Back to What Cat?

Privacy Policy

App: What Cat?  |  Last updated: May 13, 2026  |  Effective: May 10, 2026

This Privacy Policy explains how What Cat? ("we", "our", or "the app") collects, stores, and uses your information. We designed this app with privacy in mind: you can use most features without creating an account, and the cat data you enter stays on your device unless you choose to sign in.

This policy is written to comply with the Apple App Store Review Guidelines (including the App Privacy "Nutrition Label" disclosure requirements and Guideline 5.1.1(v) on account deletion), the Google Play Developer Program Policies (including the Data Safety section and User Data policy), the EU/UK General Data Protection Regulation (GDPR / UK GDPR), and the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA).

1. Who We Are

What Cat? is published by the What Cat? team ("we"). For the purposes of GDPR / UK GDPR we act as the data controller for the limited account data described below. We do not have a designated Data Protection Officer or EU/UK representative, as the volume and nature of personal data we process do not require one. You can reach us about any privacy matter at privacy@whatcat.app.

2. What We Collect and Why

2.1 Data stored only on your device (no account required)

On iOS and Android this data is stored in a local SQLite database and the operating system's secure local storage (Keychain on iOS, Keystore on Android). On the web it is stored in your browser's local storage. It is not transmitted to our servers unless you sign in and use a feature that requires it (see below). Uninstalling the app or clearing browser storage permanently deletes this data from your device.

2.2 Data stored in our cloud (only if you sign in)

Signing in is optional. If you choose to sign in with Apple or Google, the following is stored in our backend (Supabase, hosted in the United States):

Your cat profiles, health logs, favorites, quiz results, and Luna memories are not uploaded to our cloud. They remain on your device.

2.3 Data transmitted when using AI features (sign-in required)

Cat Chat and the Luna care companion require you to be signed in. When you send a message, the following is transmitted to our secure backend (a Supabase Edge Function) to generate a response:

Our backend performs security checks (topic filtering, emergency detection) before forwarding the relevant content to OpenAI to generate a response. OpenAI's use of this data is governed by OpenAI's API Privacy Policy; per OpenAI's API terms, content sent through the API is not used to train OpenAI's models. Cat Chat conversations are stored in your account (as described above) so they persist across your devices; Luna care companion conversations are not stored on our servers.

If you are not signed in, no data is transmitted to our backend or to OpenAI. The Luna companion may return a local canned response for a small set of common questions without any network call.

2.4 Data sent to Apple / Google for purchases

If you subscribe to What Cat? Premium, your purchase is processed by the App Store (Apple) or Google Play (Google). We receive a subscription status notification from RevenueCat (our subscription management platform) but we never see your payment card details. RevenueCat's privacy policy is available at revenuecat.com/privacy.

2.5 Device permissions

Some features ask for system permissions on your device:

Permissions are only requested when you use the relevant feature, and the data accessed stays on your device unless this policy says otherwise.

3. Data We Do Not Collect

4. App Store & Google Play Disclosure Summary

This section summarizes what we report on Apple's App Privacy "Nutrition Label" and Google Play's Data Safety form. The detailed treatment is in Section 2.

Data typeCollected?Linked to you?Used to track you?Purpose
Email addressOnly if you sign inYesNoAccount, customer support
Name (display name)Only if you sign inYesNoPersonalization in-app
Purchase history (subscription status)Only if you subscribeYesNoRestore Premium across devices
User content (Cat Chat messages)Only if you sign in & use Cat ChatYesNoProvide AI feature, history across devices
User content (cat profile excerpts sent for AI)Only when you send an AI messageYes (in transit)NoProvide AI feature
Identifiers (account user ID, push token)Only if you sign in / enable pushYesNoAuth, push delivery
Diagnostics, crash data, performance, location, contacts, browsing, advertising dataNo

Security practices: Data in transit is encrypted with HTTPS/TLS. Data at rest in our backend is encrypted by the cloud provider. You can request deletion of your data (Section 7).

5. How We Protect Your Data

No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.

6. Shared (Non-Personal) Data

To save cost and improve quality, the app caches AI-generated descriptions of common breed-mix combinations (e.g., "Maine Coon × Ragdoll") in a shared cloud table. These cache entries are not tied to any user and contain no personal data.

