Tamo Privacy Policy
Effective: August 30, 2026
Developer: Stella Lu (individual developer)
Contact: tamo_amorce@protonmail.com
Tamo (the “App”) is a cat health record and triage-support tool for cat owners. This policy explains what the App collects, how it uses and transfers data, how long data is kept, and how you can access, correct, or delete it.
1. Information we collect
We collect the following only when you provide it, use the relevant feature, or authorize notifications:
- Account and consent records: email address, the account ID assigned by Supabase, and the legal-policy version and timestamp accepted at registration. Email is used for registration, login, verification codes, and password recovery.
- Cat profile and health records: cat name, photo, breed, age, sex, weight, environment, daily observations, normal baseline, symptoms and courses, preventive care, medical history, tasks, medication courses and adherence, plus generated baselines, current assessments, and vet reports.
- Chat content: your messages to Tamo, Tamo’s replies, and structured results created to maintain context, extract records, and generate guidance. Your chat may contain cat-health information you choose to provide.
- Photos and files: cat photos you select from the library or take with the camera, and saved vet-report PDFs. The App does not scan your whole photo library. Photos are not currently sent to DeepSeek for image analysis.
- Push identifiers and preferences: after you allow notifications, an Expo Push Token, notification settings, delivery type, and delivery logs. The token is linked to your account and is used for evening greetings or important health reminders. Lock-screen copy does not include specific symptoms or diagnostic speculation.
- Necessary technical information: Supabase, Expo Push, Apple Push Notification service (APNs), and DeepSeek may process request time, IP address, network or device information, and service logs to deliver, secure, and troubleshoot their services, under their own policies. The App includes no advertising, cross-app tracking, or third-party analytics SDK.
The App does not intentionally collect precise location, contacts, advertising identifiers, payment information, or human HealthKit data.
2. How we use information
We use information only to create and secure accounts; store multi-cat, daily, medication, reminder, and historical records; run deterministic anomaly screening and AI-assisted triage, extraction, and explanations; create vet reports you choose whether to share; send authorized notifications; secure and troubleshoot the service; respond to support; and meet legal obligations.
We do not sell personal data, use it for third-party advertising, or use it to track you across apps or websites.
3. Limits of rules and AI
The rule engine checks recorded fields against predefined discrete rules. AI uses the profile, recent records, and chat context you provide to generate explanations and triage guidance. Both can be wrong because of incomplete or incorrect inputs and model limitations.
Tamo does not provide a veterinary diagnosis, write prescriptions, or provide specific drug names, dosages, frequencies, or treatment courses. It does not replace an in-person veterinary examination. If your cat has severe or emergency symptoms, contact a veterinarian or emergency clinic immediately and do not wait for the App.
4. Recipients and international processing
| Recipient | Data received | Purpose and location |
|---|---|---|
| Supabase | Email and account ID, cat profile and health records, chat, photo/report files, push token and preferences | Authentication, PostgreSQL database, private object storage, and Edge Functions. The current production project is hosted in Frankfurt, Germany (AWS eu-central-1). |
| DeepSeek | Prompt text needed for an AI task, which may include chat excerpts, cat profile, health records, and medication information; email and photo files are not sent | Inference through our llm-proxy hosted on Supabase. DeepSeek processes data in mainland China. Its published policy says inputs may be used to improve/train its technology and provides a right to opt out of training use by contacting privacy@deepseek.com. |
| Expo Push Service | Expo Push Token, generic notification title/body, and a pet-record ID needed for routing | Passing remote notifications to APNs. Expo states notification content is held only in delivery memory/queues and not stored in its databases. |
| Apple / APNs | Apple device push token and notification payload | Delivery to your iPhone under Apple’s privacy policy. |
Data may therefore be processed outside your country or region. Each provider is governed by its contract, privacy terms, and applicable law.
5. Retention and deletion
- Account, cat, health, chat, photo, report, and server-side push data are generally kept until you delete the account or they are no longer needed for the purposes in this policy.
- Local reminder settings and caches are kept on the device. You can clear them by disabling notifications, signing out, deleting the App, or deleting your account; some iOS system data is managed by iOS.
- In the App, go to Settings → Delete account, enter the confirmation text, and complete deletion. Account-linked data is then removed from Supabase’s active database and private storage. This cannot be undone.
- Limited copies may remain temporarily in provider security backups, anti-abuse logs, or legally required records and are later deleted or anonymized under provider retention processes.
- The App cannot instantly recall requests already sent to DeepSeek. DeepSeek handles retention, deletion, and training opt-out requests under its policy and applicable law.
6. Your choices and rights
- View and correct your cat profile and most health records in the App.
- Separately disable routine greetings and important health reminders under Settings → Push notifications, or revoke notification permission in iOS Settings.
- Stop using Tamo chat to stop new content being sent to DeepSeek.
- Delete your account and associated data under Settings → Delete account.
- Email us to request access, correction, export, or deletion, or to exercise rights available under applicable law.
See Privacy choices and data deletion.
7. Security
Data is sent over HTTPS. Photos and reports are stored in private buckets and accessed through short-lived signed links. Database row-level access controls are enabled. No method of transmission or storage is completely secure.
8. Children
The App is not directed to children under 13 and we do not knowingly collect their personal information. Contact us if you believe a child has provided personal information.
9. Changes
If our practices change materially, we will update the effective date and provide an in-App notice where appropriate. We will request new consent when a new use requires it.
10. Contact
For privacy questions or rights requests, email tamo_amorce@protonmail.com.