Clear about your pet's data β and yours.
Ostler collects only what it needs to help you care for your pet, tells you exactly what reaches our AI, and lets you delete everything, anytime.
Not used to train AI
What you send our AI processor, Anthropic, is used only to answer you β never to train any model.
Household sharing, your rules
Invite family in and they see shared pets and logs. Your chat conversations stay private to you.
Delete anytime
One tap in Settings removes your account, pets, logs, and every chat conversation β permanently.
Never a diagnosis
Ostler gives guidance, not veterinary care. Signs of an emergency send you straight to a vet.
1. Who we are
Mario Noriega, an individual established in Guatemala City, Guatemala, trading as Ostler ("Ostler", "we"), operates the Ostler mobile app and the ostlerapp.com website, and decides how your information is used. Contact: support@ostlerapp.com, or 41 Avenida 15-49, Zona 5, Jardines de la AsunciΓ³n Sur, Guatemala City, Guatemala.
Ostler is not available in the European Economic Area, the United Kingdom, or Switzerland. We do not sell the app in those territories and do not direct it at people there, so this policy is written for the places where Ostler actually is sold. If you live in one of them, please don't use the Service.
2. What we collect
| Category | What | Why |
|---|---|---|
| Account | Email address, hashed password, subscription status and plan, optional profile photo | To create and secure your account, and to unlock paid features |
| Pet profiles | Name, species, breed, sex, age, weight, your notes, optional photo | To personalise reminders, logs, and guidance |
| Care logs | Activities (walks, meals, medications, weights, vet visits), reminders | To provide tracking and reminders, and to give guidance context |
| Chat | Messages you write, and photos or PDFs you attach | To generate AI responses and to show you your conversation history |
| Vet finder | Your approximate location or the postal code you type, used for one search | To find nearby clinics. Location is used at the moment of the search and is not stored. |
| Product analytics | Event names (e.g. "pet added"), a random session identifier, platform, timestamps, and β for emergency escalations β the pet's species and the triggering category. While you are signed in these events are stored against your account, so they are linked to you rather than anonymous | To understand feature usage and to tune the emergency escalation for false positives |
| Crash diagnostics | When the app hits an error: the error message and stack trace, the screen you were on, the app version and build, your device model and iOS version, and a random session identifier. While you are signed in these are stored against your account. Messages and stack traces are automatically stripped of email addresses and access tokens before they are stored | To find out that the app broke, and to fix it |
| Notification token | Only if you allow notifications: the token Apple issues so this device can receive notifications, the app's language on that device, and whether you have family activity notifications switched on. The token is removed when you sign out of that device or delete your account | To send you family activity notifications (Section 5) |
| Waitlist | The first name and email address you enter in the early-access form on ostlerapp.com, and which link brought you there | To email you once, when Ostler launches |
| Reported responses | If you report an assistant reply: which reply it was, which of a few fixed reasons you chose, and that it was you who reported it. We do not store a second copy of the reply β it is already in your conversation | To find out when the assistant gives harmful or wrong guidance, and to fix it |
| Technical | IP address and request metadata processed by our hosting provider | Security, abuse prevention, and service operation |
We do not collect payment card details. Subscriptions are processed by Apple; we receive only subscription status via RevenueCat.
Analytics events never contain the text of your messages. Emergency escalation events record the category, the pet's species, and the time β never what you wrote.
Crash diagnostics are not analytics: nothing is recorded unless something goes wrong. A crash report describes the fault, not what you were writing β but because an error message is text the app did not choose, we strip email addresses, sign-in tokens and attached files from every report before storing it, rather than trusting that none got in.
Cookies and tracking technologies
Ostler uses none. The website sets no cookies and uses no local storage, no pixels, no advertising or analytics tags, and no third-party trackers β which is why you are not asked to accept any. The app carries no advertising or analytics SDK either; it keeps your sign-in token in the device keychain, not in a cookie. The product analytics described above are our own, are sent from the app to our own API, and reach no one else.
Because we run no cross-site tracking, there is nothing for a Global Privacy Control or Do Not Track signal to switch off. We honour them regardless β see Section 10.
What not to send us
Chat is a free-text box and it accepts photos and PDFs, so it is possible to send us far more than pet care needs. Please don't. Ostler has no use for, and asks you not to enter:
- human health information β your own or anyone else's medical records, test results, or prescriptions. Ostler is for animals, and cannot answer human medical questions;
- government identifiers β a driving licence, passport, national insurance or Social Security number, or a photo of any of them;
- payment details β card numbers, bank details, or anything similar. We never need them: subscriptions are handled entirely by Apple, and we never see your card;
- passwords, sign-in codes, or security answers, for Ostler or for anything else. We will never ask you for one;
- other people's personal information where you don't have their permission to share it β see Section 4.