7. Data Retention and Account Deletion

Retention

Account Deletion (in-app and web)

Per Apple App Store Guideline 5.1.1(v) and the Google Play User Data policy, you can permanently delete your account and the associated cloud-stored data without leaving the app:

  1. Open Settings → Account → Delete account inside the app.
  2. Confirm the prompt. Your account, Cat Chat history, alert preferences, push tokens, AI usage counters, and subscription record in our backend are removed within 30 days.

If you cannot access the in-app option (for example, you've already uninstalled the app), email privacy@whatcat.app with the subject line "Delete my data" from the address associated with your account. We will process the request within 30 days and confirm completion.

Active subscriptions managed by Apple or Google are not cancelled by deleting your account. Cancel those in your App Store or Google Play subscription settings.

8. Your Rights and Choices

Everyone

Users in the EEA, UK, and Switzerland (GDPR / UK GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights regarding your personal data:

Lawful bases: We rely on (a) performance of a contract to provide the account, subscription, and AI features you ask for; (b) legitimate interests in keeping the service secure, preventing abuse, and improving quality; and (c) consent for optional permissions such as notifications.

To exercise any of these rights, email privacy@whatcat.app. We will respond within 30 days.

Users in California (CCPA / CPRA)

California residents have the right to know what personal information we collect, the right to delete it, the right to correct inaccurate information, and the right to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use personal information for cross-context behavioural advertising. To exercise these rights, email privacy@whatcat.app. We will not discriminate against you for exercising any of these rights.

International data transfers

Our backend is hosted in the United States. If you access the app from outside the United States, your account data is transferred to and processed in the United States. Where required, we rely on the European Commission's Standard Contractual Clauses or equivalent UK addenda for transfers from the EEA, UK, or Switzerland.

9. Children's Privacy

What Cat? is not directed at children under 13 (or under 16 in the EEA / UK, where applicable). We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact privacy@whatcat.app and we will delete it promptly. We comply with the United States Children's Online Privacy Protection Act (COPPA) and Apple's Kids Category requirements (which we do not opt into).

10. Third-Party Services

We share the minimum data necessary with the following processors / sub-processors. Each acts on our instructions and is bound by appropriate data-processing terms.

ServicePurposeData sharedPrivacy Policy
SupabaseAuthentication, cloud database, AI proxy, push fan-outAccount identity, subscription status, Cat Chat history, alert preferences, push token, AI promptssupabase.com/privacy
OpenAI (API)AI responses for Cat Chat & Luna companionSanitized prompt text; no account identifiersopenai.com/policies/privacy-policy
RevenueCatSubscription receipt validation & entitlement syncAnonymous user ID, App Store / Google Play subscription receiptsrevenuecat.com/privacy
Expo Application Services (EAS)Push notification deliveryDevice push token, notification payloadexpo.dev/privacy
AppleSign in with Apple, App Store payment processingAuthentication tokens, purchase receiptsapple.com/legal/privacy
GoogleSign in with Google, Google Play payment processingAuthentication tokens, purchase receiptspolicies.google.com/privacy
Wikimedia CommonsBreed photos fetched on demandStandard HTTP request metadata onlyfoundation.wikimedia.org/wiki/Privacy_policy
TheCatAPICurated breed photos & metadata (fetched server-side, never client-side)None — we cache the assets ourselvesthecatapi.com/privacy
ResendTransactional email delivery (waitlist verification, launch announcement)Recipient email address and message contentresend.com/legal/privacy-policy

11. Marketing Website (whatcat.app)

The What Cat? marketing website at whatcat.app is separate from the mobile app. It operates a pre-launch waitlist and does not use any analytics, telemetry, or advertising scripts.

Waitlist email collection

The website does not set tracking cookies, does not use third-party analytics, and does not load any advertising scripts.

12. Changes to This Policy

We may update this policy to reflect changes in the app or applicable law. When we do, we will revise the "Last updated" date at the top of this page and, for material changes, surface an in-app notice on next launch. Continued use of the app after changes are posted means you accept the updated policy.

13. Contact

Questions, data requests, or complaints: privacy@whatcat.app