Mokelta Privacy Policy
Version: 1.9 · Status: effective · Effective date: 15 August 2026 (Europe/Lisbon)
Document status: version 1.9 became effective on 15 August 2026 after technical reconciliation, review and authorised publication. It is a transparency update about the public adoption catalogue; it does not amend the Terms or require new consent.
This Privacy Policy explains how Mokelta collects, uses, stores, and protects personal data when you use the Mokelta app and its related Firebase services.
Data Controller: Tiago Jesus Email: info@mokelta.pt
1. Scope
This Policy covers two products operated by the same data controller:
- the Mokelta app (Android), used by pet owners;
- the Mokelta Professional Portal (vet.mokelta.pt), a web application used by veterinarians and other professionals invited by an owner.
It also covers the backend services supporting both (Firebase Authentication, Firestore, Cloud Storage, Cloud Functions, Firebase Hosting, Firebase Cloud Messaging (FCM), Firebase App Check, and Firebase Installations).
2. Data We Process
2.1 Pet owners
- Account data: email, Firebase UID, and profile fields such as name and phone number (optional — only if you fill it in).
- Pet profile data: name, species, breed, sex, birth date, weight and weight history, notes, and profile photo URL.
- Electronic identification (microchip) number: if you fill it in. It is the only identifier in the record that corresponds to an official registry outside Mokelta, and so can link the animal — and indirectly its owner — to the national register. It is visible to anyone you invite and is printed on the health passport PDF you export.
- Animal health data: allergies, chronic conditions, medication, health events (vaccinations, deworming, visits), structured veterinary consultations (reason, diagnosis, treatment, follow-up), health plan, and feeding plan.
- Optional dictation: when you tap the microphone, speech recognition is requested from the operating system in on-device-only mode. Audio is not sent to or stored by Mokelta. Only text you choose to save becomes part of the animal note or visit; if the offline language is unavailable, dictation fails without falling back to cloud recognition.
- Assisted features: Symptom Check is retired from this release, while historical records remain available for export and deletion. Mokelta Assistant processes data only while the service is operational, the user starts a conversation, and explicitly approves the displayed context.
- Pet documents: uploaded files/photos and metadata (file name, type, upload date, optional notes).
- Care Circle: invitations you send (invitee email, animal, role), granted access, and the date each person last opened the record.
- Flagged entries: when you report an entry logged by a veterinarian — the reason, the entry, the veterinarian concerned, your email, and the animal's name.
- Technical installation and notification data: the technical installation identifier managed by Firebase Installations, FCM token, token update timestamp, language, and app routing metadata. This data supports the applicable Firebase services and notification delivery; it is not product analytics event data.
- Subscription data: Google Play product ID, tier, expiry, trial status, and audit events.
- Location data (optional feature): city name and/or latitude/longitude only when you use Safe Walk location features.
2.2 Professional Portal users
If you create a professional profile in the Portal, you are the data subject for the following:
- Professional profile: name, clinic, professional licence number, and optional phone. Details are self-declared; Mokelta review may control access but is not an automatic OMV lookup, endorsement, or guarantee. The Portal is read-only in this release.
- Account data: email and Firebase UID.
- Record of acceptance of the Professional Terms: version, date, and language.
- Historical authorship: entries created in earlier releases may retain the professional name for integrity and data rights; this read-only release creates no new professional entries.
- Access log: the date you last opened each animal's record, visible to that animal's owner.
- Historical flags: complaints linked to professional entries from earlier releases are processed only for integrity, response, and data-rights purposes under the applicable retention rules.
2.3 Analytics and crash diagnostics in this version
Firebase Analytics is permanently disabled in this version. There is no opt-in or activation control in the app, and the reconciled Android candidate contains neither the Firebase Analytics plugin/engine nor the GMS Measurement engine. Mokelta does not emit product analytics events through this service in this version. The analytics categories, identifiers, events, and retention periods described in earlier versions do not apply to this candidate.
Firebase Crashlytics has been removed from this version; no crash reports are sent through that service. FCM and Firebase Installations remain for notification delivery and for the technical operation of the applicable Firebase services. They are not an analytics engine and do not demonstrate analytics event collection.
Any future telemetry, including analytics or crash reporting, requires a new review before its first activation: provider, data, purpose, legal basis, retention, access, recipients, and transfers must be reconciled in the ROPA, the Data Safety declaration, and a new version of this Policy. This Policy does not authorise a future activation.