None of this is idle housekeeping. Information of these kinds carries obligations we have deliberately built Ostler not to take on, and sending it to us gives you no benefit β Ostler cannot act on it. If a document you need to ask about contains something from the list, crop it or describe the relevant part in your own words instead.
If you have already sent something you would rather we did not hold, delete that conversation β which deletes the message and any attachment with it β or write to support@ostlerapp.com and we will remove it.
3. AI processing by Anthropic
Ostler chat is powered by Anthropic's Claude API. We ask you to review and accept this disclosure before your first chat message, and again whenever it materially changes. When you send a chat message, the following is transmitted to Anthropic to generate a response:
- the text of your message and the recent messages in that conversation;
- any photo or PDF you attached to it;
- the profile of the pet the conversation is about β its name, species, breed, sex, age, weight, and your notes;
- a short summary of that pet's logged history (recent weight entries, logged medications, upcoming reminders) β including entries logged by any household member who has access to that pet, not only you. See Section 5.
The following is never sent to Anthropic:
- your name or email address;
- your precise location;
- payment or subscription details;
- your account identifier.
Your data is not used to train AI models. Anthropic processes it as our service provider under its commercial terms, solely to return the response you requested.
4. Photo retention
A photo you attach to a chat message is transmitted to Anthropic to generate that response and is not retained by Anthropic for training. On our side, the photo is stored as part of your conversation so that the conversation can be replayed and follow-up questions still have context.
- Delete the conversation and the attached photos in it are deleted with it.
- Delete your account and every photo you have uploaded is deleted.
- Photos attached to a pet's saved log entry are kept as part of that entry until you delete it.
Content about other people
What you attach can hold more than your pet β a family member in the frame, the name and signature of a vet on an invoice, a previous owner on a registry paper, a document somebody else wrote. You choose what to upload, and the Terms of Service ask you to have the right and the permission to upload it.
On our side we process it only to run the Service for you: to show you your conversation, and to generate the response you asked for. We do not use it to identify anyone, we build no profile of anyone who appears in it, and it never trains an AI model. Delete the conversation or your account and it goes with them, as above.
If you believe your own information, or material you hold the rights to, is stored in an Ostler account, write to support@ostlerapp.com. We will investigate and remove it where the claim holds up β the Terms of Service set out the copyright process in full.
5. Household sharing β who else can see your data
Ostler supports shared households. If you invite someone with your household access code, or you join someone else's household, every member of that household can see all pets in it, and all activity logs and reminders for those pets β including entries other members created. Members can also add and edit those entries.
Chat conversations are not shared. They remain private to the account that created them.
Household entries can reach our AI processor. If you chat about a shared pet, the summary described in Section 3 may include log entries that another household member created for that pet, not only entries you created yourself.
Every member accepts this themselves. Joining a household requires you to read and accept the same AI-use disclosure the account owner accepted, before you join and before you have written anything. Nobody consents on your behalf: an invitation cannot be used to enable your entries for AI processing, and accepting is a deliberate action with no pre-ticked box and no way to dismiss it. We record which version of the disclosure you accepted and when.
If a member has not accepted the current disclosure β for example someone who joined before we introduced this, or who has not yet re-accepted after we materially changed the wording β their entries are left out of the summary entirely rather than sent on someone else's agreement.
Family activity notifications. When a member logs a walk, a meal, a treat or medication, the other members who have notifications allowed receive a notification saying so: the first name of the member who logged it, the pet's name and what was done. Any note typed with the entry is never included. This tells members nothing they could not already see in the shared log. Each person can switch these notifications off in Settings β General.
The household owner can remove members at any time. If you leave or are removed, you lose access to that household's pets and logs.
6. Automated processing
Two features process what you write automatically, with no human reviewing it first:
- Chat responses are generated by AI. No veterinarian or other person reviews a response before you see it.
- Emergency escalation screens what you write for signs of an urgent situation and, when it matches, interrupts the conversation to tell you to contact a veterinarian immediately.
Both are informational, and neither decides anything about you. You are free to disregard either, and every care decision stays yours. Escalation is deliberately cautious and will sometimes fire when there is no emergency. Every chat screen is labelled as AI, so you always know what you are talking to.
7. Who we share with
We do not sell your personal information and we do not share it for cross-context behavioural advertising. Every processor listed below is contractually required to protect your information to the same or an equal standard as this Privacy Policy and Apple's App Store Review Guidelines require, whether or not this policy binds them directly. We use these processors:
- Anthropic β AI processing for chat (see Section 3).
