Menagerie

Privacy policy

Last updated September 22, 2026

Who we are

Menagerie is a vet record and health journal operated by Nicholas Horton, an individual based in the State of Maryland, United States ("we", "us"). This policy explains what the app collects, where it goes, and what you can do about it. It is written to be read, not to be survived.

Questions or requests about your data? Email info@petandnote.com. You can also use Profile → Feedback in the app.

What you give us

Your account: a name, an email address, and either a password or a Sign in with Apple or Google identifier. That is what identifies your journal as yours.

Your notes: the visits, weights, vaccines, medications, symptoms, expenses and care diary entries you record for each pet, the reminders you set, and anything you write down.

Your Household: the pets you add and their profiles, the household members you invite, and the documents and photos you attach.

Your photos: the photos of your pets and of their paperwork (vaccine certificates, invoices and medication labels) you take or choose.

Your conversations with Warren: everything you type to the in-app guide and everything it says back, kept so you can reopen a conversation.

Your feedback: anything you send through the in-app contact, feedback and bug-report forms, including a bug report you choose to attach a chat transcript to.

Household sharing

Anything you record is visible to every other member of your household.

What we collect with your permission

Camera and photo library: only if you grant it, and only to take or choose the photos you attach to your pets and their records, or to scan a document.

AI sharing: before the app sends anything to an AI provider - a message to Warren, a document photo to be read, or context from your journal - it asks you first. Your answer is saved for your account on that device. You can decline and keep using the journal normally, or turn off new AI requests later in Profile → Account settings. Turning it off does not recall what was already sent; write to us if you want a deletion request passed on.

Sensitive information

Weight, medication, vaccine and symptom records are sensitive. They are not sold, not shared outside your household, and never used to train any model.

What leaves your device, and who gets it

Supabase hosts the database, the sign-in system and the photo storage behind this app. Your account, your pets, your notes and records, your reminders, your household, your documents, your chat history and your photos are all stored there, and every row is locked to your own account so that no other user can read it.

Your login is shared with our other apps, and that is the part worth reading twice. Menagerie does not have a Supabase project to itself: it shares one with the other apps we build. Inside that project, your identity - your email address, your name, and any Apple or Google sign-in you linked - sits in a shared area that all of those apps use, while everything about species sits in an area only this app uses. The practical upshot is that if you ever install another of our apps, you can sign in with this same account instead of making a second one.

Sharing a login is not the same as sharing your journal. Each app in the family keeps its own data in its own area, and Menagerie's screens only ever read Menagerie's. Joining an app is its own deliberate step, so being signed in does not enrol you in an app you have never opened. Pro and your AI credits are per app as well: Pro here does not unlock Pro anywhere else, and credits here cannot be spent anywhere else.

Anthropic provides Warren, the AI guide. When you ask Warren something, the text of your conversation and relevant context from your journal - the records you have kept for the pet you are asking about, such as visits, weights, vaccines, medications and your notes - are sent to Anthropic's API to produce the answer. Under Anthropic's commercial terms this data is not used to train their models.

Google Gemini reads document photos. When you scan a vaccine certificate, an invoice or a medication label, the photo you chose is uploaded to Google's Gemini API along with the instruction to pull the printed details off it - the clinic name, the medication or vaccine name, the dose as printed, and the next-due date as printed. Your photo of a document leaves your phone and is processed by a Google vision model. That is the plainest way we know to say it. Scan requests do not include your journal, your Household or your chat history, and the result always lands in a review screen for you to correct before anything is saved.

Web search. When you ask Warren about a specific medication or vaccine, it may search the web. Anthropic runs that search for us: a short query derived from your question goes to its search provider, and public pages are read to build the answer. Your journal, your photos and your account details are not part of the query, and the search provider does not learn who you are. Answers that used a search show the pages they relied on.

RevenueCat manages in-app purchases. It receives an app account identifier and your store purchase history (product and transaction) so the app knows whether Pro is active, can restore it, and can add the credits you bought. We keep a record of credits you bought and spent, per app. Apple or Google (whichever store you purchased through) handles the payment itself; Menagerie never sees your card details.

Apple and Google handle sign-in when you use Sign in with Apple or Sign in with Google. They tell us that the sign-in succeeded and give us an identifier and, unless you hide it, an email address. They do not receive your journal. If you use Apple's Hide My Email, we only ever see the relay address.

How we use all of this

To run the app: storing and syncing your journal and Household, drawing your stats and achievements, and producing Warren's answers.

To keep the service affordable: per-account counters limit how often the AI features can be called, which stops one account running up a bill for everyone.

To fix what breaks: the bug reports you send.

We do not sell your data. We do not show ads - not on the free tier, not ever. We do not track you across other apps or websites, and we do not build an advertising profile of you.

Keeping it, and deleting it

We keep your data for as long as your account exists.

You can delete your account in Profile → Account settings → Delete account. That removes everything this app holds about you: the pets you added and their records, your notes, reminders, expenses and documents, your household membership, your achievements, your conversations with Warren, your feedback, every photo you uploaded, your AI credits and their history, and your membership of Menagerie itself. It is a real deletion, not a flag on a row, and it cannot be undone.

Because the login is shared, deleting here does not always delete the login. If Menagerie is the only app of ours you use, the sign-in goes too - the email address, the password and any linked Apple or Google sign-in - and nothing of you is left with us. If you also use another of our apps, the login has to survive so that app keeps working, and it is deleted when you leave the last one. Either way, the species is gone the moment you confirm here.

One honest caveat: our processors keep their own backups and transaction records on their own schedules; we ask them to delete and they do, but a backup snapshot taken before you left may exist for a while. Write to us if you want us to chase a specific one.

Deleting your account forfeits any unused AI credits. It does not refund purchases.

No longer have the app installed? See Delete your account for how to ask by email instead.

Changes to this policy

If this policy changes in a way that matters, we will update the date at the top and tell you in the app before the change takes effect. Continued use is not how we will get your permission for a genuinely new use of your journal; we will ask separately for that.

Questions about this policy? Email info@petandnote.com.