3. How We Use Data (GDPR Legal Bases)
| Purpose | Data | GDPR Basis |
|---|---|---|
| Account access and authentication | Email, UID, profile basics | Contract (Art. 6(1)(b)) |
| Pet management and reminders | Pet records, events, notes, settings | Contract (Art. 6(1)(b)) |
| Document and photo storage | Uploaded files and metadata | Contract (Art. 6(1)(b)) |
| Push notifications and reminder delivery | FCM token, Firebase Installations technical identifier, and app routing metadata | Legitimate interests (Art. 6(1)(f)); consent/OS permission where required |
| Subscription entitlement verification | Product ID, purchase token, subscription state | Contract (Art. 6(1)(b)); legal obligations where applicable (Art. 6(1)(c)) |
| Safe Walk weather and location-based recommendations | City and/or latitude/longitude, weather responses | Consent (Art. 6(1)(a)) for device location; contract (Art. 6(1)(b)) for the requested feature |
| Sharing an animal's record with people you invite (Care Circle / Professional Portal) | The animal's record, the owner's name and email; phone only for a veterinarian with a verified profile; invitations and access log | Contract (Art. 6(1)(b)) — the sharing exists only because you asked for it, and only while you keep it |
| Professional Portal profile | Name, clinic, licence number, phone, and the record of acceptance of the Professional Terms | Contract (Art. 6(1)(b)); record of contractual acceptance of the Professional Terms |
| Reviewing entries flagged by an owner | Reason, the entry concerned, the named veterinarian, owner's email, and animal's name | Legitimate interests (Art. 6(1)(f)) — record accuracy and complaint handling |
| Mokelta Assistant (conditional availability, AI-generated answers) | Your question, up to six earlier conversation turns, the generated answer and — only after explicit approval for that conversation — the animal's name and species, approximate age/life stage and, when present, breed, weight, allergies, and chronic conditions | Processed only while the service is operational and the user starts a conversation: contract (Art. 6(1)(b)) for the requested feature |
4. Data Sharing and Processors
Mokelta uses trusted processors to operate the service:
- Google Firebase: Authentication, Firestore, Cloud Storage, Cloud Functions, Hosting, Cloud Messaging (FCM), App Check, and Firebase Installations. Firebase Analytics is permanently disabled and Crashlytics has been removed in this version.
- Google Play Billing: subscription purchase, renewal, cancellation, and payment processing.
- Google Weather/Geocoding APIs: Safe Walk weather forecast and location search.
- Anthropic (Claude): processor for Mokelta Assistant only while the service is operational. Each conversation requires explicit approval of the context: the question, up to six earlier turns, and the minimum animal fields listed in section 3. We do not send the owner's name/email, exact birth date, microchip, notes, photos, or documents. The conversation remains in memory during use and Mokelta's backend does not write it to Firestore. Provider retention must be validated against the agreement in force before GO.
Mokelta does not store your full payment card details. Card processing is handled by Google Play.
4.1 Sharing with veterinarians and caregivers (Professional Portal)
If you invite a veterinarian, caregiver, or anyone else into an animal's Care Circle, that person gains access to that animal's data. This happens only if and when you do it — never on our initiative.
In the professional Portal, the person you invite can:
- View in read-only mode the record of the animal named in the invitation, including identification, health, visits, documents, notes, plans, and existing history.
- See your name and email to contact you about the animal; optional phone access follows the applicable role and authorisation.
- They cannot create, change, or delete clinical information, care logs, or documents in this release.
Access is per animal, not per account: inviting someone for one animal does not give them access to your other animals.
You can revoke access at any time, in the app, under Caregivers. Revocation immediately blocks the animal's record and the issue of new document links. Every download checks current authorisation again and uses a temporary link, without a persistent download token, that is valid for up to 60 seconds. A link already issued may remain usable only until that short period ends. A copy the person has already downloaded is outside Mokelta's technical control and they must delete it when access ends. You can also see the date that person last opened the record.
A veterinarian who logs clinical information acts within their own professional duties and is bound by the Professional Terms, which they accept before gaining access, and by professional confidentiality.
4.2 Public adoption catalogue
If and when this feature is activated, Mokelta will make available a limited public projection of profiles that an eligible Association chooses to publish, to help people discover animals that are available or reserved. Mokelta hosts and displays that information, but does not decide adoptions, represent the Association, conclude adoption agreements, transfer ownership, or make SIAC registrations.
- Purpose: perform the Association's publication instruction, display limited public information, maintain profile status, protect the catalogue against abuse, and enable notice and removal of inaccurate, unauthorised, or illegal content.
- Legal bases: performance of the terms requested by the Association and its representative (GDPR Article 6(1)(b)); the legitimate interests of Mokelta, Associations, and the public in catalogue integrity, security, fraud prevention, moderation, notice, and removal (Article 6(1)(f)), balanced against affected rights; and compliance with a legal obligation only where a specific obligation applies (Article 6(1)(c)). We do not use generic consent as the basis for this activity.
- Public V1 information: a random public profile identifier, available or reserved status, the animal's public name, species, sex, optional breed or mix, approximate age band, and publication and update dates. Additional structured fields require prior review and documentation.
- Information excluded from V1: photographs, personal or Association contact details, internal identifiers, UIDs, microchip or SIAC numbers, addresses or coordinates, owner or adopter identity, exact birth date, clinical information, vaccinations, medication, appointments, documents, billing, private notes, free links, and unmoderated free text.
- Pseudonymisation: the projection is minimised and pseudonymised, not anonymised. Mokelta keeps the internal link to the Association and animal needed to update or remove the profile, but the public API must not return those internal keys.
- Recipients: public fields may be viewed by any catalogue visitor and processed by the technical providers described in this Policy. V1 does not send adoption enquiries or visitor data to the Association.