- Vercel β application hosting.
- Neon β database hosting.
- Resend β delivery of sign-in code emails.
- Expo (650 Industries, Inc.) β delivery of family activity notifications to Apple's push notification service. It receives the device's notification token and the text of the notification, and nothing else about you.
- Google β sign-in, and the clinic listings, ratings and opening hours in the vet finder. Googleβs handling of what it receives is governed by the Google Privacy Policy.
- Apple β app distribution and subscription payments.
- RevenueCat β subscription status management.
- OpenStreetMap β clinic data and postal-code lookup for the vet finder, through the OpenStreetMap Foundationβs Nominatim and Overpass services. A postal code or coordinates are sent to perform the search; no account information is sent. Map data is Β© OpenStreetMap contributors, available under the Open Database Licence, and the Foundationβs handling of requests is governed by its Privacy Policy.
We may also disclose information where required by law, or as part of a merger or acquisition (you will be notified).
8. Retention
We keep personal information only for as long as we need it for the purpose it was collected for. Every period below is a maximum, not a target. Where a law requires us to keep a particular record longer β a tax or accounting record, for example β we keep only that record, and only for as long as the law requires.
- Account, pets, logs, reminders, conversations: kept until you delete them or delete your account.
- Chat photos: as described in Section 4.
- Analytics events: retained for 90 days, then deleted. No law requires us to keep them, and nothing in Ostler reads an event older than 30 days β the extra 60 is headroom for investigating a problem after the fact, not a store we draw on.
- Crash reports: retained for 90 days, then deleted, on the same basis as analytics events. We keep an anonymous record of the fault for longer β its error message and the code it happened in, with no user, device or session attached β because knowing that a bug fixed last year has come back is the point of collecting it at all.
- Reported responses: kept until you delete your account, and deleted with it. Unlike analytics and crash rows these are not aged out on a timer, because a report of harmful guidance is worth most when it can be read months later against a pattern rather than as a single incident.
- Sign-in codes: the six-digit codes we email you expire after 10 minutes, and the record of them is deleted within 24 hours whether it was used or not.
- Waitlist entries: kept until Ostler launches and the one announcement email has been sent, then deleted. A waitlist entry is not attached to an account, so deleting an account does not remove it β write to support@ostlerapp.com and we will remove it at any time.
- Backups: deleted data may persist in our database provider's encrypted backups for up to 30 days before those backups roll over.
9. Deleting your data
You can delete your account in the app: Settings β Delete account. This permanently deletes your account, your pets, activity logs, reminders, chat conversations and their attachments, and your analytics, crash-diagnostic and AI-usage records. Family members you invited are returned to their own household. This cannot be undone.
You can also email support@ostlerapp.com with the subject "Data deletion request". We will verify that you control the account's email address and complete the deletion within 30 days β well inside the 45 days the CCPA allows.
10. Your rights
California (CCPA/CPRA). You have the right to know what personal information we collect and how it is used, to request deletion, to request correction, to receive a copy of it in a portable form, and to not be discriminated against for exercising these rights. You do not have to wait on us for the portable copy: Export vet report (PDF) on a pet's log page produces that pet's full history β profile, activities, reminders and weights β as a file you keep. Write to us for anything it does not cover. We do not sell or share personal information as those terms are defined by the CPRA, and we have not done so in the preceding 12 months. Submit requests to support@ostlerapp.com.
By statutory category, we collect:
| CPRA category | Collected | Examples in Ostler |
|---|---|---|
| Identifiers | Yes | Email address, account ID, IP address |
| Customer records | Yes | Hashed password, subscription status |
| Commercial information | Yes | Subscription plan and purchase status from Apple |
| Internet or network activity | Yes | Feature-usage events, random session identifier |
| Geolocation | Approximate only | Used for a single vet search; not stored |
| User content | Yes | Chat messages, photos, PDFs, pet notes and care logs |
| Sensitive personal information | No | We do not collect precise geolocation, government identifiers, or health data about people |
| Biometric, financial account, or education data | No | β |
Pet health information describes an animal, not a person. It is not protected health information under HIPAA, and HIPAA does not apply to Ostler. We treat it as confidential regardless.
