Meddor

Privacy policy

Meddor — last updated: October 7, 2026. The French version is the reference text.

Meddor is a health record for pets. This page explains, plainly, what data the app stores, why, who it is entrusted to, how long it is kept, and what you can do about it.

What we store

Signing in with Google or Apple

You can create your account with an email address and a password, or with Google (on iPhone and Android) or Apple (on iPhone). Either way, the service identifies you itself, then passes on your email address — with Apple, possibly a relay address that hides yours — and your name. Google also includes the address of its profile photo, which the app doesn’t show. We keep the email and the name with your account, and never receive your Google or Apple password. When you delete an account created with Apple, we also remove Meddor’s access from your Apple account.

Automatic reading with AI

Some features send an image or a text to OpenAI (United States), only when you trigger them yourself, and only to provide that feature:

We send it neither your name, nor your email, nor the rest of the record. Under its API terms, OpenAI does not use this data to train its models, and keeps it for up to 30 days (to detect abuse, and, for the food search, the answer itself), unless the law requires it to keep it longer. A prescription often shows the owner’s and the vet’s names: if you don’t want it read by this service, enter the treatment by hand. The number of readings per person per day is capped.

Place search

When you search for a clinic or a shop to save, the text you type is sent to Google Places (Google), with the app language, to suggest addresses. Our server is what queries Google: Google receives neither your name, nor your email, nor your internet address. The place you pick (name, address, phone number, coordinates) is saved in your record. If you prefer, enter the place by hand: nothing is then sent to Google.

What we don’t store. No location of your phone (a place’s coordinates are those of the business you picked, not yours), no advertising identifier, no cross-app tracking and no usage analytics in the app. We never sell your data or share it with third parties for commercial purposes.

Who can see your data

Your data belongs to your household: you and the people you invite. The database rejects any read coming from another household: this isn’t an app setting, it’s a rule enforced on the server for every request. An invite code is valid for seven days, works once, and is never stored in plain text.

One exception: your pets’ drawn portraits are served from a public web address that is long and impossible to guess. Anyone who knows that address can see the image — the portrait alone, with no name or other information. The photos you take are never public.

How your data is protected

Where your data is hosted

On Supabase infrastructure, in the Western Europe region (Ireland). Only what the sections above and below describe leaves the European Union, at the moment the service is provided: images and text read by OpenAI, place searches sent to Google, and dose reminders delivered by Expo and Apple.

Other services we use

How long we keep it

Deleting your account

From the app: Household tab → Account → Delete my account. Or by email, to connect.meddor@gmail.com, from the account’s address. What deletion erases depends on your household:

In both cases, what stays, detached from you: foods added to the shared catalog, and, until their retention period ends, the log of sensitive operations (technical ID only) and copies at our service providers. The full details are on the Delete your account page.

Your rights

Under the GDPR, you can ask to access your data, correct it, erase it, or take it with you, and object to its processing. Write to connect.meddor@gmail.com: we reply within 30 days. If our answer doesn’t satisfy you, you can file a complaint with the French data protection authority, the CNIL.

Permissions the app asks for

Meddor · connect.meddor@gmail.com