- Association responsibility: the Association must have authority to care for and publicise the animal, hold the necessary content rights, provide accurate and current information, avoid prohibited personal or clinical data, and immediately update or remove the profile when its status changes.
- Removal: the profile ceases to be public when the animal is adopted or unavailable, or when the Association is no longer eligible or requests removal. The public projection is deleted in the withdrawal flow and catalogue responses are not cached. Any withdrawal failure suspends the listing and is handled as an operational incident.
- Notice and reporting: the channel for reporting inaccurate, unauthorised, or illegal information is info@mokelta.pt. Mokelta may request only the minimum details needed, restrict or remove the profile as a precaution, and communicate the decision where applicable. The operational record has restricted access and follows the periods in section 5.
- Rights: the rights in section 6 also apply to any personal data linked to this activity. An objection to processing based on legitimate interests will be assessed under GDPR Article 21.
The public catalogue is live with a minimised, read-only projection. Publication, withdrawal, reporting and retention remain subject to the technical and operational controls described in this Policy.
5. Data Retention
- Account, pets, events, notes, settings, and document metadata: kept while your account is active, or until deletion is requested.
- Public adoption catalogue: the public projection is removed immediately when a listing is withdrawn, suspended or no longer eligible. The private mapping between the public identifier, Association and animal is deleted within 30 days, unless an open report, legal obligation or documented need to establish or defend legal claims requires longer retention.
- Catalogue reports: the minimised record is retained for up to 12 months after closure, with access restricted to GM-00 and LEG-00, unless a legal obligation or dispute justifies additional documented retention.
- Flagged entries: if you report an entry logged by a veterinarian, we keep a copy of what you reported (reason, the entry concerned, the veterinarian, your email, and the animal's name) so we can review it. It is deleted when you delete your account.
- Data shared with caregivers: when you delete your account we also delete the records identifying you in the accounts of people you shared animals with (name, email, animal name), revoke that access, and delete pending or never-claimed invitations containing your email. Clinical entries a veterinarian logged in the animal's history are deleted along with the animal.
- Professional profile (Professional Portal): kept while the profile exists. The professional can delete it at any time in the Portal's Settings; deleting their account deletes it too. Clinical entries they already logged remain in the animal's history, with their name — the animal's owner is who can remove them.
- Uploaded files in Cloud Storage: kept while linked records exist, or until deleted by user/request.
- FCM token: updated regularly and removed on logout where possible. The Firebase Installation ID used by FCM is retained by the provider until Mokelta requests deletion through the applicable API; the provider states that associated data is removed from live and backup systems within 180 days after that request and that inactive identifiers may be deleted or rotated after 270 days of inactivity. These technical periods follow the provider's documentation and may be updated by the provider.
- Subscription audit records: retained for fraud prevention, compliance, and support for a limited business-necessary period.
- Safe Walk weather cache in backend: short-term cache (target TTL around 45 minutes).
- Firebase Analytics and Crashlytics: there is no new collection through these services in this version. Historical data from earlier versions, if any, remains subject to the provider's controls and retention periods and to applicable data-subject requests; Mokelta does not use it for new product analytics in this version.
6. Your Rights (GDPR)
You may request access, correction, deletion, restriction, objection, and data portability where applicable. You may withdraw consent for location at any time in your device/app settings.
You can delete your account in-app at Settings → Session → Delete account. If you use the Professional Portal, you can delete your professional profile under Settings inside the Portal itself.
Limit on erasure: the name of the veterinarian who logged a clinical entry forms part of the animal's health record and stays in the history even after that professional deletes their account. The basis for keeping it is the owner's legitimate interest in the integrity of their animal's record (Art. 6(1)(f)) — without the attribution they would no longer know who logged what. The animal's owner is who can remove those entries.
To request deletion or exercise your rights, email info@mokelta.pt with the subject "Mokelta Privacy Request".
7. Security Measures
- Firebase Authentication for access control.
- Firestore and Storage security rules scoped by authenticated user ownership.
- App Check and token-based backend access controls for protected endpoints.
- Transport encryption (HTTPS/TLS) for network communication.
8. Children's Privacy
Mokelta is not directed to children under 13. If you believe a child has provided personal data without appropriate authorisation, contact us so we can remove it.
9. International Transfers
Your account and animal data are hosted on Google Cloud/Firebase
infrastructure. Application processing (Cloud Functions) runs in the
European region europe-west1.
If the Mokelta Assistant is activated in a future release, Anthropic may process the approved data outside the European Economic Area, in the United States. That transfer will rely on the applicable contractual safeguards and will occur only when the feature is active and the user sends a question. Anthropic publishes its DPA incorporating Standard Contractual Clauses.
Other service providers may process data in regions outside your country. We rely on provider safeguards and contractual commitments where required.
10. Changes to This Policy
We may update this Policy when product or legal requirements change. The status, version and effective date above identify the applicable document. A material change requires renewed review, coordinated evidence and authorised publication.
11. Contact
Tiago Jesus
Email: info@mokelta.pt