Other US states. As of 2026, the states below have comprehensive consumer privacy laws in effect. Residents of these states have rights similar to the CPRA table above β to know and access, correct, delete, and opt out of the sale or sharing of personal information and of targeted advertising and certain profiling. We do not sell or share personal information and do not serve targeted advertising, so there is no sale/sharing/advertising opt-out to exercise for any state; the access, correction, and deletion rights above work the same way everywhere. Submit requests to support@ostlerapp.com.
| State | Law |
|---|---|
| Virginia | Virginia Consumer Data Protection Act (VCDPA) |
| Colorado | Colorado Privacy Act (CPA) |
| Connecticut | Connecticut Data Privacy Act (CTDPA) |
| Utah | Utah Consumer Privacy Act (UCPA) |
| Iowa | Iowa Consumer Data Protection Act (ICDPA) |
| Indiana | Indiana Consumer Data Protection Act (INCDPA) |
| Tennessee | Tennessee Information Protection Act (TIPA) |
| Montana | Montana Consumer Data Privacy Act (MTCDPA) |
| Oregon | Oregon Consumer Privacy Act (OCPA) |
| Texas | Texas Data Privacy and Security Act (TDPSA) |
| Delaware | Delaware Personal Data Privacy Act (DPDPA) |
| New Jersey | New Jersey Data Privacy Act (NJDPA) |
| New Hampshire | New Hampshire Privacy Act (NHPA) |
| Nebraska | Nebraska Data Privacy Act (NDPA) |
| Minnesota | Minnesota Consumer Data Privacy Act (MCDPA) |
| Maryland | Maryland Online Data Privacy Act (MODPA) |
| Kentucky | Kentucky Consumer Data Protection Act (KCDPA) |
| Rhode Island | Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) |
| Arkansas | Arkansas Consumer Data Privacy Act (ACDPA) |
This list changes as new state laws take effect β several more states have enacted similar laws that are not yet in force. Verify the current list and each law's effective date with counsel before relying on it.
Global Privacy Control. We do not sell or share personal information, so there is no opt-out to exercise. We honour a GPC signal where one is transmitted, and we do not track you across third-party sites or apps.
11. International transfers
We are established in Guatemala, and the providers listed in Section 7 are located in the United States, so your information is processed outside the country you use Ostler from. It is protected by this policy, and by our contracts with those providers, wherever it is processed β see Section 13.
12. Children
Ostler is not directed to children under 13 and we do not knowingly collect personal information from them. The app is not offered in the Kids Category. Users aged 13 to 17 may use Ostler only with the consent and involvement of a parent or legal guardian, who accepts the Terms of Service on their behalf and is responsible for any subscription purchased through the account.
How we check. On iOS, before an account is created or signed in to, Ostler asks the operating system for an age range using Apple’s Declared Age Range API. We ask about two thresholds only — 13 and 18 — so the most we can be told is which of three bands you fall into: under 13, 13 to 17, or adult. We do not receive your date of birth, and there is no way for us to request it. Alongside the band, Apple tells us how it was established (you declared it, a guardian declared it, or it was confirmed by some stronger method) and whether parental controls are active on the account.
What we do with each answer. If the answer is under 13, we refuse to create the account and nothing is sent to our servers. If it is 13 to 17, or adult, the account proceeds. You can decline to share your age range, your guardian can switch sharing off, and accounts created before iOS 26 have nothing to share — in all of those cases we are told nothing, and the account proceeds as normal. We do not treat an absent answer as a refusal, because it usually is not one.
What happens to the age signal. It is read on your device and used on your device. It is never transmitted to our servers, never written to our database, and never shared with any third party. It is held in the app’s memory for as long as the app is running and discarded when the app closes, and it is cleared when you sign out. There is nothing for us to delete on request because we never receive it.
We do not ask you to type a birthday. A birthday field would not establish anyone’s age either — it would only move the guess into our database and create a record about a minor where we currently hold none. Asking the operating system, and receiving a band rather than a date, collects strictly less about you.
Purchases are handled by Apple, not by us. Where an account belongs to a minor in a Family Sharing group, Apple’s own Ask to Buy sends the purchase to a parent or guardian for approval before any payment is taken.
If you are a parent or guardian and believe your child has given us information without your consent, contact support@ostlerapp.com and we will delete the account and its data.
13. Security
Passwords are stored salted and hashed; authentication tokens are stored in the device keychain; data is transmitted over TLS. No system is perfectly secure, and we cannot guarantee absolute security.
If a breach affects your personal information we will notify you, and the relevant regulators, as required by the law that applies to you. Every US state has a breach-notification law, and we follow the one for the state you live in.
14. Changes
We will post updates here and update the date above. Material changes will be notified in the app, and where the change affects AI processing you will be asked to review and accept the AI-use disclosure again.
15. Contact
Mario Noriega (trading as Ostler)
41 Avenida 15-49, Zona 5
Jardines de la AsunciΓ³n Sur
Guatemala City, Guatemala
support@ostlerapp.com