Mokelta Privacy Policy

Version: 1.9 · Status: effective · Effective date: 15 August 2026 (Europe/Lisbon)

Document status: version 1.9 became effective on 15 August 2026 after technical reconciliation, review and authorised publication. It is a transparency update about the public adoption catalogue; it does not amend the Terms or require new consent.

This Privacy Policy explains how Mokelta collects, uses, stores, and protects personal data when you use the Mokelta app and its related Firebase services.

Data Controller: Tiago Jesus Email: info@mokelta.pt

1. Scope

This Policy covers two products operated by the same data controller:

It also covers the backend services supporting both (Firebase Authentication, Firestore, Cloud Storage, Cloud Functions, Firebase Hosting, Firebase Cloud Messaging (FCM), Firebase App Check, and Firebase Installations).

2. Data We Process

2.1 Pet owners

2.2 Professional Portal users

If you create a professional profile in the Portal, you are the data subject for the following:

2.3 Analytics and crash diagnostics in this version

Firebase Analytics is permanently disabled in this version. There is no opt-in or activation control in the app, and the reconciled Android candidate contains neither the Firebase Analytics plugin/engine nor the GMS Measurement engine. Mokelta does not emit product analytics events through this service in this version. The analytics categories, identifiers, events, and retention periods described in earlier versions do not apply to this candidate.

Firebase Crashlytics has been removed from this version; no crash reports are sent through that service. FCM and Firebase Installations remain for notification delivery and for the technical operation of the applicable Firebase services. They are not an analytics engine and do not demonstrate analytics event collection.

Any future telemetry, including analytics or crash reporting, requires a new review before its first activation: provider, data, purpose, legal basis, retention, access, recipients, and transfers must be reconciled in the ROPA, the Data Safety declaration, and a new version of this Policy. This Policy does not authorise a future activation.

3. How We Use Data (GDPR Legal Bases)

Purpose Data GDPR Basis
Account access and authentication Email, UID, profile basics Contract (Art. 6(1)(b))
Pet management and reminders Pet records, events, notes, settings Contract (Art. 6(1)(b))
Document and photo storage Uploaded files and metadata Contract (Art. 6(1)(b))
Push notifications and reminder delivery FCM token, Firebase Installations technical identifier, and app routing metadata Legitimate interests (Art. 6(1)(f)); consent/OS permission where required
Subscription entitlement verification Product ID, purchase token, subscription state Contract (Art. 6(1)(b)); legal obligations where applicable (Art. 6(1)(c))
Safe Walk weather and location-based recommendations City and/or latitude/longitude, weather responses Consent (Art. 6(1)(a)) for device location; contract (Art. 6(1)(b)) for the requested feature
Sharing an animal's record with people you invite (Care Circle / Professional Portal) The animal's record, the owner's name and email; phone only for a veterinarian with a verified profile; invitations and access log Contract (Art. 6(1)(b)) — the sharing exists only because you asked for it, and only while you keep it
Professional Portal profile Name, clinic, licence number, phone, and the record of acceptance of the Professional Terms Contract (Art. 6(1)(b)); record of contractual acceptance of the Professional Terms
Reviewing entries flagged by an owner Reason, the entry concerned, the named veterinarian, owner's email, and animal's name Legitimate interests (Art. 6(1)(f)) — record accuracy and complaint handling
Mokelta Assistant (conditional availability, AI-generated answers) Your question, up to six earlier conversation turns, the generated answer and — only after explicit approval for that conversation — the animal's name and species, approximate age/life stage and, when present, breed, weight, allergies, and chronic conditions Processed only while the service is operational and the user starts a conversation: contract (Art. 6(1)(b)) for the requested feature

4. Data Sharing and Processors

Mokelta uses trusted processors to operate the service:

Mokelta does not store your full payment card details. Card processing is handled by Google Play.

4.1 Sharing with veterinarians and caregivers (Professional Portal)

If you invite a veterinarian, caregiver, or anyone else into an animal's Care Circle, that person gains access to that animal's data. This happens only if and when you do it — never on our initiative.

In the professional Portal, the person you invite can:

Access is per animal, not per account: inviting someone for one animal does not give them access to your other animals.

You can revoke access at any time, in the app, under Caregivers. Revocation immediately blocks the animal's record and the issue of new document links. Every download checks current authorisation again and uses a temporary link, without a persistent download token, that is valid for up to 60 seconds. A link already issued may remain usable only until that short period ends. A copy the person has already downloaded is outside Mokelta's technical control and they must delete it when access ends. You can also see the date that person last opened the record.

A veterinarian who logs clinical information acts within their own professional duties and is bound by the Professional Terms, which they accept before gaining access, and by professional confidentiality.

4.2 Public adoption catalogue

If and when this feature is activated, Mokelta will make available a limited public projection of profiles that an eligible Association chooses to publish, to help people discover animals that are available or reserved. Mokelta hosts and displays that information, but does not decide adoptions, represent the Association, conclude adoption agreements, transfer ownership, or make SIAC registrations.

The public catalogue is live with a minimised, read-only projection. Publication, withdrawal, reporting and retention remain subject to the technical and operational controls described in this Policy.

5. Data Retention

6. Your Rights (GDPR)

You may request access, correction, deletion, restriction, objection, and data portability where applicable. You may withdraw consent for location at any time in your device/app settings.

You can delete your account in-app at Settings → Session → Delete account. If you use the Professional Portal, you can delete your professional profile under Settings inside the Portal itself.

Limit on erasure: the name of the veterinarian who logged a clinical entry forms part of the animal's health record and stays in the history even after that professional deletes their account. The basis for keeping it is the owner's legitimate interest in the integrity of their animal's record (Art. 6(1)(f)) — without the attribution they would no longer know who logged what. The animal's owner is who can remove those entries.

To request deletion or exercise your rights, email info@mokelta.pt with the subject "Mokelta Privacy Request".

7. Security Measures

8. Children's Privacy

Mokelta is not directed to children under 13. If you believe a child has provided personal data without appropriate authorisation, contact us so we can remove it.

9. International Transfers

Your account and animal data are hosted on Google Cloud/Firebase infrastructure. Application processing (Cloud Functions) runs in the European region europe-west1.

If the Mokelta Assistant is activated in a future release, Anthropic may process the approved data outside the European Economic Area, in the United States. That transfer will rely on the applicable contractual safeguards and will occur only when the feature is active and the user sends a question. Anthropic publishes its DPA incorporating Standard Contractual Clauses.

Other service providers may process data in regions outside your country. We rely on provider safeguards and contractual commitments where required.

10. Changes to This Policy

We may update this Policy when product or legal requirements change. The status, version and effective date above identify the applicable document. A material change requires renewed review, coordinated evidence and authorised publication.

11. Contact

Tiago Jesus
Email: info@mokelta.pt