1. Who we are
Kona is provided by TIC Group ("we", "us", "our"), based in Ireland. When we talk about "the app" we mean the Kona iPhone and Android apps and the marketing website at kona.pet.
For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, we are the data controller for the information you provide when using Kona.
Contact for privacy matters: hello@kona.pet.
2. What we collect
2.1 Account information
- Email address — so you can sign in and we can send you invites, notifications and support replies.
- Optional profile info you choose to add: name, country, currency preference, language.
- Password — stored only as a one-way hash by our authentication provider (Supabase Auth). We never see or store your plain-text password.
2.2 Pet information you put in
- Pets' identity data (name, species, breed, sex, date of birth, colour, microchip number, photo).
- Health records, vaccinations, medications, supplements, weight history, allergies, conditions, insurance details and any other fields you choose to fill in.
- Uploaded documents, images, and audio recordings of consultations, along with the transcript and summary derived from them.
- Reminders, notes and consultation entries you create.
- Services / vet practices / contact people you add to your service list.
- Any data you receive from another user who has shared a pet with you (they remain the primary controller for that data).
2.3 Technical / diagnostic data
- Device model, operating system version, app version and language — used to reproduce bugs.
- Anonymous product analytics events (screen views, feature usage) that let us see which parts of the app people use.
- Crash reports (via Sentry) — automatic, anonymised where possible.
We do not collect location data, contacts, or browsing history outside the app.
2.4 Cookies & the website
The marketing website (kona.pet) uses only strictly-necessary cookies for basic functionality. We do not use analytics cookies, advertising cookies, or third-party trackers on the site. Because we don't use non-essential cookies, no consent banner is required under ePrivacy / PECR / EU cookie law.
3. Why we collect it (legal bases)
Under GDPR and UK GDPR, we rely on the following legal bases:
- Contract — to provide the Kona service you've signed up for (account, records, sync, sharing, notifications).
- Legitimate interests — to keep the app secure (fraud detection, crash reporting), improve reliability (anonymised diagnostics), and communicate essential service updates. We balance these against your rights; you can object at any time.
- Consent — where you opt in specifically (for example, to receive push notifications, or to enable microphone access for recording consultations). You can withdraw consent at any time via your device settings or in-app.
- Legal obligation — where we must retain or disclose data to comply with a law we're subject to.
4. Who we share it with
We do not sell your personal data. We do not share it for advertising. We share only with the processors we need to run the service:
- Supabase (Frankfurt, EU) — database and authentication.
- Vercel — serverless functions that back the app (invite emails, bug reports, document analysis routing).
- Anthropic (Claude API) — for AI features like consultation summaries and Ask Kona. Requests are made per-query; content is not used by Anthropic to train models per their commercial terms.
- Deepgram — speech-to-text for consultation recordings.
- Resend — transactional email delivery (invites, welcome emails, replies).
- Sentry — crash reporting.
- Expo / EAS — over-the-air update delivery and build infrastructure.
- Apple / Google — the App Store and Google Play, for app distribution and platform-level analytics you can opt out of in your device settings.
- Other Kona users you explicitly invite — when you share a pet, the invitee gets exactly the access level you granted (Co-Owner or View only) and only to that pet.
- Law enforcement or regulators — only where we're legally required to disclose data, and only what's required.
Each of the third parties above is bound by a data processing agreement with us and processes personal data only on our instructions.
5. Where it's stored
Your data is stored primarily in the European Union (Supabase EU region, Frankfurt). Some processors above operate globally. Where transfers outside the EEA / UK are necessary (e.g. Anthropic in the US), we rely on the European Commission's Standard Contractual Clauses (SCCs) and equivalent UK safeguards, along with additional technical measures where appropriate.
6. How long we keep it
- Account data — while your account exists, plus a short backup retention window (up to 30 days) after deletion.
- Pet data you add — same as above; when you delete your account, we delete the associated pet records from active systems.
- Diagnostic logs, crash reports, analytics — retained for up to 90 days.
- Legal / accounting records — retained only where the law requires (e.g. tax records, subject-request logs).
7. Your rights (EU / UK / Ireland)
Under GDPR and UK GDPR, you have the right to:
- Access — get a copy of the personal data we hold about you.
- Rectification — correct data that's inaccurate.
- Erasure ("right to be forgotten") — ask us to delete your data.
- Restriction of processing — pause our processing while a query is resolved.
- Data portability — receive your data in a portable format. You can also export any pet's health summary as a PDF from inside the app at any time.
- Object to processing — including to processing based on legitimate interests.
- Withdraw consent — for any processing based on consent, without affecting the lawfulness of what came before.
- Lodge a complaint with a supervisory authority. In Ireland: the Data Protection Commission (DPC). In the UK: the Information Commissioner's Office (ICO). In any other EU / EEA country: your local supervisory authority.
To exercise any of these rights, email hello@kona.pet. We'll respond within 30 days.
8. Your rights (California / other US states)
Under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents have the right to:
- Know what personal information we collect, use and disclose about you.
- Request deletion of your personal information.
- Correct inaccurate personal information.
- Opt out of the "sale" or "sharing" of personal information for cross-context behavioural advertising — we do neither, so there's nothing to opt out of.
- Limit use of sensitive personal information (health-related information) — again, we only use it to provide the service you asked for.
- Non-discrimination for exercising any of these rights.
Similar rights exist under Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA) and other US state privacy laws. If you're covered by one of them and want to exercise your rights, the process is the same: email hello@kona.pet.
9. Your rights (rest of world)
Regardless of where you live, we give every Kona user the same core set of rights: access, correction, export, and deletion of your data. Email hello@kona.pet and we'll help.
Local laws that give you additional rights (e.g. Brazil's LGPD, Canada's PIPEDA, South Africa's POPIA, Australia's Privacy Act, Japan's APPI) apply to you as well and we will honour them.
10. Children
Kona is not designed for children. You must be at least 16 years old (or the local minimum age of consent for online services, whichever is higher) to create an account. We do not knowingly collect personal data from children under that age. If you believe a child has created an account, contact us at hello@kona.pet and we'll delete it promptly.
11. Security
- Data is encrypted in transit (HTTPS/TLS) and at rest (AES-256 on Supabase-managed volumes).
- Row-level security (RLS) means every request the app makes can only access rows belonging to the signed-in user (or a pet they've been explicitly invited to).
- Passwords are stored as one-way hashes and never in plain text.
- Access to production systems is restricted, logged, and requires multi-factor authentication.
- If a breach affects your personal data, we will notify you and (where required) the relevant supervisory authority within 72 hours, as required by GDPR Article 33.
12. Changes to this policy
If we make substantive changes to this policy, we'll tell you in the app and update the "Last updated" date above. For material changes (like adding a new category of data or a new processor), we'll notify you before the change takes effect and give you a chance to review it.
13. Contact & complaints
Every question about this policy — including subject rights requests, GDPR / CCPA / other privacy law questions, and complaints — goes to:
A human on the Kona team will reply within a week, usually much sooner. If we haven't resolved your concern to your satisfaction, you're entitled to lodge a complaint with your local data protection authority — see the EU / UK rights section for links.