relying on consent given for something narrower.

12. Contact

For privacy questions or deletion requests: pickycatapp@gmail.com