← purzi.dog

Privacy Policy

EU GDPR · UK GDPR · PECR · ePrivacy

Updated: May 2026

1. Data controller

ControllerAntonio Sierra Saavedra
ProjectcanAI.dog
Contacthola@purzi.dog
ScopeEuropean Union — primarily users from Spain, Germany and the UK

For privacy enquiries write to hola@purzi.dog. We respond within 72 business hours.

2. What data we collect

We only collect data that is needed to provide the service:

Email addressTo create your account via magic link or Google OAuth. Stored in Supabase Auth.
Dog profileName, breed, sex, age, weight, energy level, allergies, fears, goals. Provided voluntarily by you.
Chat messagesConversations with the AI assistant. Stored to keep the conversation context.
Vaccination recordsVaccine name, date administered and next due date. Provided voluntarily.
Dog photosIf you upload a profile photo, it is stored in Supabase Storage (encrypted at rest).
Session preferencesCountry and language detected from IP/browser or selected by you. Session cookies only.
Technical usage dataIP address (anonymised), browser type, operating system. Required for service operation and security.

We do not collect: payment data (no paid features active), data from children, or human health data. Dog data is not "health data" within the meaning of UK GDPR / EU GDPR Article 9 (it concerns companion animals).

3. Purpose and legal basis

Providing the service (chat, profile, recommendations)Performance of a contract — Art. 6(1)(b) GDPR
Improving the service and debuggingLegitimate interest — Art. 6(1)(f) GDPR
Email communications (sign-in confirmation)Performance of a contract — Art. 6(1)(b) GDPR
Product analytics (PostHog) and non-essential cookiesConsent — Art. 6(1)(a) GDPR + PECR (UK) / ePrivacy (EU)
Compliance with legal obligationsLegal obligation — Art. 6(1)(c) GDPR

4. Processors (sub-processors)

To operate the service we share data with the following providers, each covered by a Data Processing Agreement (DPA) compliant with GDPR Art. 28:

Supabase, Inc.Database, authentication and storage. Servers in the EU. DPA at supabase.com/privacy. Data hosted in the EU — no transfer to third countries.
Anthropic PBCClaude AI model for chat. US-based. DPA incorporated in their commercial terms (SCCs Module 2 and 3). Chat messages may be processed on their servers.
OpenAI LLCImage generation (DALL-E) and semantic embeddings. US-based. Transfers under SCCs (Decision 2021/914/EU) or UK IDTA where applicable.
Vercel, Inc.Hosting, CDN and Vercel Analytics (anonymous usage analysis). Global edge servers including EU/UK. DPA at vercel.com/legal/dpa. US transfers under SCCs/UK IDTA.
PostHog (EU Cloud)Product analytics: page views, usage events, Web Vitals and session recording. Only enabled after your consent (the "Analytics" category). Data hosted in the EU (eu.i.posthog.com) — no transfer to third countries. DPA at posthog.com/privacy.
Google LLCOAuth authentication (if you sign in with Google). We only receive your verified email address.
Amazon EU S.à r.l.Amazon Associates Program. Product links marked (*) generate a small commission for canAI at no additional cost to you. Amazon may set affiliate tracking cookies. Privacy policy: amazon.co.uk/privacy.

For international transfers to the US (Anthropic, OpenAI, Vercel) we rely on Standard Contractual Clauses (Implementing Decision 2021/914/EU) and, for UK users, the UK International Data Transfer Addendum issued by the ICO.

Amazon affiliate disclosure: canAI participates in the Amazon Associates Program. Links marked (*) generate a small commission for canAI at no extra cost to you. Affiliate tags: canaidog-21 (Spain), canaidog0c-21 (Germany).

5. Retention

Account and profile dataWhile your account is active. After deletion, data is removed within 30 calendar days.
Chat historyWhile your account is active or until you delete it manually.
Vaccination recordsWhile your account is active or until you delete them.
BackupsMaximum 90 days in Supabase backups.
Technical data (IP, logs)Maximum 30 days in server logs.

6. Your rights (GDPR arts. 15–22)

You can exercise the following rights by writing to hola@purzi.dog with subject "GDPR rights" and a copy of your ID document:

  • Access (art. 15): obtain a copy of your data.
  • Rectification (art. 16): correct inaccurate data.
  • Erasure / "right to be forgotten" (art. 17): delete your account and all data.
  • Restriction (art. 18): suspend use of your data.
  • Portability (art. 20): receive your data in machine-readable format (JSON).
  • Objection (art. 21): object to processing based on legitimate interest.

We respond within 30 calendar days. If you are not satisfied you can lodge a complaint with the supervisory authority of your country — for example the UK ICO, the Spanish AEPD or your local German Landesbehörde.

7. Security

  • TLS 1.3 encrypted communications between browser and our servers.
  • Data at rest encrypted by Supabase (AES-256).
  • Passwordless authentication (magic link / Google OAuth).
  • Row Level Security (RLS) in Supabase: each user only sees their own data.
  • No third-party access to personal data except the processors listed in section 4.

8. Cookies and analytics

We use technically essential cookies for service operation (user session), which do not require consent. In addition, if you accept it, we use PostHog (hosted in the EU) for product analytics: page views, usage events and performance metrics, with the purpose of improving the service. Analytics is disabled by default and only enabled with your consent (Art. 6(1)(a) GDPR).

You can withdraw your consent at any time using the “Manage cookies” link in the footer. See the Cookie Policy for full details.

9. Children

The service is aimed at users aged 13 and over (UK) / 16 and over (EU, unless national law sets a lower threshold). We do not knowingly collect data from anyone below that age. If we learn an underage user has registered we will delete the account promptly.

10. Changes to this policy

We may update this policy when necessary. We will notify you by email if changes are substantial. The updated date is always shown at the top of this document.

PrivacyTermsCookiesImprinthola@purzi.dog
BETA