LEGAL · UPDATED MARCH 2026

Privacy policy

How MiauMiau collects, processes, and protects your personal data. GDPR-compliant, EU-hosted, privacy-first.

1. Data Controller

MiauMiau is operated from the Netherlands. For the purposes of the General Data Protection Regulation (GDPR), MiauMiau acts as the data controller for all personal data processed through our application and website.

Contact: [email protected]

2. What Data We Collect

We collect only the data necessary to provide and improve our service:

Account Information

Email address and display name (provided during sign-up via email, Google, or Apple OAuth). We do not store passwords — authentication is handled via OAuth providers or magic links.

Cat Health Data

Cat profiles (name, breed, age, weight), health records (vaccinations, medications, vet visits), daily check-ins, feeding logs, AI health advisor conversations, and media you choose to upload (photos, videos, and audio notes). This data is stored solely to provide the service and is never sold.

Usage Analytics

We use Plausible Analytics, a privacy-friendly, cookie-free analytics tool. Plausible collects no personal data, uses no cookies, and is fully GDPR-compliant. We see aggregate page views and referral sources — nothing that identifies individual users. In the mobile app, optional crash, performance, and masked session diagnostics are collected only if you enable Analytics & Improvements.

Food Search Queries

Search terms entered in our cat food database are logged anonymously to improve search relevance and product coverage. These queries are not linked to user accounts.

3. How We Process Your Data

Core account, cat, and health records are processed on servers located within the European Union. Our primary infrastructure is hosted on Hetzner Cloud in Germany. Selected third-party providers may process limited data outside the European Economic Area when needed for authentication, subscriptions, diagnostics, storage, email, or AI features; those transfers are covered by appropriate contractual and security safeguards.

Data is encrypted in transit (TLS 1.3) and at rest. Photo metadata (EXIF data including location) is stripped upon upload.

4. Third-Party Services

We work with a minimal number of carefully selected third-party providers:

Plausible Analytics

Privacy-friendly website analytics

No personal data collected. Cookie-free. EU-hosted.

Resend

Transactional email delivery

Email address only, for sending account-related emails (verification, password reset).

Google OAuth / Apple Sign In

Authentication

We receive your name and email from the OAuth provider. We do not access any other account data.

RevenueCat

Subscription management

App user ID, product identifiers, entitlement status, and purchase status. Payment card details stay with the app stores.

Cloudflare R2

Private media storage

Photos, videos, and audio notes you upload, stored under user-scoped object keys.

Sentry

Optional crash and performance diagnostics

Device, app, error, performance, and masked session diagnostic data when Analytics & Improvements is enabled.

OpenRouter / AI model providers and Google Gemini

AI advisor, scan analysis, and embeddings

Prompts, cat context, uploaded media, and generated responses when you request AI-powered features.

5. Data Retention

Account data (profile, cat health records, AI conversations) is retained for as long as your account is active. When you request account deletion, all personal data is permanently erased within 30 days.

Analytics data is anonymized and aggregated — it cannot be traced back to individual users at any point.

6. Your Rights Under GDPR

As a data subject, you have the following rights:

  • Right of AccessRequest a copy of all personal data we hold about you.
  • Right to RectificationRequest correction of inaccurate or incomplete data.
  • Right to ErasureRequest deletion of your personal data ("right to be forgotten").
  • Right to Data PortabilityReceive your data in a structured, machine-readable format.
  • Right to RestrictionRequest limitation of processing in certain circumstances.
  • Right to ObjectObject to processing based on legitimate interests.

To exercise any of these rights, email [email protected] or use the data management options in the app settings. We will respond within 30 days.

7. Cookies

MiauMiau does not use tracking cookies. We use Plausible Analytics, which is entirely cookie-free. The only cookies we set are strictly necessary session cookies for authentication when you are logged in. No consent banner is required because we do not track you.

8. Children's Privacy

MiauMiau is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

9. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of significant changes via email or an in-app notification. The "last updated" date at the top reflects the most recent revision.

10. Contact

For any privacy-related questions or concerns, contact us at [email protected].

If you are unsatisfied with our response, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.