Skip to content

Privacy Policy

The short answer: as a guest, nothing you enter reaches us. With an account, only what's needed to sign you in and back up your records — never for ads, tracking, or anything else.

Last updated


Lukkie is built local-first: by default, your pets' records live on your own device and never touch our servers. This page explains the few cases where data does reach us, what we do with it, and what we never do.

We are the people who make Lukkie. You can reach us at hi@hellolukkie.app.

The short version

  • If you use Lukkie without an account (as a guest), we receive none of your pet data. It is stored in your browser or app on your device.
  • If you create an account, we store your email address so we can sign you in. If you sign in with Google, we also receive your name and a Google account identifier.
  • If cloud sync is on (it is whenever you're signed in), a copy of your pet records is stored in our database so it's backed up and available on your other devices. Only you can read it.
  • We do not run ads, analytics, tracking, or cookies for tracking. We do not sell, rent, or share your data. We do not look at your records.

What we collect, and why

Pet and household data you enter

Pets, health records, medications, supplies, reminders, routines, travel checklists, photos, weigh-ins, and the profile details you add (your name, and optionally your date of birth, gender, phone, and city).

  • As a guest: stored only on your device (in the browser's local database or the app's local storage). It is not sent to us.
  • Signed in: the same data is also copied to our database (hosted by Supabase) so you don't lose it and can see it on another device. Access is locked to your account — other users cannot read your rows, and we do not use this data for anything except giving it back to you.

You can export all of it at any time from the app's settings, and you can delete any of it from within the app.

Account information

  • Email + password sign-up: we store your email address. Your password is hashed by our authentication provider (Supabase) — we never see it.
  • Google sign-in: we receive your email address, your name, and a Google account ID from Google, used only to create and identify your account. Google's handling of your Google account is governed by Google's Privacy Policy.

We use this only to authenticate you and to associate your synced data with you.

Waitlist email

If you join the waitlist on this website, we store the email address you enter so we can tell you when Lukkie is ready. Reply to any message from us to be removed.

Basic technical logs

Our website and API are hosted by Netlify, and our database and authentication by Supabase. Like any web service, their servers keep short-lived request logs that can include your IP address, the time of the request, and your browser type, for security and reliability. We do not build profiles from these and do not combine them with your account.

What we do not do

  • No advertising, and no advertising or analytics trackers.
  • No cookies used for tracking. Your sign-in is kept in your browser's local storage, not in a tracking cookie.
  • No selling, renting, or trading your personal information.
  • No sharing your pet data or account data with third parties, except the infrastructure providers below who process it strictly to run the service.
  • No reading, mining, or training anything on your records.

Who processes data for us

ProviderWhat they handleWhere
NetlifyHosting this website and the app front-end; request logsCloud (AWS)
SupabaseDatabase (synced records + waitlist), account authenticationCloud (AWS)
GoogleOnly if you choose "Continue with Google" — sign-inGoogle

Each is contractually a data processor acting on our instructions. Their infrastructure runs on cloud data centres (Amazon Web Services) that may be located outside your country. If you need to know the current hosting region, email us.

How long we keep it

  • Local (on-device) data stays until you delete it, clear your browser's site data, or uninstall the app.
  • Synced data stays in our database until you delete your account. When you delete a record it is marked as deleted rather than erased immediately (this keeps sync consistent across your devices); deleting your account permanently removes your rows.
  • Waitlist emails are kept until launch or until you ask to be removed.

Your choices and rights

  • Use Lukkie without an account and keep everything on your device.
  • Export your data from the app whenever you want.
  • Delete your data — individual records from within the app; your whole account and its synced data by emailing us at hi@hellolukkie.app (self-serve account deletion is on the roadmap).
  • Access or correct the personal data we hold — email us.

Depending on where you live (for example the EU/EEA, UK, or California), you may have additional rights to access, correct, delete, or restrict processing of your personal data, and to lodge a complaint with your local data protection authority. Email us and we'll help.

Children

Lukkie is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect personal data from children. If you believe a child has given us personal data, email us and we will delete it.

Security

Traffic to our website and database is encrypted in transit (HTTPS). Synced data is isolated per account at the database level, and passwords are hashed by our authentication provider. No method of storage or transmission is completely secure, so we can't guarantee absolute security — keeping your own export as a backup is always a good idea.

Changes to this policy

If we change how we handle data, we'll update this page and the "last updated" date above. For material changes we'll also flag it in the app or by email where we can.


This document is written in good faith to describe how Lukkie actually works. It is not legal advice.

Questions about any of this? Email hi@hellolukkie.app.